The definition, in one paragraph
High-risk AI is a legal classification with a written test, not a description of how dangerous a system feels. Article 6 of the EU AI Act makes a system high-risk by either of two independent routes. The product route asks whether the AI is a safety component of, or is itself, a product covered by the Union harmonisation legislation listed in Annex I, where that product must undergo third-party conformity assessment before it can be placed on the market. The use-case route asks whether the intended purpose of the system falls in one of the eight areas listed in Annex III. The routes are alternatives. A system is high-risk if either bites, and clearing one proves nothing about the other.
That is the whole definition. Everything else people argue about, model capability, autonomy, whether the system is "real AI", sits outside the test. The full walkthrough of both Article 6 routes works each condition against the text; this piece is about what the label means, what it does not mean, and what follows from it.
Where high-risk sits in the Act, and why the pyramid misleads
Most introductions to the AI Act open with a four-level risk pyramid: unacceptable, high, limited, minimal. It is a useful picture and a poor map. The operative text does not sort systems into levels. It applies separate regimes with separate triggers, and one system can sit in several of them at once. A hiring chatbot can be high-risk under Article 6 and owe Article 50 disclosure at the same time, on different dates.
| Regime | What triggers it | What it costs | Applies from |
|---|---|---|---|
| Article 5 prohibitions | One of the listed practices, to which the Digital Omnibus added a ninth entry | No lawful route at all. There is no conformity assessment that makes a prohibited practice permissible | 2 February 2025, the ninth from 2 December 2026 |
| Article 6 high-risk | The Annex I product route or the Annex III intended-purpose route | Articles 9 to 15, Article 43 conformity assessment, Article 47 declaration, Article 49 registration | 2 December 2027 standalone, 2 August 2028 embedded |
| Article 50 transparency | Direct interaction with people, emotion recognition, biometric categorisation, or generating or manipulating synthetic content | Disclosure and marking duties, owed regardless of risk tier | 2 August 2026, the 50(2) marking duty from 2 December 2026 |
| Chapter V, general-purpose models | The model shows significant generality and performs a wide range of tasks competently, under Article 3(63) | Article 53 documentation, copyright policy and training-data summary, plus Article 55 above the systemic-risk presumption | 2 August 2025 |
| Everything else | Nothing in Articles 5, 6 or 50 bites | No specific obligations under the Act | Not applicable |
Read down the trigger column rather than up the pyramid. The question is never "how risky is this system", it is "which of these four triggers does it pull". That reframing is what stops teams concluding that an internal tool must be low risk because it is internal, or that a chatbot must be high-risk because it talks to customers. The Article 50 transparency duties in particular run on their own track and reach systems that are nowhere near Article 6.
Five things high-risk does not mean
- It does not mean banned. High-risk systems are lawful once they meet the Chapter III requirements and clear conformity assessment. Prohibition is Article 5, a different regime with a different penalty tier, and it is the one to screen first.
- It does not mean advanced. Nothing in Annex III turns on parameter count, training compute or autonomy. A logistic regression that scores loan applications is high-risk. A frontier multimodal model drafting ad copy is not, on the Article 6 test.
- It does not attach to a form factor. A chatbot is not high-risk for being a chatbot. The same interface is high-risk when it screens job applicants under Annex III point 4 and outside Article 6 when it answers questions about opening hours. Intended purpose decides it.
- It is not only the vendor's problem. Deployers carry their own obligations, and three acts flip a deployer into a provider under Article 25, with the full Article 16 set attached. The roles guide sets out which acts do it, putting your own name on the system among them.
- It is not an EU-only concern. Article 2 reaches a provider with no EU establishment the moment the output of the system is used in the Union. See the extraterritorial scope guide for the test as it applies to US companies.
What high-risk AI actually looks like
The Annex III list reads abstractly and lands concretely. These are ordinary business systems, most of them bought rather than built:
- Employment, point 4. Applicant tracking that ranks candidates, targeted job advertising, CV filtering, interview scoring, promotion and termination decisions, shift allocation and productivity monitoring. Broadest in practice, because every organisation of any size hires and manages people. Worked through in the recruitment and HR guide.
- Essential services, point 5. Credit scoring and credit checks are named expressly, as are risk assessment and pricing in health and life insurance, and systems that decide eligibility for public benefits. See the credit and insurance guide.
- Education, point 3. Admissions and course allocation, automated exam scoring, systems that evaluate learning outcomes, remote proctoring during a test.
- Biometrics, point 1. Remote biometric identification, biometric categorisation and emotion recognition, with the caveat that several biometric uses are prohibited outright under Article 5 rather than merely high-risk.
- The Annex I route. AI inside regulated products: medical devices and toys remain fully in scope. AI embedded in Machinery Regulation products received a targeted carve-out from the AI Act high-risk rules, with AI-specific requirements layered into the Machinery Regulation instead, which moves the requirements rather than deleting them.
Falling in an Annex III area is not always the end of it. Article 6(3) lets a provider conclude that such a system is not high-risk where it poses no significant risk of harm and meets one of four conditions, but a system that performs profiling of natural persons is always high-risk, with no balancing exercise available. The derogation guide covers where that exit gets over-claimed.
What the label costs once it attaches
Classification is the cheap part. What follows is Articles 9 to 15: a risk management system running across the lifecycle, data governance for training, validation and testing sets, technical documentation against the nine Annex IV blocks drawn up before market placement, automatic logging, instructions for use directed at deployers, human oversight designed into the system, and an appropriate level of accuracy, robustness and cybersecurity. On top sit the Article 43 conformity assessment, which may route through a notified body and put a third party on your critical path, the Article 47 declaration of conformity and Article 49 registration in the EU database.
The derogation does not clear the paperwork. Article 6(4) requires the assessment to be documented before the system is placed on the market, not produced afterwards when an authority asks. Under the Digital Omnibus, a system the provider self-assesses as not high-risk must still be registered in the EU database: the Commission proposed dropping that duty and it did not survive negotiations.
Getting the classification wrong sits in the middle Article 99 tier, €15,000,000 or 3% of total worldwide annual turnover, the higher figure for companies and the lower for SMEs and start-ups under Article 99(6). Supplying incorrect, incomplete or misleading information to an authority is its own tier at €7,500,000 or 1%, which is what a badly evidenced classification file exposes you to on top of the underlying breach. The penalty breakdown covers who enforces which tier.
When high-risk starts to bite, and what already binds
The Digital Omnibus split the original single date by route, so the high-risk regime arrives in two waves:
A later date is not a stand-down. The Article 5 prohibitions and the Article 4 AI-literacy duty have bound since 2 February 2025, the general-purpose model chapter and the penalty provisions since 2 August 2025, and the Article 50 transparency duties land on 2 August 2026 whatever your risk tier. A risk management system, an Annex IV file and a notified-body assessment are multi-quarter projects, which is why teams that paused their programmes on the headline that deadlines moved have less runway than the calendar suggests.
One caveat on the dates themselves. The Digital Omnibus was adopted by the European Parliament on 16 June 2026 and by the Council on 29 June 2026, and was signed on 8 July 2026, but it had not been published in the Official Journal as at the 22 July 2026 review date, and it enters into force on the third day after publication. The amended dates are agreed and final in substance, while the consolidated text and the final regulation number are not yet authoritative. The full application timeline tracks each date as it settles.
Telling whether your own system is high-risk
The order matters more than the effort. Run it like this:
- Write the intended purpose down. One specific paragraph describing what the system is intended to be used for and by whom. Every step below reads from it, and a vague purpose statement is the most common cause of a wrong answer.
- Confirm scope. Article 2 excludes exclusive military, defence and national-security use, scientific research and development before market placement, and purely personal non-professional use, and reaches you when output is used in the Union.
- Screen Article 5. Prohibited practices first, always. That is the €35,000,000 or 7% tier, and it has been live since February 2025.
- Run both Article 6 routes in parallel. Annex I product plus third-party conformity assessment, and the eight Annex III areas. Record each answer.
- If Annex III bites, test profiling before the derogation. Profiling ends the analysis. Otherwise work the significant-risk gate and the four conditions, and document the result under Article 6(4).
- Fix your role. Provider, deployer, importer, distributor, product manufacturer or authorised representative, and you can hold more than one at once.
The free classifier walks these stages in order and returns the article each determination rests on, which gives you the skeleton of the record Article 6(4) expects either way. For a genuinely contested classification the missing Commission guidance means counsel and a paper trail, not a confident answer. The primary text is Regulation (EU) 2024/1689 on EUR-Lex.