AI Governance & Regulation: EU AI Act, NIST AI RMF and ISO/IEC 42001 · EU AI Act deep dive · lesson 4 of 17 · 18 min
High-risk AI systems: classification and obligations
Why high-risk matters even if you never build AI
High-risk AI carries the AI Act's heaviest obligations. Providers bear most of them, but deployers have real duties too, and you can become a provider through Article 25. Recruitment, credit, insurance and education tools are the high-risk systems SMEs most often buy.
Two routes into high-risk (Article 6)
- Product route (Annex I). The AI system is a product, or a safety component of a product, covered by EU harmonization legislation listed in Annex I (for example machinery, toys, medical devices, radio equipment) and that product requires third-party conformity assessment.
- Use-case route (Annex III). The system is used in one of these areas:
| Annex III area | Examples | |---|---| | Biometrics (where permitted) | Remote biometric identification, biometric categorization, emotion recognition outside prohibited contexts | | Critical infrastructure | Safety components in road traffic, water, gas, heating, electricity, digital infrastructure | | Education and vocational training | Admissions, grading, assessing appropriate education level, proctoring | | Employment and worker management | Recruitment ads targeting, CV filtering, candidate evaluation, promotion, termination, task allocation, performance monitoring | | Access to essential services | Eligibility for public benefits, creditworthiness and credit scores (except fraud detection), life and health insurance risk pricing, emergency call triage | | Law enforcement | Risk assessments, polygraph-type tools, evidence reliability | | Migration, asylum, border control | Risk assessments, application examination | | Justice and democratic processes | Assisting judicial authorities; systems intended to influence election outcomes or voting behavior |
The Article 6(3) filter
An Annex III system is not high-risk if it does not pose a significant risk of harm and only performs a narrow procedural task, improves the result of a previously completed human activity, detects decision-making patterns or deviations without replacing or influencing human assessment without proper review, or performs a preparatory task. But a system that profiles natural persons is always high-risk. Providers relying on this filter must document their assessment before placing the system on the market and make it available to authorities on request. Check the current consolidated text for any registration requirement attached to this derogation, as the Omnibus revisited it.
Example: a tool that reformats CVs into a standard template before a human reads them is arguably preparatory. A tool that ranks candidates is not.
Provider obligations (Articles 8 to 22, summarized)
- Risk management system across the lifecycle.
- Data and data governance: training, validation and testing data that is relevant, sufficiently representative and, to the best extent possible, free of errors and complete, with bias examination.
- Technical documentation (Annex IV) and record-keeping through automatic logs.
- Transparency and instructions for use for deployers.
- Human oversight designed into the system.
- Accuracy, robustness and cybersecurity appropriate to the purpose.
- Quality management system, conformity assessment, EU declaration of conformity, CE marking, registration in the EU database.
- Post-market monitoring and serious incident reporting.
Deployer obligations (Article 26 and related)
If you use a high-risk system, you must:
- Use it in accordance with the provider's instructions for use.
- Assign human oversight to people with the competence, training, authority and support to do it.
- Ensure input data under your control is relevant and sufficiently representative for the intended purpose.
- Monitor operation and inform the provider (and, where relevant, authorities) of risks and serious incidents; suspend use if needed.
- Keep automatically generated logs under your control for at least six months, unless other law says otherwise.
- Inform workers' representatives and affected workers before putting a high-risk system into use in the workplace.
- Inform natural persons that they are subject to a high-risk system that makes or assists decisions about them.
- Carry out a fundamental rights impact assessment (FRIA) (Article 27) if you are a public body, a private entity providing public services, or a deployer of credit-scoring or life/health insurance pricing systems.
- Where relevant, use the provider's information to carry out a GDPR data protection impact assessment.
Affected people also gain a right to an explanation of individual decisions taken on the basis of certain high-risk system outputs that significantly affect them (Article 86).
Timing after the Omnibus
The Digital Omnibus on AI (Regulation (EU) 2026/1744) postponed the application of the high-risk rules: Annex III systems from 2 December 2027, and Annex I product-embedded systems from 2 August 2028. The delay exists largely because harmonized standards from European standardization bodies were not ready. Do not read the delay as a reason to wait. Procurement cycles, vendor contracts and HR processes signed now will still be running then.
Worked example: an SME buying an AI recruitment tool
A 60-person logistics firm in the Netherlands buys a SaaS tool that ranks applicants. Deployer checklist in practice:
| Duty | What they did | |---|---| | Instructions for use | Requested them from the vendor; configured the tool only for the documented purpose | | Human oversight | Two trained recruiters review every shortlist; they can override rankings and must record why | | Input data | Removed irrelevant fields (photos, date of birth) from the application form | | Worker information | Informed the works council before go-live | | Candidate information | Added a notice to the job ad and privacy notice | | Logs | Confirmed the vendor retains logs for 6+ months and that the firm can export them | | DPIA | Completed a GDPR DPIA using the vendor's documentation |
Hands-on: vendor questions for any high-risk system
1. What is the intended purpose, exactly as stated in your instructions for use?
2. Is this system high-risk under the EU AI Act? If you rely on Article 6(3), share your documented assessment.
3. What is your conformity assessment status and timeline, and will you provide the EU declaration of conformity?
4. What data was used to train and test the system? How was bias examined, and for which groups?
5. What accuracy and robustness metrics do you report, measured on what population?
6. What human oversight features exist (override, explanation, confidence scores)?
7. What logs are generated, how long are they kept, and can we export them?
8. How will you notify us of serious incidents, model changes and updates?
9. Where is data processed and stored? Which sub-processors are involved?
Pitfalls
- Treating "the vendor is compliant" as the end of your obligations. Deployer duties are yours.
- Assigning oversight to someone without authority to override the system.
- Letting a tool drift beyond its documented purpose, for example using a scheduling tool to evaluate performance.
Video lecture: High-risk AI systems: classification and obligations
Lecture coming soon · 13 chapters · about 9 minutes. Read the full transcript below.
- High-risk AI
- Why it matters now
- Two routes into high risk
- Analogy: a certified boiler
- The Article 6(3) filter
- Provider duties
- Deployer duties
- Worked example: Dutch logistics SME
- New high-risk dates
- Example 2: online exam proctoring
- Common mistakes
- Watch me do it: deployer duties tab
- Recap and next step
Lecture transcript
High-risk AI
If your company uses AI to screen CVs, score credit, price insurance, or grade students, you are probably using a high-risk AI system under the EU AI Act. And even if the vendor built it, some of the obligations are yours. In this lesson you'll learn the two routes into high risk, the escape hatch in Article six paragraph three, what providers must do, what deployers must do, and how the twenty twenty-six Omnibus changed the dates.
Why it matters now
Why does this matter now, when the high-risk dates have moved to twenty twenty-seven and twenty twenty-eight? Because the tools you buy this year will still be running then, and switching an HR or credit system later is expensive. Because GDPR rules on automated decisions and discrimination law already apply today. And because enterprise clients are already asking vendors and service providers how they handle high-risk AI. Getting the deployer basics in place early, oversight, logs, notices, is cheap. Retrofitting them under deadline pressure is not.
Two routes into high risk
There are two routes in. The product route, under Annex one, covers AI that is a product or a safety component of a product already regulated by EU safety law, like machinery, toys or medical devices, where third-party conformity assessment is required. The use-case route, under Annex three, covers sensitive areas: biometrics, critical infrastructure, education, employment and worker management, access to essential services like credit and insurance, law enforcement, migration, and justice and democratic processes. For most businesses, the Annex three areas that matter are employment, credit, insurance and education.
Analogy: a certified boiler
An analogy helps separate provider and deployer duties. Think of a commercial boiler in a building. The manufacturer must design it safely, test it, document it, certify it and attach a label. That's the provider. But the building owner must install it as instructed, have a qualified person oversee it, keep service records, report dangerous faults and tell residents what they need to know. That's the deployer. A certified boiler operated badly is still dangerous, and a well-run building can't fix a badly designed boiler. Both sets of duties matter.
The Article 6(3) filter
Now the filter in Article six paragraph three. An Annex three system is not high-risk if it poses no significant risk and only does a narrow procedural task, improves a completed human activity, spots patterns without replacing human judgment, or does a preparatory task. But there's a hard rule: if it profiles people, it's always high-risk. A tool that reformats CVs into a standard template before a human reads them is arguably preparatory. A tool that ranks candidates is not. Providers who rely on this filter must document their reasoning before placing the system on the market.
Provider duties
Providers carry the heaviest load. They need a risk management system across the lifecycle, good data governance with bias examination, technical documentation, automatic logging, clear instructions for deployers, human oversight built into the design, and appropriate accuracy, robustness and cybersecurity. Then come the formalities: a quality management system, conformity assessment, a declaration of conformity, CE marking, registration in the EU database, post-market monitoring, and reporting serious incidents.
Deployer duties
Now the deployer duties, which is where most businesses sit. Use the system according to the provider's instructions. Assign human oversight to people who have the competence, training and authority to override it. Make sure input data you control is relevant. Monitor it, and report risks and serious incidents. Keep the logs under your control for at least six months. Tell workers and their representatives before using high-risk AI in the workplace. Tell people when a high-risk system is making or assisting decisions about them. And if you're a public body, provide public services, or use AI for credit scoring or life and health insurance pricing, carry out a fundamental rights impact assessment.
Worked example: Dutch logistics SME
Here's how a sixty-person logistics firm in the Netherlands handled an AI tool that ranks job applicants. They got the instructions for use and configured the tool only for its documented purpose. Two trained recruiters review every shortlist and can override the ranking, recording why. They removed photos and date of birth from the application form. They informed the works council before launch, added a notice to job ads, confirmed they could export six months of logs, and completed a data protection impact assessment using the vendor's documentation. None of it required a lawyer on staff. It required a checklist and an owner.
New high-risk dates
What about timing? The Digital Omnibus on AI, Regulation twenty twenty-six slash seventeen forty-four, postponed the high-risk rules. Annex three systems now apply from the second of December twenty twenty-seven, and Annex one product systems from the second of August twenty twenty-eight. The main reason was that harmonized technical standards weren't ready. But don't treat the delay as permission to wait. The vendor contracts and HR processes you set up this year will still be running when the rules apply.
Example 2: online exam proctoring
A simpler example from education. A private school in Riyadh with branches serving EU families online wants AI to proctor online exams and flag suspected cheating. Proctoring to detect prohibited behavior during tests is listed in Annex three under education. So the school, as a deployer, needs trained staff who review every flag before any consequence, clear notices to students and parents, logs retained, and a route to challenge a decision. The AI flags. A human decides. That one principle covers most of what deployers need to get right.
Common mistakes
The mistakes to avoid. Treating the vendor is compliant as the end of your obligations, when deployer duties are yours alone. Assigning human oversight to someone who can't actually override the system, like a junior employee with no authority, which makes oversight a fiction. And letting a tool drift beyond its documented purpose, for example, using a shift-scheduling tool to evaluate staff performance. That drift can change your classification overnight, without anyone noticing.
Watch me do it: deployer duties tab
Watch me do it. Our CV screening pilot is flagged high-risk, so I create a tab called Deployer duties with one row per duty and three columns: What we'll do, Owner, Evidence. Row one, use per instructions: I request the vendor's instructions for use and note that we'll only use ranking for warehouse roles, as documented. Owner: HR lead. Row two, human oversight: two trained recruiters review every shortlist and can override, recording why. Evidence: training certificate and an override log. Row three, input data: remove photo and date of birth from the form. Row four, logs: confirm the vendor keeps logs for at least six months and that we can export them. Row five, worker information: brief the staff representatives before go-live. Row six, candidate notice: add a line to the job ad and privacy notice. Row seven, fundamental rights assessment: I check, and as a private employer we're not in the mandatory group, so I write not required, with reasoning. Row eight, data protection impact assessment: yes, using the vendor's documentation. Finally I add a target date before December twenty twenty-seven, though we'll aim for launch day.
Recap and next step
Recap. Two routes lead into high risk: regulated products and Annex three uses. The Article six three filter can take narrow tasks out, but profiling is always high-risk. Providers carry most of the burden, but deployers must provide real human oversight, keep logs, inform people and sometimes carry out a fundamental rights impact assessment. Your next step: take the nine vendor questions in the lesson text and send them to the provider of any HR, credit, insurance or education AI tool you use or plan to buy.
Key takeaways
- High-risk status comes from Annex I (regulated products) or Annex III (sensitive uses such as employment, credit, insurance, education).
- Article 6(3) can exclude narrow or preparatory tasks, but systems that profile people are always high-risk.
- Deployers must follow instructions, provide competent human oversight, manage inputs, keep logs 6+ months and inform workers and affected people; some must do a FRIA.
- After the Omnibus, Annex III rules apply from 2 December 2027 and Annex I from 2 August 2028.
Try it
Pick one HR, credit, insurance or education AI tool you use or are evaluating. Send the provider the nine vendor questions and map their answers to the deployer duties table.