What makes an AI system high-risk under the EU AI Act?
Under the EU AI Act (Regulation (EU) 2024/1689), an AI system is high-risk in one of two situations. First, where it is intended to be used as a safety component of a product — or is itself a product — covered by the Union harmonisation legislation listed in Annex I, and that product must undergo a third-party conformity assessment. Second, where its intended purpose falls within one of the use cases listed in Annex III, such as employment, education, biometrics, or access to essential services.
- •Everything else is either a prohibited practice, a system subject only to transparency obligations, or a system with no specific obligations beyond general law. Classification is therefore not a formality: it is the gate that decides whether an organisation carries the full high-risk obligation set or a much lighter one.
Route one: AI as a safety component of a regulated product
This route matters for manufacturers. If your organisation already places products on the EU market under legislation such as the Machinery Regulation, medical devices rules, lifts, radio equipment, or toy safety — the sectoral regimes listed in Annex I — then AI embedded in those products as a safety component may be high-risk under the AI Act.
In practice, the AI Act obligations are designed to be integrated into the conformity assessment you already run for the product, rather than duplicated alongside it. The trigger condition is that the product is required to undergo third-party conformity assessment under that sectoral legislation.
For a typical software SME with no CE-marked hardware, this route is usually not relevant. Check it once, record the conclusion, and move on to Annex III.
Route two: the eight Annex III areas in plain language
Annex III lists standalone use cases. Read it as a list of contexts where an automated decision can materially affect a person's life chances, safety, or rights.
- Biometrics — including remote biometric identification, biometric categorisation, and emotion recognition, to the extent permitted at all.
- Critical infrastructure — safety components in the management and operation of road traffic, or the supply of water, gas, heating and electricity.
- Education and vocational training — admission decisions, evaluating learning outcomes, assessing the appropriate level of education, and monitoring prohibited behaviour during tests.
- Employment and worker management — CV screening and candidate filtering, targeted job advertising, and decisions on promotion, termination, task allocation, or performance monitoring.
- Access to essential private and public services — eligibility for public benefits, creditworthiness and credit scoring, risk assessment and pricing in life and health insurance, and emergency call triage.
- Law enforcement — for example, assessing the risk of a person offending or the reliability of evidence, where permitted.
- Migration, asylum and border control — including risk assessments, examination of applications, and verification of travel documents.
- Administration of justice and democratic processes — assisting judicial authorities in researching and interpreting facts and law, and systems intended to influence election outcomes or voting behaviour.
- •Two areas catch far more SMEs than they expect: employment and worker management, and access to essential services. A recruitment tool that ranks applicants, an internal system that scores staff performance, or a lending workflow that scores an applicant's creditworthiness will normally sit inside Annex III, regardless of how modest the software is.
What is the Article 6(3) exemption, and when can you rely on it?
Article 6(3) is the safety valve. A system that falls within an Annex III area is not high-risk where it does not pose a significant risk of harm to the health, safety, or fundamental rights of natural persons, including by not materially influencing the outcome of decision-making.
The Regulation sets out the conditions under which this applies, in substance where the system:
- performs a narrow procedural task — for example, converting unstructured application text into a structured format;
- improves the result of a previously completed human activity — for example, tidying the language of a decision already taken by a person;
- detects decision-making patterns or deviations from prior patterns, without replacing or influencing the human assessment already made; or
- performs a preparatory task to an assessment relevant to an Annex III use case.
- •Relying on Art. 6(3) is a documented act. A provider that concludes a system is exempt documents that assessment before the system is placed on the market or put into service, registers the system in the EU database, and provides the documentation to national competent authorities on request. In practice, an undocumented exemption is indistinguishable from an unclassified system.
A decision path you can run per system
Six questions, in order
- 1. Is it an AI system as defined in the Regulation? Deterministic rule-based scripts with no inference may fall outside the definition — record why.
- 2. Does it involve a prohibited practice under the Act? If so, no classification exercise saves it; the use has to stop.
- 3. Is it a safety component of, or itself, a product under the Annex I harmonisation legislation requiring third-party conformity assessment? If yes, high-risk.
- 4. Does the intended purpose fall within any Annex III area? Write the intended purpose down in one sentence first, then match it.
- 5. If yes, does one of the Art. 6(3) conditions genuinely apply, and does the system avoid profiling natural persons? Document the reasoning either way.
- 6. Whatever the outcome, check Art. 50 transparency duties separately — they apply independently of risk classification.
Run this per system and per intended purpose, not per vendor. One supplier may provide you with one out-of-scope tool and one Annex III tool. Note your role for each: provider, deployer, importer, or distributor — the obligations differ, and an SME that materially modifies a purchased system or puts its own name on it can become a provider.
Is my chatbot a high-risk AI system?
Usually not. A chatbot that answers product questions, books appointments, or searches internal documentation does not fall within an Annex III area, so it is not high-risk. It does, however, fall under Art. 50: people interacting with an AI system are to be informed of that fact, unless it is obvious to a reasonably well-informed person in the circumstances. Synthetic content also carries marking obligations.
- •The chatbot becomes a classification question when it is placed inside an Annex III context. A conversational front end that screens job applicants sits in the employment area. One that determines eligibility for a public benefit sits in essential services. One that triages emergency calls is expressly covered. In each case, the conversational interface is incidental — the decision it feeds is what counts.
Why classification is the step everything depends on
The high-risk obligation set — risk management, data and data governance, technical documentation, record-keeping, instructions for use, human oversight, accuracy and robustness, quality management, conformity assessment, and EU database registration — is entirely conditional on classification. Getting it wrong in either direction is costly: over-classify and an SME spends months on a tool that needed a transparency notice; under-classify and the whole downstream file rests on a false premise.
Timing matters as well. The prohibitions and AI literacy provisions have applied since 2 February 2025, and the general-purpose AI model rules since 2 August 2025. The main body of obligations, including much of the high-risk regime, applies from 2 August 2026, with a later date for high-risk AI embedded in regulated products. Classification decisions taken now determine how much work sits between an organisation and those dates.
Practically, keep a system inventory with one row per AI system: intended purpose, your role, classification outcome, the Annex III area or the Art. 6(3) condition relied on, the date, and who signed it off. Revisit each row when the intended purpose changes. This article is general information about the Regulation, not legal advice.