If you’re using AI in your organisation, the EU AI Act is not optional.
The problem is most companies do not actually know where they sit.
They assume they are low risk.
They are not.
Let’s break it down properly with real examples.
🔴 High Risk AI
This is where regulation gets serious.
If your AI is making decisions about people, or heavily influencing them, you are likely in this category.
Examples:
AI used for CV screening or hiring decisions
Credit scoring or loan approval
Healthcare diagnosis or triage systems
Facial recognition or biometric identification
Insurance risk pricing
Why it matters:
These systems can:
Deny someone a job
Block access to money
Impact someone’s health
If they are wrong, people feel it.
What’s expected:
You need proper governance:
Risk management
Human oversight
Transparency
Auditability
Ongoing monitoring
If you cannot explain what your system is doing and why, you have a problem.
🟠 Medium Risk AI
This is where most companies actually are.
Not officially high risk, but still very capable of causing issues.
Examples:
Customer service chatbots making decisions on refunds or complaints
Fraud detection systems freezing accounts
Employee monitoring or productivity scoring
Marketing personalisation engines
AI-generated summaries used to support decisions
Why it matters:
These systems:
Still affect outcomes
Can be biased or inconsistent
Can damage trust fast
And when something goes wrong, you will be asked to explain it.
What’s expected:
You need structure, not overkill:
Clear intended use
Transparency
Guardrails
Regular review
This is the category most people underestimate.
🟢 Low Risk AI
This is the easy end of the scale.
Minimal impact, easy to control.
Examples:
Grammar and writing assistants
Image enhancement tools
Internal analytics dashboards
Email autocomplete
Why it matters:
These tools:
Do not meaningfully impact people
Are easy to override
Keep humans in control
What’s expected:
Basic transparency
Minimal governance
Do not overcomplicate it.
Prohibited AI
Some things are simply not allowed.
Examples:
Social scoring of individuals
AI that manipulates vulnerable people
Certain types of real-time biometric surveillance
If you are anywhere near this, stop.
The Reality Most Companies Miss
Most organisations think they are low risk.
They are not.
They are:
Using AI to influence decisions
Affecting customers or employees
Without clear oversight
That puts them in medium or high risk whether they realise it or not.
Where CXO Ready Comes In
The real challenge is not understanding the categories.
It is being able to answer simple questions:
What is this AI system doing?
What happens if it is wrong?
Who owns it?
Can we prove we are in control?
CXO Ready gives you:
A central AI system inventory
Visibility of risks and gaps
Clear actions on what to fix
Evidence you can stand behind
Because under the EU AI Act, thinking you are fine is not enough.
Final Thought
AI risk is not about the tech.
It is about the impact.
If your AI affects people, even indirectly, you need control over it.
If you do not have that, it is just a matter of time before it bites you.

