What makes an AI system high-risk
Determining if an AI system is "high-risk" requires a classification exercise to see if the system falls under specific categories defined in the Act. If classified as high-risk, the organization must implement a comprehensive set of mandatory governance and technical requirements before placing the system on the market or putting it into service.
What it means
The EU AI Act adopts a risk-based approach. Most AI systems are not considered high-risk; however, those that pose significant threats to health, safety, or fundamental rights are subject to strict oversight. The classification is binary: your system is either high-risk or it is not.
A system is classified as high-risk if it meets one of two criteria. First, it may be a safety component of a product (or the product itself) already covered by specific EU health and safety legislation (Annex II), provided that product requires a third-party conformity assessment. Second, it may fall into the specific "use-case" categories listed in Annex III, such as biometrics, critical infrastructure, education, employment, or law enforcement.
Importantly, an AI system that falls under the Annex III categories but does not pose a significant risk to health, safety, or fundamental rights—for example, because it performs a purely preparatory task or improves a previous human activity without influencing decision-making—may be exempt from the high-risk classification.
How to meet it
- Conduct an AI Inventory: Create a comprehensive list of all AI systems developed or used within the organization, documenting their intended purpose and functionality.
- Perform Annex II Mapping: Check if the AI is integrated into products regulated by EU safety laws (e.g., medical devices, machinery, toys) that require third-party audits.
- Perform Annex III Mapping: Compare each system's use case against the specific categories in Annex III to identify potential high-risk triggers.
- Apply the "Significant Risk" Filter: For systems identified in Annex III, analyze whether the tool actually influences decision-making or if it performs a narrow, preparatory task that does not pose a significant risk.
- Document the Classification Logic: Create a formal record for every AI system explaining why it was classified as high-risk or why it was deemed low/minimal risk.
- Determine Role Responsibility: Identify whether the organization is the "Provider" (developer) or "Deployer" (user), as this dictates who must evidence the compliance requirements.
Evidence an auditor asks for
- AI System Registry: A detailed inventory of all AI tools, including versioning and a description of their intended purpose.
- Classification Assessment Report: A formal document detailing the step-by-step logic used to determine the risk level for each system.
- Exemption Justifications: Written evidence providing technical and legal reasoning for why an Annex III system was deemed NOT high-risk under Art 6(3).
- Mapping Matrix: A table linking specific system features directly to the categories listed in Annex II or Annex III of the Regulation.
Common pitfalls
- Assumption of Low Risk: Assuming a tool is "just software" and failing to check if it falls into an Annex III category like HR/recruitment or credit scoring.
- Ignoring Product Safety Laws: Overlooking the link between AI and existing EU product safety regulations (Annex II), which can trigger high-risk status regardless of the use case.
- Lack of Documentation: Failing to document "non-high-risk" decisions, leaving the organization unable to prove to regulators that a conscious classification exercise took place.
- Static Analysis: Treating classification as a one-time event rather than updating it when the system's intended