HIGH-RISK SYSTEMS

High-risk AI systems: who they cover and from when

Most companies using AI do not have a high-risk system. But a fair share of those that do have no idea - because one department bought the tool and nobody checked which category that put the company in. Here we set out how to recognise it and what follows from it.

Where the high-risk category comes from

The AI Act does not sort companies by industry. It sorts use cases. Whether a system is high-risk depends on what it is used for, not on how advanced the technology underneath happens to be.

The classification rules are set out in Article 6 of the AI Act , and there are two routes into the category. The first is a use case listed in Annex III: recruitment, education, credit scoring, access to public services and a few other areas. The second is AI embedded in a product that is already covered by separate EU safety legislation - that is Annex I.

Most companies using AI do not have a high-risk system. The catch is that you cannot know until someone walks through the list of use cases.

How companies end up here unknowingly

Not through a big AI project. Through a tool one department bought because it saved two days of work a month.

Recruitment

The most common case by far. A tool that screens CVs, scores candidates or ranks them is a high-risk system - even where a human makes the final call. It also covers targeted placement of job advertisements. HR buys it independently, usually on a subscription, and nobody in the company registers that the organisation has just entered Annex III.

Managing people

Systems that evaluate performance, allocate tasks or monitor workers. The provision covers decisions affecting terms of employment, promotion and termination.

Finance and insurance

Creditworthiness assessment and credit scoring of individuals, plus risk assessment and pricing in life and health insurance.

Education

Decisions on admission to an institution, assessment of learning outcomes, and detection of prohibited behaviour during tests.

Public services and social support

Assessing eligibility for essential public benefits and services, including healthcare.

Safety and critical infrastructure

Classifying emergency calls and prioritising the dispatch of first-response services, and managing critical infrastructure.

The full list of use cases is in Annex III to the AI Act .

What it involves

The high-risk regime is markedly wider than the obligations that apply today to any company using AI. In short, without reprinting the regulation:

  • A risk management system maintained across the entire lifecycle of the system (Article 9 AI Act).
  • Event logging and retention of logs (Article 12 AI Act).
  • Human oversight - real, with the ability to intervene, not on paper (Article 14 AI Act).
  • Deployer obligations: use in line with the provider's instructions, monitoring, informing workers, retaining logs (Article 26 AI Act).
  • On the provider side, conformity assessment of the system before it is placed on the market (Article 43 AI Act).
  • In some cases, a certificate issued by a notified body (Article 44 AI Act).

Fundamental rights impact assessment (FRIA)

This obligation is often over-simplified, so it is worth being precise. Article 27 of the AI Act does not cover every deployer of a high-risk system. It applies to bodies governed by public law, private entities providing public services, and deployers of systems used for creditworthiness assessment and credit scoring of individuals, or for risk assessment and pricing in life and health insurance.

Deadlines

  1. 2 December 2027

    obligations for stand-alone high-risk systems, i.e. those classified by use case (Annex III).

  2. 2 August 2028

    obligations for AI embedded in products covered by Annex I.

Both dates were moved by Regulation 2026/1744, the Digital Omnibus on AI , which entered into force on 27 July 2026. The first of them previously fell in August 2026. The current implementation timeline is published by the European Commission .

Why the delay is not a reason to wait

Sixteen months sounds like a lot. In practice it means the advisory, audit and legal market will be booked solid through the second half of 2027, and you will be standing in the same queue as everyone else.

On top of that, the delay touches nothing outside the high-risk regime. The AI literacy obligation has applied since February 2025, the prohibited practices likewise, transparency obligations since August 2026, and from 28 October 2026 the Polish supervisory authority can accept complaints and carry out inspections. A company with a high-risk system is subject to all of these today, exactly like everyone else - the stakes are simply higher.

The one thing worth doing right away is establishing whether you are in this category at all. That can be done now and does not depend on anything else.

What we can do today, and what we are building

Today

  • Classifying your AI use cases and establishing whether any fall under Annex III
  • An inventory of the AI tools used across the organisation
  • AI usage policies and rules, with employee acknowledgements
  • AI Literacy training for teams, with an exam and a certificate
  • Documenting the obligations that already apply now

In preparation

  • Support for the Article 9 risk management system
  • Technical documentation
  • Human oversight procedures
  • Fundamental rights impact assessment (FRIA)

We are not pretending to have a finished package for the high-risk regime today. Leave us your details if you want to be first to know when it is ready.

Independently of us, the European Commission offers its own classification tool: the EU AI Act compliance checker . It ends with a list of obligations. We help you carry them out.

Let us check whether this applies to you

Write to us with your organisation name and which of the use cases above might apply to you. We reply within one business day. The first conversation is free and does not end in a quote if it turns out you are not in this category.

Where it starts

Whether or not you are in the high-risk category: the AI literacy obligation has applied to you since February 2025, and transparency obligations since August 2026. A company with a high-risk system is subject to them just the same, only more urgently.

You keep the AI tool register, policies and records of action in the AI Governance platform, included in the price of your training licence.

FAQ

Frequently asked questions

  • How do I know whether we have a high-risk system?

    You go through the list of use cases in Annex III and compare it with what you actually use AI for. The most common way into this category is a recruitment tool bought by HR - CV screening, candidate scoring, ranking. Classification is done today, regardless of the obligations themselves starting later.

  • Does the deadline shift mean we are fine until 2027?

    No. Only the obligations for high-risk systems moved. The AI literacy obligation has applied since February 2025, the prohibited practices likewise, and transparency obligations since 2 August 2026. A company with a high-risk system is subject to them exactly like everyone else.

  • We are only a deployer, we bought an off-the-shelf tool. Does this apply to us?

    Yes, though more narrowly than to a provider. A deployer of a high-risk system has its own set of obligations under Article 26 of the AI Act: use in line with the provider's instructions, monitoring how the system operates, informing workers and retaining logs. Conformity assessment and certificates stay on the provider's side.

  • Does everyone with a high-risk system have to carry out a FRIA?

    No, and this is a common over-simplification. The fundamental rights impact assessment covers bodies governed by public law, private entities providing public services, and those deploying systems for creditworthiness assessment and credit scoring of individuals, or for risk assessment and pricing in life and health insurance. The scope is set out in Article 27 of the AI Act.

  • What exactly can you do for us today?

    Classification of your AI use cases, an inventory of your tools, AI usage policies, training for your teams and documentation of the obligations that already apply. Full support for the high-risk regime - risk management system, technical documentation, human oversight procedures, FRIA - is in preparation, and we do not pretend otherwise.

  • Is classification the same thing as the AI Ready Check?

    No. The AI Ready Check is a free preliminary diagnosis in your browser that points you in a direction within minutes. Classifying use cases against Annex III is work on your real tools and processes, which we do together with you.

Have another question? Get in touch →

Not sure where to start?

Check in 3 minutes which AI Act obligations apply to your organisation. No commitment.

The AI Act is now in force. Transparency obligations under Article 50 of the AI Act have applied since 2 August 2026, and the European Commission has started enforcing the rules. Documented diligence is what counts.
Check your AI Act readiness →