← Practice

Reality Lab · 12 MIN · Judge

Place a use on the risk map

Before asking ‘is this legal?’, ask two sharper questions: how risky is this use, and what is our role in it? Practise the triage that a specialist actually needs from you.

THE SITUATION

A mid-size company plans three AI uses and wants to “get compliant.” Someone’s first instinct is to google article numbers. But the useful first move under the EU AI Act isn’t a legal verdict — it’s classifying each use by risk tier and identifying whether the company is the provider (making/branding the system) or the deployer (using someone else’s under its own authority). That triage is what a qualified reviewer needs to give a real answer.

Your task: For three uses, place each on the risk map (roughly: prohibited, high-risk, limited/transparency, or minimal) and name the company’s role — then say what you’d hand to a specialist.

THE THREE PROPOSED USES
A. A chatbot on the public website that answers product questions, built on a third-party model.
B. An in-house tool that scores and ranks job applicants to shortlist for interviews.
C. A system that infers employees’ emotions from webcam video during performance reviews.

This box is local to your browser. Nothing you type is sent anywhere or saved after you leave.

Check your own work

There's no grade here — checking against these is the exercise. Compare each point to what you wrote.

  • Each use is placed by what it does to people, not by how advanced it feels.Risk tiers track impact on rights and safety. A simple tool that decides who gets a job interview is higher-risk than a flashy one that suggests product names.
  • The applicant-scoring use is recognised as likely high-risk, with human-oversight and fairness duties.Employment and access decisions about people sit in the high-risk band precisely because a biased or opaque system there causes real harm at scale.
  • The emotion-inference-at-work use is flagged as possibly prohibited, and escalated rather than assumed fine.Inferring emotions in the workplace is one of the practices the Act treats as unacceptable-risk in many cases. This is a ‘stop and get expert review before building’ signal, not a design detail.
  • The company’s role is stated per use, and you note that using a third-party model doesn’t automatically make you only a deployer.Obligations differ sharply by role, and the same organisation can be a deployer of one system and a provider of another. Getting the role wrong misdirects every duty that follows.
Reveal a worked approach

A sound triage: A (website chatbot) — likely limited-risk with a transparency duty (tell users they’re talking to AI); company is a deployer of the third-party model, though branding it as your own product can pull you toward provider duties. B (applicant scoring) — likely high-risk: expect obligations around data quality, documentation, human oversight, and fairness; the company is the provider if it built the tool. C (emotion inference in performance reviews) — treat as potentially prohibited; do not build pending specialist review.

Notice the move you did not make: you didn’t declare any of it definitively legal or illegal. You classified risk and role and produced a clean hand-off — the exact inputs a qualified reviewer turns into an actual determination.

The habit to carry: ‘classify before you conclude.’ Risk tier and role first; article numbers and legal calls are a specialist’s job, and this triage is what makes their answer fast and correct rather than a guess. This is training, not legal advice.