# High-Risk AI Classification — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/high-risk-ai-classification
> Sources are cited per item. Verify against the official texts before relying on them.

The content specifically addresses classification rules for high-risk AI systems under the AI Act, which is a distinct regulatory concept requiring its own dedicated topic beyond the general 'AI Risk Assessment' category.

## Overview

## High-Risk AI Classification

## Legal Framework

The AI Act establishes a risk-tiered regulatory architecture, with high-risk AI systems subject to the most extensive obligations. Classification as high-risk triggers the full suite of provider and deployer duties, making accurate categorisation the decisive compliance question for any organisation developing or deploying AI.

Article 6 of the AI Act sets out two pathways to high-risk classification. First, Article 6(1) captures AI systems that serve as safety components of products, or are themselves products, covered by existing Union harmonisation legislation listed in Annex I — including machinery, medical devices, vehicles, and toys. These systems are high-risk regardless of their specific application context, because the underlying product safety framework already presupposes significant harm potential.

Second, Article 6(2) designates as high-risk any AI system falling within the use cases enumerated in Annex III. These span eight domains: biometric identification and categorisation, critical infrastructure management, education and vocational training, employment and self-employment, essential private and public services, law enforcement, migration and border control, and the administration of justice and democratic processes. The Annex III listing is exhaustive — an AI system not covered by Annex I or Annex III is not high-risk, even if it presents meaningful risks.

Article 7 provides the Commission with delegated authority to expand Annex III through implementing acts, applying defined criteria including the potential for harm to health, safety, or fundamental rights, the extent of deployment, and whether the system influences decision-making in ways that produce significant effects on persons. This dynamic mechanism means the high-risk perimeter is not static.

Article 71 establishes an EU database for high-risk AI systems listed in Annex III, requiring providers to register their systems before market placement. This registration obligation itself operates as a compliance checkpoint — if a system must be registered, it is high-risk.

Once classified as high-risk, the obligations cascade across the supply chain. Article 22 imposes requirements on authorised representatives of providers, ensuring a designated EU-based point of accountability. Article 26 governs deployers, requiring fundamental rights impact assessments, human oversight measures, and incident reporting — obligations that apply downstream from the provider's conformity assessment duties.

## Key Developments

The AI Act entered into force on 1 August 2024, with high-risk system obligations becoming applicable on 2 August 2026. No enforcement decisions have yet been issued, as supervisory authorities are still being designated and operationalised across Member States. The European AI Office is developing guidance on classification methodology, but no formal interpretive notices have been published on the Annex III boundaries.

A February 2026 civil society initiative urged legislators to preserve transparency safeguards in the AI Act, reflecting ongoing political pressure around the scope of obligations applicable to high-risk systems — particularly in the context of law enforcement and border control exemptions.

## Practical Guidance

- **Map your system against Annex III before deployment.** The Annex III use cases are specific and technical — a system used in recruitment is high-risk under Annex III(4), but the same algorithm used for internal workforce planning may not be. The intended purpose declared at market placement is determinative, not the technical capability alone.

- **Assess whether your system qualifies as a safety component under Annex I.** If your AI system is integrated into or functions as a safety element of a regulated product (e.g., medical device software under the MDR), it inherits high-risk status through Article 6(1) without needing Annex III analysis.

- **Prepare for EU database registration under Article 71.** Providers of Annex III systems must register before placing them on the market. Deployers of certain Annex III systems — particularly in law enforcement — also face registration duties. Build registration into your go-to-market timeline.

- **Designate an authorised representative under Article 22 if you are a non-EU provider.** This must occur before the system enters the EU market and requires a written mandate covering conformity assessment obligations.

- **Conduct a fundamental rights impact assessment as a deployer under Article 26.** This is mandatory for deployers of high-risk systems in sectors such as employment, credit, and essential services, and must document the specific risks to affected persons and the mitigation measures adopted.

## Legislation (full text of key provisions)

### EU database for high-risk AI systems listed in Annex III

*Source: AI Act, aiact-art-71-en, 2024-06-12 — https://overview.legal/posts/93161*

### Classification rules for high-risk AI systems

*Source: AI Act, aiact-art-6-en, 2024-06-12 — https://overview.legal/posts/92035*

### Obligations of providers of high-risk AI systems

*Source: AI Act, aiact-art-16-en, 2024-06-12 — https://overview.legal/posts/92242*

Providers of high-risk AI systems shall:

### Fundamental rights impact assessment for high-risk AI systems

*Source: AI Act, aiact-art-27-en, 2024-06-12 — https://overview.legal/posts/92424*

### Authorised representatives of providers of high-risk AI systems

*Source: AI Act, aiact-art-22-en, 2024-06-12 — https://overview.legal/posts/92312*

### Obligations of deployers of high-risk AI systems

*Source: AI Act, aiact-art-26-en, 2024-06-12 — https://overview.legal/posts/92382*

### Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes

*Source: AI Act, aiact-art-60-en, 2024-06-12 — https://overview.legal/posts/92962*

### Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems

*Source: AI Act, aiact-art-72-en, 2024-06-12 — https://overview.legal/posts/93175*

### Prohibited AI practices

*Source: AI Act, aiact-art-5-en, 2024-06-12 — https://overview.legal/posts/91996*

### Procedure for dealing with AI systems classified by the provider as non-high-risk in application of Annex III

*Source: AI Act, aiact-art-80-en, 2024-06-12 — https://overview.legal/posts/93332*

## Recent developments

### A call to EU legislators: protect rights and reject the call to delete transparency safeguard in AI Act

*Source: Access Now, 2026-02-10 — https://overview.legal/posts/52552 — original: https://www.accessnow.org/press-release/a-call-to-eu-legislators-protect-transparency-safeguard-in-ai-act/*

We, the undersigned organisations and individuals, urge you in the strongest possible terms to reject the deletion of the Article 49(2) transparency safeguard for high-risk AI systems that is proposed in the AI Omnibus. This transparency safeguard ensures that providers of AI systems cannot circumvent the core obligations of the AI Act.

### The AI Act isn&#8217;t enough: closing the dangerous loopholes that enable rights violations

*Source: European Digital Rights, 2025-11-13 — https://overview.legal/posts/49203 — original: https://edri.org/our-work/the-ai-act-isnt-enough-closing-the-dangerous-loopholes-that-enable-rights-violations/*

While the EU's AI Act aims to regulate high-risk AI systems, it is undermined by major loopholes that allow their unchecked use in the context of national security and law enforcement. These exemptions risk enabling, among others, mass surveillance of protests and discriminatory migration practices. To prevent this, EDRi affiliate Danes je nov dan has published recommendations for Slovenia to adopt stricter national safeguards and transparent oversight mechanisms. The post The AI Act isn&#8217;t

### Is the AI Act caging ChatGPT and other General Purpose Artificial Intelligence systems?

*Source: Gaming Tech Law, 2023-03-29 — https://overview.legal/posts/6223 — original: https://www.gamingtechlaw.com/2023/03/draft-ai-act-general-purpose-artificial-intelligence/#entry-4244*

> The growth of generative artificial intelligence systems has led EU lawmakers to focus on General Purpose AI in drafting the AI Act, which will set the framework governing artificial intelligence in the European Union. As previously reported, the EU Parliament has already broadened the definition of artificial intelligence for the purposes of the AI Act…

## Related topics

- **Annex III Amendments** — https://overview.legal/topics/annex-iii-amendments
  This new topic is needed because amendments to Annex III represent specific regulatory changes to the AI Act's classification framework that warrant dedicated t
- **AI Risk Assessment** — https://overview.legal/topics/ai-risk-assessment
  The AI Act employs a risk-based regulatory approach to determine which practices are prohibited, requiring assessment and classification of AI system risks, whi
- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection
- **AI Value Chain Actors and Roles** — https://overview.legal/topics/ai-value-chain-actors
  The content focuses on responsibilities distributed across different actors in the AI value chain. A dedicated topic for understanding the various actors, their
- **Provider Obligations for AI Systems** — https://overview.legal/topics/provider-obligations-ai
  The content specifically addresses obligations imposed on providers of high-risk AI systems, which is a distinct and important category of requirements that des
- **Conformity Assessment for AI Systems** — https://overview.legal/topics/conformity-assessment-ai
  Provider obligations typically include conformity assessment procedures and documentation requirements, which is a specific compliance mechanism under the AI Ac

---
Generated by overview.legal · https://overview.legal/topics/high-risk-ai-classification · 2026-08-22
