Chapter 5: High-Risk AI — Does Your System Qualify?

EU AI Act Implementation Guide · 1 min read

The EU AI Act classifies AI systems as high-risk based on what they are used for — not how they are built. A simple decision-tree algorithm used for hiring can be high-risk. A large language model used for internal search can be minimal-risk. The classification follows the consequences, not the complexity.

Two Pathways Into High-Risk

There are two pathways into high-risk. The first is Annex III, which lists eight domains: biometrics, critical infrastructure, education, employment and HR, essential services (including credit scoring, insurance, and emergency triage), law enforcement, migration and border control, and justice and democratic processes. If your AI system operates in any of these areas, it is almost certainly high-risk.

The second pathway captures AI used as a safety component in regulated products — medical devices, machinery, vehicles.

The Article 6(3) Exception

A narrow exception exists under Article 6(3) for systems that perform only procedural or preparatory tasks. But it never applies when the system profiles individuals. And the burden of proof is on you.

The Cost of Getting It Wrong

The cost of incorrectly classifying a high-risk system as minimal-risk can reach €15 million or 3% of global annual turnover. When in doubt, classify as high-risk.

What the Full Chapter Covers

Our full chapter covers all eight Annex III domains in detail, both pathways into high-risk classification, the Article 6(3) exception and its limits, a five-step assessment procedure, and a self-check worksheet for every AI system in your organisation.

Read the Full Chapter

Get the complete Chapter 5 with all eight Annex III domains, both classification pathways, the Article 6(3) exception analysis, and the self-check worksheet.

Read the Full Chapter Check Your AI Risk Level — Free