What is a high-risk AI system?
A high-risk AI system is an AI system that the EU AI Act subjects to strict requirements because of how it is used. Examples include use in hiring, credit scoring, education or policing, or as a safety component of a regulated product.
Also known as: high-risk AI, high-risk artificial intelligence system
Researched and fact-checked by AI, with no human review. 11 sources listed below. How we verify
Last updated
How the EU AI Act classifies it
The European Union's AI Act sets strict obligations for high-risk AI systems. Article 6 sets two routes into the category.
The first covers an AI system that is a safety component of a product, or is itself a product, under the EU product laws listed in Annex I. The product must also need third-party conformity assessment.
The second covers systems used in the areas listed in Annex III. They are biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration and border control, and the administration of justice and democratic processes.
An Annex III system is not high-risk if it poses no significant risk of harm to health, safety or fundamental rights. For example, it may perform only a narrow procedural task. One that profiles individuals always counts as high-risk.
What the label requires
The European Commission's summary of the Act lists the requirements. They are risk assessment and mitigation, high-quality datasets, activity logging, detailed documentation, clear information for deployers (the organizations that use a system), human oversight, and robustness, cybersecurity and accuracy.
Article 99 covers breaches of the obligations on providers, deployers and other operators. Fines can reach 15 million euros or, for a company, 3% of worldwide annual turnover if that is higher.
Where things stand in 2026
Annex III rules were first due to apply from August 2, 2026. Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, entered into force on July 27, 2026. It postponed the high-risk rules, citing delays to standards, guidance and national authorities. Under the amended Article 113, they apply from December 2, 2027 for Annex III systems. For systems covered through Annex I, they apply from August 2, 2028. The regulation also specified that systems used solely for non-safety purposes such as convenience or performance optimization are not safety components.
On May 19, 2026, the Commission published draft guidelines with examples of systems that should and should not be classified as high-risk. It said a final version would follow a consultation ending July 23, 2026.
Outside the EU, Colorado's 2024 law SB24-205 set duties for developers and deployers of high-risk AI systems. Its start date was later moved to June 30, 2026. SB26-189, signed on May 14, 2026, repealed and reenacted those provisions as rules for automated decision-making technology, with a developer documentation duty from January 1, 2027.
Sources
- Article 6: Classification rules for high-risk AI systems, European Commission, AI Act Service Desk
- ANNEX III, European Commission, AI Act Service Desk
- AI Act, European Commission
- Article 99: Penalties, European Commission, AI Act Service Desk
- Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 (Digital Omnibus on AI), EUR-Lex, Official Journal of the European Union
- Article 113: Entry into force and application, European Commission, AI Act Service Desk
- Draft Commission guidelines on the classification of high-risk AI systems, European Commission
- Guidelines for providers and deployers of AI high-risk systems, European Commission
- SB24-205 Consumer Protections for Artificial Intelligence, Colorado General Assembly
- SB25B-004 Increase Transparency for Algorithmic Systems, Colorado General Assembly
- SB26-189 Automated Decision-Making Technology, Colorado General Assembly