Global AI Regulation in CIB
EU AI Act Tiers
The EU AI Act's Risk Pyramid
The EU AI Act doesn't treat all artificial intelligence the same. Instead, it organizes AI systems into a four-tier pyramid based on their potential to cause harm. This risk-based approach focuses regulatory attention where it's needed most, creating different rules for different levels of risk.
The EU AI Act divides AI systems into four risk categories—minimal, limited, high, and unacceptable—each with its own set of obligations.
Think of it like this: the higher the potential risk to health, safety, or fundamental rights, the stricter the rules. The four tiers are Unacceptable, High, Limited, and Minimal Risk. For financial institutions, understanding which tier their AI systems fall into is the first step toward compliance.
Unacceptable Risk: The Red Lines
At the very top of the pyramid are practices deemed so threatening to human dignity and safety that they are banned entirely in the European Union. These systems pose an 'unacceptable risk' and are prohibited.
This category includes AI that uses manipulative subliminal techniques to distort a person's behavior in a harmful way. It also forbids the use of AI for social scoring by public authorities, where citizens are rated based on their social behavior, leading to unfavorable treatment.
High Risk: The Core of Compliance
This is the most critical category for the financial services industry. High-risk AI systems are not banned, but they are subject to strict obligations before and after they are put on the market. An AI system is classified as high-risk if it's listed in a specific annex of the Act (Annex III) and poses a significant risk to health, safety, or fundamental rights.
For a corporate and investment bank, several key functions fall squarely into this category. These include:
- Credit scoring: AI systems used to evaluate the creditworthiness of natural persons or establish their credit score.
- Risk assessment and pricing: Systems used for life and health insurance.
- Recruitment: AI used for sorting job applications or evaluating candidates.
A special class of models known as General Purpose AI (GPAI) models, like the ones that power advanced chatbots or analytical tools, also face specific rules. If a bank integrates a GPAI model into one of its high-risk systems, the model itself must meet certain transparency and documentation requirements.
Compliance for High-Risk Systems
If a bank deploys a high-risk AI system, it must fulfill several key obligations. The goal is to ensure these systems are safe, transparent, and fair throughout their lifecycle.
A central requirement is the conformity assessment. This is a mandatory self-assessment where the provider must verify that its AI system meets all the Act's requirements for high-risk applications. This involves rigorous testing, establishing a solid risk management framework, and ensuring data quality.
Once a system passes this assessment, the provider must affix a CE marking to it. This marking declares that the product meets EU standards. Finally, the provider must register the system in a public EU database, increasing transparency and allowing regulators to monitor its use across the European Economic Area.
For systems at the bottom of the pyramid, the rules are much lighter. Limited-risk AI, such as chatbots, must simply be transparent. Users need to know they are interacting with a machine, not a human. For minimal-risk systems, like spam filters or AI in video games, the Act imposes no legal obligations. Providers of these systems can choose to voluntarily follow codes of conduct.
| Risk Tier | Example Use Case | Key Obligation |
|---|---|---|
| Unacceptable | Social scoring by governments | Banned |
| High | Credit scoring for individuals | Conformity assessment, risk management, CE marking |
| Limited | Customer service chatbot | Transparency (inform users they're interacting with AI) |
| Minimal | Email spam filter | No obligations (voluntary codes of conduct) |
This tiered structure allows the EU AI Act to target regulation effectively, fostering trust in AI without stifling innovation in low-risk applications.
What is the primary principle behind the EU AI Act's four-tier pyramid structure?
According to the EU AI Act, which of the following is an example of an 'unacceptable risk' AI system that is banned entirely?
