As of: 24 June 2026 · Reading time: 6 min
Key takeaways
- Whether an AI system qualifies as high-risk under the EU AI Act determines your compliance scope.
- This guide explains classification with practical examples.
Whether an AI system qualifies as high-risk under the EU AI Act determines your compliance scope. This guide explains classification with practical examples.
“Digitalization is not an IT project—it is a business strategy.”
– Björn Groenewold, Managing Director, Groenewold IT Solutions
Whether an AI system is classified as high-risk under the EU AI Act determines your entire compliance roadmap. The grouping is not trivial—and is often misjudged.
This article explains the scheme with practical examples.
Two Paths to the High-Risk Category
Whether an AI system is considered "high-risk" determines the full compliance scope.
For high-risk AI under the EU AI Act, start with AI development cost calculator and explore related solutions.
The EU AI Act defines high-risk AI in two ways:
**Path 1.
Annex I – Safety relevant product categories ** AI systems that are used as security components in products that are already subject to EU security policies are automatically high risk.
Among other things:
- Machines (machine directive)
- Medical products (MDR/IVDR)
- Aviation
- Motor vehicles
- Lifts
- Toys with AI components
**Path 2: Annex III – Explicitly listed high risk areas ** This is about AI systems in certain socially sensitive areas of application:
| Area | Examples |
|---|---|
| Biometric identification | facial recognition, gait review |
| Critical infrastructure | AI control in energy networks, water supply |
| Education | Automated examination assessment, approval decisions |
| Employment & HR | AI recruitment, performance assessment, dismissal decisions |
| Major services | AI in credit lending, credit assessment, insurance |
| Law enforcement | AI-based risk assessment, lies detection |
| Migration & Asylum | Risk grouping of persons |
| Legal care | AI support for court decisions |
Practical examples: High risk or not?
**AI-assisted recruiting tool that prequalifies CVs:**High risk.**Current under Annex III, Employment Section. Subject HR decisions with major influence on persons.
Chatbot on the company website for customer requests: → No high risk. Clarity obligation (identification as AI), but no high risk grouping for pure information provision.
**AI system for creditworthiness testing of a customer:High risk. Explicit listed in Annex III.
- AI-supported stock forecast: → No high risk. Internal process optimization case without major impact on people.
AI system automatically calculates prices for end customers: → Contextual. For insurance premiums or credit conditions: high risk. For dynamic product prices in e-commerce: usually no high risk.
AI in a machine tool that makes safety-relevant decisions: → High risk over Annex I (machine directive), regardless of Annex III.
AI recommendation system for internal training: → Grey zone. If recommendations affect career-relevant decisions, possibly high risk. If purely informative, rather not.
Non-high risk exceptions: When does Annex III still not apply?
The AI Act contains an important exception: A system does not fall under high risk despite belonging to an Annex III area if:
- Exercise only a help function for human decision (the person decides that the AI system only prepares).
- No essential effect on the outcome of the human decision.
- Only used for administration (e.g. calendar planning, document formatting).
**This exception does not apply automatically. The provider or operator must document and justify why the system is not to be classified as high risk despite Annex III.
Classification process: How to proceed?
**Step 1: Create technical description of the system. ** What exactly does the system do? What inputs does it process? What expenditure does it produce?
How does the expenditure go into decisions?
**Step 2: Check Annex I. ** Is the system safety component in a product subject to an EU security policy?
**Step 3: Check Annex III. ** In what area of use is the system used? Does this range fall below one of the eight high-risk areas?
**Step 4: Exemptions check. ** Does the auxiliary function take effect? Is the impact on personal decisions actually essential?
**Step 5. Document grouping. ** The grouping decision and its justification must be recorded – even if the result is "no high risk".
In the event of a doubt, an external legal assessment may be useful.
Characteristics: AI systems in software development
If you have individual software and this software contains AI components, the grouping should be clarified early:
- Who is a provider within the meaning of the AI Act? (Oft the client, not the agency).
- What duties do the provider have?
- Yes. How are duties between client and development partner contractually divided? ?These questions should be ** before project start** in the contract. Retroactive assignments are complicated and expensive. Our team plans AI development projects from the outset, taking into account the AI-Act needs.
What threatens wrong classification
Anyone who misclassifies a high-risk system as a non-high risk and operates:
- Risks fines up to €15 million or 3% of global sales.
- Liability for damages arising from the operation of a non-compliant system.
- Risks product recalls and sales locks in commercially distributed systems.
The authorities have the right to request and examine grouping documentation.
Conclusion
Grouping is not an administrative formal act, but a material decision with considerable effects. The 'grey'.
Area is large and is gradually clearer by future guidance from the EU-AI authorities (AIDA).
Anyone who invests today in a resilient grouping documentation will later avoid expensive reworking.
Our contribution EU AI Act: What companies 2026 need to know offers the full compliance overview.
Frequently Asked Questions (FAQ)
Can classification change over time?
Yes. If a system is significantly changed, the grouping should be reassessed. New EU leadership can also lead to a reassessment. Grouping is not a one-off process.
Who decides final whether a system is high risk – the provider or an authority?
Primary providers (self-grouping). Market surveillance authorities may examine and contest the grouping. For certain high-risk systems, an separate conformity assessment by a notified body is required.
Does the AI Act apply to AI systems developed outside the EU, but used in the EU?
Yes. The AI Act applies to all AI systems used in the EU, regardless of the development location. Importers and operators from third countries carry their own duties.
How does the AI Act relate to existing data protection requirements of the GDPR?
AI Act and GDPR are complementary. GDPR regulates the handling of personal data, AI Act regulates the security and clarity of AI systems.
Both can apply simultaneously – and the duties add up.
Learn more:
EU AI Act Consulting – technical and organizational compliance support for your company: risk grouping, documentation duties and AI governance. Artificial Intelligence
Next consultation appointment →
Technical sources and further links
The following separate references complement the grouping on the topics of this Article:
- Bitkom – Digital Economy Association.
- BSI – Federal Office for Information Security.
- European Commission – Digital Strategy.
- MDN Web Docs (Mozilla)
- W3C – World Wide Web Consortium.
"Privacy by Design is not a subsequent checkbox, but an architectural question – especially for personal master data."
— *Björn Groenewold, Managing Director, Groenewold IT Solutions *
About the author

Managing Director of Groenewold IT Solutions GmbH and Hyperspace GmbH
Since 2009 Björn Groenewold has been developing software solutions for the mid-market. He is Managing Director of Groenewold IT Solutions GmbH (founded 2010) and Hyperspace GmbH. As founder of Groenewold IT Solutions he has successfully supported more than 250 projects – from legacy modernisation to AI integration.
Blog recommendations
Related articles
These posts might also interest you.

EU AI Act: What companies 2026 need to know and implement
The EU AI Act has been in force since August 2024 and applies gradually until 2027. What does this specifically mean for medium-sized companies that have AI deployed or developed? This article…

EU AI Act Compliance Checklist for mid-sized businesses
A structured checklist that enables medium-sized companies to systematically build up their EU AI Act compliance – from stocktaking to risk classification to ongoing governance.

Combine funding: How to maximize your support
In today's digital landscape, the development of tailor-made software for many companies is a key factor in growth and competitiveness. But the investments...
Free download
Checklist: 10 questions before software development
Key points before you start: budget, timeline, and requirements.
Get the checklist in a consultationRelevant next steps
Related services & solutions
Based on this article's topic, these pages are often the most useful next steps.
Related services
Related solutions
Cost calculators
Practical next steps after High-Risk AI under the EU AI Act: How to Classify Your Systems Correctly
High-Risk AI under the EU AI Act: How to Classify Your Systems Correctly addresses a practical choice for product and IT teams. Start with one clear goal: turn a useful AI idea into a governed process with clear data and risk boundaries.
Check the current process, the data involved, and the result users need. Then record the main risks and define a small first step. This keeps the decision easy to review and gives your team a shared basis.
For implementation support, our AI development for business connects the article's guidance with architecture, delivery, and stable operations. Engineering and project ownership stay with our team in Leer, Germany.
This post belongs to EU AI Act. Browse the related EU AI Act articles or use the English software blog for other topics.
When budget is the next question, the software cost calculators provide planning ranges. The IT glossary explains key terms, while in-depth technology guides cover wider decisions.
If the topic affects a live project, book a technical consultation or send the context through our project contact form. We usually reply within one working day.
