What is a high-risk AI system under the EU AI Act?
Published by Zero Hunt, an autonomous AI red team on an on-premise appliance running private AI: automated penetration testing for networks and infrastructure, black-box or gray-box, with a human approving every step that matters.
Short definition
Under Regulation (EU) 2024/1689 an AI system is high-risk when it is a safety component of, or is itself, a product covered by the EU harmonization laws in Annex I, or when its intended use falls into one of the Annex III areas — biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and border control, justice and democratic processes. High-risk systems must meet Articles 8–15 before they reach the market.
Why this matters now
The AI Omnibus, in force since 27 July 2026, moved the start of the high-risk obligations to 2 December 2027 for Annex III systems and 2 August 2028 for systems covered by Annex I. That is time to prepare, not a reprieve: procurement teams already ask vendors for AI Act documentation, human-oversight evidence and logging, and the rules on prohibited practices, AI literacy and general-purpose AI models already apply.
Key points
- ▸Classification follows the intended use (Annex III) or the product legislation (Annex I), not the model architecture.
- ▸New dates after the AI Omnibus (in force 27 July 2026): Annex III systems from 2 December 2027, Annex I systems from 2 August 2028.
- ▸Already applicable: prohibited practices and AI literacy since 2 February 2025; general-purpose AI model rules since 2 August 2025.
- ▸Core requirements: risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness and cybersecurity (Articles 9–15).
- ▸Human oversight (Article 14) includes the ability to override and to stop the system — a working stop control, not a policy statement.
- ▸Breaching high-risk obligations can cost up to 15 million euro or 3% of worldwide annual turnover (Article 99).
When is an AI system high-risk?
There are two routes.
Annex I (products). The AI system is a safety component of a product — or is the product — covered by EU harmonization legislation such as machinery, medical devices, toys, lifts or radio equipment, and that product needs a third-party conformity assessment.
Annex III (use cases). The intended use falls into one of eight areas:
- Biometrics (remote identification, categorization, emotion recognition)
- Critical infrastructure: safety components in the management and operation of critical digital infrastructure, road traffic, and the supply of water, gas, heating and electricity
- Education and vocational training
- Employment and workers management
- Access to essential private and public services, such as creditworthiness and emergency dispatch
- Law enforcement
- Migration, asylum and border control
- Administration of justice and democratic processes
An Annex III system is not high-risk when it does not pose a significant risk of harm — for example it performs a narrow procedural task, or only improves the result of a completed human activity (Article 6(3)). The provider must document that assessment, and an Annex III system that profiles natural persons is always high-risk.
The timeline after the 2026 AI Omnibus
- 1 August 2024 — the AI Act enters into force.
- 2 February 2025 — prohibited practices and the AI literacy duty (Article 4) apply.
- 2 August 2025 — obligations for general-purpose AI models, plus the governance and penalties framework.
- 27 July 2026 — the AI Omnibus enters into force and moves the high-risk dates.
- December 2026 — an additional prohibition, covering AI used to generate non-consensual intimate imagery and child sexual abuse material, applies.
- 2 December 2027 — high-risk obligations for Annex III systems.
- 2 August 2028 — high-risk obligations for Annex I (product-embedded) systems.
The Commission's stated aim is to apply the rules when support tools such as harmonized standards are available. Plan against the new dates, but remember that risk management, technical documentation, logging and oversight design take most providers well over a year to get right.
Provider and deployer obligations
Providers — whoever places the system on the market under their name — carry the conformity assessment, technical documentation (Article 11, Annex IV), quality management system (Article 17), registration in the EU database (Article 49), CE marking, post-market monitoring (Article 72) and serious-incident reporting (Article 73).
Deployers — organizations using the system under their own authority — must use it according to the instructions, assign human oversight to competent people, monitor its operation, keep the automatically generated logs for at least six months, and inform affected workers (Article 26). Public bodies, private entities providing public services, and deployers using AI for creditworthiness or life and health insurance pricing must also carry out a fundamental rights impact assessment (Article 27).
Human oversight in practice (Article 14)
Article 14 asks for a system that people can actually supervise: they must be able to understand its capabilities and limits, stay aware of automation bias, interpret its output correctly, decide not to use it or to override it, and intervene or interrupt it through a stop button or a similar procedure.
For autonomous systems this becomes a design question. Useful patterns: graduated autonomy levels with explicit approval gates for high-impact actions, a stop control that works mid-operation, and a signed log of every approval, override and action. See human-in-the-loop in AI security testing.
What it means for AI security tools and their buyers
Security testing tools are not listed as such in Annex III. Whether a given AI security product is high-risk depends on its intended use — for example if it serves as a safety component in the management and operation of critical infrastructure, or sits inside a product covered by Annex I.
In practice, buyers in critical sectors increasingly apply high-risk standards through procurement regardless: they ask for documentation against Articles 9–15, evidence of human oversight and logging, and proof that the AI system itself is resilient against manipulation (Article 15 covers data and model poisoning, adversarial inputs and confidentiality attacks).
Deployment model matters here. With private AI running on-premise, data governance, logs and oversight stay inside the deployer's perimeter, and there is no third-party model provider in the chain to assess. Zero Hunt maintains high-risk documentation according to Articles 9–19 and makes it available to customers under NDA — see the Trust Center.
Checklist: preparing for 2 December 2027
- Inventory every AI system you provide or deploy, and classify each one (Annex I, Annex III, or documented Article 6(3) exemption).
- For each high-risk system, run a gap assessment against Articles 9–15.
- Design human oversight: named roles, competence, a working stop control and logged overrides.
- Set up logging and retention — at least six months for deployers.
- Update procurement: require technical documentation, instructions for use and cooperation on incident reporting from vendors.
- Plan the fundamental rights impact assessment where Article 27 applies.
- Keep AI literacy training current — it has been mandatory since February 2025.
Goes deeper
Want this against your environment?
Book a 30-minute scoping call — we will map this directly to your current compliance scope and threat profile.