Back to KISYN

High-risk AI

What is high-risk AI under the AI Act?

An AI system is high-risk when it is used in one of the areas listed in Annex III of the AI Act — recruitment, education, essential services, law enforcement and similar — or when it is a safety component of a product already regulated under Annex I. The tool itself is never high-risk in the abstract: the same assistant is minimal risk when it fixes spelling and high risk when it screens job applicants. The obligations were deferred to 2 December 2027 for Annex III systems.

By Yassin BahriPublished and reviewed 1 August 20268 min read

The Annex III areas

Annex III lists the use areas that make a standalone AI system high-risk. Employment is the one that reaches almost every organisation, because it covers recruitment, task allocation and decisions affecting the employment relationship.

  • Employment: recruitment, screening, promotion, termination, task allocation, monitoring.
  • Education: admission, assessment, and monitoring of prohibited behaviour during tests.
  • Essential services: creditworthiness, life and health insurance pricing, emergency triage.
  • Public services: eligibility for benefits and assistance.
  • Biometrics, critical infrastructure, law enforcement, migration, and administration of justice.

Why the tool is not the unit of assessment

Naming the vendor tells you nothing about the risk class. The purpose, the data involved, and the decision the output influences are what determine it. This is the single most common mistake in AI inventories: a list of tool names that cannot support any compliance conclusion.

The practical consequence is that the same licence can sit in two risk classes at once inside one organisation, depending on which team uses it for what.

  • A chatbot correcting a draft email: minimal risk.
  • The same chatbot ranking job applicants: high risk.
  • The same chatbot inferring employees' emotions: prohibited.
  • Record the use case and its owner, not just the tool.

When an Annex III use is not high-risk

Article 6(3) allows a system in an Annex III area to escape the high-risk class where it does not pose a significant risk of harm to health, safety or fundamental rights — for instance where it performs a narrow procedural task, or improves the result of a previously completed human activity.

The exception is not self-certifying in effect: a provider relying on it must document the assessment, and a system that profiles natural persons is always high-risk.

  • Narrow procedural tasks may fall outside.
  • Improving the output of completed human work may fall outside.
  • Preparatory tasks for an assessment may fall outside.
  • Profiling of natural persons is always high-risk, with no exception.

What the obligations require, and from when

For providers of high-risk systems the obligations are substantial: a risk management system across the lifecycle, data governance, technical documentation, automatic logging, human oversight by design, accuracy and cybersecurity, conformity assessment, CE marking and registration in the EU database.

The Digital Omnibus adopted in June 2026 deferred these. Annex III standalone systems now apply from 2 December 2027, and Annex I systems embedded in regulated products from 2 August 2028.

  • Providers: risk management, data governance, documentation, logging, oversight, conformity assessment.
  • Deployers: follow the instructions, ensure competent human oversight, keep logs, inform affected people.
  • Annex III obligations apply from 2 December 2027.
  • Annex I embedded product obligations apply from 2 August 2028.

Frequently asked questions

Is ChatGPT a high-risk AI system?

Not in itself. High risk is determined by the use, not the tool. A general assistant used to draft text is minimal risk; the same assistant used to screen job applications falls into the Annex III employment area and is high risk. The question can only be answered per use case.

Is using AI in recruitment always high-risk?

Recruitment is an Annex III area, so the starting point is yes. Article 6(3) can take a system out of the class where it performs only a narrow procedural task and poses no significant risk to fundamental rights, but any system that profiles natural persons remains high-risk without exception.

When do the high-risk requirements start to apply?

For standalone Annex III systems, 2 December 2027, after the Digital Omnibus deferred the original date. For AI embedded as a safety component in products regulated under Annex I, 2 August 2028. Neither date is yet Norwegian law, because the regulation has not been incorporated into the EEA Agreement.

What is the difference between high-risk and prohibited?

Prohibited uses cannot be used at all — social scoring, manipulative techniques, emotion recognition at work, and untargeted facial scraping among them, banned since February 2025. High-risk uses are permitted but carry the heaviest requirements before and during use.

How do we find out which of our uses are high-risk?

Start from an inventory of actual use cases rather than a list of tools, with the purpose, the data and the decision the output affects recorded for each, and a named person who confirms it. Then compare each use case against the Annex III areas.

Free orientation tool

Understand how the EU AI Act may apply

Answer plain-language questions, get explanations as you go, and see the official legal basis behind your result.

Start the AI Act assessment