High-Risk AI Systems
This is the centre of gravity of the entire Act. High-risk systems are allowed, but they carry the heaviest obligations - a stack of seven core requirements plus a conformity assessment before you can ship. If any of your systems is high-risk, this is where most of your compliance budget goes.
The Two Routes to High-Risk
As introduced in Lesson 2, a system is high-risk by one of two routes. The first is being a safety component of a product already covered by EU product-safety legislation (medical devices, machinery, toys, vehicles, and so on) that requires third-party conformity assessment. The second is falling into one of the Annex III use-cases.
The Annex III Use-Cases
Annex III lists the application areas the EU considers inherently high-risk for fundamental rights. In summary:
| Area | Typical systems |
|---|---|
| Biometrics | Remote biometric identification, biometric categorisation, permitted emotion recognition |
| Critical infrastructure | Safety components in the management of water, gas, electricity, and digital infrastructure or road traffic |
| Education | Admissions, scoring exams, evaluating learning outcomes, monitoring for cheating |
| Employment | Recruiting and screening, promotion and termination decisions, task allocation, performance monitoring |
| Essential services | Credit scoring and creditworthiness, risk assessment and pricing in health and life insurance, public-benefit eligibility, emergency call triage |
| Law enforcement | Risk assessments, polygraph-type tools, evidence evaluation, profiling |
| Migration & borders | Visa and asylum assessments, risk assessment of travellers, document verification |
| Justice & democracy | Assisting judicial decision-making, influencing elections and voter behaviour |
The Seven Core Requirements
A high-risk system’s provider must build and maintain all of the following before and after the system goes to market:
- Risk management system - a continuous, documented process to identify, evaluate, and mitigate risks across the system’s lifecycle, not a one-time sign-off.
- Data governance - training, validation, and test datasets that are relevant, representative, and as free of errors and bias as feasible, with documented data provenance and preparation.
- Technical documentation - a complete description of the system, its design, capabilities, limitations, and the evidence of compliance, drawn up before the system is placed on the market and kept current.
- Record-keeping and logging - automatic logging of events over the system’s lifetime so behaviour can be traced and audited.
- Transparency to deployers - clear instructions for use so the deployer can understand the system’s capabilities, limitations, and how to exercise oversight.
- Human oversight - the system must be designed so that a human can effectively monitor it, interpret its output, intervene, and override or stop it.
- Accuracy, robustness, and cybersecurity - appropriate levels of performance, resilience to errors and adversarial manipulation, and security against attacks, declared and maintained.
On Top of That: The System-Level Duties
Beyond the seven requirements, providers of high-risk systems must:
- Operate a quality management system that bakes compliance into the organisation’s processes;
- Carry out a conformity assessment - for most Annex III systems an internal self-assessment, but for some (and for product-safety systems) a notified-body assessment;
- Draw up an EU declaration of conformity and affix the CE marking;
- Register the system in the EU public database before placing it on the market;
- Run post-market monitoring and report serious incidents to authorities.
Deployers Have Duties Too
If you use a high-risk system rather than build it, you carry a lighter but real set of obligations:
- Use the system in accordance with the provider’s instructions;
- Assign competent human oversight with the authority and training to intervene;
- Monitor operation and suspend use and inform the provider if you spot a serious risk or incident;
- Keep the logs the system generates;
- Inform workers and their representatives before putting a high-risk system into use in the workplace;
- Where required, carry out a fundamental rights impact assessment (notably for public bodies and certain essential-services deployers) and meet existing data-protection (GDPR) obligations.
The Bottom Line
High-risk classification is not a ban - it is a licence to operate that you earn through documentation, testing, oversight, and ongoing monitoring. The work is front-loaded (you cannot ship until the conformity assessment is done) and continuous (risk management and post-market monitoring never stop). If you suspect a system is high-risk, start the risk-management and documentation work early; it is the long pole in any AI-Act programme.
Ready to Go Deeper?
Live instructor-led courses from our partners. Affiliate disclosure.
AI & ML Courses - 30% Off
Live instructor-led AI, machine learning, data science, and cloud courses for working professionals. Use code Limited30 at checkout.
EdurekaDataCamp - AI & Data Science
Hands-on Python, machine learning, and AI courses with interactive exercises and real projects.
DataCampedX - Top AI Courses
University-level AI courses from MIT, Harvard, Stanford. Earn certificates that employers recognize.
edX