Unit 5 / 12

EU AI Law and Risk Classes

Gains:

  • Recognizing the EU AI Law's four risk classes and prohibited practices
  • Reasonable evaluation of which risk category a use falls into
  • Understand why high risk and general purpose AI liabilities impact Turkish companies

The EU Artificial Intelligence Act (EU AI Act), which comes into force in 2024, is the world's first comprehensive AI regulation and its impact extends far beyond the borders of the European Union. This law may be directly binding for a company based in Türkiye but serving the EU market, having EU customers or selling products to the EU. In this unit, you will learn the basic logic of the law — its risk-based approach — with its four classes, prohibited practices and high-risk liabilities; We will try to evaluate which box a usage falls into.

Basic idea: the higher the risk, the tighter the rule

The EU AI Law does not lump all AI together. It divides an artificial intelligence system into four categories according to its potential harm and imposes different obligations on each category. A music recommendation does not carry the same risk as a hiring screening system; The law does not apply the same rule to them. This risk-based approach is the backbone of the law.

Risk class

Meaning

example

rule

Prohibited (unacceptable)

Open threat to fundamental rights

Social scoring, subconscious manipulation

total ban

high risk

It seriously affects human life

Recruitment, credit, healthcare, education, critical infrastructure

Strict liability

limited risk

Requires transparency

Chat bot, deepfake, AI content

Information is mandatory

minimal risk

Insignificant risk

Spam filter, game AI, recommendation engine

free

Prohibited apps: red line

Some uses of AI are deemed so harmful that they cannot be released no matter how much risk is reduced. These are in the prohibited (unacceptable risk) category:

  • State-supported social scoring (scoring people according to their behavior/characteristics and disadvantaging them).
  • Systems that manipulate people's subconscious and cause harm.
  • Systems that exploit vulnerabilities such as age and disability.
  • Certain real-time biometric identification and mass surveillance applications (with narrow exceptions).
  • Specific applications such as emotion recognition in the workplace and education.
Attention: The fact that a use is in the "prohibited" category is not an obstacle that can be overcome by saying "I have a good reason". These practices are completely prohibited; cannot be released even with risk-reducing measures. The first check to be made is whether the project is included in this list.

High risk liabilities

High risk systems are not prohibited but are subject to strict conditions. Typical high-risk areas: recruiting and employee management, credit and insurance, education and exam assessment, healthcare, critical infrastructure, law enforcement and immigration. Typical obligations in these systems:

  1. Establishing and maintaining a risk management system.
  2. Data quality and bias management (representative and accurate of training data).
  3. Technical documentation and record keeping (traceability).
  4. Transparency and providing information to the user.
  5. Human control (human ability to intervene and override).
  6. Accuracy, robustness and cybersecurity assurances.

General purpose AI (GPAI) obligations

The law imposes specific transparency and documentation obligations on general-purpose AI models (GPAI) — that is, multi-purpose base models such as large language models — as well as on individual uses: provision of summaries on training data, copyright compliance policy, additional assessment for models with systemic risk. If an organization embeds these models into its own product, some of these liabilities may be reflected in the chain.

three mini cases

Case 1 — Recruitment screening (high risk). A software company in Izmir develops a recruitment platform serving EU companies; The system automatically scores and eliminates candidates. This is an area that the law clearly deems high risk. Company; must meet data quality, bias testing, human auditing and documentation obligations. The argument "We are in Turkey, it does not bind us" is invalid; Since the system is used in the EU market, the law applies.

Case 2 — Customer chatbot (limited risk). An e-commerce site deploys a chatbot serving its EU customers. This is in the limited risk category; The main obligation is transparency: the user must be clearly informed that "you are talking to an artificial intelligence". Hiding this is a violation; It is enough to specify.

Case 3 — Approaching the prohibited line. A retail chain wants to analyze customers' emotional reactions through store cameras and give a "potential shoplifter" score. This falls into the prohibited/very high risk area with both emotion recognition and scoring dimensions. The legal team stops the project at the design stage; It is clear that it cannot be implemented even with risk-reducing measures.

Tip: The first question when starting a new AI project is “how useful is this?” but rather "what risk class does this fall into?" should be. Doing the classification in the first place avoids wasting resources on a project that will be canceled later.

Copiable templates

TEMPLATE 1 — Risk class preliminary assessment: "Pre-evaluate the following AI use according to the EU AI Law: [describe the use]. State which risk class (prohibited / high / limited / minimal) it may fall into, with justification. Mark the points you are not sure of as 'legal confirmation required'; do not make a definitive legal judgment."

TEMPLATE 2 — Prohibited application scanning: "Scan the following project idea only against the 'EU AI Act prohibited applications' list: [describe the project]. Is there a risk in terms of social scoring, subconscious manipulation, vulnerability exploitation, unauthorized biometric surveillance, emotion recognition? Write yes/no and justification in each heading."

TEMPLATE 3 — High-risk liability checklist: "For this high-risk AI use, [describe the use] creates a 'what's our current situation, what's missing' table across six liability headings (risk management, data quality, documentation, transparency, human auditing, robustness). Suggest a concrete action in each row."

TEMPLATE 4 — Transparency notification (limited risk): "For a chatbot serving EU users, write a short 'you are talking to AI' notification to be displayed to the user. Simple, reassuring, 2 sentences maximum. Include the option to switch to a human agent."

Weak prompt / Strong prompt

WEAK: “Does the EU AI Law concern us?”-> The model gives a general answer; It does not classify your concrete use, it does not evaluate your connection to the EU market. GÜÇLÜ: "We are a company based in Izmir, we sell recruitment and screening AI to a company in Germany. What risk class does this use fall under the EU AI Law, what obligations fall on us and why does being in Turkey not exempt us? Mark where you are not sure." -> The model produces a context-specific classification and liability list.

Common mistakes

  • Thinking "We are in Turkey, EU law does not bind us"; However, touching the EU market is sufficient.
  • Making risk classification after developing the project; However, it should be done in the first place.
  • Mistaking a prohibited practice as an obstacle that can be overcome with "good justification".
  • Bypassing transparency reporting in limited risk systems (making the bot look like a human).
  • Neglecting human auditing and bias management from high risk liabilities.
  • Overlooking that general purpose AI (GPAI) liabilities may reverberate down the chain.
  • Interchange the EU AI Law with the KVKK; they are different but complementary.

In summary

  • The EU AI Law takes a risk-based approach and divides AI into four classes: prohibited, high, limited, minimal.
  • Prohibited practices (social scoring, manipulation, etc.) cannot be released even if the risk is reduced.
  • High risk systems; It is subject to strict obligations such as risk management, data quality, human control and documentation.
  • In limited risk systems, the main obligation is transparency (reporting that there is AI).
  • Turkish companies touching the EU market are also affected by the law; Classification should be done at the very beginning of the project.

Application task

Consider three different uses of AI that your organization (or a fictitious company) might use in relation to the EU market. Place each in one of the four risk classes of the EU AI Act and write your justification. Put the six high-risk obligations for the use you find highest risk in a control chart: fill in the “current status” and “incomplete/action” columns. Write a transparency statement that will be displayed to the user for a use that falls into the limited risk category. Finally, if any of your uses are approaching the prohibited line, note that and why.

checklist

  • [ ] I placed each use of AI into one of four risk classes.
  • [ ] I scanned my projects against the list of prohibited applications.
  • [ ] I created a liability control chart for high risk usage.
  • [ ] I included human auditing and bias management in the obligations.
  • [ ] I have prepared a transparency statement for limited risk use.
  • [ ] I understand why my EU market connection triggered the law.
  • [ ] I did the risk classification at the beginning of the project, not at the end.