Is my AI system high-risk under the EU AI Act?
A decision tree to classify AI systems under Articles 6 and Annex III of the EU AI Act, with concrete SaaS, HR, finance, and healthcare examples for European SMEs.
“Is my AI system high-risk?” is the single most important question the EU AI Act forces every European company to answer. Get it wrong by underclassifying and you face fines of €15 million or 3% of global turnover (Article 99). Get it wrong by overclassifying and you spend two quarters and a six-figure consulting budget meeting obligations that don’t apply to you.
The Act’s classification logic lives in Article 6 and Annex III. Here’s the decision tree.
The two paths to high-risk
A system is high-risk if either of two conditions is true:
- Article 6(1): the system is intended to be used as a safety component of a product, or is itself a product, covered by EU harmonisation legislation listed in Annex I (medical devices, machinery, toys, lifts, etc.) — and that product requires a third-party conformity assessment.
- Article 6(2): the system is intended for one of the use cases listed in Annex III.
For most SaaS startups and SMEs, path (1) doesn’t apply. Path (2) is where most of the action is.
The Annex III list — eight categories
Annex III lists eight categories of high-risk AI systems. The full list is in our Annex III explainer, but here’s the shorthand:
- Biometric identification, categorisation, and emotion recognition (when not prohibited under Article 5)
- Critical infrastructure — road traffic, water, gas, electricity, digital infrastructure safety
- Education and vocational training — admissions, assessment, exam supervision
- Employment, workers management, access to self-employment — recruitment screening, promotion decisions, task allocation
- Access to essential services — public benefits, credit scoring, life and health insurance pricing, emergency dispatch
- Law enforcement — risk assessment of individuals, evidence evaluation, polygraph tools
- Migration, asylum, and border control management
- Administration of justice and democratic processes
If your system’s intended use falls into one of these, it is presumed high-risk and the full provider/deployer obligations apply.
The Article 6(3) carve-out — most relevant for SaaS
The 2024 Act introduced Article 6(3), which lets a system that would otherwise be Annex III escape the high-risk classification if it does not pose a significant risk of harm. There are four specific paths:
- The system performs a narrow procedural task (e.g. converting unstructured input to structured)
- The system is intended to improve the result of a previously completed human activity
- The system detects decision-making patterns or deviations from prior patterns and isn’t meant to replace or influence the previous assessment without human review
- The system performs a preparatory task to an assessment relevant to the Annex III use case
Path 4 is the one most SaaS products end up under. It’s the legal basis for Maditon’s own classification of itself as not high-risk: Maditon prepares a draft risk classification, a named human in your organisation accepts or rejects it. We explain this in detail in Article 6(3)(d) explained.
But — and this is the critical fine print — the carve-out does not apply when the system “performs profiling of natural persons.” If your AI scores or ranks individual people, you cannot use the carve-out.
Worked examples
To make this concrete, here are five SME-typical scenarios:
| System | Classification | Why | |---|---|---| | A SaaS that ranks job candidates by predicted fit | High-risk (Annex III, point 4) | Direct employment-decision use case, and explicitly profiles persons — no carve-out | | A SaaS that drafts interview questions for a hiring manager | Limited risk | Doesn’t decide or rank candidates; transparency obligations under Article 50 | | A B2B credit-decisioning model that approves SME loans | High-risk (Annex III, point 5) | Access to essential service (credit), profiling | | A B2B credit-decisioning model used purely for internal portfolio analytics | Likely not high-risk | Article 6(3) carve-out may apply — does not influence individual decisions | | A customer-support chatbot on a healthcare website | Limited risk | Article 50 transparency only — chatbot disclosure required |
Notice how two systems with the same underlying model can land in different tiers depending on intended use. That’s why your written purpose statement matters more than the model architecture.
What you do once you’ve classified
If the answer is high-risk, you owe the full Article 9–17 obligations (if you are the provider) or Article 26 obligations (if you are the deployer). See our compliance checklist for the practical next steps.
If the answer is limited risk, you owe the transparency obligations in Article 50. Document the disclosure design in your audit trail.
If the answer is minimal risk, you still owe AI literacy under Article 4 — see AI literacy under Article 4. And it’s good practice to document the classification reasoning anyway.
Document the classification with reviewer notes
Whatever you classify, write down the reasoning. A “minimal risk” determination with one sentence of explanation will not survive a supervisory authority’s questions. Capture:
- The intended use of the system
- Which Annex III categories you considered and ruled out (or in)
- Whether the Article 6(3) carve-out applies and why
- Who reviewed and accepted the classification (with name and date)
This is the audit trail the Act expects. It’s also what a software platform should generate for you, so you don’t end up with a 30-page Google doc that nobody can find next year.