Compliance

High-Risk AI Under the EU AI Act: Which Systems Are Covered

How to tell whether your AI system is high-risk, and which deadlines actually apply now that the rules have moved.

Author
Kutluhan Abut
Date
31.7.2026
Updated on
27.8.2026
High-Risk AI Under the EU AI Act: Which Systems Are Covered

Key takeaways

  • There are two routes to high-risk status: Article 6(1), as a product or safety component under existing EU product law (Annex I), and Article 6(2), as a use case listed in Annex III.
  • Annex III names eight areas: biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration and border control, and administration of justice and democratic processes.
  • Article 6(3) exempts systems that pose no significant risk. Providers relying on it must still document the assessment and register the system. Any system that performs profiling of natural persons is always high-risk.
  • The high-risk deadlines have moved. Regulation (EU) 2026/1744 pushed Annex III systems from 2 August 2026 to 2 December 2027, and Annex I product-embedded systems from 2 August 2027 to 2 August 2028.
  • Nothing else moved. The Article 50 transparency obligations, the general-purpose AI rules and the Article 5 prohibitions all kept their original dates.

Whether an AI system counts as high-risk decides almost everything else under the EU AI Act. This tier carries the substantive obligations, from conformity assessment through to registration, while most other systems face only transparency duties or none at all. This article covers how the classification works, what the eight Annex III areas actually say, which exemptions apply, and which deadlines apply now that Regulation (EU) 2026/1744 amended the AI Act on 27 July 2026.

What are the EU AI Act risk categories?

The EU AI Act regulates by risk rather than by technology. This is commonly described as four tiers, and that maps well onto the structure of the regulation: prohibited practices under Article 5, high-risk systems under Chapter III, systems carrying transparency obligations under Article 50, and everything else with no specific duties. The large majority of commercial AI sits in the lower two tiers. Because the work concentrates on the high-risk tier, classification is the first step in any AI Act programme.

When is an AI system high-risk?

Article 6 sets out two routes.

Route 1 (Article 6(1)): the system is intended to be used as a safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in Annex I, and that product must undergo a third-party conformity assessment. Both conditions have to be met. Medical devices and toys are the standard examples.

Route 2 (Article 6(2)): the system falls within one of the use cases listed in Annex III. This route captures most software and SaaS companies, so it is the focus here.

Route 1 changed in July 2026, and the change is easy to miss. Regulation (EU) 2026/1744 takes AI embedded in products governed by the Machinery Regulation outside the direct scope of the high-risk rules, and narrows the definition of a safety component so that AI used purely for performance optimisation, convenience or quality control does not become high-risk simply by being embedded. Medical devices and toys remain fully in scope. If you have seen machinery listed alongside medical devices as a high-risk example, that guidance predates the amendment.

The eight Annex III areas

Annex III is an exhaustive list of use cases. What matters is the function the system performs, not the industry it sits in. The table below summarises the eight headings and the carve-outs that appear expressly in the text.

Area (Annex III)Systems covered, and express carve-outs
1. Biometrics
where permitted
Remote biometric identification; biometric categorisation according to sensitive or protected attributes; emotion recognition.
Not covered: biometric verification whose sole purpose is to confirm that a person is who they claim to be.
2. Critical infrastructureSafety components in the management and operation of critical digital infrastructure, road traffic, and the supply of water, gas, heating or electricity.
3. Education and vocational trainingDetermining access, admission or assignment to institutions; evaluating learning outcomes; assessing the appropriate level of education a person will receive; monitoring and detecting prohibited behaviour during tests.
4. Employment, workers management and access to self-employmentRecruitment and selection, including targeted job advertisements, filtering applications and evaluating candidates; decisions on terms of work, promotion and termination; task allocation based on behaviour or personal traits; monitoring and evaluating performance and behaviour.
5. Access to essential private and public servicesEvaluating eligibility for essential public assistance benefits and services, including healthcare; evaluating creditworthiness or establishing credit scores; risk assessment and pricing in life and health insurance; evaluating and prioritising emergency calls and triage.
Not covered: systems used to detect financial fraud.
6. Law enforcement
where permitted
Assessing the risk of a person becoming a victim of crime; polygraphs and similar tools; evaluating the reliability of evidence; assessing the risk of offending or re-offending; profiling in the course of detection, investigation or prosecution.
7. Migration, asylum and border control
where permitted
Polygraphs and similar tools; assessing security, irregular migration or health risks posed by people entering a Member State; assisting with the examination of asylum, visa and residence permit applications; detecting, recognising or identifying people.
Not covered: the verification of travel documents.
8. Administration of justice and democratic processesAssisting judicial authorities in researching and interpreting facts and the law and applying the law, including in alternative dispute resolution; influencing the outcome of an election or referendum, or voting behaviour.
Not covered: systems whose output natural persons are not directly exposed to, such as tools used to organise or structure campaigns administratively or logistically.

The Article 6(3) exemption

A system in an Annex III area is not high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making. That applies where any one of the following four conditions is met:

  • The system is intended to perform a narrow procedural task.
  • It is intended to improve the result of a previously completed human activity.
  • It is intended to detect decision-making patterns or deviations from prior patterns, and is not meant to replace or influence the previously completed human assessment without proper human review.
  • It is intended to perform a preparatory task to an assessment relevant to the Annex III use cases.

Two points get missed. First, an Annex III system is always high-risk where it performs profiling of natural persons, and the exemption does not apply. Second, the exemption is not a free pass. A provider who considers a system not to be high-risk must document that assessment before placing the system on the market under Article 6(4), is subject to the registration obligation in Article 49(2), and must produce the documentation on request. That registration duty was proposed for removal during the Digital Omnibus negotiations and survived, with a lighter process.

Where this gets difficult in practice. Say your product ranks inbound job applications and surfaces the strongest ten to a recruiter, who reads all of them and decides alone. Is that a narrow procedural task, or is it evaluating candidates under Annex III point 4? The honest answer is that it depends on how much the ranking shapes the outcome, and that a recruiter who only ever reads the top ten is being materially influenced. If your system builds any profile of the applicants to do the ranking, the question closes: profiling is always high-risk. This is exactly the judgment the Commission addressed when it published draft Article 6(5) guidelines on 19 May 2026, in three documents with practical examples of systems that should and should not be classified as high-risk. The consultation closed on 23 July 2026 and the final version is expected by the end of 2026. Work from the drafts before you rely on an exemption.

What applies if your system is high-risk?

You must demonstrate conformity before placing the system on the market and keep it conformant in operation. The requirements sit in Chapter III Section 2: a risk management system (Article 9), data and data governance (Article 10), technical documentation (Article 11), record-keeping (Article 12), transparency towards deployers (Article 13), human oversight (Article 14), and accuracy, robustness and cybersecurity (Article 15). Provider obligations in Section 3 follow, including a quality management system (Article 17), then conformity assessment (Article 43), the EU declaration of conformity (Article 47), CE marking (Article 48) and registration (Article 49).

For the full path to conformity, see our guide to EU AI Act compliance, and for the regulation in the round, the EU AI Act overview.

When do the obligations apply?

Two deadlines moved, and they moved by different amounts.

DateWhat applies
2 August 2026Article 50 transparency obligations become applicable. For the machine-readable marking of AI-generated content under Article 50(2), systems placed on the market before this date have a grace period until 2 December 2026.
2 December 2026End of that grace period. End of the transitional period for the new prohibition on AI generating CSAM and non-consensual intimate imagery.
2 August 2027Deadline for Member States to establish AI regulatory sandboxes.
2 December 2027Obligations for stand-alone high-risk systems under Annex III.
Originally 2 August 2026, deferred by 16 months.
2 August 2028Obligations for product-embedded high-risk systems under Annex I.
Originally 2 August 2027, deferred by 12 months.

The stated reason for the deferral is that the harmonised standards providers need in order to demonstrate conformity were not going to be ready in time.

Only the high-risk package moved. The transparency obligations in Article 50 apply from 2 August 2026, the general-purpose AI model rules have applied since 2 August 2025, and the Article 5 prohibitions have applied since 2 February 2025. If you run a chatbot in the EU, generate synthetic media, or deploy emotion recognition, the postponement does not help you. The one narrow concession is a grace period until 2 December 2026 for the machine-readable marking of AI-generated content under Article 50(2), and only for systems already on the market before 2 August 2026.

These dates are unlikely to move again. The Commission's November 2025 draft contained a conditional trigger that would have tied the high-risk dates to the completion of the harmonised standards. That mechanism was removed from the final text and replaced with fixed calendar dates. A further delay would now require a fresh legislative procedure rather than an administrative decision.

The extra runway is a deferral, not a reprieve. The obligations themselves are unchanged, and a risk management system, defensible data governance and auditable technical documentation do not come together in a few weeks. Classifying your systems remains the task to start now, not least because it determines how large the programme is.

Frequently asked questions

How do I know if my AI system is high-risk?

Ask two questions. Is the system a product or safety component under the EU legislation listed in Annex I that requires third-party conformity assessment? And does it perform one of the functions listed in Annex III? If either applies and no carve-out and no Article 6(3) exemption is available, it is high-risk. If the system performs profiling of natural persons, it is high-risk in any case.

What are the eight Annex III areas?

Biometrics; critical infrastructure; education and vocational training; employment, workers management and access to self-employment; access to essential private and public services, including creditworthiness and life and health insurance; law enforcement; migration, asylum and border control management; and administration of justice and democratic processes.

Is every system in an Annex III area automatically high-risk?

No. Annex III contains its own carve-outs, including biometric verification, financial fraud detection within creditworthiness assessment, and the verification of travel documents. Article 6(3) additionally exempts systems that pose no significant risk. The classification must be documented and the system registered regardless. Systems that perform profiling stay high-risk.

Does 2 August 2026 still apply to high-risk AI?

No. Under Regulation (EU) 2026/1744, in force since 27 July 2026, high-risk obligations apply from 2 December 2027 for Annex III systems and from 2 August 2028 for Annex I systems. 2 August 2026 does still apply to the Article 50 transparency obligations, which were not deferred.

Was the whole EU AI Act postponed?

No, and this is the most common misreading of the amendment. Only the high-risk obligations moved. The Article 5 prohibitions have applied since February 2025, the general-purpose AI model obligations since August 2025, and the Article 50 transparency obligations from August 2026. The architecture of the regulation, its risk-based approach and its governance structure are unchanged.

What does the amendment mean for AI in machinery?

AI embedded in products governed by the Machinery Regulation falls outside the direct scope of the EU AI Act's high-risk rules. The Commission can, however, impose AI-specific health and safety requirements through delegated acts under the Machinery Regulation. Medical devices and toys remain within the AI Act.

See how Kertos inventories your AI systems, classifies them and prepares you for the high-risk obligations: Book a demo.

Legal status: 2 August 2026. This article is based on Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. It is general information and does not replace legal advice on individual cases.

The Founder's Guide about NIS2: Prepare your company Now before

Protect your startup: Discover how NIS2 can impact your business and what you need to consider now. Read the free white paper now!

Ready, your compliance to put on autopilot?
Kutluhan Abut

Kutluhan Abut

Information Security & AI Governance Specialist

Kutluhan Abut is an Information Security & GRC Specialist at Kertos, where he supports companies with ISO 27001 implementation, SOC 2 audit readiness, and AI governance topics. His work focuses on translating information security and compliance requirements into practical policies, evidence, controls, and processes that can stand up to audits and customer scrutiny. With a legal and data protection background, he brings a structured compliance perspective to information security, privacy, and emerging technology governance."

About Kertos

Kertos is the modern backbone of the data protection and compliance activities of scaling companies. We enable our customers to implement integrated data protection and information security processes in accordance with GDPR, ISO 27001, TISAX®, SOC2 and many other standards quickly and cheaply through automation.

Ready to simplify GDPR compliance?

CTA Image

📅 Schedule Your 5min Compliance Check

Please enter your business email to continue. We require a company email address to ensure we can best serve your organization.

📞 5min Compliance Check