Last updated:
The two classifications of high-risk AI systems under the EU AI Act: standalone systems listed in Annex III (covering biometrics, critical infrastructure, employment, education, law enforcement, and other named uses), and AI embedded in regulated products listed in Annex I (covering medical devices, vehicles, machinery, and other regulated product categories).
The EU AI Act treats certain AI systems as high-risk because of their potential to affect fundamental rights, safety, or critical societal functions. Annex III lists eight standalone categories where the system itself is classified as high-risk based on its intended purpose, while Annex I covers AI components embedded in products already subject to existing EU sectoral safety legislation. Following the Digital Omnibus deal of 7 May 2026, Annex III obligations apply from 2 December 2027 and Annex I obligations from 2 August 2028. Both categories require conformity assessment, technical documentation, post-market monitoring, and adherence to the AI Act's risk management and human oversight requirements.
Real world example:
A retail bank's CV-screening AI is classified as Annex III high-risk under the employment and worker management category. The same bank's AI-driven fraud-detection model embedded in payment-processing infrastructure may also qualify as Annex I high-risk if the underlying payment system is regulated under existing EU financial-services safety law. Each system requires its own Article 6 classification and a separate conformity assessment.




