AI Act high-risk classification — how to decide, and how to prove it
Almost every AI Act question a company has runs through this one. If a system is high-risk, a substantial compliance programme follows. If it is not, the obligations are modest. Getting the answer right — and being able to show your work — is the single highest-value piece of AI Act analysis.
First hour’s on us. No commitment.
What you get
- A classification decision for each system, with the reasoning written out
- An assessment of the exemptions where a system falls in an Annex III area but may not be high-risk in your use
- The documentation to support it, in a form you can hand to a customer, an investor or a supervisor
- A clear line between what needs the full high-risk programme and what does not
The two routes into high-risk
A system becomes high-risk in one of two ways, and they behave very differently.
Annex I — AI inside a regulated product
If the AI is a safety component of a product already covered by EU product legislation, or is itself such a product, and that product requires third-party conformity assessment, the AI is high-risk. Medical devices, machinery, lifts, toys, radio equipment, vehicles and similar.
This route is comparatively mechanical: the underlying product legislation tells you whether third-party assessment applies. The AI Act obligations then integrate into the conformity assessment you already run. These obligations apply from 2 August 2028.
Annex III — the listed use cases
This is where the judgement sits. Annex III lists eight areas: biometrics; critical infrastructure; education and vocational training; employment and worker management; access to essential private and public services, including creditworthiness and insurance pricing; law enforcement; migration, asylum and border control; and administration of justice and democratic processes.
A system in one of these areas is presumed high-risk. These obligations apply from 2 December 2027.
The exemption that decides most borderline cases
Article 6(3) is the provision worth knowing. A system that falls within an Annex III area is not high-risk if it does not pose a significant risk of harm to health, safety or fundamental rights — specifically where it does not materially influence the outcome of decision-making. The regulation gives four situations: the system performs a narrow procedural task; it improves the result of a previously completed human activity; it detects decision-making patterns or deviations from prior patterns without replacing or influencing the human assessment; or it performs a preparatory task to an assessment.
There is a hard limit: a system that profiles people is always high-risk if it is in an Annex III area, with no exemption available.
If you rely on this exemption you must document the assessment before placing the system on the market, and register the system. The exemption is real and it is used — but it is not a shortcut. It is an assessment you have to be prepared to defend, and “our tool only assists, the human decides” is a claim about how the workflow actually runs, not a sentence you can simply assert.
Where the borderline cases actually fall
Recruitment. A tool that ranks candidates is squarely in Annex III. A tool that formats CVs into a consistent layout is a narrow procedural task. Between them sits everything interesting: keyword filtering, shortlisting suggestions, interview scheduling that deprioritises some candidates. What matters is whether the output materially influences who gets the job.
Credit. Creditworthiness evaluation is listed. Fraud detection on financial transactions is explicitly carved out. Systems that sit near both need care.
Workforce management. Task allocation, monitoring and performance evaluation are listed. Rota optimisation that no one reviews may influence terms of work more than it first appears.
Education. Admissions, assessment of learning outcomes, and monitoring during exams are listed. A study-support chatbot is generally not.
What follows from a high-risk classification
For a provider: a risk management system across the lifecycle; data governance for training, validation and testing sets; technical documentation; automatic logging; instructions for use; human oversight built into the design; accuracy, robustness and cybersecurity measures; a quality management system; conformity assessment; CE marking; and registration in the EU database.
For a deployer: use in accordance with the instructions; competent human oversight; monitoring and log retention; informing affected people; and, for certain public bodies and services, a fundamental rights impact assessment.
That asymmetry is why determining your role matters as much as determining the risk category.
Frequently asked questions
Who decides whether a system is high-risk?
You do, in the first instance, and you carry the burden of showing the assessment was sound. Supervisory authorities review it afterwards. That is why the reasoning matters more than the label.
Our system is in an Annex III area but only supports a human decision. Are we exempt?
Possibly, under Article 6(3) — but only if the human assessment is genuinely not replaced or influenced in a material way, and only if you document that before placing the system on the market. And not at all if the system profiles individuals.
What if we are unsure?
Document the analysis either way. An assessment that concludes “not high-risk” with clear reasoning is a defensible position. Silence is not.
Does the classification change if we modify the system?
It can. Substantial modification can also make a deployer into a provider, which changes the obligations entirely.
How long does a classification review take?
For a handful of systems, usually a week or two. The time goes into understanding how decisions are actually made, not into reading the annexes.
Where to start
Bring the two or three systems you are least sure about. That is normally where the whole answer lives.
Who you’ll work with
Fidan Ibrahimzada, Legal Counsel for AI and technology law, leads this work. She advises companies on AI regulation, data protection and technology contracts, and previously led the legal department of a commercial law firm. She holds an LL.M. in European Business Law from Lund University. Lawgent is Sweden’s first law firm dedicated to AI and EU regulation — meet the team.