Linkedin-inYoutube
logotype
  • Consulting
    • Automotive
      • Functional Safety
      • Cybersecurity
      • Autonomous Product Development
      • Electric Vehicle (EV) Development
      • Assurance of AI-based Tools
    • Physical AI
      • Robotics Safety
      • Assurance of AI-based Tools
    • Responsible AI
      • Responsible Artificial Intelligence
  • Training
    • Automotive
    • Physical AI
  • Company
    • Why SRES Training
    • Leadership
    • Partnerships
    • Careers
  • Insights
    • Automotive Library
    • Physical AI Library
  • Contact
Let's Talk
logotype
  • Consulting
    • Automotive
      • Functional Safety
      • Cybersecurity
      • Autonomous Product Development
      • Electric Vehicle (EV) Development
      • Assurance of AI-based Tools
    • Physical AI
      • Robotics Safety
      • Assurance of AI-based Tools
    • Responsible AI
      • Responsible Artificial Intelligence
  • Training
    • Automotive
    • Physical AI
  • Company
    • Why SRES Training
    • Leadership
    • Partnerships
    • Careers
  • Insights
    • Automotive Library
    • Physical AI Library
  • Contact
Let's Talk
  • Consulting
    • Automotive
      • Functional Safety
      • Cybersecurity
      • Autonomous Product Development
      • Electric Vehicle (EV) Development
      • Assurance of AI-based Tools
    • Physical AI
      • Robotics Safety
      • Assurance of AI-based Tools
    • Responsible AI
      • Responsible Artificial Intelligence
  • Training
    • Automotive
    • Physical AI
  • Company
    • Why SRES Training
    • Leadership
    • Partnerships
    • Careers
  • Insights
    • Automotive Library
    • Physical AI Library
  • Contact
logotype
logotype
  • Consulting
    • Automotive
      • Functional Safety
      • Cybersecurity
      • Autonomous Product Development
      • Electric Vehicle (EV) Development
      • Assurance of AI-based Tools
    • Physical AI
      • Robotics Safety
      • Assurance of AI-based Tools
    • Responsible AI
      • Responsible Artificial Intelligence
  • Training
    • Automotive
    • Physical AI
  • Company
    • Why SRES Training
    • Leadership
    • Partnerships
    • Careers
  • Insights
    • Automotive Library
    • Physical AI Library
  • Contact
EU AI Act Overview: Risk Levels and Structure | Part 1
09/21/26
5 Likes

EU AI Act Overview: Risk Levels and Structure | Part 1


The first article in our new EU AI Act series provides direct links to the legal text, an introduction to the Act’s risk-based approach, and a practical guide to navigating and understanding the regulation. It is a useful starting point for anyone working with AI compliance, automotive AI, or AI safety.

Looking to go deeper? Explore our ISO/IEC 42001 and EU AI Act Responsible AI Training, which helps organizations build practical AI governance, risk-management, and AI management system capabilities. Need more than training? Explore our Responsible AI consulting services supporting AI governance, ISO/IEC 42001 implementation, and preparation for EU AI Act obligations.


Introduction

The European Union’s Artificial Intelligence Act (Regulation (EU) 2024/1689) is the world’s first comprehensive legal framework for artificial intelligence. It establishes a risk-based regulatory approach, with the most stringent requirements applying to high-risk AI systems, including many AI applications used in automotive products. While the AI Act is a legal regulation rather than a safety standard, it will significantly influence the development and assurance of AI-enabled vehicle systems.

The roots of the AI Act go back to April 21, 2021, when the European Commission formally presented and published its first proposal for a regulatory framework for artificial intelligence. This was a significant milestone: it represented the first comprehensive regulatory “blueprint” for AI governance proposed by a major regulatory body. The proposal provided a starting point that influenced subsequent AI policies and regulatory initiatives in many countries around the world. While approaches differ – for example, the United States has followed a substantially different and more decentralized path – many jurisdictions have looked to the European Union’s approach when developing their own AI governance frameworks.

The intention of this blog is to enable you to read and navigate the EU AI Act as needed. It provides links to the legal text, a brief introduction to the risk-based approach of the EU AI Act, and a guide to navigating and understanding the regulation.

Links to official sources are provided throughout the blog for further reading.

Before getting into the legal text, it is useful to understand an evolutionary aspect of the EU AI Act and how the regulatory framework developed from the European Commission’s initial 2021 proposal to the regulation in force today.

The Digital Omnibus on AI

An omnibus proposal is a package of legislative proposals that amends multiple existing EU legal acts at the same time, usually across the same policy area. This is done to reduce administrative burden (see the European Commission’s article on simplification).

Digital Omnibus on AI or simply ‘AI Omnibus’ – officially also referred to as ‘Omnibus VII: digital’
→ amends the EU AI Act
→ amends related EU digital legislation
→ adjusts implementation timelines
→ addresses practical implementation issues such as standards and regulatory infrastructure.

Links to the Legal EU AI Act

At the time of writing, EUR-Lex currently provides three relevant views:

  1. Original AI Act — Regulation (EU) 2024/1689, as published in July 2024.
  2. Digital Omnibus on AI — Regulation (EU) 2026/1744, which is a separate amending regulation. It does not reproduce the whole AI Act; it says what provisions of 2024/1689 are changed.
  3. Consolidated AI Act – current version, 27 July 2026 — This version incorporates the amendments introduced by the Digital Omnibus. EUR-Lex identifies it as 02024R1689-20260727 and lists Regulation (EU) 2026/1744 as amendment M1.

The current consolidated AI Act is a documentation tool rather than a legally authentic text. On the consolidated EUR-Lex page, the markings indicate the origin of the provisions:

  • B = the original/basic act — Regulation (EU) 2024/1689.
  • M1 = Modification 1 — the first amending act, Regulation (EU) 2026/1744, the Digital Omnibus.

The EU legal text is available in both HTML and PDF formats in many different languages. Compared with the PDF, the HTML version provides a structured view that is easier to navigate.

The following EU AI Act excerpt shows how the original text and modifications are shown in the legal text:

Article 6

Classification rules for high-risk AI systems

1. Irrespective of whether an AI system is placed on the market or put into service independently of the products referred to in points (a) and (b), that AI system shall be considered to be high-risk where both of the following conditions are fulfilled:

(a) the AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I;

(b) the product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service of that product pursuant to the Union harmonisation legislation listed in Annex I.

▼M1

1a. For the purposes of this Regulation, including paragraph 1 of this Article, AI systems that are solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control shall not qualify as safety components.

1b. Notwithstanding paragraph 1a, AI systems the failure or malfunctioning of which would endanger health and safety shall qualify as safety components.

1c. A product that is required to undergo a third-party conformity assessment solely due to risks other than risks to health and safety, in particular risks relating to the distribution of radio spectrum or electromagnetic interference that do not affect health and safety, shall not be considered as fulfilling the condition in paragraph 1, point (b).

▼B

2. In addition to the high-risk AI systems referred to in paragraph 1, AI systems referred to in Annex III shall be considered to be high-risk.

Source: Regulation (EU) 2024/1689 (EU AI Act), Article 6, consolidated version current as of 27 July 2026.

Brief Introduction to the EU AI Act

The EU AI Act establishes a risk-based regulatory framework for artificial intelligence (AI). It aims to promote the development and use of trustworthy and human-centric AI while protecting health, safety, fundamental rights, and other important societal interests.

The AI Act distinguishes between different levels of risk associated with AI systems and applies requirements that are proportionate to those risks.

Diagram showing the EU AI Act risk levels: unacceptable, high, limited, and minimal risk

Unacceptable risk applies to AI practices that are considered to pose a threat to the safety, livelihoods, or fundamental rights of people. These practices are prohibited under the AI Act. Examples include certain uses of AI for harmful manipulation or deception, exploitation of vulnerabilities, and social scoring.

High-risk AI systems can pose significant risks to health, safety, or fundamental rights and are therefore subject to extensive regulatory requirements. High-risk applications include certain uses of AI in areas such as education, employment, access to essential public services, justice, and law enforcement. Components used in critical infrastructure such as transportation is the aspect relevant for the automotive industry.

Limited risk refers primarily to AI systems for which the AI Act establishes specific transparency obligations. For example, users interacting directly with certain AI systems, such as chatbots, may need to be informed that they are interacting with a machine. Providers of certain AI systems that generate or manipulate content must also ensure that the content can be identified as artificially generated or manipulated.

Minimal or no risk applies to the vast majority of AI systems. Examples include AI-enabled video games and spam filters. These systems are generally not subject to mandatory requirements under the AI Act, although voluntary codes of conduct and other measures are encouraged.

More details are available in the European Commission’s Regulatory Framework for AI.

EU AI Act Structure – a Guide

The best way to read the EU AI Act may be using the official EU AI explorer.

At the time of writing, the EU AI Act Explorer reflects the original EU AI Act from 2024 and has not yet been updated to incorporate the Digital Omnibus on AI. See the introduction for more information.

The EU AI Act is structured into three main parts: the preamble, the main regulatory text, and the annexes.

  • Preamble – consists of the recitals, which provide the rationale, objectives, context, and guidance for interpreting the regulatory provisions. Unless specific background or interpretive information is needed, the recitals can be skipped.
  • Chapters – form the main structure of the regulatory text and contain the substantive requirements in the articles.
  • Annexes – provide additional regulatory provisions, lists, criteria, and technical or procedural details that are referenced by specific articles.
Diagram showing the structure of the EU AI Act, including the preamble, main regulatory text, chapters, articles, and annexes

The structural elements of the main regulatory text are:

Chapter → Section (where applicable) → Article → Paragraph → Point (where applicable)

Sections subdivide chapters into groups of related articles. Not all chapters contain sections or points.

A common method of referencing provisions is:

Article (Paragraph) (Point)

For example, Article 6(1)(a) refers to Article 6, paragraph 1, point (a).

CHAPTER III

HIGH-RISK AI SYSTEMS

SECTION 1

Classification of AI systems as high-risk

Article 6

Classification rules for high-risk AI systems

1. Irrespective of whether an AI system is placed on the market or put into service independently of the products referred to in points (a) and (b), that AI system shall be considered to be high-risk where both of the following conditions are fulfilled:

(a) the AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I;

(b) the product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service of that product pursuant to the Union harmonisation legislation listed in Annex I.

Source: EU AI Act, Chapter III, Section 1, Article 6(1) — consolidated version dated 27 July 2026.

Chapter Articles Main content
I. General Provisions 1–4 Scope and foundations. Defines the purpose, scope, key terminology, and AI-literacy obligation. Establishes who and what the Act applies to.
II. Prohibited AI Practices 5 Unacceptable-risk AI. Lists AI practices that are prohibited, e.g. certain manipulative techniques, exploitation of vulnerabilities, certain social scoring and biometric practices.
III. High-Risk AI Systems 6–49 Core product/development requirements. Defines which AI systems are high-risk and establishes requirements such as risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy, robustness and cybersecurity. Also covers provider/deployer obligations and conformity assessment.
IV. Transparency Obligations 50 Transparency for certain AI systems. Requirements for informing people when they interact with AI, marking certain AI-generated content, disclosure of deepfakes, etc.
V. General-Purpose AI Models 51–56 GPAI foundation/model layer. Classification of GPAI models, obligations for providers, additional requirements for models with systemic risk, and codes of practice.
VI. Measures in Support of Innovation 57–63 Innovation mechanisms. AI regulatory sandboxes, real-world testing, support for SMEs/start-ups and certain derogations.
VII. Governance 64–70 Who administers the Act. Establishes the EU AI Office, European AI Board, scientific panel, advisory forum and national competent authorities.
VIII. EU Database for High-Risk AI Systems 71 Registration. Establishes the EU database for specified high-risk AI systems.
IX. Post-Market Monitoring, Information Sharing and Market Surveillance 72–94 Lifecycle supervision and enforcement. Post-market monitoring, serious-incident reporting, market surveillance, investigations, complaints, remedies and enforcement of GPAI obligations.
X. Codes of Conduct and Guidelines 95–96 Soft-law implementation mechanisms. Voluntary codes of conduct and Commission guidelines for implementing the Act.
XI. Delegation of Power and Committee Procedure 97–98 Regulatory maintenance. How the Commission can exercise delegated powers and how implementing measures are adopted.
XII. Penalties 99–101 Sanctions. Administrative fines for violations, including specific provisions for GPAI providers and EU institutions.
XIII. Final Provisions 102–113 Interaction with existing legislation and implementation. Amendments to other EU legislation, treatment of existing AI systems, evaluation/review and entry into force/application.

Summary

The EU AI Act is the world’s first comprehensive legal framework for artificial intelligence. It takes a risk-based approach to protect health, safety, and fundamental rights. The framework categorizes AI applications into four levels of risk: unacceptable, high, limited, and minimal risk. Unacceptable-risk AI practices, such as certain forms of manipulation and deception, are prohibited. High-risk AI applications are subject to extensive regulatory requirements. Limited-risk applications are subject to transparency requirements, such as informing users when they are interacting with AI. Minimal-risk applications, such as video games and spam filters, are generally not subject to mandatory requirements.

The next blog will explore high-risk AI systems with the example of electronic automotive product development.


Have insights or questions? Send us an email at info@sres.ai or leave a comment below. We welcome thoughtful discussion from our technical community.

Interested in learning more about our approach? Explore why teams choose SRES training and how we support organizations with Automotive consulting and Physical AI consulting.

ISO/IEC TS 22440: The Emerging Direction for Functional Safety and AI Systems

09/03/26
ISO/IEC TS 22440: The Emerging Direction for Functional Safety and AI Systems

Insight Categories

  • Functional Safety46
  • Responsible AI33
  • Robotics & Physical AI13
  • Autonomous Systems24
  • Cybersecurity7
  • Electric Mobility3
  • Videos14
  • News22
Most Recent
  • EU AI Act Overview: Risk Levels and Structure | Part 1
    EU AI Act Overview: Risk Levels and Structure | Part 1
    09/21/26
  • ISO/IEC TS 22440: The Emerging Direction for Functional Safety and AI Systems
    ISO/IEC TS 22440: The Emerging Direction for Functional Safety and AI Systems
    09/03/26
  • Safety Standards for Humanoid and General-Purpose Robots: A Practical Guide
    Safety Standards for Humanoid and General-Purpose Robots: A Practical Guide
    08/11/26
  • ISO 26262 Challenges for ADS: Item Definition and HARA
    ISO 26262 Challenges for ADS: Item Definition and HARA
    08/07/26
  • SRES SafeStack | August 2026
    SRES SafeStack | August 2026
    08/03/26
logotype
  • Company
  • Careers
  • Contact Us
  • info@sres.ai
  • 265 Dillon Ridge Rd
    Ste C PMB 505
    Dillon, CO 80435

Services

Automotive

Physical AI

Responsible AI

Training

Resources

Insights

Video

Legal

Privacy Policy
Cookie Policy
Terms & Conditions
Training Terms & Cancellation Policy
Accessibility
Consent Preferences

© Copyright 2026 SecuRESafe, LLC. All rights reserved.

Linkedin Youtube