High-risk AI systems: does the AI Act apply to you?
The two classification routes of Article 6, the eight areas of Annex III, the exceptions, the requirements of Articles 9 to 15 and concrete examples.
A high-risk AI system is an artificial intelligence system that the AI Act subjects to its strictest requirements because it can affect people's health, safety or fundamental rights. It qualifies through one of two routes: being a safety component of an already regulated product (Annex I), or being used in a sensitive area such as recruitment, credit or education (Annex III). Since the July 2026 Digital Omnibus, the corresponding requirements will apply on 2 December 2027 for Annex III and 2 August 2028 for Annex I.
What is a high-risk AI system?
The EU AI Act sorts uses of artificial intelligence into risk levels. High risk sits between prohibited practices and uses that are merely subject to transparency: these systems are allowed, provided they meet a set of technical and organisational requirements before being placed on the market and throughout their use.
Classification does not depend on the technology used but on the system's intended purpose, as defined by its provider. The same text analysis engine can be minimal-risk when sorting emails and high-risk when assessing job candidates. Article 6 of the regulation sets the classification rules, with two separate routes.
The stakes are high: a high-risk system must meet the requirements of Articles 9 to 15, undergo conformity assessment and bear the CE marking, and its use creates obligations for the organisation deploying it. Misclassifying a system can lead to fines of up to €15 million or 3% of worldwide annual turnover.
Route 1: safety component of an Annex I product
Article 6(1) covers AI built into products already covered by EU harmonisation legislation. Two cumulative conditions must be met:
- the AI system is a safety component of a product covered by Annex I, or is itself such a product;
- that product must undergo a third-party conformity assessment (by a notified body) before being placed on the market.
Section A of Annex I includes toys, recreational craft, lifts, equipment for explosive atmospheres, radio equipment, pressure equipment, cableway installations, personal protective equipment, gas appliances, medical devices and in vitro diagnostic medical devices. Section B covers civil aviation, vehicles, marine and rail equipment: for these products, AI Act requirements apply through sector-specific legislation.
What the omnibus changed for Annex I
Regulation (EU) 2026/1744 narrowed this route. According to the consolidated version of Article 6, AI used solely for user assistance, performance optimisation, convenience or quality control is not a safety component, unless its failure would endanger health or safety. A product that requires third-party assessment for reasons unrelated to health and safety (radio interference, for example) does not meet the second condition either. The Machinery Regulation was also moved from Section A to Section B. Finally, this route now applies from 2 August 2028.
Route 2: the Annex III areas of the AI Act
Article 6(2) refers to Annex III, which lists stand-alone uses, not linked to a product, considered sensitive for people's rights. The annex is organised in eight areas; within each, only the uses precisely described are covered.
| Annex III area | Uses covered (excerpts) |
|---|---|
| 1. Biometrics | Remote biometric identification (not mere identity verification), categorisation by sensitive attributes, emotion recognition |
| 2. Critical infrastructure | Safety components in the management of critical digital infrastructure, road traffic, and the supply of water, gas, heating and electricity |
| 3. Education and training | Admission and assignment, evaluation of learning outcomes, steering to an education level, monitoring prohibited behaviour during tests |
| 4. Employment | Recruitment (targeted job ads, filtering applications, evaluating candidates), promotion or termination decisions, task allocation, performance monitoring |
| 5. Essential services | Eligibility for public assistance benefits and services, including healthcare; creditworthiness and credit scoring (except fraud detection); life and health insurance pricing; emergency call triage and patient triage |
| 6. Law enforcement | Risk of becoming a victim, reliability of evidence, risk of reoffending, profiling in investigations |
| 7. Migration and borders | Assessing risks posed by a person, examining asylum, visa and residence permit applications |
| 8. Justice and democracy | Assisting judicial authorities in researching and interpreting facts and law; systems intended to influence the outcome of an election or voting behaviour |
This list is not fixed: Article 7 allows the Commission to add or modify use cases by delegated act if a new use presents an equivalent risk. Requirements for this route will apply from 2 December 2027, instead of 2 August 2026 as originally planned.
Article 6 of the AI Act: the paragraph 3 exceptions
Being listed in Annex III is not always enough. Article 6(3) provides that a system is not high-risk if it does not pose a significant risk to health, safety or fundamental rights, in particular because it does not materially influence the outcome of decision-making. This is the case if it meets at least one of four conditions:
- it performs a narrow procedural task, for example turning unstructured documents into structured data or sorting incoming mail by category;
- it improves the result of a previously completed human activity, such as rephrasing a text already written by an officer;
- it detects decision-making patterns or deviations from prior decisions, without replacing or influencing the human assessment without proper human review;
- it performs a preparatory task for an assessment relevant to an Annex III use, such as translating or indexing documents.
The profiling lock
The exception never applies when the system performs profiling of natural persons within the meaning of the GDPR, that is, automated evaluation of personal aspects (work performance, economic situation, reliability, behaviour…). In its analysis of the Commission's draft guidelines, the law firm Osborne Clarke notes that recruitment, credit assessment, migration and policing tools usually involve some form of profiling.
The duty to document and register
Relying on an exception is not merely an internal choice. Under Article 6(4), the provider must document its assessment before placing the system on the market, provide it to authorities on request and register the system in the EU database (Article 49(2)). The omnibus lightened the content of this registration, but not the duty to document. During an inspection, Article 80 allows the market surveillance authority to re-examine the classification and to penalise a provider that knowingly misclassified its system to avoid the requirements.
As of this article (16 September 2026), the guidelines required by Article 6(5) are not final: the Commission published a draft on 19 May 2026, open for consultation until 23 July, and plans to adopt them by the end of 2026.
Classifying an AI system in four questions
Combining the two routes and the exceptions, classification boils down to a decision tree. It assumes two prior checks: the software is indeed an AI system within the meaning of Article 3, and its use is not a practice prohibited by Article 5.
Keep a written record of each pass through this tree: the question, the answer, the supporting evidence and the date. This documentation is required from a provider relying on an exception, and it is valuable for a deployer who must be able to explain why it treats a tool as high-risk or not. It fits naturally into your risk analysis.
High-risk AI: the requirements of Articles 9 to 15
Once a system is classified as high-risk, its provider must meet seven requirements, taking into account its intended purpose and the state of the art (Article 8). The table summarises them.
| Article | Requirement | In practice |
|---|---|---|
| 9 | Risk management system | Identify and assess foreseeable risks, including reasonably foreseeable misuse, mitigate them, test, and update throughout the lifecycle |
| 10 | Data and data governance | Relevant, sufficiently representative training, validation and test sets, examined for possible bias |
| 11 | Technical documentation | File described in Annex IV, drawn up before market placement and kept up to date (simplified form possible for SMEs) |
| 12 | Record-keeping | Automatic logging enabling traceability and post-market monitoring |
| 13 | Transparency towards deployers | Clear instructions for use: performance, limitations, expected input data, human oversight measures |
| 14 | Human oversight | Design enabling a person to understand outputs, resist automation bias, disregard the output and stop the system |
| 15 | Accuracy, robustness, cybersecurity | Declared performance levels, resilience to errors, protection against data poisoning, adversarial examples and confidentiality attacks |
On top of these requirements come the provider's own obligations: a quality management system (Article 17), keeping documentation for ten years, conformity assessment (usually internal control for Annex III, the sector procedure for Annex I), EU declaration of conformity, CE marking, registration, post-market monitoring and serious incident reporting. Article 15 is covered in our article on AI cybersecurity. On the user side, the deployer must in particular ensure human oversight, keep logs and, in some cases, carry out a fundamental rights impact assessment, which can build on the DPIA: see deployer obligations.
Concrete examples of high-risk AI systems
Recruitment and HR management
Software that automatically screens CVs, ranks candidates after a video interview or recommends promotions falls under Annex III (point 4). As it evaluates people, it performs profiling: the Article 6(3) exception is ruled out. On the other hand, a tool that merely anonymises CVs before a recruiter reads them may be a narrow procedural task, provided this is documented.
Credit and insurance
Assessing a borrower's creditworthiness or assigning a credit score is high-risk (point 5(b)), as is risk assessment and pricing in life and health insurance (point 5(c)). Systems that detect financial fraud are expressly excluded. Banks and insurers deploying these systems must also carry out a fundamental rights impact assessment.
Healthcare
Healthcare is concerned by both routes. Diagnostic support software that is a class IIa or higher medical device, and therefore certified by a notified body, is high-risk via Annex I, applying from 2 August 2028 with an assessment integrated into the Medical Devices Regulation procedure. An emergency department patient triage system or an emergency call dispatch system falls under Annex III (point 5(d)). Conversely, an operating theatre scheduling tool or a report transcription tool is not, in principle, high-risk.
Education
Systems that decide admission to an institution, grade papers, steer students to an education level or monitor cheating during an exam are high-risk (point 3). A tool that helps a teacher rephrase their own comments could fall under the exception for improving a previously completed human activity.
Essential public services
A public administration or social security body that uses AI to assess entitlement to a benefit, grant it, reduce it or reclaim it falls under Annex III (point 5(a)). Public bodies deploying these systems must carry out a fundamental rights impact assessment and register their use in the EU database. A chatbot that informs users about procedures is not high-risk in itself, but it is subject to transparency obligations.
Timeline and first actions
High-risk requirements will apply on 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. Systems placed on the market before these dates will only be caught if their design changes significantly, a rule now assessed per type and model of system (specific rules apply to systems used by public authorities). This time is for preparation, especially as harmonised standards and final guidelines are still pending.
- List the AI systems you use or develop, with their exact intended purpose.
- Run each system through the decision tree and document the outcome, especially any exception relied on.
- Question the providers of systems that are likely high-risk: compliance roadmap, available documentation, instructions for use, human oversight measures. This is the job of your third-party risk management process.
- Prepare how human oversight will be organised: who supervises, with what training, with what power to stop or correct.
- Link this work to your existing analyses: risk analysis, DPIA, business continuity plan.
For an overview of the regulation (risk levels, full timeline, penalties, authorities), see our main article EU AI Act: what the AI regulation changes for you. To run and track risk analyses of your AI systems, Phinasoft's risk analysis module accepts your own method.
Summary
Two ways in
An AI system is high-risk if it is a safety component of a regulated Annex I product subject to third-party assessment, or if it is used in one of the eight sensitive areas of Annex III.
Tightly framed exceptions
An Annex III use can escape high-risk status if it does not genuinely influence the decision. Never when profiling is involved, and always with a documented assessment and registration.
Requirements to prepare now
Risk management, data, documentation, logging, human oversight, robustness and cybersecurity: enforceable from 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
Frequently asked questions
What is a high-risk AI system?
It is an AI system that the AI Act subjects to its strictest requirements because it can harm health, safety or fundamental rights. It qualifies either as a safety component of a regulated Annex I product (medical device, toy, lift…) subject to third-party assessment, or because it is used in an area listed in Annex III, such as recruitment, credit or education.
What does Annex III of the AI Act contain?
Annex III lists eight areas: biometrics, critical infrastructure, education and vocational training, employment and workers management, access to essential private and public services (social benefits, credit, life and health insurance, emergency calls), law enforcement, migration and border control, administration of justice and democratic processes. For each, it specifies the uses covered.
What does Article 6 of the AI Act say?
Article 6 sets the classification rules for high-risk systems. Paragraph 1 covers safety components of Annex I products; paragraph 2 refers to Annex III uses; paragraph 3 provides exceptions for systems that do not materially influence decisions; paragraph 4 requires a provider relying on an exception to document its assessment and register the system.
Is AI recruitment software high-risk?
In most cases, yes. Annex III covers systems used to place targeted job ads, filter applications and evaluate candidates. As these tools generally profile people, the Article 6(3) exception cannot apply. The requirements will apply from 2 December 2027.
When do high-risk obligations apply?
Since the Digital Omnibus (Regulation (EU) 2026/1744, in force on 27 July 2026): 2 December 2027 for Annex III systems and 2 August 2028 for systems embedded in Annex I products. The original dates were 2 August 2026 and 2 August 2027.
Have the classification guidelines been published?
Not in final form as of 16 September 2026. The Commission published a draft on 19 May 2026, open for consultation until 23 July 2026, and plans to adopt the final text by the end of 2026.
Sources (7)
- EUR-Lex — Regulation (EU) 2024/1689 (AI Act), Article 6, Articles 8 to 15, Annexes I and III
- EUR-Lex — Regulation (EU) 2026/1744 (Digital Omnibus on AI)
- AI Act Service Desk — Article 6, consolidated text as at 27 July 2026
- European Commission — Targeted consultation on draft guidelines for the classification of high-risk AI systems (19 May 2026)
- European Commission — AI regulatory framework
- Osborne Clarke — European Commission publishes draft AI Act guidelines on high-risk classification and targeted consultation (18 June 2026)
- CNIL — Entry into force of the EU AI Act: first Q&A (in French)
A platform and service that adapt to you
Our platform is designed for fine-tuned configuration and broad adaptability to your needs.