Annex III · Applies 2 Dec 2027 · Annex I · Applies 2 Aug 2028 · Last updated 7 July 2026
High-risk AI systems: what they are and what you must do
A high-risk AI system under the EU AI Act is a system used in one of the sensitive domains listed in Annex III, or embedded as a safety-relevant component in a regulated product covered by Annex I. If your AI is high-risk, you carry the Act's heaviest obligations - full lifecycle risk management, technical documentation, human oversight, conformity assessment and post-market monitoring.
Regulation (EU) 2026/1744 (the Digital Omnibus on AI, in force since 27 July 2026) deferred these obligations from 2 August 2026 to 2 December 2027 (stand-alone Annex III systems) and 2 August 2028 (AI embedded in Annex I regulated products). The extra runway is real - but building a defensible risk file takes 12-18 months. The decision tree below gives indicators, not a definitive legal classification.
Decision tree
Am I high-risk?
Answer a handful of questions. In under a minute you will see whether your AI use is likely prohibited, high-risk (Annex III or Annex I), limited-risk (Article 50) or minimal-risk - with a clear next step. Indicative only; the definitive answer is your assessment plus legal review.
Step 1
Does your AI do any of the following?
Article 5 - prohibited practices.
Annex III categories
Annex III lists the stand-alone use cases the Act treats as high-risk by default. Any AI system operating in one of these domains is presumed high-risk unless a narrow Article 6(3) exception applies.
- Biometric identification and categorisation
- Critical infrastructure (energy, water, traffic)
- Education and vocational training
- Employment, worker management, self-employment access
- Access to essential private and public services
- Law enforcement
- Migration, asylum, border control
- Administration of justice and democratic processes
Ten provider obligations
Providers of high-risk AI must be able to evidence each of these controls before placing the system on the EU market. Deployers inherit related duties under Article 26.
- Risk management system across the full lifecycle (Art. 9)
- Data governance - representative, relevant, error-free (Art. 10)
- Annex IV technical documentation kept up to date (Art. 11)
- Automatic event logging (Art. 12)
- Transparency and information to deployers (Art. 13)
- Human oversight designed into the system (Art. 14)
- Accuracy, robustness, and cybersecurity (Art. 15)
- Quality management system (Art. 17)
- Conformity assessment and CE marking (Art. 43)
- Post-market monitoring and incident reporting (Art. 72–73)
Ready for the full picture?
The free 15-20 minute readiness assessment produces a personalised report ranking every high-risk obligation by relevance to your setup.
Take the free assessment