As of: 24 June 2026 · Reading time: 6 min
Key takeaways
- Whether an AI system qualifies as high-risk under the EU AI Act determines your compliance scope.
- This guide explains classification with practical examples.
Whether an AI system qualifies as high-risk under the EU AI Act determines your compliance scope. This guide explains classification with practical examples.
“Digitalization is not an IT project—it is a business strategy.”
– Björn Groenewold, Managing Director, Groenewold IT Solutions
Whether an AI system is classified as high-risk under the EU AI Act determines your entire compliance roadmap. The classification is not trivial—and is often misjudged.
This article explains the scheme with practical examples.
Two Paths to the High-Risk Category
Short: Short answer: Whether an AI system is considered "high-risk" determines the full compliance scope.
Short answer: Whether an AI system is considered "high-risk" determines the full compliance scope.
For high-risk AI under the EU AI Act, start with AI development cost calculator and explore related solutions.
The EU AI Act defines high-risk AI in two ways:
**Path 1: Annex I – Safety relevant product categories ** AI systems that are used as security components in products that are already subject to EU security policies are automatically high risk.
Among other things:
- Machines (machine directive)
- Medical products (MDR/IVDR)
- Aviation
- Motor vehicles
- Lifts
- Toys with AI components
**Path 2: Annex III – Explicitly listed high risk areas ** This is about AI systems in certain socially sensitive areas of application:
| Area | Examples |
|---|---|
| Biometric identification | facial recognition, gait analysis |
| Critical infrastructure | AI control in energy networks, water supply |
| Education | Automated examination assessment, approval decisions |
| Employment & HR | AI recruitment, performance assessment, dismissal decisions |
| Major services | AI in credit lending, credit assessment, insurance |
| Law enforcement | AI-based risk assessment, lies detection |
| Migration & Asylum | Risk classification of persons |
| Legal care | AI support for court decisions |
Practical examples: High risk or not?
Short: **AI-assisted recruiting tool that prequalifies CVs:**High risk.
**AI-assisted recruiting tool that prequalifies CVs:**High risk.**Current under Annex III, Employment Section. Subject HR decisions with significant influence on persons.
Chatbot on the company website for customer requests: → No high risk. Transparency obligation (identification as AI), but no high risk classification for pure information provision.
**AI system for creditworthiness testing of a customer:High risk. Explicit listed in Annex III.
AI-supported stock forecast:→ No high risk. Internal process optimization case without significant impact on people.
AI system automatically calculates prices for end customers: → Contextual. For insurance premiums or credit conditions: high risk. For dynamic product prices in e-commerce: usually no high risk.
AI in a machine tool that makes safety-relevant decisions: → High risk over Annex I (machine directive), regardless of Annex III.
AI recommendation system for internal training: → Grey zone. If recommendations affect career-relevant decisions, possibly high risk. If purely informative, rather not.
Non-high risk exceptions: When does Annex III still not apply?
Short: The AI Act contains an important exception: A system does not fall under high risk despite belonging to an Annex III area if:
The AI Act contains an important exception: A system does not fall under high risk despite belonging to an Annex III area if:
- Exercise only a help function for human decision (the person decides that the AI system only prepares)
- No essential effect on the outcome of the human decision
- Only used for administration (e.g. calendar planning, document formatting)
**This exception does not apply automatically. The provider or operator must document and justify why the system is not to be classified as high risk despite Annex III.
Classification process: How to proceed?
Short: **Step 1: Create technical description of the system.
**Step 1: Create technical description of the system. ** What exactly does the system do? What inputs does it process? What expenditure does it produce? How does the expenditure go into decisions?
**Step 2: Check Annex I. ** Is the system safety component in a product subject to an EU security policy?
**Step 3: Check Annex III. ** In what area of use is the system used? Does this range fall below one of the eight high-risk areas?
**Step 4: Exemptions check. ** Does the auxiliary function take effect? Is the impact on personal decisions actually essential?
**Step 5: Document classification. ** The classification decision and its justification must be documented – even if the result is "no high risk".
In the event of a doubt, an external legal assessment may be useful.
Characteristics: AI systems in software development
Short: If you have individual software and this software contains AI components, the classification should be clarified early:
If you have individual software and this software contains AI components, the classification should be clarified early:
- Who is a provider within the meaning of the AI Act? (Oft the client, not the agency)
- What obligations do the provider have?
- Yes. How are obligations between client and development partner contractually divided? ?These questions should be ** before project start** in the contract. Retroactive assignments are complicated and expensive. Our team plans AI development projects from the outset, taking into account the AI-Act requirements.
What threatens wrong classification
Short: Anyone who misclassifies a high-risk system as a non-high risk and operates:
Anyone who misclassifies a high-risk system as a non-high risk and operates:
- Risks fines up to €15 million or 3% of global sales
- Liability for damages arising from the operation of a non-compliant system
- Risks product recalls and sales locks in commercially distributed systems
The authorities have the right to request and examine classification documentation.
Conclusion
Short: Classification is not an administrative formal act, but a material decision with considerable consequences.
Classification is not an administrative formal act, but a material decision with considerable consequences. The 'grey' area is large and is gradually clearer by future guidance from the EU-AI authorities (AIDA).
Anyone who invests today in a resilient classification documentation will later avoid expensive reworking.
Our contribution EU AI Act: What companies 2026 need to know offers the full compliance overview.
Frequently Asked Questions (FAQ)
Can classification change over time?
Yes. If a system is significantly changed, the classification should be reassessed. New EU leadership can also lead to a reassessment. Classification is not a one-off process.
Who decides final whether a system is high risk – the provider or an authority?
Primary providers (self-classification). Market surveillance authorities may examine and contest the classification. For certain high-risk systems, an independent conformity assessment by a notified body is required.
Does the AI Act apply to AI systems developed outside the EU, but used in the EU?
Yes. The AI Act applies to all AI systems used in the EU, regardless of the development location. Importers and operators from third countries carry their own duties.
How does the AI Act relate to existing data protection requirements of the GDPR?
AI Act and GDPR are complementary. GDPR regulates the handling of personal data, AI Act regulates the security and transparency of AI systems.
Both can apply simultaneously – and the duties add up.
Learn more:
EU AI Act Consulting – technical and organizational compliance support for your company: risk classification, documentation obligations and AI governance. Artificial Intelligence
Next consultation appointment →
Technical sources and further links
Short: The following independent references complement the classification on the topics of this Article:
The following independent references complement the classification on the topics of this Article:
- Bitkom – Digital Economy Association
- BSI – Federal Office for Information Security
- European Commission – Digital Strategy
- MDN Web Docs (Mozilla)
- W3C – World Wide Web Consortium
"Privacy by Design is not a subsequent checkbox, but an architectural question – especially for personal master data."
— *Björn Groenewold, Managing Director, Groenewold IT Solutions *
About the author

Managing Director of Groenewold IT Solutions GmbH and Hyperspace GmbH
Since 2009 Björn Groenewold has been developing software solutions for the mid-market. He is Managing Director of Groenewold IT Solutions GmbH (founded 2012) and Hyperspace GmbH. As founder of Groenewold IT Solutions he has successfully supported more than 250 projects – from legacy modernisation to AI integration.
Blog recommendations
Related articles
These posts might also interest you.

EU AI Act: What companies 2026 need to know and implement
The EU AI Act has been in force since August 2024 and applies gradually until 2027. What does this specifically mean for medium-sized companies that have AI deployed or developed? This article…

EU AI Act Compliance Checklist for mid-sized businesses
A structured checklist that enables medium-sized companies to systematically build up their EU AI Act compliance – from stocktaking to risk classification to ongoing governance.

Flutter vs. React Native: A closer look at community and support
In the world of cross-platform development for mobile apps, Flutter and React Native are two of the most prominent names. Both frameworks offer developers the opportunity to use a single codeb...
Free download
Checklist: 10 questions before software development
Key points before you start: budget, timeline, and requirements.
Get the checklist in a consultationRelevant next steps
Related services & solutions
Based on this article's topic, these pages are often the most useful next steps.
Related services
Related solutions
Cost calculators
More on EU AI Act and next steps
This article is in the EU AI Act topic. In our blog overview you will find all articles; under category EU AI Act more posts on this subject.
For topics like EU AI Act we offer matching services – from app development and AI integration to legacy modernisation and maintenance. We describe typical use cases under solutions. Our cost calculators give initial estimates. Key terms are in the IT glossary. Books and long-form guides appear on the publications page; deeper articles live under topics.
If you have questions about this article or want a non-binding discussion about your project, you can book a consultation or reach us via contact. We usually respond within one working day.
