Risk-based approach · Core concept
The AI Act's risk categories
One idea organises the whole regulation: match the strictness of the rules to the risk of the use. This page walks through the levels and shows how each one appears in the game's cases.
01Why risk, and not technology
A face-recognition library can unlock your phone or scan a public square; a scoring model can rank loan offers or rank citizens. Regulating "the algorithm" would either ban too much or too little. The Act therefore regulates uses in context: purpose, data, affected people, consequences.
For learners this is the single most transferable idea — and the reason the game asks you to read a dossier before classifying anything.
02The four levels at a glance
Unacceptable risk
Practices considered incompatible with fundamental rights — e.g. generalized social scoring. Prohibited outright.
High risk
Allowed, but with risk management, quality data, documentation and effective human oversight.
Transparency
Situations where people must know AI is involved: chatbots, synthetic content, deepfakes.
Minimal risk
Most applications — spam filters, game AI, recommendations — face no specific new obligations.
03Unacceptable risk: the red lines
The prohibited practices are few and specific. What makes them teachable is their logic: harms so structural that no amount of oversight fixes them. The detailed page — with the classic boundary cases — is prohibited AI practices.
04High risk: allowed, but earned
Education, employment, essential services, health: here AI can help or quietly decide people's lives. The Act's answer is obligations, not bans — explored on high-risk AI systems.
Many high-risk systems also process personal data, and then the obligations add up. See the AI Act and the GDPR.
05Transparency situations
Sometimes the risk is simply not knowing: mistaking a bot for a person, a synthetic image for a photo. The remedy is disclosure — see transparency obligations.
06Minimal risk — and why it matters didactically
Most AI is fine. Teaching this prevents the two classic failure modes: "everything is banned" alarmism and "nothing changes" complacency. A good exercise is sorting mundane examples (spellcheck, playlist ranking) to establish the baseline before the hard cases.
07The categories in the game
The game's 13 cases deliberately span the ladder: clear prohibitions (the city of scores), high-risk systems (triage, recruitment, adaptive EdTech), transparency cases (the synthetic city, the always-answering desk) and the mirror cases where the same mechanism lands differently by context. The risk-based lesson plan builds a full session on exactly this.
08How to classify, step by step
The four categories only become usable once they turn into a sequence of questions. This is the order we use in class, and it is also the order the game asks players to reason in.
| # | Question | What it determines |
|---|---|---|
| 1 | What does the system do, said in one sentence without jargon? | Separates the real function from the sales description. |
| 2 | Who does it affect, and can those people walk away? | Distinguishes a chosen service from a decision imposed on someone. |
| 3 | What does it decide or influence: a suggestion, or access to something? | Separates minimal risk from high risk. |
| 4 | Does it touch a red line: social scoring, emotions at school or work, individual crime prediction, live biometrics for policing? | Triggers the hypothesis of a prohibited practice. |
| 5 | Does the person know an AI is involved? | Activates transparency obligations (and, for synthetic content, the deepfake rules), which stack on top of the other categories rather than replacing them. |
The most common mistake is starting at question 4. People who begin with the red lines tend to see prohibitions everywhere; people who begin with function and context reach the same conclusion through reasoning that survives discussion.
09Three worked examples
The same five steps applied to three plausible systems. The conclusions are educational readings, not legal classifications.
| System | Deciding step | Reading |
|---|---|---|
| Spam filter on council email | Question 3: it influences a suggestion, not access to rights. | Minimal risk. Useful in class precisely because it shows that most AI is not governed by heavy obligations. |
| System ranking benefit claims by audit priority | Question 2: people cannot walk away, and an essential benefit is at stake. | High risk. It needs effective human oversight, traceability and a way to contest the outcome. |
| Council virtual assistant with a realistic synthetic voice | Question 5: the user might believe they are speaking to a person. | A transparency situation — which does not rule out further obligations if the assistant starts affecting consequential decisions. |
To practise on cases more ambiguous than these, the game's thirteen files are built for it: each contains an obvious signal, an account that minimises the problem, and a contextual element that can flip the reading. The classification worksheet is in the classroom activities.