Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · EU AI Act: high-risk AI

High-risk AI system (AI Act)

Also known as: high-risk AI, high-risk system

German: Hochrisiko-KI-System

Under the EU AI Act, a high-risk AI system is an AI system that is a safety component of, or itself, a product covered by the EU harmonization legislation listed in Annex I, or that is used in one of the sensitive areas listed in Annex III, such as employment, education, credit scoring or law enforcement. High-risk systems must meet mandatory requirements and pass a conformity assessment before they are placed on the market.

  • AI regulation
  • EU

In one sentence

A high-risk AI system under the AI Act is AI in regulated products (Annex I) or sensitive uses (Annex III) that must meet strict requirements.

Example

An AI system that ranks job applicants (Annex III, employment) and an AI-based diagnostic function of a medical device (Annex I Section A) are both high-risk.

How it applies

  • Two routes: Under Article 6(1), AI that is a safety component of a product, or is itself a product, covered by EU harmonization legislation in Annex I (such as toys, lifts or medical devices) and requiring third-party conformity assessment. Whether AI counts as a safety component follows the definition as amended by Regulation (EU) 2026/1744. For sector legislation in Section B of Annex I — which since 2026 includes machinery — the requirements are brought in through the sector law instead. Under Article 6(2), stand-alone systems in the areas of Annex III: biometrics, critical infrastructure, education, employment, access to essential services (such as credit scoring), law enforcement, migration and border control, and administration of justice and democratic processes.
  • Exception: An Annex III system is not high-risk if it does not pose a significant risk of harm — for example because it only performs a narrow procedural task — unless it profiles people. The provider must document this assessment.
  • Requirements: Risk management, data governance, technical documentation, record-keeping, transparency and instructions for use, human oversight, and accuracy, robustness and cybersecurity.
  • Dates: December 2, 2027 for Annex III systems and August 2, 2028 for Annex I Section A products, as set by the Digital Omnibus on AI. AI in machinery is assessed under the Machinery Regulation from January 20, 2027; see the machinery AI timeline.

Compared with the USA, Canada and China

Colorado's original AI Act was built on a similar concept of “high-risk AI systems” in consequential decisions, but it was repealed before taking effect and replaced with narrower transparency duties. Canada's AIDA would have regulated “high-impact systems”. China has no equivalent category; instead, it imposes filing and security assessment duties on services by their influence on public opinion.

Read more on AI TechDoc Press

The in-depth analysis behind this entry, in the AI TechDoc Press newsletter. Subscribe for free