High-risk AI systems under the EU AI Act: what it is and who needs to worry

High-risk AI systems under the EU AI Act: what it is and who needs to worry

Table of Contents

TL;DR: The EU AI Act regulates high-risk AI systems rather than banning them, and the label applies to more everyday tools than you might expect, including hiring software, credit scoring, and biometric identification. The compliance deadline for most of these systems has been postponed from August 2026 to December 2027, but the underlying work of documenting data sources, testing for bias, and building in human oversight still takes months to do properly.

Have you heard the term 'high-risk AI system' and wondered if it applies to you? If so, you're in the right place. The label covers more everyday tools than most people realize, and under the EU AI Act, the responsibility to check falls on you. Keep reading for a breakdown of what models this applies to and what it actually means for your team.

What "high risk" actually means

The Act sorts AI systems into four tiers: unacceptable, high, limited, and minimal risk. Unacceptable-risk systems, like social scoring or manipulative subliminal techniques, are banned outright. High-risk systems can still operate, but they come with obligations attached including documented risk assessments, technical documentation, and ongoing human oversight, all before and after you deploy.

There are two paths that land your system in the high-risk category, as defined in Article 6 of the Act.

The first is Annex I: if your AI system is a safety component in a product already regulated by the EU, like a medical device or piece of machinery that requires third-party safety checks, that component is high-risk too.

The second, Annex III, is the one that catches most people off guard. It automatically classifies these stand-alone use cases as high-risk:

  • Biometric identification
  • Critical infrastructure
  • Education and vocational training
  • Employment and worker management
  • Access to essential services, like credit or insurance
  • Law enforcement
  • Migration
  • Justice

It's reasonable to look at your system and conclude it isn't actually risky in practice, and you might be right. But this law doesn't let you stop there. You have to document that assessment before you deploy the system. Not writing it down doesn't protect you, and neither does not knowing you needed to. That obligation lands on you whether you built the system or you're just the one deploying it.

Who this applies to

This applies to you if you deploy one of these systems in the EU, no matter where you're based, as long as the system's output reaches the EU market. That covers AI vendors and everyday users of AI tools alike.

Some recognizable examples:

  • A resume screening tool that ranks or filters candidates falls under employment and worker management
  • A performance evaluation model that feeds into promotion or termination decisions falls under the same category
  • A credit scoring engine used to approve or deny loans falls under access to essential services
  • An emotion recognition tool, or a system that verifies someone's identity through biometric data, falls under biometrics directly

For contrast, a customer service chatbot that just answers questions isn't high-risk. It faces lighter transparency obligations instead, mainly disclosing that people are talking to AI.

Once you know you're in scope, the next question is when to start addressing these regulations.

What changed with the compliance timeline

The original deadline for Annex III obligations was August 2, 2026. That date has been postponed.

In May 2026, EU negotiators reached a provisional deal on a package of amendments known as the Digital Omnibus on AI. The European Parliament endorsed it on June 16, and the Council gave final approval on June 29. The amendment is expected to publish in the EU's Official Journal by early August, setting the new dates: December 2, 2027, for Annex III stand-alone systems, and August 2, 2028, for Annex I embedded systems.

Either way, the delay doesn't remove the obligation: documentation, data governance, and human oversight take real time to build, regardless of exactly which date lands. Article 50 transparency requirements, covering disclosure of AI-generated content, are unaffected and still apply from August 2, 2026.

What high-risk obligations actually require

High-risk classification comes with a concrete set of requirements:

  • A documented risk management system covering the AI system's full lifecycle
  • Technical documentation detailed enough for a regulator to assess compliance without guesswork
  • Automatic logging that records events relevant to spotting problems after deployment
  • Data governance showing your training and evaluation data is relevant, representative, and reasonably free of errors
  • Human oversight, with real authority to catch and correct what the model outputs

Data governance is the piece that's easy to underestimate. A regulator reviewing your documentation looks past what data went in and checks who produced it and under what process. Being able to answer that clearly protects both your compliance standing and your reputation.

How PowerToFly AI fits in

When we talk to clients about high-risk classification, we point them to the human oversight and data governance requirements first, since that's where representative, domain-qualified review teams matter most. We draw on 65K+ AI specialists across our 1.1M-member community to staff the model evaluation, bias testing, and RLHF (Reinforcement Learning from Human Feedback) work your systems require, pulling reviewers from a wider pool than the one that built your model.

FAQ

What is a high-risk AI system under the EU AI Act?

Broadly, a system that serves as a safety component in an already-regulated product, like a medical device, or one built for specific use cases like hiring, credit scoring, or biometric identification. For how this fits into the Act's full four-tier risk framework, see our EU AI Act compliance guide.

What happens if your high-risk AI system doesn't comply?

Fines can reach 15 million euros or three percent of global annual turnover, whichever is higher, for most high-risk violations.

How can you tell if your AI system qualifies as high-risk?

Check whether it falls into one of the Annex III categories, like critical infrastructure, employment decisions, or law enforcement, or serves as a safety component in an Annex I product, like a medical device. If it's unclear, document your assessment anyway, since that documentation is itself a requirement.

Still unsure if this applies to you? Chat with one of our team members to find out.

You may also like View more articles
Open jobs See all jobs
Author


The Human Gap - Why most AI initiatives fail