Back to Insights
AI Act ·28 August 2026 ·9 min read

What is a high-risk AI system — and are you running one?

Not every advanced AI system is high-risk under the EU AI Act, and not every simple one is exempt. Article 6 and Annex III decide it — along with the deadlines the Digital Omnibus pushed back in mid-2026. A practical overview for SMEs — not legal advice.

A high-risk AI system under the EU AI Act is not simply an AI system that is powerful, autonomous or business-critical. The classification mainly depends on what the system is used for and the context in which it operates. Article 6 of the AI Act provides two main routes: AI that forms part of certain regulated products, and AI used for specifically listed purposes that can have significant consequences for individuals.

For an SME, this means that a chatbot, internal search tool or text-generation system will generally not become high-risk merely because it uses an advanced model. An AI system used to screen job applicants, assess creditworthiness or determine educational outcomes may fall within the high-risk regime. The classification therefore has to be checked against Article 6, Annex I and Annex III of the Regulation.

The two routes to high-risk classification under Article 6

Article 6 sets out two different ways in which an AI system can be classified as high-risk.

The first route concerns AI that is a safety component of a product, or is itself a product, covered by existing EU product-safety legislation listed in Annex I. Examples include legislation covering medical devices, machinery and toys.

This means that the same underlying AI technology can have a very different regulatory status depending on what it does. An AI component that performs a safety-critical function inside a regulated machine needs to be assessed differently from software using similar technology for an administrative task.

The second route is particularly relevant to many SMEs: AI systems used for one of the specific use cases listed in Annex III. These are applications where the legislator considers that AI may have a significant impact on safety, fundamental rights or access to important services and opportunities.

The eight categories in Annex III

Annex III contains eight categories. Importantly, not every AI system used in one of these sectors is automatically high-risk — the precise use case matters.

1. Biometrics

This category includes certain systems for remote biometric identification, biometric categorisation based on sensitive characteristics and emotion recognition. Pure identity verification is excluded from this particular high-risk category — a system that verifies whether a person matches an identity they have already claimed performs a different function from software that identifies people remotely or infers characteristics from biometric data. For SMEs, this may become relevant when deploying access-control systems, security technology or certain forms of employee-analysis software.

2. Critical infrastructure

AI can fall within the high-risk regime when it is used as a safety component in areas such as digital infrastructure, road traffic, water, gas, heating or electricity. The fact that software is used somewhere in the energy or infrastructure sector is therefore not enough on its own. The role of the system is decisive: an AI tool used for general forecasting or administrative planning is different from an AI component whose output directly affects the safe operation of critical infrastructure.

3. Education and vocational training

Annex III covers certain AI systems used for admission to education, evaluation of learning outcomes, determining the appropriate level of education or training, and detecting prohibited behaviour during examinations. This can be relevant to training providers, examination bodies and developers of educational software. An AI assistant that summarises course material has a very different function from a system whose assessment determines whether a person is admitted, passes an examination or is assigned to a particular educational level.

4. Employment

For many businesses, this is one of the most directly relevant Annex III categories. It includes AI used for recruitment and selection, targeted job advertising and screening or filtering applications, as well as systems used to support decisions about promotion, termination, task allocation and the monitoring or evaluation of employee performance.

Using generative AI to improve the wording of a vacancy is therefore not the same as using an AI system to rank applicants before a recruiter sees them. For HR applications in particular, SMEs should document what role the AI output plays in the final employment decision, rather than relying on how a vendor describes the product.

5. Access to essential services

This category covers several types of decisions that may have substantial consequences for individuals: certain AI systems used in relation to public assistance and healthcare, creditworthiness assessments and credit scoring (except where the system is used solely for fraud detection), risk assessment and pricing in life and health insurance, and AI involved in prioritising emergency calls.

For financial and insurance businesses, a useful distinction is whether the AI merely supplies information to a human decision-maker or whether its score materially determines whether a person receives a service, on what terms or at what price.

6. Law enforcement

Annex III also lists several law-enforcement applications, including systems used to assess the risk that a person will become a victim of crime, polygraph-like tools, systems assessing the reliability of evidence and certain applications for evaluating reoffending risk. This category will not directly affect most SMEs, but it is highly relevant to suppliers building AI systems for police, investigative authorities or other law-enforcement environments.

7. Migration, asylum and border control

Specific AI systems used in migration, asylum and border-management processes are also listed in Annex III: polygraph-like applications, risk assessments and systems used in the examination of asylum, visa and residence applications. Again, the organisation using the technology is not enough to determine the classification — a generic translation tool used by an immigration authority is not automatically high-risk merely because of where it is deployed. The function performed by the system must correspond to the listed use case.

8. Administration of justice and democratic processes

AI systems used to assist judicial authorities in researching and interpreting facts and applying the law can fall within Annex III. The category also covers systems intended to influence the outcome of an election or referendum or the voting behaviour of individuals — purely administrative tools used in political campaigns are excluded. For companies developing legal AI, the distinction between general research or knowledge-support tools and systems that materially assist judicial decision-making is therefore particularly important.

When an Annex III system may still not be high-risk

Appearing to fall within Annex III does not necessarily mean that an AI system must always be treated as high-risk.

Article 6(3) provides an exception where an Annex III system does not pose a significant risk to health, safety or fundamental rights, including situations where it does not materially influence the outcome of decision-making. That requires an assessment of what the system actually does in practice.

Software that performs a narrow preparatory task — for example organising information without materially determining the eventual decision — may be treated differently from a system that automatically excludes candidates or determines an individual's eligibility based on a score.

The exception should not be treated as an informal judgement that a system is "probably harmless". A provider relying on Article 6(3) must document that assessment before placing the system on the market. In practical terms, providers should record the system's intended purpose, its role in the workflow, the degree of human involvement and the extent to which its output can influence the final decision.

The timeline changed after the Digital Omnibus

Under the original AI Act timetable, the requirements for Annex III high-risk systems were due to become applicable on 2 August 2026.

That timetable has since changed through the Digital Omnibus on AI, Regulation (EU) 2026/1744, which was published on 24 July 2026 and entered into force on 27 July 2026. Standalone Annex III systems now have until 2 December 2027. AI systems embedded in products covered by Annex I have until 2 August 2028.

This does not mean that the entire AI Act has been postponed. Other parts of the Regulation already apply or follow separate deadlines: the requirements for general-purpose AI have applied since August 2025, and the prohibited practices in Article 5 have applied since February 2025. The transparency obligations under Article 50 were also not postponed together with the high-risk provisions. The amended Article 5 also introduces a prohibition concerning non-consensual intimate AI-generated image content, with its own deadline of 2 December 2026.

For the broader compliance timeline, see our pillar article The EU AI Act for SMEs and our separate guide Article 50 explained.

A practical checklist for SMEs

For each AI system you use, develop or place on the market, a useful first assessment is to ask:

  • Is the AI part of a product covered by the legislation listed in Annex I?
  • Does its concrete intended use match one of the applications in Annex III?
  • Does it affect decisions about individuals, for example in recruitment, education, credit, employment or access to essential services?
  • Does the AI materially influence that decision, or is its role limited to a preparatory or administrative task?
  • Who is the provider and who is the deployer in your particular setup?
  • Has the Article 6 assessment, including any reliance on Article 6(3), been documented?
  • Which application date applies to this specific system?
  • Have other AI Act obligations that already apply been assessed separately?

The useful unit of analysis is therefore not simply "our company uses AI". Compliance needs to be considered system by system and use case by use case, based on function, context and the influence the system has over decisions.

High-risk is about the use case, not the AI label

For SMEs, the central point is that an advanced AI system is not automatically high-risk, while relatively simple software can become high-risk when used in a sensitive decision-making context. Article 6 ties the classification to regulated products and to the concrete use cases listed in Annex III.

Start with the business process rather than the underlying model: what does the system actually do, who is affected by its output, and how much influence does that output have on the final decision? Document that assessment and then determine which obligations and transitional dates may apply.

Neuralex does not provide legal advice. Use this explanation to understand the technical structure and practical implications of the EU AI Act, consult the current text of the Regulation for the formal requirements, and have the classification of your specific AI system reviewed by a qualified lawyer.

Technology, not legal advice

Want to know if your AI application falls under Annex III?

We map out which AI systems you use, how they influence decisions about people, and where a high-risk classification may be relevant. We leave the legal review to your advisor.