UnicornWay
EU AI Act High-Risk AI Risk Assessment

High-Risk AI Under the EU AI Act: A Classification Checklist

Alexandre Boels 3 min read

“High-risk” is where the EU AI Act concentrates its regulatory firepower — and where misclassification is most costly in both directions: miss it and you face fines and forced withdrawal; over-classify and you burden your roadmap with unnecessary compliance work. Here is how the classification actually works.

The two routes to high-risk status

An AI system is high-risk if either of these applies:

Route 1 — Annex I (products). The AI is a product, or a safety component of a product, covered by EU harmonisation legislation that requires third-party conformity assessment — machinery, medical devices, in-vitro diagnostics, vehicles, aviation, toys, lifts, radio equipment, and similar. Deadline: 2 August 2027.

Route 2 — Annex III (use cases). The system is used in one of eight listed areas. Deadline: 2 August 2026.

The Annex III checklist

Work through each category and ask: does any of our AI systems do this?

  1. Biometrics — remote biometric identification, biometric categorisation, emotion recognition
  2. Critical infrastructure — safety components in traffic, water, gas, heating, electricity, and critical digital infrastructure
  3. Education & vocational training — admission, evaluation, exam proctoring, level assignment
  4. Employment & worker management — recruitment, CV filtering, candidate evaluation, promotion/termination decisions, task allocation, monitoring
  5. Essential services — creditworthiness scoring, risk assessment and pricing in life/health insurance, eligibility for public benefits, emergency-call triage
  6. Law enforcement — risk assessments, evidence-reliability evaluation, profiling
  7. Migration, asylum & border control — application examination, risk assessments
  8. Administration of justice & democratic processes — assisting judicial authorities, influencing elections

For most private-sector companies, the traps are #4 (HR tech) and #5 (credit and insurance) — often via off-the-shelf tools the business barely thinks of as “AI systems.”

The Article 6(3) escape hatch — use with care

An Annex III system is not high-risk if it does not pose a significant risk to health, safety, or fundamental rights — specifically where it only:

  • performs a narrow procedural task,
  • improves the result of a previously completed human activity,
  • detects decision-making patterns without replacing or influencing human assessment, or
  • performs a preparatory task for a relevant assessment.

Two caveats: profiling of natural persons is always high-risk, and if you rely on the derogation you must document the assessment and register the system — this is a justified, auditable decision, not a quiet opt-out.

If you land in high-risk: the obligations

As a provider (Articles 8–17): risk-management system · data governance and bias controls · technical documentation · automatic logging · transparency and instructions for deployers · human-oversight design · accuracy, robustness, cybersecurity · quality-management system · conformity assessment and CE marking · registration in the EU database · post-market monitoring and incident reporting.

As a deployer (Article 26): operate per the provider’s instructions · assign competent, trained human oversight · ensure relevant input data quality · monitor and suspend on incidents · keep logs · inform affected workers · and, for public bodies and some private deployers, a fundamental-rights impact assessment before first use.

Practical advice

  1. Classify per use case, not per tool. The same model can be minimal-risk in one workflow and high-risk in another.
  2. Interrogate your vendors. For procured tools, you need their conformity documentation — and your deployer duties remain yours.
  3. Document borderline calls. An Article 6(3) judgement without a written assessment is a liability, not a defence.
  4. Start from the deadline and work backwards. Conformity assessment and QMS build-out take months, and the Annex III deadline is 2 August 2026.

Unsure which side of the line your systems fall on? A gap analysis against the risk tiers is the first module of our EU AI Act Delivery Workshop.

Frequently Asked Questions

What counts as high-risk AI under the EU AI Act?

Two routes lead to high-risk status: (1) the AI is a safety component of a product covered by EU harmonisation legislation listed in Annex I (machinery, medical devices, vehicles…), or (2) the use case appears in Annex III — biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, or administration of justice.

Is an AI tool used for recruitment automatically high-risk?

AI systems used to recruit or select candidates — placing targeted job ads, filtering applications, evaluating candidates — are explicitly listed in Annex III and are therefore high-risk, unless the narrow Article 6(3) derogation applies (for example, the system only performs a preparatory or narrow procedural task and does not materially influence the decision). Profiling of individuals is always high-risk.

What must we do if our system is high-risk?

Providers must implement a risk-management system, data governance, technical documentation, logging, transparency to deployers, human oversight, and accuracy/robustness/cybersecurity measures — plus a quality-management system, conformity assessment, CE marking, and registration in the EU database. Deployers must use the system per instructions, ensure trained human oversight, and monitor operation.

When do high-risk obligations start to apply?

Annex III high-risk systems must comply from 2 August 2026. High-risk AI that is a safety component of Annex I regulated products has until 2 August 2027.

This guide is provided for general information and does not constitute legal advice. Regulatory details evolve — verify current requirements against official EU sources or seek qualified counsel for decisions affecting your organisation.

Turn this guide into your compliance roadmap

Our EU AI Act Delivery Workshop maps your AI systems to risk tiers and leaves your team with a prioritised, actionable plan.

Book a Workshop