When a company asks itself whether it has high-risk AI systems, it looks at its operations. The software that optimises routes, the one that forecasts demand, the assistant that drafts proposals, the chatbot that handles enquiries. That's where the AI it decided to buy sits, so that's where it looks.
It's almost never there.
Where Annex III puts it
Annex III lists the eight high-risk areas. Its point 4 is headed "Employment, workers' management and access to self-employment", and it reads:
"(a) AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates."
"(b) AI systems intended to be used to make decisions affecting terms of work-related relationships, the promotion or termination of work-related contractual relationships, to allocate tasks based on individual behaviour or personal traits or characteristics or to monitor and evaluate the performance and behaviour of persons in such relationships."
Read it twice and it turns into the exact description of an AI-powered ATS: it filters applications, scores candidates, ranks a shortlist. And of a good deal of people-management software: it evaluates performance, suggests promotions, measures behaviour.
Nobody on the team that decides about AI bought that. HR did, probably before anyone at the company had even mentioned the AI Act, as part of a payroll-and-leave suite.
Why it gets overlooked, and it isn't carelessness
There are three reasons, and all three are reasonable.
It isn't perceived as "AI". It's perceived as "the HR software". The AI feature is one tick-box inside a product that does twenty other things.
It isn't managed by whoever runs compliance. The inventory is usually built by whoever knows the business's tools. HR is a separate department, with its own contracts and its own vendor.
And the bias built into the question. "Where do we use AI?" gets answered by thinking about what the company produces, not what it administers. The AI bought to do something better is front of mind for everyone; the AI that came bundled into a suite isn't.
It's the same dynamic that makes the inventory the precondition for almost everything else: you can't classify what hasn't been listed, and what gets listed is what gets remembered.
Two caveats that prevent the opposite mistake
This article points to where to look. It doesn't say that a high-risk system is automatically there.
First: classification depends on actual use, not on the product. An HR module that only manages payroll, onboarding and renewal dates doesn't fall under point 4. What does fall under it is the feature that filters applications, scores candidates or evaluates performance. The same suite can end up inside or outside depending on which modules are switched on and how they're used.
Second: the date. The Annex III regime isn't yet in application. It starts on 2 December 2027, not before — and there's a wrong date circulating about this that's worth clearing up, because plenty of guides still say August 2026. Today, there's no possible non-compliance through this route. There's time, which is different from having nothing to do.
When the high risk really is in your business
There are sectors where the answer changes, and not by chance: they're the ones whose activity was already regulated before the AI Act.
Healthcare, when the system is part of a medical product with a safety function — there, the route is Annex I, not III. Financial services, in the creditworthiness assessment of natural persons (Annex III, point 5). Education, in admission, assessment and monitoring of students (Annex III, point 3). And staffing as a service: if recruiting is your business, point 4 doesn't describe your HR department — it describes your product.
Outside those cases, the typical operation — logistics, distribution, professional services, customer service, back-office — doesn't appear in any high-risk annex. It's minimal or limited risk, with whichever obligations apply to each case, including the Article 50 transparency obligations when there's interaction or generated content.
What this changes when you build the inventory
One practical consequence, and only one.
If the inventory is built by asking whoever runs operations, it will come out complete for the business and incomplete for the company. The part that administers people will be missing — which is exactly where Annex III looks.
The question that fixes it isn't a technical one: what software do we use to hire, evaluate or measure the people who work here, and which of its features decides something? It gets answered in a conversation with HR, and it usually changes the whole map.
And what doesn't change, even if you have no high risk at all
It's worth closing on this, because the easy conclusion from this article would be the wrong one.
Having low exposure to high risk doesn't mean the Regulation doesn't reach you. Article 4 — AI literacy — has been in force since 2 February 2025, applies to any organisation that uses AI whatever its classification, and the Digital Omnibus rewrote it without removing it: it still requires taking measures. The same goes for Article 5, which prohibits certain practices from the same date and allows no exception based on size or sector.
So the realistic outcome of looking properly isn't "I have nothing to do." It's knowing what genuinely applies to you and what doesn't — which is exactly what separates a proportionate plan from misallocated fear.
Content in line with Annex III and Articles 4 and 5 of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (Official Journal of the EU, 24 July 2026).
This article is for informational purposes only and does not constitute legal advice.