The EU AI Act — the world's first comprehensive legal framework for artificial intelligence — classifies AI systems into four risk tiers: unacceptable risk, high risk, limited risk, and minimal risk. For organizations deploying AI in the European market, understanding whether their systems fall into the high-risk category is critical. The obligations attached to high-risk AI systems are substantial, and non-compliance carries significant financial and reputational consequences.
This guide provides a complete breakdown of the high-risk AI system categories, the obligations they trigger, and what organizations must do to achieve compliance by the August 2026 deadline.
What Makes an AI System "High-Risk"?
Under the EU AI Act, an AI system is classified as high-risk if it meets either of two criteria:
- It is intended to be used as a safety component of a product covered by specific EU product safety legislation (such as medical devices, aviation, or automotive systems), or is itself such a product — and is subject to a third-party conformity assessment under that legislation.
- It falls into one of the eight categories listed in Annex III of the Act, regardless of whether it is embedded in a product.
The Annex III categories represent areas where the European legislature determined that AI systems pose significant risks to health, safety, fundamental rights, democracy, or the rule of law.
The 8 Categories of High-Risk AI Systems (Annex III)
1. Biometric Identification and Categorisation
AI systems used for remote biometric identification of natural persons, including real-time facial recognition in public spaces. Also includes AI systems used to categorize individuals based on biometric data into sensitive categories such as race, political opinion, religion, or sexual orientation. This category captures many identity verification, access control, and law enforcement AI systems.
2. Critical Infrastructure Management
AI systems used as safety components in the management and operation of critical infrastructure, including road traffic, water supply, electricity, gas, and heating networks. AI systems that could, if they malfunctioned, cause widespread disruption or harm to the physical or digital infrastructure that society depends on.
3. Education and Vocational Training
AI systems used to determine access to educational institutions or vocational training, to evaluate learning outcomes, to assess and evaluate students, and to monitor and detect prohibited behavior during tests. This category captures AI-powered admissions systems, automated grading tools, and online proctoring software.
4. Employment, Worker Management, and Self-Employment
AI systems used for recruitment and selection of natural persons (including CV screening, interview assessment, and hiring decisions), for making decisions affecting employment conditions, promotion, and termination, and for monitoring and evaluating workers' performance. This is one of the most commercially significant categories, affecting a wide range of HR technology products.
5. Access to Essential Private and Public Services
AI systems used by public authorities or private entities acting on their behalf to evaluate individuals' eligibility for essential public assistance benefits and services, including housing, healthcare, and social security. Also covers credit scoring, insurance pricing, and other AI systems that determine access to essential private services. This category has significant implications for financial services and insurance AI applications.
6. Law Enforcement
AI systems used by law enforcement authorities for individual risk assessment and profiling in criminal investigations, polygraph and similar tools, deep fake detection, evaluation of evidence reliability, crime analytics and prediction, profiling in the context of detection and investigation of criminal offenses, and crime forecasting. These applications face the strictest scrutiny given the potential impact on fundamental rights.
7. Migration, Asylum, and Border Control Management
AI systems used for risk assessment of individuals seeking to cross borders, verifying the authenticity of travel documents, examining asylum, visa, and residence permit applications, and detecting, recognizing, or identifying natural persons in the context of border control. This category covers a wide range of immigration authority AI tools.
8. Administration of Justice and Democratic Processes
AI systems used to assist judicial authorities in researching and interpreting facts and law and applying the law to a specific set of facts, and AI systems used to influence the outcome of elections and referenda. This category reflects the EU legislature's particular concern about the impact of AI on the foundations of democratic governance.
What Obligations Apply to High-Risk AI Systems?
Providers of high-risk AI systems — those who develop and place such systems on the market or put them into service — must meet a comprehensive set of obligations before their system can be deployed:
- Risk management system: Establish, implement, document, and maintain a risk management system throughout the AI system's lifecycle, identifying and analyzing known and foreseeable risks.
- Data governance: Implement data governance and management practices for training, validation, and testing datasets, ensuring they are relevant, representative, free of errors, and complete.
- Technical documentation: Prepare comprehensive technical documentation before placing the system on the market and keep it up to date throughout its lifecycle.
- Record-keeping and logging: Design AI systems with automatic logging capabilities to enable monitoring of operation after deployment.
- Transparency and user information: Provide users with clear instructions for use, including capabilities, limitations, known risks, and any necessary human oversight measures.
- Human oversight: Design systems to enable effective human oversight, including the ability to intervene, override, or halt the system.
- Accuracy, robustness, and cybersecurity: Achieve appropriate levels of accuracy, robustness, and security throughout the system's lifecycle.
- Conformity assessment: Conduct a conformity assessment (either self-assessment or third-party) before placing the system on the market.
- EU Declaration of Conformity: Draw up a declaration of conformity and affix the CE marking.
- Registration in EU database: Register the high-risk AI system in the EU AI Act public database before deployment.
- Post-market monitoring: Implement a post-market monitoring system and report serious incidents to national authorities.
Conformity Assessment Requirements
For most high-risk AI systems listed in Annex III, providers can conduct a self-assessment based on internal controls, provided they follow the requirements of the Act. However, for AI systems used in biometric identification and some law enforcement applications, third-party conformity assessment by a notified body is mandatory.
Providers that develop high-risk AI systems in accordance with harmonized European standards (including ISO 42001 once it receives harmonized status under the Act) will benefit from a presumption of conformity for the elements covered by those standards. This makes ISO 42001 certification particularly valuable for high-risk AI system providers.
Key Compliance Timeline
- February 2, 2025: Prohibitions on unacceptable-risk AI systems entered into force.
- August 2, 2025: Obligations on general-purpose AI models became applicable.
- August 2, 2026: Obligations on high-risk AI systems listed in Annex III become applicable. This is the critical deadline for most commercial AI products.
- August 2, 2027: Obligations for high-risk AI systems embedded in regulated products (Annex I) become applicable.
What Should Organizations Do Now?
With August 2026 approaching, organizations should take the following steps immediately:
- Conduct an AI inventory to identify all AI systems used or developed within the organization.
- Classify each system against the Annex III categories to determine if high-risk obligations apply.
- Initiate a gap analysis against the high-risk AI system requirements.
- Implement an AI Management System aligned with ISO 42001 to provide the governance foundation for compliance.
- Prepare the required technical documentation and risk management documentation for each high-risk system.
- Plan for registration in the EU AI Act database.
Organizations that begin this process now will be well-positioned to meet the August 2026 deadline without the disruption and cost of last-minute compliance efforts.
Ready to Get Certified?
AICerty provides end-to-end ISO 42001, EU AI Act, and ISO 27001 certification services for AI companies worldwide. 100% online, 6-10 weeks, powered by BALTUM Bureau.
Visit aicerty.io