The four risk levels
🚫 Unacceptable risk
Prohibited (social scoring, manipulation and the like).
⚠️ High risk
Heavy obligations: risk management, human oversight, logging, registration. It covers in particular the assessment of eligibility for essential public services and benefits (annex III).
ℹ️ Limited risk
Transparency obligation: tell users they are interacting with an AI, and label generated content. This is the case for a generic document assistant.
✅ Minimal risk
No specific obligation (spam filters and so on).
The decision point for a local authority
An AI document assistant is generally limited risk. But if it is used to process citizens' case files (income support, housing, welfare payments), it can shift into high risk (annex III §5a).
Good practice: settle that use in writing in a usage charter, and either frame it or exclude it explicitly. We support you through that decision.
Key obligations & deadlines
| AI literacy (training users) | art. 4 |
| Transparency: “AI-generated content” | art. 50 · 2026 |
| Documented human oversight | high-risk systems |
| Obligations for general-purpose AI models (GPAI) | borne by the model provider |
What a sovereign AI brings
- ✓ Transparency banner and labelling of generated content
- ✓ Logging and human oversight made easier (everything stays with you)
- ✓ Technical documentation of the system provided
- ✓ Usage charter designed with you to frame the risk level
Official sources
- Regulation (EU) 2024/1689 (AI Act): full text on EUR-Lex
The official text of the European regulation on artificial intelligence.
- European Commission: regulatory framework for AI
An overview of the risk-based approach and of the application timetable.
- AI Act Explorer (Future of Life Institute)
Article-by-article navigation through the regulation, in French.
Get ahead of the 2026 deadlines
See also GDPR compliance and digital sovereignty.
Take stock of your compliance