Last updated:
The two classifications of high-risk AI systems under the EU AI Act: standalone systems listed in Annex III (covering biometrics, critical infrastructure, employment, education, law enforcement, and other named uses), and AI embedded in regulated products listed in Annex I (covering medical devices, vehicles, machinery, and other regulated product categories).
The EU AI Act treats certain AI systems as high-risk because of their potential to affect fundamental rights, safety, or critical societal functions. Annex III lists eight standalone categories where the system itself is classified as high-risk based on its intended purpose, while Annex I covers AI components embedded in products already subject to existing EU sectoral safety legislation. Following the Digital Omnibus deal of May 7, 2026, Annex III obligations apply from December 2, 2027, and Annex I obligations from August 2, 2028. Both categories require conformity assessment, technical documentation, post-market monitoring, and adherence to the AI Act's risk management and human oversight requirements.
Real world example:
A retail bank's CV-screening AI is classified as Annex III high-risk under the employment and worker management category. The same bank's AI-driven fraud-detection model embedded in payment-processing infrastructure may also qualify as Annex I high-risk if the underlying payment system is regulated under existing EU financial-services safety law. Each system requires its own Article 6 classification and a separate conformity assessment.





