Limited-Risk AI — The Transparency Obligations You Cannot Skip
Not every AI system needs a conformity assessment, a FRIA, or a human-oversight officer. But if your system falls into one of four specific use-case types under Article 50, it carries transparency obligations that are legally binding — with fines up to €15 million or 3% of global annual turnover for non-compliance. Limited-risk is lighter than high-risk. It is not optional.
The four types
The four types are clearly defined. First, AI systems that interact directly with people — chatbots, virtual assistants, AI phone agents — must disclose they are AI before or at the start of the interaction. The “obvious from context” exception is narrow: a voice agent that sounds human and does not identify itself does not qualify. Second, emotion-recognition and biometric-categorisation systems must inform exposed individuals before processing begins — what is being detected, what data is collected, how long it is retained. Remember: the same technology is prohibited in workplaces and schools, high-risk in law enforcement, and limited-risk in other contexts. Where you deploy it determines the classification. Third, AI-generated or manipulated images, audio, and video that could be mistaken for real must be labelled — both with visible disclosure and machine-readable metadata or watermarks where technically feasible. The artistic exception is narrow and does not cover corporate marketing or social media content. Fourth, AI-generated text published on matters of public interest must be disclosed as AI-generated, unless a human editor has substantially edited the output and holds editorial responsibility.
Provider and deployer obligations
Both providers and deployers carry obligations, with the split depending on the type. Providers must design systems that enable disclosure. Deployers must ensure disclosure actually happens in their specific deployment context. And these obligations apply in addition to — not instead of — GDPR transparency requirements and any high-risk obligations that may also apply to the same system.
What’s in the full chapter
The full chapter covers each of the four types with practical implementation steps, the provider-versus-deployer responsibility split, overlap with high-risk and GDPR obligations, the five most common mistakes, and an 8-item self-check for every AI system you operate.
Read the Full Chapter
Get the complete Chapter 9 with implementation guidance for all four types, common mistakes, and the 8-item self-check.
Read the Full Chapter Check Your AI Risk Level — Free