
An AI system is not high-risk merely because it uses a powerful model or handles an important task. Classification depends on the system’s intended purpose, role in a regulated product, and whether it falls within the AI Act’s listed high-risk uses. Start with the actual decision and affected person, apply Article 6 and the annexes, document the result, and reassess when the purpose or workflow changes.
AI
An AI system is not high-risk merely because it uses a powerful model or handles an important task. Classification depends on the system’s intended purpose, role in a regulated product, and whether it falls within the AI Act’s listed high-risk uses. Start with the actual decision and affected person, apply Article 6 and the annexes, document the result, and reassess when the purpose or workflow changes.
Scope and July 2026 Timing
This article is educational information, not legal advice. High-risk classification is fact-specific and can affect substantial provider and deployer duties. Obtain qualified EU legal advice before relying on an internal classification.
The original AI Act establishes two main high-risk routes:
• Article 6(1) and Annex I: AI used as a safety component of, or itself constituting, certain products subject to listed EU harmonisation law, where third-party conformity assessment is required.
• Article 6(2) and Annex III: listed use cases in areas such as biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and administration of justice.
The final AI Omnibus changed the application schedule. Regulation (EU) 2026/1744 sets:
• 2 December 2027 for Chapter III requirements applying to Article 6(2) and Annex III high-risk systems.
• 2 August 2028 for the relevant requirements applying to Article 6(1) and Annex I product-related systems.
The Commission’s high-risk classification page describes practical guidelines, but as reviewed in July 2026 the detailed classification guidance is still presented as draft and non-binding. Use it as regulator guidance, not enacted law.
Other provisions can apply sooner. A conclusion that a system is not high-risk does not remove GDPR, consumer, employment, equality, sectoral, contractual, or Article 50 transparency responsibilities.
The Six-Step Classification Decision
Step 1: Confirm that the product contains an AI system
Use the Act’s definition and current Commission guidance. Do not classify a feature from its marketing label. Document what inputs it receives, how it infers outputs, what outputs it produces, and how those outputs influence a physical or virtual environment.
A deterministic rule such as “if invoice total exceeds GBP 10,000, require approval” may not be an AI system. A model that predicts invoice fraud and changes routing may be.
Step 2: Record the intended purpose
The intended purpose is the use specified by the provider, including the context and conditions described in instructions, technical documentation, promotional material, and statements.
Write it precisely:
The system ranks applicants for a customer-support position and recommends which applicants receive a first interview.
Do not write:
The system helps HR.
Classification follows the real function. Vague descriptions hide the decision being influenced.
Step 3: Test the Annex I product route
Ask:
1. Is the AI a safety component of a product, or itself a product, covered by legislation listed in Annex I?
2. Must that product or safety component undergo third-party conformity assessment before market placement or service?
Examples can include certain machinery, medical devices, lifts, toys, aviation, or other regulated products, but the product legislation and Omnibus amendments must be checked directly. Ordinary CRM automation does not become Annex I high-risk merely because it is business-critical.
Step 4: Test each relevant Annex III area
For SMBs, the most likely categories include:
Employment and worker management. Recruitment advertising, filtering applications, evaluating candidates, promotion, termination, task allocation based on individual behaviour or traits, and monitoring or evaluating performance can require careful Annex III analysis.
Education and vocational training. Admission, access, learning-outcome evaluation, education-level assignment, or monitoring prohibited behaviour during tests may fall within listed uses.
Access to essential private services. Evaluating creditworthiness or establishing a credit score is a listed area, with stated exceptions. Certain risk assessment and pricing in life and health insurance are also listed.
Biometrics. Remote biometric identification, biometric categorisation using sensitive attributes, and emotion recognition have specific treatment and exceptions.
Critical infrastructure. AI used as a safety component in managing or operating listed critical digital or physical infrastructure can be high-risk.
The question is not whether a tool is used somewhere inside HR or finance. The question is whether its intended use matches the legal description.
Step 5: Evaluate Article 6(3) limitations
The Act provides that an Annex III system may not be high-risk when it does not pose a significant risk of harm to health, safety, or fundamental rights, including by not materially influencing decision-making, and when it performs specified narrow tasks. Examples in the Act include certain procedural, preparatory, pattern-detection, or improvement activities.
Do not use this as a broad “human in the loop” exemption. Profiling within the meaning referenced by the Act receives special treatment, and the conditions must be applied carefully. Record the relied-on condition and evidence.
The 2026 Omnibus also changed registration treatment for systems considered exempt. Check the final amended law instead of copying an older registration checklist.
Step 6: Determine your role and change triggers
A provider, deployer, importer, distributor, and authorised representative have different duties. An SMB can become a provider for a specific system by placing it under its name, changing its intended purpose, or making a substantial modification in circumstances described by the Act.
Create reassessment triggers:
• New intended users or affected groups.
• Expansion from advice to ranking or decision.
• New data that enables profiling.
• Addition of biometric or emotion functions.
• Integration into a regulated product.
• Removal of meaningful human review.
• Change to provider name, branding, or market placement.
• Model, prompt, or workflow change affecting compliance or intended purpose.
What High-Risk Status Changes
When the relevant rules apply, providers of high-risk systems face requirements involving risk management, data governance, technical documentation, records, transparency to deployers, human oversight, accuracy, robustness, cybersecurity, quality management, conformity assessment, registration in applicable cases, and post-market monitoring.
Deployers have their own obligations. The original Article 26 includes following instructions, assigning competent human oversight, ensuring relevant input data, monitoring operation, retaining logs under their control, conducting certain impact assessments where applicable, and reporting risks or incidents.
These are legal categories, but exact duties depend on role and system. A generic compliance badge is not a substitute for the applicable articles.
Evidence and Artifacts
Maintain a classification file containing:
• System name, version, owner, and vendor.
• Plain-language functional description.
• Intended purpose and prohibited uses.
• Inputs, outputs, decisions, and affected groups.
• AI-system definition assessment.
• Annex I legislation and assessment result.
• Annex III category-by-category analysis.
• Article 6(3) analysis and supporting evidence, if relied upon.
• Profiling assessment.
• Provider/deployer role assessment.
• Human oversight design.
• Data-flow and privacy assessment links.
• Legal review and decision date.
• Change and reassessment triggers.

Recommended practice is to version the classification with the workflow. A 2026 assessment should not silently cover a substantially different 2027 implementation.
Common Failure Modes
Classifying the foundation model instead of the deployed system. The use context and intended purpose are central.
Assuming all HR AI is high-risk. Some listed employment uses are high-risk; an internal meeting summariser is not automatically in the same category.
Assuming human review always removes high-risk status. Human involvement must be analysed against Article 6 and the actual material influence.
Ignoring shadow features. A CRM may introduce employee scoring or emotion analysis through a product update.
Treating draft guidance as legislation. Commission guidance helps interpretation but does not amend the regulation.
Using obsolete dates. The July 2026 Omnibus moved Annex III application to 2 December 2027 and Annex I product-related application to 2 August 2028.
Failing to reassess purpose changes. Turning a drafting tool into an autonomous ranking or eligibility system can change the analysis.
SMB Classification Checklist
• [ ] Describe the actual system, not the vendor category.
• [ ] Record the intended purpose in one testable sentence.
• [ ] Identify outputs, decisions, actions, and affected people.
• [ ] Confirm whether the AI Act definition is met.
• [ ] Test the Annex I product route.
• [ ] Test every plausible Annex III category.
• [ ] Evaluate Article 6(3) only with documented evidence.
• [ ] Check whether profiling is involved.
• [ ] Identify provider and deployer roles.
• [ ] Record applicable dates under the 2026 Omnibus.
• [ ] Link the GDPR and sectoral-law assessments.
• [ ] Obtain legal review for borderline or consequential uses.
• [ ] Define change triggers and a review cadence.
• [ ] Preserve the signed classification record.
Use the AI agent governance guide to translate the result into permissions, approvals, logs, and rollback controls.
FAQs
Is every recruitment chatbot high-risk?
Not automatically. A chatbot that answers general vacancy questions differs from a system that filters applications, evaluates candidates, or materially influences selection. Assess the intended purpose and Annex III wording.
Does using a general-purpose model make a system high-risk?
No. High-risk classification is not based only on the power or generality of the model. It depends on the deployed AI system, intended purpose, product route, and listed use cases.
When do the EU high-risk AI rules apply?
Following Regulation (EU) 2026/1744, relevant Annex III rules apply from 2 December 2027 and relevant Annex I product-related rules from 2 August 2028. Other AI Act and data-protection provisions may apply earlier.
Can an Annex III system be treated as not high-risk?
Article 6(3) provides limited conditions, but they require careful application and documentation. Profiling and material influence are important. Seek legal advice rather than relying on a broad low-risk assertion.
Does an SMB only need to classify systems it builds?
No. Deployers need to understand systems they use, and a business can assume provider responsibilities in some branding, intended-purpose, or substantial-modification scenarios.
Get a 20-Minute AI Workflow Audit
AI Operator can map the intended purpose, decisions, data, roles, and controls of one workflow into a review-ready classification and implementation brief.