ISHIGHRISK AI
Analysis

What is high-risk AI?

High-risk is a classification, not a severity rating. Where it sits among the AI Act's risk categories, what it catches and what it does not.

Published Regulation (EU) 2024/1689, as amended by the Digital Omnibus
In short

High-risk is a classification, not a severity rating. Article 6 assigns it two ways: the AI is a safety component of, or is itself, a product covered by Annex I harmonisation legislation requiring third-party conformity assessment, or its intended purpose falls in one of the eight Annex III areas. Nothing in the test turns on model size, capability or autonomy, which is why a small model that ranks job applicants is high-risk and a frontier model writing marketing copy is not. The label attaches from 2 December 2027 for standalone Annex III systems and 2 August 2028 for Annex I products, and what it costs is Articles 9 to 15, a conformity assessment, a declaration and registration.

The definition, in one paragraph

High-risk AI is a legal classification with a written test, not a description of how dangerous a system feels. Article 6 of the EU AI Act makes a system high-risk by either of two independent routes. The product route asks whether the AI is a safety component of, or is itself, a product covered by the Union harmonisation legislation listed in Annex I, where that product must undergo third-party conformity assessment before it can be placed on the market. The use-case route asks whether the intended purpose of the system falls in one of the eight areas listed in Annex III. The routes are alternatives. A system is high-risk if either bites, and clearing one proves nothing about the other.

That is the whole definition. Everything else people argue about, model capability, autonomy, whether the system is "real AI", sits outside the test. The full walkthrough of both Article 6 routes works each condition against the text; this piece is about what the label means, what it does not mean, and what follows from it.

Where high-risk sits in the Act, and why the pyramid misleads

Most introductions to the AI Act open with a four-level risk pyramid: unacceptable, high, limited, minimal. It is a useful picture and a poor map. The operative text does not sort systems into levels. It applies separate regimes with separate triggers, and one system can sit in several of them at once. A hiring chatbot can be high-risk under Article 6 and owe Article 50 disclosure at the same time, on different dates.

RegimeWhat triggers itWhat it costsApplies from
Article 5 prohibitionsOne of the listed practices, to which the Digital Omnibus added a ninth entryNo lawful route at all. There is no conformity assessment that makes a prohibited practice permissible2 February 2025, the ninth from 2 December 2026
Article 6 high-riskThe Annex I product route or the Annex III intended-purpose routeArticles 9 to 15, Article 43 conformity assessment, Article 47 declaration, Article 49 registration2 December 2027 standalone, 2 August 2028 embedded
Article 50 transparencyDirect interaction with people, emotion recognition, biometric categorisation, or generating or manipulating synthetic contentDisclosure and marking duties, owed regardless of risk tier2 August 2026, the 50(2) marking duty from 2 December 2026
Chapter V, general-purpose modelsThe model shows significant generality and performs a wide range of tasks competently, under Article 3(63)Article 53 documentation, copyright policy and training-data summary, plus Article 55 above the systemic-risk presumption2 August 2025
Everything elseNothing in Articles 5, 6 or 50 bitesNo specific obligations under the ActNot applicable

Read down the trigger column rather than up the pyramid. The question is never "how risky is this system", it is "which of these four triggers does it pull". That reframing is what stops teams concluding that an internal tool must be low risk because it is internal, or that a chatbot must be high-risk because it talks to customers. The Article 50 transparency duties in particular run on their own track and reach systems that are nowhere near Article 6.

Five things high-risk does not mean

  • It does not mean banned. High-risk systems are lawful once they meet the Chapter III requirements and clear conformity assessment. Prohibition is Article 5, a different regime with a different penalty tier, and it is the one to screen first.
  • It does not mean advanced. Nothing in Annex III turns on parameter count, training compute or autonomy. A logistic regression that scores loan applications is high-risk. A frontier multimodal model drafting ad copy is not, on the Article 6 test.
  • It does not attach to a form factor. A chatbot is not high-risk for being a chatbot. The same interface is high-risk when it screens job applicants under Annex III point 4 and outside Article 6 when it answers questions about opening hours. Intended purpose decides it.
  • It is not only the vendor's problem. Deployers carry their own obligations, and three acts flip a deployer into a provider under Article 25, with the full Article 16 set attached. The roles guide sets out which acts do it, putting your own name on the system among them.
  • It is not an EU-only concern. Article 2 reaches a provider with no EU establishment the moment the output of the system is used in the Union. See the extraterritorial scope guide for the test as it applies to US companies.

What high-risk AI actually looks like

The Annex III list reads abstractly and lands concretely. These are ordinary business systems, most of them bought rather than built:

  • Employment, point 4. Applicant tracking that ranks candidates, targeted job advertising, CV filtering, interview scoring, promotion and termination decisions, shift allocation and productivity monitoring. Broadest in practice, because every organisation of any size hires and manages people. Worked through in the recruitment and HR guide.
  • Essential services, point 5. Credit scoring and credit checks are named expressly, as are risk assessment and pricing in health and life insurance, and systems that decide eligibility for public benefits. See the credit and insurance guide.
  • Education, point 3. Admissions and course allocation, automated exam scoring, systems that evaluate learning outcomes, remote proctoring during a test.
  • Biometrics, point 1. Remote biometric identification, biometric categorisation and emotion recognition, with the caveat that several biometric uses are prohibited outright under Article 5 rather than merely high-risk.
  • The Annex I route. AI inside regulated products: medical devices and toys remain fully in scope. AI embedded in Machinery Regulation products received a targeted carve-out from the AI Act high-risk rules, with AI-specific requirements layered into the Machinery Regulation instead, which moves the requirements rather than deleting them.

Falling in an Annex III area is not always the end of it. Article 6(3) lets a provider conclude that such a system is not high-risk where it poses no significant risk of harm and meets one of four conditions, but a system that performs profiling of natural persons is always high-risk, with no balancing exercise available. The derogation guide covers where that exit gets over-claimed.

What the label costs once it attaches

Classification is the cheap part. What follows is Articles 9 to 15: a risk management system running across the lifecycle, data governance for training, validation and testing sets, technical documentation against the nine Annex IV blocks drawn up before market placement, automatic logging, instructions for use directed at deployers, human oversight designed into the system, and an appropriate level of accuracy, robustness and cybersecurity. On top sit the Article 43 conformity assessment, which may route through a notified body and put a third party on your critical path, the Article 47 declaration of conformity and Article 49 registration in the EU database.

The derogation does not clear the paperwork. Article 6(4) requires the assessment to be documented before the system is placed on the market, not produced afterwards when an authority asks. Under the Digital Omnibus, a system the provider self-assesses as not high-risk must still be registered in the EU database: the Commission proposed dropping that duty and it did not survive negotiations.

Getting the classification wrong sits in the middle Article 99 tier, €15,000,000 or 3% of total worldwide annual turnover, the higher figure for companies and the lower for SMEs and start-ups under Article 99(6). Supplying incorrect, incomplete or misleading information to an authority is its own tier at €7,500,000 or 1%, which is what a badly evidenced classification file exposes you to on top of the underlying breach. The penalty breakdown covers who enforces which tier.

When high-risk starts to bite, and what already binds

The Digital Omnibus split the original single date by route, so the high-risk regime arrives in two waves:

2 Dec 2027High-risk obligations apply to standalone Annex III systems, a seventeen-month extension from the original 2 August 2026 date.
2 Aug 2028High-risk obligations apply to AI embedded in Annex I products, medical devices and toys included.

A later date is not a stand-down. The Article 5 prohibitions and the Article 4 AI-literacy duty have bound since 2 February 2025, the general-purpose model chapter and the penalty provisions since 2 August 2025, and the Article 50 transparency duties land on 2 August 2026 whatever your risk tier. A risk management system, an Annex IV file and a notified-body assessment are multi-quarter projects, which is why teams that paused their programmes on the headline that deadlines moved have less runway than the calendar suggests.

One caveat on the dates themselves. The Digital Omnibus was adopted by the European Parliament on 16 June 2026 and by the Council on 29 June 2026, and was signed on 8 July 2026, but it had not been published in the Official Journal as at the 22 July 2026 review date, and it enters into force on the third day after publication. The amended dates are agreed and final in substance, while the consolidated text and the final regulation number are not yet authoritative. The full application timeline tracks each date as it settles.

Telling whether your own system is high-risk

The order matters more than the effort. Run it like this:

  1. Write the intended purpose down. One specific paragraph describing what the system is intended to be used for and by whom. Every step below reads from it, and a vague purpose statement is the most common cause of a wrong answer.
  2. Confirm scope. Article 2 excludes exclusive military, defence and national-security use, scientific research and development before market placement, and purely personal non-professional use, and reaches you when output is used in the Union.
  3. Screen Article 5. Prohibited practices first, always. That is the €35,000,000 or 7% tier, and it has been live since February 2025.
  4. Run both Article 6 routes in parallel. Annex I product plus third-party conformity assessment, and the eight Annex III areas. Record each answer.
  5. If Annex III bites, test profiling before the derogation. Profiling ends the analysis. Otherwise work the significant-risk gate and the four conditions, and document the result under Article 6(4).
  6. Fix your role. Provider, deployer, importer, distributor, product manufacturer or authorised representative, and you can hold more than one at once.

The free classifier walks these stages in order and returns the article each determination rests on, which gives you the skeleton of the record Article 6(4) expects either way. For a genuinely contested classification the missing Commission guidance means counsel and a paper trail, not a confident answer. The primary text is Regulation (EU) 2024/1689 on EUR-Lex.

Check your own system

The free classifier walks the same tests in order and tells you which of them your system actually trips, with the article each answer rests on.

Run the triage →

Frequently asked questions

What does high-risk mean under the EU AI Act?

It means the system falls inside Article 6, which sets two independent routes. Route one: the AI is a safety component of, or is itself, a product covered by the Union harmonisation legislation listed in Annex I, and that product must undergo third-party conformity assessment. Route two: the intended purpose of the system falls in one of the eight Annex III areas, which run from biometrics and critical infrastructure through education, employment, essential public and private services, law enforcement, migration and the administration of justice. The routes are alternatives, so clearing one tells you nothing about the other. High-risk is not a judgement about how powerful or dangerous the technology is, and nothing in the test turns on model size, training compute or autonomy.

Is high-risk AI banned in the EU?

No. High-risk systems are lawful and regulated: you can place one on the EU market once it meets the Chapter III requirements, passes the Article 43 conformity assessment, carries an Article 47 declaration of conformity and is registered under Article 49. Banning is a separate regime. Article 5 lists prohibited practices, and no amount of documentation, human oversight or testing makes one of those lawful. The two regimes sit in different penalty tiers as well: prohibited practices carry €35,000,000 or 7% of total worldwide annual turnover, while breaches of the high-risk regime carry €15,000,000 or 3%. Screen Article 5 before Article 6, because a prohibited practice is not a high-risk system with extra paperwork.

Are large language models high-risk?

Not because they are large language models. Article 6 classifies by intended purpose, not by architecture or parameter count, so a frontier model used to draft marketing copy is outside the high-risk regime on that test, while a small gradient-boosted model that ranks job applicants is inside it. General-purpose AI models are governed on a separate axis in Chapter V, whose Article 53 duties have applied since 2 August 2025, with the Article 55 duties on top for models above the systemic-risk presumption. A general-purpose model also becomes part of a high-risk system the moment someone puts it to an Annex III use, and Article 25 can make that person the provider of the resulting high-risk system.

Who decides whether an AI system is high-risk?

The provider does, in the first instance, and has to be able to defend it. Classification is a self-assessment against Article 6, made and recorded before the system is placed on the market. Where a provider concludes that an Annex III system is not high-risk under the Article 6(3) derogation, Article 6(4) requires that assessment to be documented before market placement, and under the Digital Omnibus the system must still be registered in the EU database. National market surveillance authorities test the answer afterwards. The Commission missed its February 2026 statutory deadline for Article 6 classification guidelines, so a thorough contemporaneous record is doing more work than it otherwise would.

Does the high-risk regime apply to companies outside the EU?

Yes, wherever the Article 2 hooks are met. The Act reaches providers that place a system on the EU market or put it into service in the Union, whatever their place of establishment, and it reaches providers and deployers in third countries where the output produced by the system is used in the Union. A US company with no EU entity can therefore be the provider of a high-risk AI system. Article 22 adds a hard requirement on top: before making a high-risk system available on the Union market, a third-country provider must appoint an authorised representative established in the Union, by written mandate.

When do the high-risk obligations start?

Two dates, split by route. Standalone Annex III systems come into the regime on 2 December 2027, and AI embedded in Annex I products follows on 2 August 2028, both moved by the Digital Omnibus from the original 2 August 2026 date. Other parts of the Act already bind: the Article 5 prohibitions and the Article 4 AI-literacy duty since 2 February 2025, the general-purpose AI model chapter and the penalty provisions since 2 August 2025, and the Article 50 transparency duties from 2 August 2026, with the Article 50(2) marking duty from 2 December 2026 for generative systems placed on the market before 2 August 2026.

This article is analysis, not legal advice. It reflects Regulation (EU) 2024/1689 as amended by the Digital Omnibus, as that text stood at the last site review on 22 July 2026, when the Omnibus was adopted and signed but awaiting Official Journal publication. Final classification for ambiguous cases needs qualified counsel.