The EU AI Act reserves its most demanding compliance requirements for high-risk AI systems. But what exactly makes an AI system “high-risk” — and how do you know if yours qualifies? This guide walks through the legal definition, the full Annex III list, and real-world examples for each category.
- High-risk classification triggers 13 mandatory compliance obligations — including conformity assessment, technical documentation, and EU database registration.
- Annex III lists eight specific use-case domains where AI is presumed high-risk: from biometrics and HR to credit scoring and law enforcement.
- Many organisations discover their existing AI tools — HR screening software, credit APIs, proctoring platforms — are already in scope.
- The compliance deadline for high-risk AI is 2 August 2026. Conformity assessments take 4–12 months.
The Legal Definition of “High-Risk” Under the EU AI Act
Article 6 of the EU AI Act (Regulation EU 2024/1689) establishes two routes to high-risk classification:
For most businesses, Route 2 — Annex III — is what matters. It captures the AI systems your legal, HR, finance, and operations teams are most likely already using or building.
One important nuance: Article 6(3) allows a provider to rebut the high-risk presumption if they can document that an Annex III use case “does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons.” This exception is narrow and requires documented justification — it cannot be claimed without a formal written assessment.
The Eight Annex III High-Risk AI Categories
Here is each Annex III category with the legal scope, real-world examples of in-scope systems, and the specific compliance challenge it creates.
What High-Risk Classification Actually Means for Your Organisation
Being classified as high-risk under Annex III is not a ban — it is an invitation to prove your AI system is safe and trustworthy through a rigorous compliance process. The obligations apply to Providers (who build the AI) and Deployers (who use it in operations) differently, but both carry significant responsibilities.
| Obligation | Article | Provider | Deployer |
|---|---|---|---|
| Risk Management System | Art. 9 | ✅ | — |
| Technical Documentation (Annex IV) | Art. 11 | ✅ | — |
| Human Oversight Controls | Art. 14 | ✅ design | ✅ operate |
| Conformity Assessment | Art. 43 | ✅ | — |
| EU AI Database Registration | Art. 49 | ✅ | ✅ some |
| Fundamental Rights Impact Assessment | Art. 27 | — | ✅ |
| 6-Month Use Log Retention | Art. 26 | — | ✅ |
Not sure which role applies to your organisation — or whether you might be both? Use our free 2-minute EU AI Act Risk Assessment Tool to get a personalised classification instantly.
How to Identify Your High-Risk AI Systems: A Practical Approach
The EU AI Act does not self-identify which of your systems are in scope. That determination is your responsibility. Here is a proven three-step approach used by compliance teams:
Frequently Asked Questions
Quick answers to the most common questions about Annex III high-risk AI classification.






