AI Act High-Risk AI Systems, Classification and Obligations
Last updated: 23 June 2026
Under the EU AI Act (Regulation (EU) 2024/1689), high-risk AI systems are systems that either act as a safety component of a regulated product listed in Annex I, or are intended for one of eight sensitive use-case areas in Annex III, and they carry the heaviest compliance load in the whole Regulation. Most companies meet the category through Annex III, where ordinary software such as CV-screening tools, credit-scoring models and biometric identification systems is presumed high-risk unless a narrow exemption applies. That is how a recruitment vendor with no hardware ends up in the same regime as a medical-device maker. This guide covers both classification routes under Article 6, the eight Annex III areas with examples, the Article 6(3) exemption, the obligations that follow, and the deadlines that moved in May 2026.
The timing matters more than it did a year ago, and not for the obvious reason. The headline rules were pushed back. After the Digital Omnibus political agreement of 7 May 2026, the deadline for standalone Annex III systems shifted from 2 August 2026 to 2 December 2027. That looks like breathing room. It is not, because the Commission’s classification guidelines are still in draft, harmonised standards are unfinished, and the prohibitions and general-purpose AI rules already apply. In our assessment the clock on classification started months ago, and the delay only removed your excuse for not having an inventory.
What Makes an AI System High-Risk Under the EU AI Act
An AI system is high-risk if it meets the test in Article 6 by one of two independent routes. It is a safety component of, or itself is, a product covered by the Union harmonisation legislation in Annex I that requires third-party conformity assessment (Article 6(1)), or it is intended for one of the purposes listed in Annex III (Article 6(2)). A system needs to satisfy only one route.
The Annex I route follows product-safety logic. Both conditions must hold. The AI has to be a safety component of a product such as a medical device, machine, lift, toy or vehicle, and that product already has to pass third-party conformity assessment under its sectoral law. This route catches manufacturers who never thought of themselves as AI companies. The Annex III route follows fundamental-rights logic instead of physical safety, so a recruitment tool can be high-risk even though it never touches a factory floor. The test turns on intended purpose, meaning what you state in documentation and marketing, not how a customer happens to use the system.
This is worth flagging for anyone selling into regulated products. The Commission’s draft classification guidelines read Article 6(1) broadly, treating any product that needs harmonised standards to reach the market as inside the regime, not only products facing a formal third-party assessment. Our read is that more systems land in high-risk than a plain reading of the text suggests, and engineering teams will find out late. Most obligations fall on providers who place the system on the market (Article 16), a lighter set on deployers who use it (Article 26).
The AI Act Sorts AI Into Four Risk Levels
The AI Act runs four risk tiers. Unacceptable risk is banned outright, high risk carries the bulk of the obligations, limited risk carries transparency duties, and minimal risk carries none. High-risk sits second and absorbs most of the Regulation’s weight, which is why it is the only tier most companies need to study closely.
Prohibited practices under Article 5, including social scoring and untargeted scraping of facial images, have been banned since 2 February 2025, with penalties reaching 35 million euros or 7 percent of worldwide turnover. Limited-risk systems such as chatbots and deepfake generators face transparency duties under Article 50. Minimal-risk systems, which is nearly everything from spam filters to recommendation engines, carry no specific obligations. If you are not certain which tier a system sits in, the AI Act Risk Classifier sorts it against Annex I and Annex III in minutes.
Examples of High-Risk AI Systems Across the Eight Annex III Areas
Annex III lists eight areas where an AI system is presumed high-risk under Article 6(2): biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services, law enforcement, migration and border control, and the administration of justice and democratic processes. Falling within any one of them triggers the full regime unless the Article 6(3) exemption applies.
Biometrics covers remote biometric identification and, where not outright banned, emotion recognition, such as matching faces against a reference database. Critical infrastructure covers AI as a safety component managing electricity, water, gas, traffic or digital networks. Education reaches tools that decide admission or score exams. Employment captures recruitment and selection systems, which the Regulation describes as covering targeted job advertising, the filtering of applications and the evaluation of candidates, along with decisions on promotion, termination or task allocation. A CV-screening tool and a performance-scoring system both qualify.
The essential-services area surprises finance teams. It includes creditworthiness assessment and credit scoring, with one carve-out for systems whose purpose is detecting financial fraud, plus benefit-eligibility decisions and risk pricing in life and health insurance. The last three areas cover law enforcement, migration and border control, and the administration of justice. The list is not fixed. The Commission can amend it through delegated acts under Article 7, so a minimal-risk system today can be reclassified without Parliament voting again.
The Article 6(3) Exemption Is Narrower Than It Looks
A system that falls within an Annex III area is not high-risk if it does not pose a significant risk to health, safety or fundamental rights, including by not materially influencing the outcome of decision-making (Article 6(3)). The exemption applies only where the system meets one of four narrow conditions, and it never applies where the system profiles natural persons.
The four conditions are a narrow procedural task, improving the result of a previously completed human activity, detecting decision patterns or deviations without replacing human judgement, and performing a preparatory task for an Annex III assessment. Then comes the catch. If the system profiles people, it is always high-risk, whichever condition it might otherwise meet. And claiming the exemption is itself work. The provider must document the assessment before market entry and still register the system under Article 49(2), a duty the Omnibus kept rather than removed.
The draft guidelines tighten the screw. A human in the loop does not declassify a high-risk system, because human involvement does not change the system’s intended purpose. Neither does a line in your terms of service excluding high-risk use, if your marketing effectively promotes it. Regulators read the substance, not the disclaimer. In our assessment the Article 6(3) filter is not the escape hatch many SMEs hope for. It converts the burden from complying with the high-risk regime into producing documented evidence that you do not have to, and for a small team without legal support that is not obviously the lighter task.
High-Risk AI System Obligations Run From Article 9 to Article 15
Providers of high-risk systems must meet a stack of duties in Chapter III, and breaches sit in the 15 million euros or 3 percent of worldwide turnover penalty tier under Article 99(4). Strip away the article numbers and the duties collapse into three jobs. Most of the real work is in proving the system is safe to ship. That means a lifecycle risk management system (Article 9), training data that is representative and checked for bias (Article 10), and tested accuracy, robustness and cybersecurity (Article 15). Then there is the paper trail that proves you did it, through technical documentation (Article 11), automatic logs (Article 12), instructions for deployers (Article 13) and human oversight someone can actually exercise (Article 14). Before any of it reaches the market, the system needs a conformity assessment (Article 43), a declaration of conformity (Article 47), CE marking (Article 48) and registration in the EU database (Article 49). Deployers get a shorter list under Article 26, with a fundamental rights impact assessment under Article 27 for some. SMEs and start-ups get one real concession, Article 99(6), which caps the fine at the lower of the two figures rather than the higher.
The duty that breaks small teams in practice is Article 10. Assembling training, validation and test datasets that are representative and as free of error and bias as possible takes data, tooling and people a 200-person company usually does not have, and the harmonised standards that would tell you what good enough looks like are unfinished. Our read is that data governance, not the conformity paperwork, is where most mid-sized providers will stall. To see what a worst-case penalty looks like against your turnover, the AI Act Fines Calculator runs the Article 99 tiers.
The Omnibus Pushes High-Risk Deadlines Back to December 2027
High-risk obligations were originally due on 2 August 2026 for Annex III systems and 2 August 2027 for Annex I systems, but the Digital Omnibus political agreement of 7 May 2026 defers them to 2 December 2027 and 2 August 2028. Until that agreement is published in the Official Journal, 2 August 2026 remains the binding date.
The phased timeline so far is set. Prohibitions and AI literacy duties applied from 2 February 2025. Governance rules and general-purpose AI obligations applied from 2 August 2025, and the Omnibus does not touch them. The high-risk dates are the ones in motion. The European Parliament endorsed the Omnibus on 16 June 2026, the Council still has to adopt it formally, and publication is expected in July, ahead of the 2 August 2026 cliff edge. The Union is racing to pass a law before 2 August 2026 whose only purpose is to move 2 August 2026, and if it misses, the old date stands. The practical point is simple. Plan around 2 December 2027 as your Annex III baseline, and treat 2 August 2026 as legally live until the Official Journal says otherwise. Most transparency duties under Article 50 still bite from 2 August 2026, and the new watermarking deadline lands on 2 December 2026, so the delay is narrower than the headlines imply. You can track each date against the others in the EU Compliance Deadline Tracker.
High-risk is only one track of four. Our overview of every AI Act compliance deadline sets the December 2027 date against the obligations that did not move.
The Classification Guidelines Are Still Draft, and Read the Rules Broadly
The Commission’s guidelines on classifying high-risk AI systems remain in draft as of June 2026. They were published on 19 May 2026 under Article 6(5), are open for consultation until 23 July 2026 after a four-week extension, and the final version is expected by the end of 2026. They are interpretive, not law, so you classify now against guidance that can still change.
The draft runs to three documents covering general principles, the Annex I route and the Annex III route. The original deadline for these guidelines, set in Article 6(5), was no later than 2 February 2026. The Commission set itself that date, wrote the rule, and still missed it by more than three months, which tells you how hard classification is even for the people who drafted it. National regulators have filled the gap, with Spain’s AESIA publishing practical compliance guides in December 2025 and Germany’s Bundesnetzagentur running a high-risk service desk, none of it binding. Until the guidelines are final you are aiming at a moving target, and in our assessment the honest response is to document the assumptions behind every classification decision and book a re-assessment for early 2027.
Classification Is the Work You Can Do Before the Standards Land
The most useful step does not depend on the final standards at all. Building an inventory of every AI system you develop, deploy or procure, then mapping each one against Annex III and Annex I to decide whether it is high-risk, is work you can finish before any deadline and before the guidelines are final.
- The inventory comes first. Map every AI system you build, deploy or procure against Annex III and Annex I, standalone, embedded, in-house and procured alike. For borderline cases the Article 6(3) exemption is the thing to test and document, since profiling cancels it. The AI Act Risk Classifier gives a defensible first pass.
- The classification decisions are worth writing down. A “not high-risk” conclusion still carries the documented assessment Article 6(4) requires and registration under Article 49(2), so the exemption shifts the paperwork rather than removing it.
- Exposure is easy to size. The high-risk tier runs to 15 million euros or 3 percent of turnover and the prohibited tier to 35 million euros or 7 percent, which is the difference between a line item and a board-level number.
- The dates reward watching rather than panic. Until the Omnibus reaches the Official Journal, 2 August 2026 is the binding date and 2 December 2027 the working baseline for Annex III.
- The Article 9 to 15 gap analysis takes the longest. Risk management, data governance and human oversight are months of work, and notified-body queues for third-party assessment are already filling.
Of all of it, the inventory is the piece that cannot be deferred, because every other step assumes you already know which systems you run. “We are not sure what AI is running across the business” is how a manageable classification project becomes a scramble against the deadline. In our assessment one person and one week on a rough AI register buys more than any amount of waiting for the standards to settle.
Common Questions About High-Risk AI Systems
Which AI systems are prohibited under the AI Act
AI practices banned under Article 5 since 2 February 2025, including social scoring, untargeted scraping of facial images, and emotion recognition in workplaces and schools. The Digital Omnibus adds a prohibition on AI “nudifiers” and AI-generated child sexual abuse material, applying from 2 December 2026.
What are the four risk levels in the EU AI Act
Unacceptable risk (prohibited), high risk, limited risk and minimal risk. High-risk systems carry most of the obligations, limited-risk systems face transparency duties, and minimal-risk systems face none specific to the Act.
Does the AI Act apply to companies outside the EU
Yes. Under Article 2 it reaches providers placing AI systems on the EU market and providers or deployers whose system output is used in the EU, wherever they are established.
What is the difference between Annex I and Annex III high-risk systems
Annex I systems are high-risk because they are safety components of, or are, products regulated by EU product-safety law requiring third-party conformity assessment (Article 6(1)). Annex III systems are high-risk because they are intended for one of the eight sensitive use-case areas (Article 6(2)). After the Omnibus they follow different deadlines, 2 August 2028 for Annex I and 2 December 2027 for Annex III.
Not sure whether a given system is high-risk? Run it through the free AI Act Risk Classifier for a first-pass result against Annex I and Annex III. The broader AI Act Readiness Assessment then covers where you stand on the obligations themselves. For a monthly brief on EU compliance deadlines as they move, subscribe to the RegDossier newsletter.
RegDossier
Making EU compliance almost enjoyable. Almost.
EU regulatory updates in your inbox every two weeks. Free.
Get the next briefing