CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
Podcast

EU AI Act Summary: 4 Risk Tiers Decide Hiring and Loans

EU AI Act Summary: 4 Risk Tiers Decide Hiring and Loans

EU AI Act Summary: 4 Risk Tiers Decide Hiring and Loans

0:00-0:00

This episode is based on our article:

Read the full article →

EU AI Act Summary: 4 Risk Tiers Decide Hiring and Loans

Full Episode Transcript


A facial recognition system can be ninety-nine percent accurate and still be illegal to use. Not because it's broken. Because of what someone decided to point it at. Under European law, the exact same software can be perfectly fine in one room and banned in the room next door.


That sounds like a technicality

That sounds like a technicality. It isn't. If you've ever applied for a job online, or asked a bank for a loan, an algorithm may have looked at you first. And the rules that decide whether that's allowed don't ask how smart the software is. They ask what happens to you when it's wrong. That shift — from accuracy to consequence — is the single most important idea in A.I. regulation right now. So how does a machine get sorted into "fine" or "forbidden"?

The European Union's A.I. Act sorts every system into one of four buckets. At the top, unacceptable risk. Those are simply banned — things like social scoring, or scanning faces in a crowd in real time. Below that, high risk. Legal, but heavily regulated. Then limited risk, where you mostly just have to tell people a machine is involved. And minimal risk, which is most of the harmless stuff — spam filters, video game A.I.

Now, what lands a system in that high-risk tier? Not its error rate. The law names eight sectors. Hiring. Credit and essential services. Education. Law enforcement. Border and migration. The courts. Critical infrastructure. And biometric identification. If your tool touches one of those, you're in the heavy tier — no matter how well it performs.

Picture a face-matching tool used to help find a missing child. Now picture the identical tool screening job applicants. Same code. Same accuracy. Completely different legal obligations — because one of them can quietly cost someone a career.


Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

Most of us assume a high accuracy number means a

Most of us assume a high accuracy number means a system is safe. That's a reasonable belief. Accuracy is a number you can compare, and vendors put it on the brochure. But run the math. A ninety-five percent match rate against a database of ten million faces produces five hundred thousand false hits. Five hundred thousand people who look close enough to the machine. The question stops being "how often is it right," and becomes "what happens to a real human being the moment it's wrong here."

On the American side, the National Institute of Standards and Technology takes a similar angle. N.I.S.T. sorts A.I. harm into three kinds. Harm to people — your rights, your safety, your shot at a paycheck. Harm to an organization — breaches, losses, a wrecked reputation. And harm to a whole ecosystem — financial systems, supply chains, public trust. A misidentification at a police department manages to hit all three at once. The person's life is upended, the agency's case falls apart, and everyone watching trusts the system a little less.

N.I.S.T. also lays out four jobs for managing that risk. Govern. Map. Measure. Manage. Notice which one comes first. Not measuring. Governing. Somebody has to own the decision before anyone runs a single test. And that's exactly the step organizations skip. They buy the software, plug it in, and never appoint the human who's accountable when it misfires. That missing human is the difference between a tool and a trap.

Here's what surprises most people who work with this technology. Classification isn't paperwork you file after launch. It's the gate you pass through before launch. Get it wrong, or skip it, and you've built something you legally cannot deploy — even if it works flawlessly. The tool never changes. The rules around it change entirely, based on whose life it touches.


The Bottom Line

So, three sentences. Europe sorts A.I. into four risk levels, and the level depends on what the system decides — not how accurate it is. Anything touching hiring, loans, policing, or your face automatically lands in the strictest tier. And the law requires a real person in that loop, reviewing the machine's answer before it changes your life.

You don't need a law degree to hold onto that. The next time a company tells you their A.I. is ninety-nine percent accurate, you now know the better question — accurate at what, and who pays when it isn't? The full breakdown's in the show notes.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search