High risk
Category of the Regulation grouping two sets: AI systems that are safety components of products regulated by the Union harmonisation legislation of Annex I (Article 6(1)), and systems falling within the eight areas of Annex III (Article 6(2)).
It is not “the important AI”: it is a list of areas of use, and being in one of them is not enough.
Which obligations it carries
The requirements of Chapter III are a legal obligation applicable from 2 December 2027 for systems classified as high-risk under Article 6(2) and Annex III, and from 2 August 2028 for those classified under Article 6(1) and Annex I. The exception of Article 6(3) — under which an Annex III system is not considered high-risk where it does not pose a significant risk — shares the Annex III date: 2 December 2027.
What it is not
It is not a label put on a system for its power or its reach: it depends on the area of use and, within it, on whether it poses a significant risk. And being in an Annex III area does not automatically make it high-risk: Article 6(3) excludes it where it does not pose a significant risk of harm to health, safety or fundamental rights, and lists four conditions — a narrow procedural task; improving the result of a previously completed human activity; detecting decision-making patterns or deviations from prior patterns, provided it does not replace or influence a previously completed human assessment unless there is proper human review; a preparatory task to an assessment relevant for the purposes of the use cases listed in Annex III. But that exception has a hard limit: Annex III systems are always considered high-risk where they perform profiling of natural persons.
The nuance almost nobody captures
Of the eight areas, the two that reach an ordinary SME are not in its product: they are in its internal processes and its relationship with customers. Area 4 — employment, workers’ management and access to self-employment — covers the screening of applications and decisions on the employment relationship. Area 5, points (b) and (c), covers evaluating the creditworthiness or establishing the credit score of natural persons — with the express exception of systems used to detect financial fraud — and risk assessment and pricing in life and health insurance. And an asymmetry worth knowing: invoking the Article 6(3) exception is not free. The provider that invokes it must document its assessment before placing the system on the market and is subject to the registration obligation of Article 49(2). The exception does not remove the burden: it moves it.
Related terms
To find out more
- The Digital Omnibus is now in force: what changes in the AI Act and what stays the same
- High risk: what the Commission's classification guidelines aim to clarify
- Your company's high risk probably isn't in your business: it's in HR
- Annex III: the high-risk date is December 2027, not August 2026
- The AI Act's grace period: the article stopped stating the date
- Advisory firms and law practices: the Annex III point you fear isn't about you
- Private education: Annex III has four letters for your school, and the fourth surprises everyone
- Financial services: high risk is in your business, but narrower than you'd think
- AI in the dental clinic: where the real risk sits and what to document now
- AI in B2B and food distribution: your operations aren't high-risk; your HR might be
- AI in logistics and transport: telematics, fatigue and the two boundaries you need to know
- AI in recruitment: the high-risk zone arriving in December 2027
- Harmonised standards under the AI Act: why the presumption of conformity still doesn't exist
- Private healthcare: the sector where high risk really is in the core activity — and through two different routes
- Recruitment: when HR is the business, high risk stops hiding