High-Risk AI Classification
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal โ legal information, not advice.The content specifically addresses classification rules for high-risk AI systems under the AI Act, which is a distinct regulatory concept requiring its own dedicated topic beyond the general 'AI Risk Assessment' category.
Overview
9 sources ยท Jul 23, 2026High-Risk AI Classification
Legal Framework
The AI Act establishes a risk-tiered regulatory architecture, with high-risk AI systems subject to the most extensive obligations. Classification as high-risk triggers the full suite of provider and deployer duties, making accurate categorisation the decisive compliance question for any organisation developing or deploying AI.
Article 6 of the AI Act sets out two pathways to high-risk classification. First, Article 6(1) captures AI systems that serve as safety components of products, or are themselves products, covered by existing Union harmonisation legislation listed in Annex I โ including machinery, medical devices, vehicles, and toys. These systems are high-risk regardless of their specific application context, because the underlying product safety framework already presupposes significant harm potential.
Second, Article 6(2) designates as high-risk any AI system falling within the use cases enumerated in Annex III. These span eight domains: biometric identification and categorisation, critical infrastructure management, education and vocational training, employment and self-employment, essential private and public services, law enforcement, migration and border control, and the administration of justice and democratic processes. The Annex III listing is exhaustive โ an AI system not covered by Annex I or Annex III is not high-risk, even if it presents meaningful risks.
Article 7 provides the Commission with delegated authority to expand Annex III through implementing acts, applying defined criteria including the potential for harm to health, safety, or fundamental rights, the extent of deployment, and whether the system influences decision-making in ways that produce significant effects on persons. This dynamic mechanism means the high-risk perimeter is not static.
Article 71 establishes an EU database for high-risk AI systems listed in Annex III, requiring providers to register their systems before market placement. This registration obligation itself operates as a compliance checkpoint โ if a system must be registered, it is high-risk.
Once classified as high-risk, the obligations cascade across the supply chain. Article 22 imposes requirements on authorised representatives of providers, ensuring a designated EU-based point of accountability. Article 26 governs deployers, requiring fundamental rights impact assessments, human oversight measures, and incident reporting โ obligations that apply downstream from the provider's conformity assessment duties.
Key Developments
The AI Act entered into force on 1 August 2024, with high-risk system obligations becoming applicable on 2 August 2026. No enforcement decisions have yet been issued, as supervisory authorities are still being designated and operationalised across Member States. The European AI Office is developing guidance on classification methodology, but no formal interpretive notices have been published on the Annex III boundaries.
A February 2026 civil society initiative urged legislators to preserve transparency safeguards in the AI Act, reflecting ongoing political pressure around the scope of obligations applicable to high-risk systems โ particularly in the context of law enforcement and border control exemptions.
Practical Guidance
Map your system against Annex III before deployment. The Annex III use cases are specific and technical โ a system used in recruitment is high-risk under Annex III(4), but the same algorithm used for internal workforce planning may not be. The intended purpose declared at market placement is determinative, not the technical capability alone.
Assess whether your system qualifies as a safety component under Annex I. If your AI system is integrated into or functions as a safety element of a regulated product (e.g., medical device software under the MDR), it inherits high-risk status through Article 6(1) without needing Annex III analysis.
Prepare for EU database registration under Article 71. Providers of Annex III systems must register before placing them on the market. Deployers of certain Annex III systems โ particularly in law enforcement โ also face registration duties. Build registration into your go-to-market timeline.
Designate an authorised representative under Article 22 if you are a non-EU provider. This must occur before the system enters the EU market and requires a written mandate covering conformity assessment obligations.
Conduct a fundamental rights impact assessment as a deployer under Article 26. This is mandatory for deployers of high-risk systems in sectors such as employment, credit, and essential services, and must document the specific risks to affected persons and the mitigation measures adopted.