Français

High-risk AI systems: how to tell whether yours is one

The two routes into the high-risk category, the eight areas of Annex III, and the Article 6(3) exit filter that almost nobody reads correctly.

This is the question that decides everything: a high-risk system triggers the heaviest regime in the Regulation, and a system that is not one triggers almost none of it. The answer is narrower than the summaries suggest.

This page deals with classification, and only that. The obligations that follow (risk management, documentation, data governance, logging) are a separate subject.

The dates, and they moved

2 December 2027 for Annex III systems, 2 August 2028 for Annex I. Both result from the postponement made by Regulation (EU) 2026/1744. They do not yet tell you to whom they apply: Article 111 exempts much of the installed base. That is the last section of this page.

How do you know whether your system is high risk?

Two routes in, and only one concerns most companies. The first, Annex I, catches AI built into an already regulated product as a safety component, under two cumulative conditions. The second, Annex III, classifies by use. A third step then exists: the exit filter in Article 6(3).

Route 1: AI inside an already regulated product (Annex I)

A system is high-risk on this basis where both conditions are met: it is intended to be used as a safety component of a product covered by the Union harmonisation legislation listed in Annex I, or is itself such a product; and that product is required to undergo a third-party conformity assessment under that legislation.

Both, not either. A system embedded in an Annex I product that is not subject to third-party assessment is not high-risk on this basis.

Regulation (EU) 2026/1744 added three filters, and they are its most business-favourable changes. Note that the first of them is framed “for the purposes of this Regulation, including paragraph 1 of this Article”, and that the second operates inside that framing (“Notwithstanding paragraph 1a”): the safety-component test they define also governs the reading of Annex III, point 2.

Systems “solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control” do not qualify as safety components. But systems “the failure or malfunctioning of which would endanger health and safety” do qualify, notwithstanding the preceding rule. And a product required to undergo third-party assessment “solely due to risks other than risks to health and safety, in particular risks relating to the distribution of radio spectrum or electromagnetic interference that do not affect health and safety” does not meet the second condition.

Route 2: the use cases in Annex III

This is the one that covers most of the market. Annex III lists eight areas, and within each, named uses.

AreaWhat is coveredWhat the text itself excludes
1. Biometrics, in so far as their use is permitted under relevant Union or national lawRemote biometric identification; biometric categorisation according to sensitive or protected attributes; emotion recognitionBiometric verification whose sole purpose is to confirm that a person is who they claim to be
2. Critical infrastructureSafety components in the management and operation of critical digital infrastructure, road traffic, or the supply of water, gas, heating or electricityNone
3. Education and vocational trainingAccess, admission or assignment; evaluation of learning outcomes; assessing the appropriate level of education; monitoring and detecting prohibited behaviour during testsNone
4. Employment, workers’ management and access to self-employmentRecruitment or selection (targeted job advertisements, filtering applications, evaluating candidates) and decisions on terms of work-related relationships, promotion, termination, task allocation and performance monitoringNone
5. Access to and enjoyment of essential private services and essential public services and benefitsEligibility for essential public assistance benefits and services, including healthcare, by or on behalf of public authorities, and granting, reducing, revoking or reclaiming them; creditworthiness or credit scoring; risk assessment and pricing in life and health insurance; evaluating and classifying emergency calls, dispatching or prioritising the dispatch of emergency first response services, and emergency healthcare patient triageDetecting financial fraud, but at point 5(b) only, the creditworthiness one. Point 5(c), insurance, provides no such exception
6. Law enforcement, in so far as their use is permitted under relevant Union or national lawAssessing the risk of becoming a victim; polygraphs; reliability of evidence; assessing the risk of offending or re-offending not solely on the basis of profiling, or assessing personality traits and characteristics or past criminal behaviour; profiling in the course of detecting offencesNone
7. Migration, asylum and border control management, in so far as their use is permitted under relevant Union or national lawPolygraphs; risk assessment of a person entering the territory; examination of asylum, visa and residence permit applications; detecting, recognising or identifying personsVerification of travel documents
8. Administration of justice and democratic processesAssisting a judicial authority in researching and interpreting facts and the law and in applying the law to a concrete set of facts, or used in a similar way in alternative dispute resolution; systems intended to influence the outcome of an election or referendum, or voting behaviourSystems “to the output of which natural persons are not directly exposed”, such as tools used to organise, optimise or structure political campaigns “from an administrative or logistical point of view”

Point 4 is the one that concerns the largest number, and it does not target “HR”. It targets named uses. A payroll tool is not in it; a tool that filters job applications is. Being an HR tool is not the test, in either direction.

Can you exit high risk while listed in Annex III?

Yes, and it is the most misread provision in the Regulation. Article 6(3) lets you set the classification aside where the system poses no significant risk of harm and does not materially influence the outcome of decision-making. It is neither automatic nor declaratory: relying on it means documenting your assessment before placing the system on the market, and registering.

“By derogation from paragraph 2, an AI system referred to in Annex III shall not be considered to be high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making.”

Source: Article 6(3), first subparagraph

The second subparagraph lists four situations: a narrow procedural task; improving the result of a previously completed human activity; detecting decision-making patterns or deviations from prior patterns, without replacing or influencing the previously completed human assessment, without proper human review; and performing a preparatory task.

How the two subparagraphs fit together is unsettled, and that has to be said. One reading makes the absence of significant risk a free-standing test, with the four situations as gateways. The other treats those four situations as exhausting the assessment.

The wording of the second subparagraph (“The first subparagraph shall apply where any of the following conditions is fulfilled”) supports the second reading, and the Commission’s draft guidelines take the same line, stating that there is no separate or independent assessment while adding that the conditions must also be interpreted in the light of the first subparagraph. That document is a draft and is not adopted.

Two safeguards, on the other hand, admit no argument.

Profiling bars the exemption in all cases. A system referred to in Annex III “shall always be considered to be high-risk where the AI system performs profiling of natural persons”.

Leaving the high-risk category is not leaving the Regulation. Article 6(4) requires a provider relying on this derogation to document its assessment before the system is placed on the market or put into service, and to register under Article 49(2). On request, it must provide that documentation to national competent authorities.

What do the Commission guidelines say, and are they adopted?

The Commission was required, no later than 2 February 2026, to provide guidelines on the practical implementation of Article 6, together with “a comprehensive list of practical examples of use cases of AI systems that are high-risk and not high-risk”. That deadline has passed. A draft was put online on 19 May 2026: as at 24 August 2026, the date of our last check, no adopted version of the guidelines on high-risk classification was found, only a draft exists. The Commission’s page still presents it as a draft and the draft states that it will be further consulted with the AI Board and published for additional stakeholder feedback.

That draft is not adopted, it carries neither a C() reference nor a date of its own, and it exists in English only. What follows is therefore what the draft proposes, not what the Regulation provides.

Human oversight does not take a system out of the high-risk category. The draft holds that human involvement changes neither the intended purpose nor the area of use, and therefore not the classification.

A clause in the terms of use is not enough. Writing that high-risk uses are excluded does not take anything out: the draft asks for consistency across all materials, including commercial ones.

In HR, the draft proposes excluding employer branding, contextual advertisement targeting, tools assisting candidates, and office space optimisation.

In insurance, only life and health are covered by the text itself. The draft adds that motor and home insurance are out, but also that long-term private care insurance is in, that personal pension products are in “in so far as these can have a significant impact of a person’s livelihood in old age”, and that credit life insurance contracts are in “since they constitute life insurance regardless of their function as payment protection insurance”. It should not be read for the half that suits.

In education, the draft proposes that only summative assessment falls under point 3(b), that tools used by students on their own initiative are out of scope, and that plagiarism checking on already-submitted work is not exam monitoring, which presupposes real time.

On critical infrastructure, the draft suggests point 2 would be limited to entities designated as critical under the CER Directive. This is the weakest reading in the document: it is drafted as what the reference “should be understood” to mean, without express support in the Regulation, and the draft still has to go before the AI Board and a second consultation. It should not be taken to mean that a non-designated operator is out of scope.

Where do you start to classify a system?

Start from the intended purpose, not the technology. Annex III classifies by use. The same technical building block can be in or out depending on what it is for and what the provider says about it in its documentation and its commercial materials.

Check the exclusions written into the text itself: biometric verification at point 1(a), financial fraud detection at point 5(b), verification of travel documents at point 7(d), and systems to whose output people are not directly exposed at point 8(b). Those are in the Regulation, not in an interpretative document.

Do not confuse the Article 6(3) exemption with leaving the Regulation. It is documented in advance, and it is registered.

And do not rest anything on the draft guidelines without saying so. They are not adopted, and the Commission says itself that they will change.

Is a system already in service caught?

Usually not, unless it undergoes significant design changes — with one exception: systems intended for use by public authorities must comply by 2 August 2030 in any event. The two dates at the top of this page are dates of application. They do not say to whom they apply, and Article 111 does.

A page written from the calendar alone would say that every high-risk system must comply by 2 December 2027 or 2 August 2028. That is wrong for most of the installed base.

“Without prejudice to the application of Article 5 as referred to in Article 113, third paragraph, point (a), this Regulation shall apply to operators of high-risk AI systems, other than the systems referred to in paragraph 1 of this Article, that have been placed on the market or put into service before the date of application of Chapter III referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. In any case, the providers and deployers of high-risk AI systems intended to be used by public authorities shall take the necessary steps to comply with the requirements and obligations laid down in this Regulation by 2 August 2030.”

Source: Article 111(2), consolidated version of 27 July 2026, as rewritten by Regulation (EU) 2026/1744

Three rules, which should not be run together.

A system already on the market is not caught until it changes. Placed on the market or put into service before the date of application of Chapter III (2 December 2027 for Annex III, 2 August 2028 for Annex I) it falls under the Regulation only if, from that date, it is subject to “significant changes in their designs”.

Unless it is intended for public authorities. The grandfathering is then bounded: providers and deployers must have complied by 2 August 2030, whether or not any significant change occurred. This is not extra time on top of the general dates; it is the boundary of an exemption.

And Article 5 is never covered. Paragraphs 1 and 2 of Article 111 both open with that reservation. A legacy system remains subject to the prohibitions from 2 February 2025, and from 2 December 2026 for the two points added by the omnibus.

A separate regime, finally, for systems that are components of the large-scale IT systems established by the legal acts listed in Annex X: placed on the market or put into service before 2 August 2027, they must be brought into compliance by 31 December 2030 (Article 111(1)).

What this page rests on

Articles 6, 7 and 111 and Annex III of Regulation (EU) 2024/1689 in the consolidated version of 27 July 2026, as amended by Regulation (EU) 2026/1744, the authentic text remaining the one published in the Official Journal. Quotations are reproduced from the official English text. The Commission’s draft guidelines on the classification of high-risk AI systems, three files, English only, put online on 19 May 2026 and not adopted as at 24 August 2026: what they propose is never presented here as settled law.

Sources. Regulation (EU) 2024/1689, consolidated text of 27 July 2026 and Regulation (EU) 2026/1744, both consulted on 27 August 2026.

Frequently asked questions

When do the high-risk obligations start to apply?

2 December 2027 for systems classified under Annex III, and 2 August 2028 for those under Annex I. Both dates result from the postponement made by Regulation (EU) 2026/1744. But Article 111 sharply limits their reach: a system placed on the market or put into service before the date of application of Chapter III is caught only if it is subject to significant changes in its design from that date. That exemption is not open-ended for systems intended to be used by public authorities, which must comply by 2 August 2030; and components of the large-scale IT systems established by the legal acts listed in Annex X, placed on the market or put into service before 2 August 2027, must comply by 31 December 2030.

Is being listed in Annex III enough to be high risk?

No. Article 6(3) provides that a system referred to in Annex III is not high-risk where it does not pose a significant risk of harm, and lists four situations: a narrow procedural task, improving the result of a previously completed human activity, detecting deviations without replacing human assessment, and a preparatory task. Two reservations: profiling of natural persons bars the exemption in all cases, and relying on it requires documenting the assessment before placing on the market or putting into service, and registering.

Does human oversight take a system out of the high-risk category?

No. It is a widespread belief and the Commission’s draft guidelines say the opposite: human involvement changes neither the intended purpose of the system nor the area in which it is used, so it does not change the classification. It belongs to the obligations that follow qualification, not to qualification itself. That document is a draft and is not adopted.

Is HR high risk?

Not as a block. Annex III, point 4 targets named uses: recruitment or selection, in particular placing targeted job advertisements, analysing and filtering job applications and evaluating candidates; and decisions affecting terms of work-related relationships, promotion, termination, task allocation and performance monitoring. A payroll tool is not in scope; a tool that filters job applications is. Being an HR tool is not the test, in either direction.

Read next

This content is a technical and regulatory information resource. It does not constitute legal advice.