Skip to content

Is your AI system high-risk under the EU AI Act?

By Sam Rivera, Founder, SentinelPanda · June 2, 2026 · 4 min read · AI Governance

Most AI Act compliance work attaches to the high-risk tier. Knowing whether your system is in it is the most consequential reading you do all year.

The four tiers

The AI Act takes a risk-based approach with four tiers. Prohibited practices (Article 5) are banned outright — no compliance path exists. High-risk systems (Article 6) face the bulk of substantive obligations: risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy and robustness, conformity assessment, CE marking, EU database registration. Limited-risk systems face transparency-only obligations (labelling AI interactions, watermarking AI-generated content). Minimal-risk systems carry no specific obligations beyond voluntary codes.

Most of the engineering and documentation work the Act demands lives in the high-risk tier. If your system is high-risk, you need a conformity assessment before placing it on the market; if it is not, the burden drops dramatically. The classification is therefore the most consequential reading you do.

Two paths to high-risk: Article 6(1) and Annex III

There are two ways an AI system gets classified as high-risk. Article 6(1) covers AI systems that are themselves safety components of products already regulated by EU harmonisation legislation listed in Annex I — toys, machinery, lifts, medical devices, in-vitro diagnostics, civil aviation, and so on. If the product needs third-party conformity assessment under the listed legislation, and the AI is a safety component, the AI system is high-risk.

Annex III is the other path: a list of standalone AI use cases that the Act treats as high-risk by virtue of their domain. The eight categories are biometrics (categorisation and emotion recognition outside prohibited cases); critical infrastructure (safety-related management of road traffic, water, gas, electricity); education and vocational training (admissions, evaluation, behaviour detection); employment and worker management (recruitment, promotion, task allocation, performance monitoring); access to essential services (creditworthiness, life and health insurance pricing, public benefits, emergency dispatching); law enforcement (specific uses around victim profiling, evidence evaluation, predictive policing); migration, asylum, and border control; and administration of justice and democratic processes.

The Article 6(3) derogation

A system that falls under one of the Annex III categories can self-classify as not high-risk under Article 6(3) if it "does not pose a significant risk of harm to the health, safety, or fundamental rights of natural persons, including by not materially influencing the outcome of decision-making." The derogation has four narrow grounds: the system performs a narrow procedural task; improves the result of a previously completed human activity; detects decision-making patterns without replacing or influencing human assessment; or performs a preparatory task for a high-risk assessment.

The derogation is not a get-out-of-jail-free card. You must document the reasoning, register the system in the EU database, and the market surveillance authority can challenge your classification. Profiling of natural persons always counts as a significant risk, so any system that does profiling cannot use this derogation.

How to actually do the classification

  • List every AI system in scope. Include systems you build, systems you deploy, and white-labelled AI features in third-party products you offer to your customers.
  • For each system, check Article 5: does it match any prohibited practice? If yes, stop using it.
  • Check Article 6(1): is the system a safety component of a product covered by Annex I requiring third-party conformity assessment? If yes, it is high-risk.
  • Check Annex III: does the intended purpose match one of the eight categories? If yes, the system is presumed high-risk.
  • For Annex III presumed-high-risk: evaluate Article 6(3) derogation grounds. Document the reasoning in a risk classification record, even if the conclusion is "still high-risk".
  • For anything not high-risk: check Article 50 transparency obligations (interaction labelling, deepfake disclosure, AI-generated content marking).
  • Re-classify when intended purpose, deployment context, or system behaviour changes materially.

A note on intended purpose

The Act ties classification to the intended purpose of the AI system, as stated by the provider in the instructions for use. Two systems with identical model architecture and similar capabilities can be classified differently if their stated intended purposes differ. This means the documentation of intended purpose — including the explicit exclusion of high-risk uses — carries real legal weight. Vague "general-purpose" intended-purpose statements are dangerous: a regulator can construe ambiguous wording broadly.

EU AI Act timeline AI impact assessments ISO 42001 vs EU AI Act

Run your compliance program in one workspace.