Skip to content
Rubra Digital

Governance & regulation

Is our AI system high-risk under the EU AI Act?

Short answer

High-risk classification under the EU AI Act follows the use case, not the technology. Annex III lists the high-risk categories: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services including creditworthiness and insurance pricing, law enforcement, migration and border control, and administration of justice. An internal knowledge assistant is normally minimal or limited risk, carrying mainly transparency obligations. The same underlying technology used to screen job applicants is high-risk. Classify each use case separately and document the reasoning, because the reasoning is what you have to defend.

Last reviewed

Engineering guidance, not legal advice. Your counsel should own the legal classification; I help produce the technical evidence behind it.

The four tiers

Unacceptable risk, prohibited. Social scoring by public authorities, manipulative techniques exploiting vulnerabilities, untargeted scraping of facial images to build recognition databases, emotion inference in workplaces and schools, and certain biometric categorisation. These have been prohibited since February 2025.

High risk, the substantive obligations. Two routes in. Annex I covers AI as a safety component of products already subject to EU product legislation such as medical devices, machinery, vehicles and lifts. Annex III lists standalone high-risk use cases:

  • Biometric identification and categorisation
  • Critical infrastructure management and operation
  • Education and vocational training: admission, evaluation, proctoring
  • Employment and worker management: recruitment, screening, promotion, task allocation, monitoring
  • Access to essential private and public services: creditworthiness, benefits eligibility, emergency dispatch, life and health insurance pricing
  • Law enforcement
  • Migration, asylum and border control
  • Administration of justice and democratic processes

There is a narrowing provision: a system in an Annex III area may fall outside high-risk if it only performs a narrow procedural task, improves the result of a previously completed human activity, or does preparatory work, but not if it profiles individuals. Relying on this requires documented assessment, not an assumption.

Limited risk, transparency. Chatbots must disclose that a user is interacting with an AI system. Synthetic image, audio, video and text must be marked as artificially generated in machine-readable form. Deepfakes must be disclosed. Most customer-facing assistants land here.

Minimal risk. Everything else. No mandatory obligations. Most internal productivity tooling sits here.

Applying it honestly

The question “is my RAG system high-risk?” has no answer. The system is not the unit of classification. The use case is.

One retrieval platform inside a company might simultaneously power:

  • An HR policy assistant for staff. Limited risk, disclosure only
  • A CV screening tool for recruiters. High risk, Annex III employment
  • A customer support assistant. Limited risk, disclosure
  • A credit memo drafting aid. Likely high risk, creditworthiness

Same infrastructure, four different classifications. Inventory by use case.

What high-risk actually requires

Risk management across the lifecycle (Art. 9); data governance covering provenance, representativeness and bias examination (Art. 10); technical documentation to Annex IV (Art. 11); automatic logging (Art. 12); transparency and instructions for use (Art. 13); effective human oversight (Art. 14); accuracy, robustness and cybersecurity with declared metrics (Art. 15); a quality management system (Art. 17); conformity assessment and CE marking; and registration in the EU database.

That is a substantial programme. It is also, for the engineering half, largely the same evidence a well-run evaluation and observability practice already produces.

Timeline

In force since August 2024, applying in stages: prohibitions and AI literacy from February 2025, general-purpose AI model obligations from August 2025, the main Annex III high-risk obligations from August 2026, and Annex I embedded systems from August 2027.

The Commission has proposed adjustments to parts of this schedule, so confirm the current position with your counsel before planning around specific dates.

Extraterritorial reach

The Act applies if you place a system on the EU market, put it into service in the EU, or if the system’s output is used in the EU, wherever your company is established. That final limb catches a large number of US and Canadian companies serving European customers who assume they are out of scope.

People also ask this as

  • What counts as high-risk AI in the EU?
  • Does the EU AI Act apply to chatbots?
  • What are the EU AI Act deadlines?

Still have a question?

I answer questions from people who are not clients. It is how most engagements start, and there is no obligation attached.

No NDA needed to talk. EU and UK hours in full, with afternoons overlapping US Eastern and Central.