Annex III · Applies 2 Dec 2027 · Annex I · Applies 2 Aug 2028 · Last updated 7 July 2026

    High-risk AI systems: what they are and what you must do

    A high-risk AI system under the EU AI Act is a system used in one of the sensitive domains listed in Annex III, or embedded as a safety-relevant component in a regulated product covered by Annex I. If your AI is high-risk, you carry the Act's heaviest obligations - full lifecycle risk management, technical documentation, human oversight, conformity assessment and post-market monitoring.

    Regulation (EU) 2026/1744 (the Digital Omnibus on AI, in force since 27 July 2026) deferred these obligations from 2 August 2026 to 2 December 2027 (stand-alone Annex III systems) and 2 August 2028 (AI embedded in Annex I regulated products). The extra runway is real - but building a defensible risk file takes 12-18 months. The decision tree below gives indicators, not a definitive legal classification.

    Decision tree

    Am I high-risk?

    Answer a handful of questions. In under a minute you will see whether your AI use is likely prohibited, high-risk (Annex III or Annex I), limited-risk (Article 50) or minimal-risk - with a clear next step. Indicative only; the definitive answer is your assessment plus legal review.

    Step 1

    Does your AI do any of the following?

    Article 5 - prohibited practices.

    Annex III categories

    Annex III lists the stand-alone use cases the Act treats as high-risk by default. Any AI system operating in one of these domains is presumed high-risk unless a narrow Article 6(3) exception applies.

    • Biometric identification and categorisation
    • Critical infrastructure (energy, water, traffic)
    • Education and vocational training
    • Employment, worker management, self-employment access
    • Access to essential private and public services
    • Law enforcement
    • Migration, asylum, border control
    • Administration of justice and democratic processes

    Ten provider obligations

    Providers of high-risk AI must be able to evidence each of these controls before placing the system on the EU market. Deployers inherit related duties under Article 26.

    • Risk management system across the full lifecycle (Art. 9)
    • Data governance - representative, relevant, error-free (Art. 10)
    • Annex IV technical documentation kept up to date (Art. 11)
    • Automatic event logging (Art. 12)
    • Transparency and information to deployers (Art. 13)
    • Human oversight designed into the system (Art. 14)
    • Accuracy, robustness, and cybersecurity (Art. 15)
    • Quality management system (Art. 17)
    • Conformity assessment and CE marking (Art. 43)
    • Post-market monitoring and incident reporting (Art. 72–73)

    Ready for the full picture?

    The free 15-20 minute readiness assessment produces a personalised report ranking every high-risk obligation by relevance to your setup.

    Take the free assessment