Dev.to AI πŸ€– Ai πŸ‘ 0 πŸ“– 5 min read

High-Risk AI Classification: Is Your System Affected?

What Is High-Risk AI Under the EU AI Act? High-risk AI under the EU AI Act refers to systems that pose significant risk to health, safety, or fundamental rights (European Commission, 2024). The Act defines two categorie

What Is High-Risk AI Under the EU AI Act?

High-risk AI under the EU AI Act refers to systems that pose significant risk to health, safety, or fundamental rights (European Commission, 2024). The Act defines two categories of high-risk systems: those deployed in specific regulated areas (Annex III), and AI systems that are safety components of regulated products (Annex I). Systems classified as high-risk must comply with the Act's most stringent requirements, including conformity assessments, risk management, and human oversight.

The European Commission's impact assessment accompanying the AI Act estimated that approximately 5–15% of AI systems deployed in the EU market would qualify as high-risk (European Commission, 2024, Staff Working Document). While the Digital Omnibus on AI moved the Annex III high-risk deadline to December 2, 2027 (Annex I products follow August 2, 2028), the classification process and documentation requirements demand starting now (European Commission, 2024).

Annex III High-Risk Categories

  • Biometric identification (remote facial recognition, fingerprint matching) β€” typical compliance lead time 12–18 months.

  • Critical infrastructure management (traffic control, power grid AI) β€” 10–14 months.

  • Educational and vocational training (exam scoring, student admission AI) β€” 8–12 months.

  • Employment and worker management (CV screening, performance monitoring) β€” 6–10 months.

  • Access to essential services (credit scoring, insurance pricing) β€” 8–12 months.

  • Law enforcement (risk assessment, evidence analysis) β€” 12–18 months.

  • Migration and border control (visa processing, travel document verification) β€” 10–14 months.

  • Administration of justice (sentencing recommendations, evidence evaluation) β€” 14–18 months.

High-Risk Classification Criteria

The AI Act uses a two-pronged test for high-risk classification (European Commission, 2024). A system is high-risk if it meets both conditions:

Condition A: Scope

The system is deployed in one of the Annex III areas listed above. This is a broad scope covering most AI applications in regulated industries.

Condition B: Significant risk

The system poses a significant risk of harm to health, safety, or fundamental rights. The Act presumes that systems operating in Annex III areas meet this condition unless the provider can demonstrate otherwise.

Derogation: When a High-Risk System Is Not High-Risk

The Act allows providers to opt out of high-risk classification if they can demonstrate all of the following (European Commission, 2024):

The system performs a narrow procedural task

If the AI system is limited to a specific, well-defined step in a broader process (e.g., document classification before human review), it may qualify for derogation.

The system improves outcomes of a human activity

Systems that augment rather than replace human decision-making β€” providing recommendations or flagging anomalies β€” may be excluded if the human retains meaningful control.

The system prepares decisions only

Systems that prepare or pre-process information for human decision-makers without influencing the outcome directly may qualify. The key requirement is that the human decision-maker conducts a substantive review.

The system does not profile natural persons

Systems that do not create profiles of individuals based on their behavior, preferences, or characteristics are more likely to qualify for derogation.

Obligations for High-Risk AI Systems

If your system is classified as high-risk, the following obligations apply beginning December 2, 2027 for Annex III systems (August 2, 2028 for Annex I product components) under the Digital Omnibus rescheduling (European Commission, 2024):

Risk management system

A continuous, iterative process throughout the system lifecycle. Must identify known and foreseeable risks, evaluate potential unintended consequences, and implement mitigation measures. Documentation of risk management decisions must be maintained and updated regularly.

Technical documentation

Comprehensive documentation covering system design, development methodology, training data sources, performance metrics, and intended purpose. Must be detailed enough to enable conformity assessment by a notified body.

Record-keeping and logging

Automatic logging of system operations during high-risk use. Logs must capture input data, output decisions, human override events, and system errors. Retention period is at least 6 months unless otherwise specified by applicable sectoral law.

Transparency and provision of information

Users must receive clear information about the system's capabilities, limitations, and intended purpose. High-risk systems must be labeled as such in their technical documentation and user interface.

Human oversight

Design appropriate human oversight measures based on the nature of the system and its risk profile. Options include human-in-the-loop (human must approve each decision), human-on-the-loop (human monitors and can intervene), and human-in-command (human controls the overall system governance).

Accuracy, robustness, and cybersecurity

Systems must achieve appropriate levels of accuracy, robustness, and cybersecurity performance given their intended purpose. Providers must establish validation and testing procedures, define performance benchmarks, and implement cybersecurity protections commensurate with risk.

Frequently Asked Questions

How do I determine if my system is Annex I or Annex III high-risk?

Annex I covers AI systems that are safety components of products already regulated under EU harmonization legislation (medical devices, machinery, toys). Annex III covers standalone AI systems in specific domains. If your system could fall under both, Annex I takes precedence (European Commission, 2024).

What happens if I incorrectly classify a high-risk system as limited risk?

The AI Office may reclassify systems during compliance audits. Incorrect classification that leads to non-compliance with applicable obligations can result in penalties up to 35 million EUR or 7% of global annual turnover, as set out in Article 99 of the AI Act (European Commission, 2024). If you are uncertain about classification, consulting a notified body before the compliance deadline is recommended.

Can a high-risk classification change over time?

Yes. The AI Act requires providers to continuously monitor their systems and update classification if system changes affect risk profile. Significant updates to functionality, deployment context, or data inputs may trigger reclassification. The European Commission also reviews the Annex III list periodically and may add new categories (European Commission, 2024).

Do high-risk obligations apply to AI systems developed before the deadlines?

Yes, with a transition period. If your system falls in an Annex III category, the high-risk obligations apply from December 2, 2027; systems placed on the market after that date must comply from the start. Annex I product components follow on August 2, 2028, and public-sector deployments on August 2, 2030, under the Digital Omnibus rescheduling (European Commission, 2024).

Sources

European Commission. (2024). Regulation (EU) 2024/1689 of the European Parliament and of the Council. *Official Journal of the European Union*. https://eur-lex.europa.eu/eli/reg/2024/1689

European Commission. (2024). Commission Staff Working Document: Impact Assessment Accompanying the AI Act. SWD(2024) 150 final.

NIST. (2023). *Artificial Intelligence Risk Management Framework (AI RMF 1.0)*. National Institute of Standards and Technology.

CNIL (Commission nationale de l'informatique et des libertΓ©s). (2025). *AI Compliance Guide*. CNIL.

ICO (Information Commissioner's Office). (2025). *AI and Data Protection Guidance*. ICO.
πŸ“° Read the original article on Dev.to AI

Originally published by Dev.to AI. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.