Hlinix.com

Chapter 5: High-Risk AI Systems — What Makes AI “High-Risk”?

EU AI Act Implementation Guide · Full Chapter

What you will know after reading this chapter: You will understand in detail why certain AI systems are classified as high-risk, what the full scope of Annex III covers, how the two pathways into high-risk classification work, and how to determine whether the Article 6(3) exception applies to your system. This chapter explains the “what” and “why” of high-risk classification. Chapters 6 and 7 explain the “what to do” — the specific obligations for deployers and providers respectively.

The Logic Behind High-Risk Classification

The EU AI Act does not classify AI systems as high-risk because the technology is complex or powerful. A large language model with billions of parameters might be minimal-risk. A simple decision-tree algorithm might be high-risk. The classification is based entirely on what the AI system is used for and what harm it could cause.

The principle is this: when an AI system is used in a context where its errors, biases, or failures could seriously harm a person’s health, safety, fundamental rights, or access to essential services, that system is high-risk. The law demands additional safeguards — not because the AI is inherently dangerous, but because the stakes of getting it wrong are too high to rely on self-regulation alone.

This is why a spam filter is minimal-risk but a CV screening tool is high-risk. The spam filter incorrectly flagging an email is an inconvenience. The CV screening tool incorrectly rejecting a qualified candidate based on biased training data can alter the course of someone’s career. The technology might be similar. The consequences are not.

The Two Pathways Into High-Risk Classification

As introduced in Chapter 3, there are two distinct ways an AI system can be classified as high-risk.

Pathway 1: Annex III — The Listed Domains

Annex III of the AI Act provides an exhaustive list of eight domains. If your AI system is used in any of these domains and performs the functions described, it is classified as high-risk by default (subject to the Article 6(3) exception, discussed below).

Domain 1: Biometrics

What is covered: AI systems intended for remote biometric identification of natural persons. Annex III point 1(a) excludes AI systems used for biometric verification whose sole purpose is to confirm that a specific person is who they claim to be. Separately, real-time remote biometric identification in publicly accessible spaces for law enforcement purposes is prohibited under Article 5(1)(h) rather than high-risk; the same technology used outside law enforcement remains high-risk here. AI systems intended for biometric categorisation according to sensitive or protected attributes or characteristics based on the inference of those attributes or characteristics. AI systems intended for emotion recognition.

Why it matters: Biometric systems process uniquely personal data — your face, voice, gait, fingerprints. Errors in identification can lead to wrongful accusations. Categorisation based on inferred sensitive attributes can enable discrimination. Emotion recognition in non-prohibited contexts (outside workplaces and schools) still carries significant risks to privacy and dignity.

Practical example: A company providing facial recognition for building access control. The system identifies individuals based on facial features. This is remote biometric identification — high-risk under Domain 1, even though it operates in a private space.

Common confusion: Emotion recognition appears in three categories of the AI Act — prohibited (in workplaces and schools), high-risk under Annex III point 1(c) (biometrics), and limited-risk in other contexts under Article 50(3). Where your system sits depends entirely on the deployment context.

Domain 2: Critical Infrastructure

What is covered: AI systems intended to be used as safety components in the management and operation of road traffic and the supply of water, gas, heating, or electricity. This also covers AI systems intended to be used as safety components in digital infrastructure.

Why it matters: Failures in critical infrastructure can endanger lives on a large scale. An AI system managing electricity grid load balancing that makes an error could cause blackouts affecting hospitals, emergency services, and vulnerable populations. The stakes demand rigorous oversight.

Practical example: An AI system that manages traffic signal timing at intersections based on real-time traffic flow data. If the system malfunctions — for example, giving green lights to conflicting traffic streams — the consequences could be fatal. This is a safety component in road traffic management: high-risk.

What is not covered: AI systems used for non-safety functions in infrastructure, such as an AI tool that analyses energy consumption patterns for billing optimisation. If the system has no safety function, it does not fall under this domain.

Domain 3: Education and Vocational Training

What is covered: AI systems intended to determine access to or admission into educational institutions or vocational training programmes. AI systems intended to evaluate learning outcomes, including when those outcomes are used to steer the learning process. AI systems intended to assess the appropriate level of education an individual will receive or be able to access. AI systems intended to monitor and detect prohibited behaviour of students during tests.

Why it matters: Education is a fundamental right and a key determinant of life outcomes. AI systems that decide who gets admitted, how students are evaluated, or what level of education they can access have the power to shape entire life trajectories. Biased or inaccurate AI in education can systematically disadvantage certain groups.

Practical example: A university using an AI system to rank and filter applicants for admission. Even if a human admissions officer makes the final decision, the AI system that determines which applications the officer sees is high-risk under Domain 3.

What is not covered: AI systems used for administrative tasks in educational settings that do not affect access, evaluation, or educational levels. For example, an AI system that optimises classroom scheduling is not high-risk under this domain.

Domain 4: Employment, Workers Management, and Access to Self-Employment

What is covered: AI systems intended to be used for recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates. AI systems intended to be used to make decisions affecting the terms of work-related relationships, including promotion, termination, task allocation based on individual behaviour or personal traits or characteristics, and performance and behaviour monitoring.

Why it matters: Employment decisions directly affect livelihoods. AI systems used in hiring can perpetuate historical biases — against women, minorities, older workers, people with disabilities — at scale. Performance monitoring systems can create hostile work environments. The consequences of errors are not theoretical: people lose income, career opportunities, and dignity.

Practical example: A company using an AI-powered tool to screen incoming CVs and rank candidates before human recruiters review them. Even though a human makes the final hiring decision, the AI system is performing the initial filtering — determining which candidates get considered and which do not. This is high-risk under Domain 4.

Important note: This domain is one of the most commonly triggered in practice. Many companies use AI in some part of their recruitment or HR process without realising that doing so makes the system high-risk. If your organisation uses any AI-powered tool for hiring, screening, performance evaluation, or workforce management, it almost certainly falls here.

Domain 5: Access to Essential Private Services and Public Services and Benefits

What is covered: This domain has four sub-categories:

Point 5(a) — Public assistance: AI systems intended to be used by public authorities or on behalf of public authorities to evaluate the eligibility of natural persons for essential public assistance benefits and services, including healthcare services, or to grant, reduce, revoke, or reclaim such benefits and services.

Point 5(b) — Credit scoring: AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud. This means a fraud detection system is not high-risk under this point, but a credit scoring system is.

Point 5(c) — Life and health insurance: AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance.

Point 5(d) — Emergency services: AI systems intended to evaluate and classify emergency calls by natural persons or to be used to dispatch, or to establish priority in the dispatching of, emergency first response services, including by police, firefighters, and medical aid, as well as emergency healthcare patient triage systems.

Why it matters: These are all contexts where AI decisions can have life-altering consequences. Being denied credit can prevent someone from buying a home. Being denied public assistance can push someone into poverty. Being wrongly triaged in an emergency can cost a life. Insurance pricing based on biased AI can systematically disadvantage entire groups.

Common confusion: Fraud detection AI used by banks and financial institutions is specifically excluded from point 5(b). If your AI system’s primary purpose is detecting fraudulent transactions, it is not high-risk under this point. However, if the same system also generates credit scores as a secondary function, the credit scoring function is high-risk.

Domain 6: Law Enforcement

What is covered: AI systems intended to be used by law enforcement authorities, or on their behalf, for several specific purposes. Annex III point 6 lists five: assessing the risk of a natural person becoming a victim of criminal offences; use as polygraphs or similar tools; evaluating the reliability of evidence in the course of investigation or prosecution of criminal offences; assessing the risk of a natural person offending or re-offending not solely on the basis of profiling (profiling alone would be prohibited under Article 5(1)(d)), or assessing personality traits and characteristics or past criminal behaviour; and profiling of natural persons in the course of detection, investigation, or prosecution of criminal offences.

Why it matters: Law enforcement AI directly implicates fundamental rights — the right to liberty, the presumption of innocence, the right to a fair trial, and the right to non-discrimination. Errors in law enforcement AI do not just cause inconvenience; they can lead to wrongful arrests, unjust imprisonment, and destruction of lives.

Important note regarding the right to explanation (Article 86): Affected persons subject to a decision taken on the basis of the output of a high-risk AI system listed in Annex III — every domain except point 2, critical infrastructure — have the right to obtain from the deployer a clear and meaningful explanation of the role the AI system played in the decision and the main elements of the decision, where that decision produces legal effects or similarly significantly affects them. This is a separate right from the deployer’s notification duty under Article 26(11). For high-risk AI systems used for law enforcement purposes, Article 26(11) defers instead to Article 13 of Directive (EU) 2016/680.

Domain 7: Migration, Asylum, and Border Control Management

What is covered: AI systems intended to be used by competent public authorities, or on their behalf, as polygraphs or similar tools; to assess certain risks posed by natural persons who enter or have entered the territory of a Member State; to assist competent public authorities in the examination of applications for asylum, visa, or residence permits, and associated complaints regarding the eligibility of the natural persons applying for that status; and for the purpose of detecting, recognising, or identifying natural persons in the context of migration, asylum, and border control management, with the exception of the verification of travel documents.

Why it matters: People seeking asylum or crossing borders are often in situations of extreme vulnerability. AI systems used in migration decisions affect fundamental rights including the right to asylum, the right to non-refoulement (not being sent back to face persecution), and the right to family life.

Important note regarding the right to explanation (Article 86): As in the other Annex III domains apart from point 2, affected persons in the migration domain can require an explanation of an AI-assisted decision under Article 86, and deployers must notify them of the system’s use under Article 26(11).

Domain 8: Administration of Justice and Democratic Processes

What is covered: AI systems intended to be used by judicial authorities, or on their behalf, to assist in researching and interpreting facts and the law and in applying the law to a concrete set of facts, or to be used in a similar way in alternative dispute resolution. AI systems intended to influence the outcome of an election or referendum, or the voting behaviour of natural persons in the exercise of their vote in elections or referendums. This does not include AI systems whose output does not directly interact with natural persons, such as tools used to organise, optimise, or structure political campaigns from an administrative and logistical point of view.

Why it matters: AI in judicial decision-making raises profound questions about the right to a fair trial, judicial independence, and equal treatment before the law. AI systems that influence elections strike at the heart of democratic governance.

Important note regarding the right to explanation (Article 86): Affected persons in the justice and democratic processes domain can likewise require an explanation of an AI-assisted decision under Article 86, and deployers must notify them of the system’s use under Article 26(11).

Pathway 2: Safety Components Under EU Product Legislation

The second pathway into high-risk classification is defined by Article 6(1). An AI system is classified as high-risk if both of the following conditions are met: the AI system is intended to be used as a safety component of a product, or the AI system is itself a product, that is covered by certain EU harmonisation legislation listed in Annex I; and the product whose safety component is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment with a view to the placing on the market or the putting into service of that product.

What this means in practice: If AI is embedded in a product that is already regulated for safety — such as a medical device, a piece of industrial machinery, a toy, a personal protective equipment, or a vehicle component — and that product requires third-party safety certification, the AI component is automatically high-risk.

Key EU product legislation (Annex I) includes the Machinery Regulation, the Medical Devices Regulation (MDR), the In Vitro Diagnostic Medical Devices Regulation (IVDR), the Radio Equipment Directive, the Civil Aviation Regulation, certain vehicle type-approval regulations, the Marine Equipment Directive, the Railway Interoperability Directive, and others.

Practical example: A company developing an AI-powered diagnostic algorithm embedded in a medical device. The medical device is regulated under the MDR and requires a conformity assessment by a notified body. Because the AI is a safety component of a product that requires third-party conformity assessment, the AI system is high-risk under Pathway 2, regardless of whether it appears in Annex III.

Why both pathways exist: Pathway 1 (Annex III) covers AI used in specific high-stakes domains. Pathway 2 covers AI used in any product where safety is already regulated. Together, they ensure that high-risk AI is captured whether the risk comes from the domain of use or from the product context.

The Article 6(3) Exception

Not every AI system that appears in Annex III is automatically high-risk. Article 6(3) provides a narrow exception. An Annex III system is not considered high-risk if it does not pose a significant risk of harm to the health, safety, or fundamental rights of natural persons, taking into account the severity and probability of such harm.

Specifically, an AI system listed in Annex III may be excluded if it meets one of the following conditions: it is intended to perform a narrow procedural task (such as an AI system that only sorts incoming documents by file type before a human reviews them); it is intended to improve the result of a previously completed human activity; it is intended to detect decision-making patterns or deviations from prior decision-making patterns without replacing or influencing the previously completed human assessment, without proper human review; or it is intended to perform a preparatory task to an assessment relevant to the use cases listed in Annex III.

Critical limitation: This exception does not apply if the AI system performs profiling of natural persons within the meaning of GDPR Article 4(4). If your system profiles individuals — processing personal data to evaluate aspects of their personality, behaviour, interests, reliability, location, movements, health, or preferences — the exception cannot be claimed, regardless of how narrow or preparatory the task might seem.

The burden of proof: If you rely on this exception, you must document your reasoning thoroughly. The provider or deployer must demonstrate that the system meets the exception criteria. If a national authority challenges your classification, you need to be able to defend it with evidence. When in doubt, classify as high-risk and comply with the full obligations — the cost of compliance is far lower than the cost of a mis-classification enforcement action.

How to Determine If Your System Is High-Risk: Detailed Assessment

For each AI system in your organisation, work through the following assessment:

Step 1: Check Article 5 first. If the system is prohibited, high-risk classification is irrelevant. You covered this in Chapter 4.

Step 2: Check Annex III domains. Go through each of the eight domains. For each one, ask: does my AI system perform any of the functions described in this domain? Be specific. Do not rely on your general impression of what the system does — look at its actual functions and the decisions it influences.

Step 3: Check Pathway 2. Is the AI system a safety component of a product regulated under any of the Annex I legislation? Does that product require third-party conformity assessment?

Step 4: If Annex III applies, assess Article 6(3). Does the system perform only a narrow procedural task? Does it improve a previously completed human activity? Does it detect patterns without replacing human judgment? Is it purely preparatory? Does it perform profiling? Document your answers.

Step 5: Determine your conclusion. If the system falls under Annex III and the Article 6(3) exception does not apply, or if it falls under Pathway 2, it is high-risk. If you are uncertain, classify as high-risk.

Self-Check: High-Risk Assessment

For each AI system you identified in Chapter 2, answer the following:

AI System: ____________________

#QuestionYes / No
1Does it perform any function listed in Annex III Domains 1–8?
2If yes, which domain(s)?
3Does the Article 6(3) exception apply?
4Does the system perform profiling? (If yes, exception cannot apply)
5Is the system a safety component of a product requiring third-party conformity assessment?
6Final classification: High-Risk?

Summary

High-risk classification under the EU AI Act is determined by what an AI system is used for, not how it is built. There are two pathways: Annex III (eight specific domains covering biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice) and Pathway 2 (AI as a safety component of regulated products). The Article 6(3) exception allows certain Annex III systems to avoid high-risk classification if they perform narrow procedural tasks, improve previous human activities, detect patterns without replacing human judgment, or perform preparatory tasks — but this exception never applies when the system performs profiling.

When in doubt, classify as high-risk. The cost of over-compliance is manageable; the cost of under-classification — up to €15 million or 3% of global annual turnover — is severe. Now that you understand what makes a system high-risk, the next chapters explain what you need to do about it — Chapter 6 for deployers, Chapter 7 for providers.

← Back to Blog Summary