Is your AI system “high-risk” under the EU AI Act?
The EU AI Act reserves its heaviest obligations — and its largest fines — for one tier: high-risk AI. If your system lands in it, you inherit a stack of engineering and governance duties before you can put it on the market. If it doesn't, most of the Act simply doesn't apply to you. So the single most valuable question you can answer is a blunt one: is our AI high-risk?
This is an information service to help you orient, not legal advice — but it walks the actual test in the law. When you want the specific obligations for your own situation, see which apply to your company.
Why the label matters so much
High-risk is the tier that carries the substantive rules. A high-risk system needs a risk-management process, data governance, technical documentation, event logging, meaningful human oversight, and demonstrated accuracy, robustness, and cybersecurity — plus a conformity assessment and registration before it goes to market (Articles 8–15, 17, 43, and 49). It is also where the real penalties sit.
And it is on a clock — one the EU has since moved. The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) postponed the high-risk obligations: the Annex III use cases now apply from 2 December 2027, and AI built into regulated products (Annex I) from 2 August 2028. The transparency duties for chatbots and AI-generated content were not deferred. See what the Digital Omnibus changed and the full EU AI Act timeline.
The two doors into "high-risk" (Article 6)
An AI system is high-risk if it comes in through either of two doors.
Door 1 — a safety component of a regulated product (Annex I). If your AI is a safety component of — or is itself — a product already covered by EU product-safety law that requires third-party conformity assessment (machinery, medical devices, toys, lifts, vehicles, and similar), it is high-risk.
Door 2 — a listed use case (Annex III). The Act names eight sensitive areas. AI used for these purposes is presumptively high-risk:
- Biometrics — remote identification, biometric categorisation, and emotion recognition, where such use is permitted.
- Critical infrastructure — safety components in the supply of water, gas, heating, and electricity, or in road-traffic and digital infrastructure.
- Education and vocational training — admissions, scoring exams, evaluating learning outcomes, and monitoring for prohibited behaviour during tests.
- Employment and worker management — recruiting and screening candidates, decisions on promotion or termination, task allocation, and performance monitoring.
- Access to essential services — creditworthiness and credit scoring, risk assessment and pricing in life and health insurance, eligibility for public benefits, and emergency-call triage.
- Law enforcement, migration and border control, and the administration of justice — where such use is permitted.
If your AI does one of these jobs, treat it as high-risk until you can show otherwise.
The exception most companies miss (Article 6(3))
Being in an Annex III area does not automatically make you high-risk. A system escapes the label if it does not pose a significant risk to health, safety, or fundamental rights — because it only:
- performs a narrow procedural task;
- improves the result of a previously completed human activity;
- detects decision-making patterns or deviations without replacing or influencing a human's own assessment; or
- performs a preparatory task for an assessment relevant to one of the Annex III use cases.
Two catches. A system that profiles individuals is always high-risk — no exemption. And if you rely on this carve-out, you must document the assessment that led you there; it is not a judgment you can leave unwritten.
Worked examples
| Your AI system | High-risk? | Why |
|---|---|---|
| CV-screening or candidate-ranking tool | Yes | Annex III — employment and worker selection |
| Credit-scoring or loan-approval model | Yes | Annex III — creditworthiness and access to essential services |
| Exam-scoring or online proctoring software | Yes | Annex III — education and vocational training |
| Customer-support chatbot | No — transparency only | Limited-risk: you must disclose it's AI, but it isn't high-risk |
| Spam filter or internal document search | No | Minimal risk — no new obligations |
| Tool that only flags anomalies for a human to review | Possibly not | May qualify for the Article 6(3) exemption — but document the reasoning |
What it means if you are high-risk
If you build it (provider), the full obligation stack applies: risk management, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity, a quality-management system, a conformity assessment, CE marking, and registration in the EU database.
If you use it (deployer), the duties are lighter but real (Article 26): use the system according to the provider's instructions, assign competent human oversight, keep the logs, monitor for problems, and report serious incidents. Certain deployers — public bodies and providers of essential services — must also carry out a fundamental-rights impact assessment (Article 27).
A trap worth repeating: if you put your own name on a high-risk system, or substantially modify one, you can become its provider in the eyes of the law — and inherit the heavier set of duties.
What to do next
- Check both doors for each AI system — the regulated-product route and the Annex III list.
- Apply the Article 6(3) test honestly, and write down your reasoning if you claim the exemption.
- Watch the date — and the update. The Annex III high-risk obligations were postponed to 2 December 2027 by the Digital Omnibus (Annex I products to 2 August 2028) — but the transparency duties for chatbots and AI-generated content still apply from 2 August 2026, so a "we have more time" message on one clock shouldn't quietly delay the other.
The fastest way to get your own answer: answer three questions about your AI use and we'll show you the verified obligations that match, sorted by deadline. Not sure yet where you stand? Start with which obligations apply to your company. To be told the moment any of them change, join the waitlist.
The official text is Regulation (EU) 2024/1689. This article is an information service to help you orient — it is not legal advice.
Frequently asked questions
What makes an AI system high-risk under the EU AI Act?
There are two routes (Article 6). Either the AI is a safety component of a regulated product that needs third-party conformity assessment (Annex I), or it is used for one of the sensitive purposes listed in Annex III — such as employment, creditworthiness, education, or biometric identification. High-risk systems carry the Act's substantive engineering and governance obligations.
Is an AI hiring or CV-screening tool high-risk?
Generally yes. Recruitment, candidate screening, and decisions on promotion or termination are Annex III use cases, so systems doing that work are high-risk. Both the provider that builds the tool and the employer that deploys it have obligations.
When do the high-risk AI obligations start to apply?
These dates were moved by the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026). For the Annex III use cases (employment, credit, education, and so on), the high-risk obligations now apply from 2 December 2027; for AI that is a safety component of a regulated product (Annex I), from 2 August 2028. The transparency duties were not deferred.
Can an AI system in an Annex III area avoid being high-risk?
Yes. Under the Article 6(3) exemption, a system is not high-risk if it only performs a narrow procedural or preparatory task and does not pose a significant risk to health, safety, or fundamental rights. But a system that profiles individuals is always high-risk, and the provider must document the assessment either way.
See which obligations apply to your company → or join the waitlist
This is an information service, not legal advice.