High-risk AI system
What is a high-risk AI system?
High-risk is one of the categories in the EU AI Act, and it is the one that carries the heaviest obligations for systems that are still allowed. Above it sit the prohibited practices, which you simply cannot do. Below it sit systems with limited transparency duties, and systems with no specific obligations at all.
If a system of yours falls into the high-risk category, a substantial set of duties comes with it: a risk management system, requirements on the quality of your training data, technical documentation, logging, human oversight, and a conformity assessment before it goes on the market.
What matters for most companies is that this is a question about the use case and not about the technology. The same model can be entirely unregulated in one application and high-risk in another. A language model that summarises meeting notes carries no special duties. That same model used to rank job applicants does.
The two routes into the category
Article 6 of the AI Act gives two ways in, and it is worth knowing which one could apply to you.
Route one: safety component of a regulated product. If the AI is a safety component of a product that already falls under EU product safety legislation and needs third-party conformity assessment, then it is high-risk. Think machinery, medical devices, lifts, toys. If you build machines, this is the route that concerns you.
Route two: a use case listed in Annex III. This is the route most service companies end up on. Annex III lists specific applications that are high-risk regardless of what product they sit in.
The eight areas in Annex III
The list covers eight areas, and it is worth reading properly rather than assuming it is about robots.
Biometrics. Remote identification, categorising people by sensitive attributes, and emotion recognition. Verifying that someone is who they claim to be is excluded.
Critical infrastructure. AI managing digital infrastructure, road traffic, or the supply of water, gas, heating or electricity.
Education and vocational training. Admissions, assessing learning outcomes, determining someone's level, and monitoring behaviour during exams.
Employment and worker management. Recruitment, job advertising, evaluating candidates, decisions affecting the terms of a working relationship, performance monitoring and task allocation.
Essential private and public services. Eligibility for benefits and healthcare, creditworthiness and credit scoring, risk assessment and pricing for life and health insurance, and dispatching emergency services. Fraud detection is excluded from the credit point.
Law enforcement. Risk assessments, evaluating the reliability of evidence, predicting reoffending, and profiling.
Migration, asylum and border control. Security risk assessments, examining applications, and identifying people.
Administration of justice and democratic processes. Assisting judicial authorities with legal research and applying the law to facts, and influencing the outcome of an election or a referendum.
Two of those catch ordinary companies far more often than people expect. Employment and worker management covers a recruitment tool that scores CVs, and it also covers a system that allocates shifts or monitors performance. Essential services covers credit scoring, which reaches well beyond banks into anyone offering payment terms.
The exception in Article 6(3)
Being on the Annex III list does not automatically make a system high-risk. Article 6(3) provides a way out, and it is narrower than most summaries suggest.
A system escapes the category if it does not pose a significant risk of harm to health, safety or fundamental rights, and it meets at least one of four conditions. Those are: it performs a narrow procedural task, it improves the result of an activity a human already completed, it detects patterns in decision-making without replacing the human assessment, or it performs a preparatory task for an assessment.
There is one hard limit on that exception. A system that performs profiling of natural persons is always high-risk, no matter which of the four conditions it appears to meet.
Because this assessment decides whether a whole set of obligations applies to you, it is not something to settle in a meeting and never write down. If you rely on the exception, document why, at the time, with the reasoning that led you there.
When the rules apply
This changed in 2026, so anything you read from 2025 is out of date.
The AI Act originally put the high-risk obligations for Annex III systems at 2 August 2026. The Digital Omnibus on AI, Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026, moved that date. Stand-alone high-risk systems listed in Annex III now have until 2 December 2027, and AI embedded in products covered by Annex I product safety law has until 2 August 2028.
Not everything moved, and that is the part people get wrong. The prohibitions in Article 5 have applied since February 2025. The obligations for general-purpose AI models have applied since August 2025. And the transparency duties in Article 50 still started on 2 August 2026. So a later high-risk deadline does not mean the AI Act is not already affecting you.
What to do with the extra time
Make an inventory first. You cannot classify systems you have not listed. That includes the AI inside software you bought, which is where most companies find their surprises.
Classify per use case, not per tool. Ask what decision the system influences and about whom. That question, not the technology, is what determines the category.
Ask your suppliers now. If a system in your process turns out to be high-risk, you need documentation from whoever built it. That conversation is much easier eighteen months before a deadline than two months before.
Keep the paperwork you will need anyway. A record of what a system does, which data it uses, who is responsible for it and how a human can override it is useful long before it is required.
Get the classification checked. The line between an Annex III use case and the Article 6(3) exception is genuinely a legal question. This entry explains the structure so you know what to ask. It does not replace advice on your specific situation.