top of page
Search

Key Obligations for Limited-Risk AI Systems Under the EU AI Act

  • Writer: David J. Kinsella
    David J. Kinsella
  • Jun 15
  • 3 min read
Eye-level view of a modern AI device with a digital interface

To ensure Artificial Intelligence (AI) technologies are safe and trustworthy, the European Union passed the EU AI Act in 2024, a regulatory framework that classifies AI systems based on their risk levels. Among these, limited-risk AI systems face specific obligations designed to protect users, while encouraging innovation. Limited-risk AI systems do not pose significant threats to safety or fundamental rights, but still require some transparency, and accountability measures. These include chatbots, spam filters, and AI-powered recommendation systems. Understanding these obligations is essential for developers, providers, and users of AI solutions.


Under the EU AI Act, limited-risk AI systems are primarily subject to specified transparency obligations, rather than the heavy conformity assessments required for high-risk systems. The first step in any assessment of an AI system is to check that it does not fall into a prohibited category or indeed, a high-risk category. For limited-risk AI systems, the primary objective under the EU AI Act is to ensure that end-users are aware that they are interacting with AI or exposed to synthetic content, either generated or manipulated by AI.


The EU AI Act identifies two primary actors in the AI ecosystem, each having their own responsibilities:


1) "providers" are essentially developers of AI systems; and

2) "deployers" are those who are deploying the AI-system for use in the market.


However, it is worth noting that the EU AI Act, and the recent Guidelines on Transparency for Certain AI Systems refer to the principle of "downstream compliance", so that a provider of an AI system should in designing the solution, also consider downstream compliance obligations on the deployer.


Obligations for Providers


Providers (i.e. developers) of limited-risk AI systems must focus on user awareness and disclosure:


  • Direct Interaction Disclosure: AI systems that interact directly with humans (e.g. chatbots or virtual assistants) must be designed to clearly notify the user that they are interacting with an AI system, unless this is obvious from the context.


  • Synthetic Content Marking and Identification: Providers of generative AI systems that output audio, image, video, or text must ensure that their outputs are detectable and clearly marked in machine-readable formats, indicating they have been artificially generated or manipulated. The guidelines provide further details on the usage of technical solutions to mark AI-generated or manipulated content, specifying that a 2-layer approach should be used (e.g. watermarks and meta-data identification tags). In addition, the provider should consider making publicly available a system to allow users to check that content was created or manipulated by a specific AI system.


Obligations for Deployers


Deployers (i.e. those who use the AI system in a business context) have specific disclosure and informational duties, depending on the type of system:


  • Deepfakes and Altered Media: Deployers who generate or manipulate audio, image, or video content that constitutes a "deepfake" (where content resembles a real existing person, and would be considered by the recipient as false) must explicitly disclose that the content has been artificially generated.


  • Public Interest Text: If a deployer uses AI to publish text intended to inform the public on matters of public interest, they must disclose that the text is artificially created. This does not apply if the content is for artistic or creative works (where disclosure does not hamper enjoyment of the works), or if the AI-generated text has undergone human review, and editorial control.


  • Biometric / Emotion Systems: Deployers of emotion recognition systems or biometric categorization systems must inform the users exposed to them.


Shared Obligations


  • AI Literacy: Both providers and deployers must ensure that their staff, and any agents operating the AI system have a sufficient level of "AI literacy" regarding the risks, and proper use of the systems.


  • Timing of Disclosures: All required transparency and disclosure notifications must be provided to the user in a clear, distinguishable manner at, or before, the very first interaction with, or exposure to, the AI.


Limited-risk AI systems catch a wide range of AI-based technologies that fall outside the prohibited use category and high-risk category. The EU AI Act requires both providers and deployers to ensure that they are transparent on the use of such AI technologies, with the underlying objective to promote trust in AI technologies, and avoid or limit the potential for misuse.


These obligations balance innovation with user protection. They encourage developers to build AI systems that are transparent, reliable, and respectful of user rights without imposing excessive burdens. By meeting these requirements, providers can foster trust and wider adoption of AI technologies, benefiting both businesses and consumers.


Disclaimer: Content is not intended to, and does not constitute, legal advice, and no attorney-client relationship is formed.

 
 
bottom of page