The heart of the EU AI Act is its regime for high-risk AI systems, and the timetable is now settled: the core obligations for high-risk systems listed in Annex III apply from 2 December 2027, after the Digital Omnibus on AI, Regulation (EU) 2026/1744, deferred them from the original date of 2 August 2026. If your business builds, sells or deploys AI in certain sensitive areas, you may now carry real duties. This guide explains how to work out whether your system is high-risk and what compliance involves.
What counts as high-risk
There are two broad routes into the high-risk category. The first is AI used as a safety component of products already regulated under EU law, such as machinery or medical devices. The second, more relevant to most businesses, is AI used in the areas listed in Annex III: for example recruitment and worker management, access to education, essential private and public services such as credit scoring, and certain uses in law enforcement, migration and the administration of justice.
The main obligations
Providers of high-risk systems must put in place a risk-management system, ensure appropriate data governance and quality, prepare technical documentation, enable record-keeping and logging, provide clear information to users, and design for human oversight, accuracy, robustness and cybersecurity. The system must undergo a conformity assessment, carry CE marking and, in many cases, be registered in an EU database before it goes to market.
Deployers have duties too
Even if you only use a high-risk system, you have obligations. Deployers must use the system in line with the provider’s instructions, ensure meaningful human oversight, monitor its operation and keep logs, and inform workers and their representatives where a high-risk system is used in the workplace. In some cases deployers must also carry out a fundamental rights impact assessment before putting the system into use.
Practical example: an AI CV-screening tool
A company adopts an AI tool that ranks job applicants. Recruitment is an Annex III area, so the tool is high-risk. The provider must meet the design and documentation obligations, but the employer deploying it must also ensure a human meaningfully reviews decisions, monitor for bias, inform candidates and staff, and keep records. Buying the tool does not transfer all responsibility to the vendor.
Common mistakes companies make
Frequent errors include assuming the rules only bind developers, not the businesses that deploy AI; treating a vendor’s compliance claim as enough without checking the documentation; overlooking Annex III areas such as HR and creditworthiness that are easy to fall into; and leaving human oversight as a box-ticking exercise rather than a real check on the system’s output.
Recommended actions
Map where your business builds or uses AI and flag anything touching an Annex III area. For each high-risk system, confirm who is the provider and who is the deployer, and pin down the obligations that fall on you. Ask vendors for their technical documentation and conformity evidence, build genuine human oversight into your processes, and keep records. Where the classification is unclear, get advice before you rely on the system.
Frequently asked questions
When do the high-risk obligations apply?
The obligations for high-risk systems listed in Annex III apply from 2 December 2027, with rules for AI embedded in certain regulated products under Annex I following from 2 August 2028. Both dates were pushed back by the Digital Omnibus on AI in July 2026. High-risk compliance is now current, not future.
How do I know if my AI is high-risk?
Check whether it is a safety component of a regulated product, or whether it is used in an Annex III area such as recruitment, credit scoring or essential services. If either applies, treat it as high-risk until advised otherwise.
We only use AI, we do not build it. Are we affected?
Yes. Deployers of high-risk systems must ensure human oversight, monitor the system, keep logs and inform affected workers, and sometimes assess fundamental-rights impacts. Responsibility is shared between provider and deployer.
Conclusion
High-risk classification brings the AI Act’s most demanding obligations, and they are live now for Annex III systems. Knowing whether your AI falls into the category, and who carries which duties, is the essential first step. Lawgent helps businesses classify their AI systems, allocate provider and deployer obligations and build the oversight and documentation the Act requires. Contact us for a high-risk AI assessment.