Which AI systems are high-risk under the EU AI Act?
Two routes. A system is high-risk if it is a safety component of a product covered by the EU harmonisation legislation in Annex I, or if it falls into one of the eight standalone use-case categories in Annex III — biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice or democratic processes.
Article 6 sets out the two routes into the high-risk tier.
Annex I route. The AI system is a safety component of a product already covered by EU harmonisation legislation — medical devices, machinery, lifts, toys and the rest — or is itself such a product.
Annex III route. The system falls into one of eight standalone categories:
- Biometrics
- Critical infrastructure
- Education and vocational training
- Employment and workers’ management
- Access to essential private and public services
- Law enforcement
- Migration, asylum and border control
- Administration of justice and democratic processes
Category 4 catches more European SMEs than any other: recruitment and selection, including systems that place targeted job advertisements, filter applications or evaluate candidates. Most applicant-tracking and candidate-scoring products land here.
The carve-out. Article 6(3) lets a system that would otherwise be Annex III escape the tier when it performs a narrow preparatory task and does not materially influence the decision’s outcome. It is narrower than it first appears, and claiming it requires you to document the assessment. Guessing at it is one of the more expensive mistakes available.
Regulation references
- Regulation (EU) 2024/1689 (EU AI Act) · CELEX 32024R1689
Read next
A free Solo account runs a real classification on one of your own systems — no card, no sales call.
Run a free classification