🇩🇪
EU AI Act High Risk Classification – Classify AI Systems

High-Risk AI under the EU AI Act: How to Classify Your Systems Correctly

EU AI Act • 4 May 2026

As of: 24 June 2026 · Reading time: 6 min

Teilen:

Key takeaways

  • Whether an AI system qualifies as high-risk under the EU AI Act determines your compliance scope.
  • This guide explains classification with practical examples.

Whether an AI system qualifies as high-risk under the EU AI Act determines your compliance scope. This guide explains classification with practical examples.

Digitalization is not an IT project—it is a business strategy.

Björn Groenewold, Managing Director, Groenewold IT Solutions

Whether an AI system is classified as high-risk under the EU AI Act determines your entire compliance roadmap. The classification is not trivial—and is often misjudged.

This article explains the scheme with practical examples.

Two Paths to the High-Risk Category

Short: Short answer: Whether an AI system is considered "high-risk" determines the full compliance scope.

Short answer: Whether an AI system is considered "high-risk" determines the full compliance scope.

For high-risk AI under the EU AI Act, start with AI development cost calculator and explore related solutions.

The EU AI Act defines high-risk AI in two ways:

**Path 1: Annex I – Safety relevant product categories ** AI systems that are used as security components in products that are already subject to EU security policies are automatically high risk.

Among other things:

  • Machines (machine directive)
  • Medical products (MDR/IVDR)
  • Aviation
  • Motor vehicles
  • Lifts
  • Toys with AI components

**Path 2: Annex III – Explicitly listed high risk areas ** This is about AI systems in certain socially sensitive areas of application:

Area Examples
Biometric identification facial recognition, gait analysis
Critical infrastructure AI control in energy networks, water supply
Education Automated examination assessment, approval decisions
Employment & HR AI recruitment, performance assessment, dismissal decisions
Major services AI in credit lending, credit assessment, insurance
Law enforcement AI-based risk assessment, lies detection
Migration & Asylum Risk classification of persons
Legal care AI support for court decisions

Practical examples: High risk or not?

Short: **AI-assisted recruiting tool that prequalifies CVs:**High risk.

**AI-assisted recruiting tool that prequalifies CVs:**High risk.**Current under Annex III, Employment Section. Subject HR decisions with significant influence on persons.

Chatbot on the company website for customer requests:No high risk. Transparency obligation (identification as AI), but no high risk classification for pure information provision.

**AI system for creditworthiness testing of a customer:High risk. Explicit listed in Annex III.

AI-supported stock forecast:→ No high risk. Internal process optimization case without significant impact on people.

AI system automatically calculates prices for end customers: → Contextual. For insurance premiums or credit conditions: high risk. For dynamic product prices in e-commerce: usually no high risk.

AI in a machine tool that makes safety-relevant decisions: → High risk over Annex I (machine directive), regardless of Annex III.

AI recommendation system for internal training: → Grey zone. If recommendations affect career-relevant decisions, possibly high risk. If purely informative, rather not.

Non-high risk exceptions: When does Annex III still not apply?

Short: The AI Act contains an important exception: A system does not fall under high risk despite belonging to an Annex III area if:

The AI Act contains an important exception: A system does not fall under high risk despite belonging to an Annex III area if:

  • Exercise only a help function for human decision (the person decides that the AI system only prepares)
  • No essential effect on the outcome of the human decision
  • Only used for administration (e.g. calendar planning, document formatting)

**This exception does not apply automatically. The provider or operator must document and justify why the system is not to be classified as high risk despite Annex III.

Classification process: How to proceed?

Short: **Step 1: Create technical description of the system.

**Step 1: Create technical description of the system. ** What exactly does the system do? What inputs does it process? What expenditure does it produce? How does the expenditure go into decisions?

**Step 2: Check Annex I. ** Is the system safety component in a product subject to an EU security policy?

**Step 3: Check Annex III. ** In what area of use is the system used? Does this range fall below one of the eight high-risk areas?

**Step 4: Exemptions check. ** Does the auxiliary function take effect? Is the impact on personal decisions actually essential?

**Step 5: Document classification. ** The classification decision and its justification must be documented – even if the result is "no high risk".

In the event of a doubt, an external legal assessment may be useful.

Characteristics: AI systems in software development

Short: If you have individual software and this software contains AI components, the classification should be clarified early:

If you have individual software and this software contains AI components, the classification should be clarified early:

  • Who is a provider within the meaning of the AI Act? (Oft the client, not the agency)
  • What obligations do the provider have?
  • Yes. How are obligations between client and development partner contractually divided? ?These questions should be ** before project start** in the contract. Retroactive assignments are complicated and expensive. Our team plans AI development projects from the outset, taking into account the AI-Act requirements.

What threatens wrong classification

Short: Anyone who misclassifies a high-risk system as a non-high risk and operates:

Anyone who misclassifies a high-risk system as a non-high risk and operates:

  • Risks fines up to €15 million or 3% of global sales
  • Liability for damages arising from the operation of a non-compliant system
  • Risks product recalls and sales locks in commercially distributed systems

The authorities have the right to request and examine classification documentation.

Conclusion

Short: Classification is not an administrative formal act, but a material decision with considerable consequences.

Classification is not an administrative formal act, but a material decision with considerable consequences. The 'grey' area is large and is gradually clearer by future guidance from the EU-AI authorities (AIDA).

Anyone who invests today in a resilient classification documentation will later avoid expensive reworking.

Our contribution EU AI Act: What companies 2026 need to know offers the full compliance overview.

Frequently Asked Questions (FAQ)

Can classification change over time?

Yes. If a system is significantly changed, the classification should be reassessed. New EU leadership can also lead to a reassessment. Classification is not a one-off process.

Who decides final whether a system is high risk – the provider or an authority?

Primary providers (self-classification). Market surveillance authorities may examine and contest the classification. For certain high-risk systems, an independent conformity assessment by a notified body is required.

Does the AI Act apply to AI systems developed outside the EU, but used in the EU?

Yes. The AI Act applies to all AI systems used in the EU, regardless of the development location. Importers and operators from third countries carry their own duties.

How does the AI Act relate to existing data protection requirements of the GDPR?

AI Act and GDPR are complementary. GDPR regulates the handling of personal data, AI Act regulates the security and transparency of AI systems.

Both can apply simultaneously – and the duties add up.


Learn more:

EU AI Act Consulting – technical and organizational compliance support for your company: risk classification, documentation obligations and AI governance. Artificial Intelligence

Next consultation appointment →

Short: The following independent references complement the classification on the topics of this Article:

The following independent references complement the classification on the topics of this Article:

"Privacy by Design is not a subsequent checkbox, but an architectural question – especially for personal master data."

— *Björn Groenewold, Managing Director, Groenewold IT Solutions *

About the author

Björn Groenewold
Björn Groenewold(Dipl.-Inf.)

Managing Director of Groenewold IT Solutions GmbH and Hyperspace GmbH

Since 2009 Björn Groenewold has been developing software solutions for the mid-market. He is Managing Director of Groenewold IT Solutions GmbH (founded 2012) and Hyperspace GmbH. As founder of Groenewold IT Solutions he has successfully supported more than 250 projects – from legacy modernisation to AI integration.

Software ArchitectureAI IntegrationLegacy ModernisationProject Management

Blog recommendations

Related articles

These posts might also interest you.

Free download

Checklist: 10 questions before software development

Key points before you start: budget, timeline, and requirements.

Get the checklist in a consultation

Relevant next steps

Related services & solutions

Based on this article's topic, these pages are often the most useful next steps.

Related services

Related solutions

More on this topic

More on EU AI Act and next steps

This article is in the EU AI Act topic. In our blog overview you will find all articles; under category EU AI Act more posts on this subject.

For topics like EU AI Act we offer matching services – from app development and AI integration to legacy modernisation and maintenance. We describe typical use cases under solutions. Our cost calculators give initial estimates. Key terms are in the IT glossary. Books and long-form guides appear on the publications page; deeper articles live under topics.

If you have questions about this article or want a non-binding discussion about your project, you can book a consultation or reach us via contact. We usually respond within one working day.

Next Step

Questions about this topic? We're happy to help.

Our experts are available for in-depth conversations – practical and without obligation.

30 min strategy call – 100% free & non-binding

ip stresser
Article: High-Risk AI under the EU AI Act: How to…
🇩🇪
EU AI Act High Risk Classification – Classify AI Systems

High-Risk AI under the EU AI Act: How to Classify Your Systems Correctly

EU AI Act • 4 May 2026

As of: 24 June 2026 · Reading time: 6 min

Teilen:

Key takeaways

  • Whether an AI system qualifies as high-risk under the EU AI Act determines your compliance scope.
  • This guide explains classification with practical examples.

Whether an AI system qualifies as high-risk under the EU AI Act determines your compliance scope. This guide explains classification with practical examples.

Digitalization is not an IT project—it is a business strategy.

Björn Groenewold, Managing Director, Groenewold IT Solutions

Whether an AI system is classified as high-risk under the EU AI Act determines your entire compliance roadmap. The classification is not trivial—and is often misjudged.

This article explains the scheme with practical examples.

Two Paths to the High-Risk Category

Short: Short answer: Whether an AI system is considered "high-risk" determines the full compliance scope.

Short answer: Whether an AI system is considered "high-risk" determines the full compliance scope.

For high-risk AI under the EU AI Act, start with AI development cost calculator and explore related solutions.

The EU AI Act defines high-risk AI in two ways:

**Path 1: Annex I – Safety relevant product categories ** AI systems that are used as security components in products that are already subject to EU security policies are automatically high risk.

Among other things:

  • Machines (machine directive)
  • Medical products (MDR/IVDR)
  • Aviation
  • Motor vehicles
  • Lifts
  • Toys with AI components

**Path 2: Annex III – Explicitly listed high risk areas ** This is about AI systems in certain socially sensitive areas of application:

Area Examples
Biometric identification facial recognition, gait analysis
Critical infrastructure AI control in energy networks, water supply
Education Automated examination assessment, approval decisions
Employment & HR AI recruitment, performance assessment, dismissal decisions
Major services AI in credit lending, credit assessment, insurance
Law enforcement AI-based risk assessment, lies detection
Migration & Asylum Risk classification of persons
Legal care AI support for court decisions

Practical examples: High risk or not?

Short: **AI-assisted recruiting tool that prequalifies CVs:**High risk.

**AI-assisted recruiting tool that prequalifies CVs:**High risk.**Current under Annex III, Employment Section. Subject HR decisions with significant influence on persons.

Chatbot on the company website for customer requests:No high risk. Transparency obligation (identification as AI), but no high risk classification for pure information provision.

**AI system for creditworthiness testing of a customer:High risk. Explicit listed in Annex III.

AI-supported stock forecast:→ No high risk. Internal process optimization case without significant impact on people.

AI system automatically calculates prices for end customers: → Contextual. For insurance premiums or credit conditions: high risk. For dynamic product prices in e-commerce: usually no high risk.

AI in a machine tool that makes safety-relevant decisions: → High risk over Annex I (machine directive), regardless of Annex III.

AI recommendation system for internal training: → Grey zone. If recommendations affect career-relevant decisions, possibly high risk. If purely informative, rather not.

Non-high risk exceptions: When does Annex III still not apply?

Short: The AI Act contains an important exception: A system does not fall under high risk despite belonging to an Annex III area if:

The AI Act contains an important exception: A system does not fall under high risk despite belonging to an Annex III area if:

  • Exercise only a help function for human decision (the person decides that the AI system only prepares)
  • No essential effect on the outcome of the human decision
  • Only used for administration (e.g. calendar planning, document formatting)

**This exception does not apply automatically. The provider or operator must document and justify why the system is not to be classified as high risk despite Annex III.

Classification process: How to proceed?

Short: **Step 1: Create technical description of the system.

**Step 1: Create technical description of the system. ** What exactly does the system do? What inputs does it process? What expenditure does it produce? How does the expenditure go into decisions?

**Step 2: Check Annex I. ** Is the system safety component in a product subject to an EU security policy?

**Step 3: Check Annex III. ** In what area of use is the system used? Does this range fall below one of the eight high-risk areas?

**Step 4: Exemptions check. ** Does the auxiliary function take effect? Is the impact on personal decisions actually essential?

**Step 5: Document classification. ** The classification decision and its justification must be documented – even if the result is "no high risk".

In the event of a doubt, an external legal assessment may be useful.

Characteristics: AI systems in software development

Short: If you have individual software and this software contains AI components, the classification should be clarified early:

If you have individual software and this software contains AI components, the classification should be clarified early:

  • Who is a provider within the meaning of the AI Act? (Oft the client, not the agency)
  • What obligations do the provider have?
  • Yes. How are obligations between client and development partner contractually divided? ?These questions should be ** before project start** in the contract. Retroactive assignments are complicated and expensive. Our team plans AI development projects from the outset, taking into account the AI-Act requirements.

What threatens wrong classification

Short: Anyone who misclassifies a high-risk system as a non-high risk and operates:

Anyone who misclassifies a high-risk system as a non-high risk and operates:

  • Risks fines up to €15 million or 3% of global sales
  • Liability for damages arising from the operation of a non-compliant system
  • Risks product recalls and sales locks in commercially distributed systems

The authorities have the right to request and examine classification documentation.

Conclusion

Short: Classification is not an administrative formal act, but a material decision with considerable consequences.

Classification is not an administrative formal act, but a material decision with considerable consequences. The 'grey' area is large and is gradually clearer by future guidance from the EU-AI authorities (AIDA).

Anyone who invests today in a resilient classification documentation will later avoid expensive reworking.

Our contribution EU AI Act: What companies 2026 need to know offers the full compliance overview.

Frequently Asked Questions (FAQ)

Can classification change over time?

Yes. If a system is significantly changed, the classification should be reassessed. New EU leadership can also lead to a reassessment. Classification is not a one-off process.

Who decides final whether a system is high risk – the provider or an authority?

Primary providers (self-classification). Market surveillance authorities may examine and contest the classification. For certain high-risk systems, an independent conformity assessment by a notified body is required.

Does the AI Act apply to AI systems developed outside the EU, but used in the EU?

Yes. The AI Act applies to all AI systems used in the EU, regardless of the development location. Importers and operators from third countries carry their own duties.

How does the AI Act relate to existing data protection requirements of the GDPR?

AI Act and GDPR are complementary. GDPR regulates the handling of personal data, AI Act regulates the security and transparency of AI systems.

Both can apply simultaneously – and the duties add up.


Learn more:

EU AI Act Consulting – technical and organizational compliance support for your company: risk classification, documentation obligations and AI governance. Artificial Intelligence

Next consultation appointment →

Short: The following independent references complement the classification on the topics of this Article:

The following independent references complement the classification on the topics of this Article:

"Privacy by Design is not a subsequent checkbox, but an architectural question – especially for personal master data."

— *Björn Groenewold, Managing Director, Groenewold IT Solutions *

About the author

Björn Groenewold
Björn Groenewold(Dipl.-Inf.)

Managing Director of Groenewold IT Solutions GmbH and Hyperspace GmbH

Since 2009 Björn Groenewold has been developing software solutions for the mid-market. He is Managing Director of Groenewold IT Solutions GmbH (founded 2012) and Hyperspace GmbH. As founder of Groenewold IT Solutions he has successfully supported more than 250 projects – from legacy modernisation to AI integration.

Software ArchitectureAI IntegrationLegacy ModernisationProject Management

Blog recommendations

Related articles

These posts might also interest you.

Free download

Checklist: 10 questions before software development

Key points before you start: budget, timeline, and requirements.

Get the checklist in a consultation

Relevant next steps

Related services & solutions

Based on this article's topic, these pages are often the most useful next steps.

Related services

Related solutions

More on this topic

More on EU AI Act and next steps

This article is in the EU AI Act topic. In our blog overview you will find all articles; under category EU AI Act more posts on this subject.

For topics like EU AI Act we offer matching services – from app development and AI integration to legacy modernisation and maintenance. We describe typical use cases under solutions. Our cost calculators give initial estimates. Key terms are in the IT glossary. Books and long-form guides appear on the publications page; deeper articles live under topics.

If you have questions about this article or want a non-binding discussion about your project, you can book a consultation or reach us via contact. We usually respond within one working day.

Next Step

Questions about this topic? We're happy to help.

Our experts are available for in-depth conversations – practical and without obligation.

30 min strategy call – 100% free & non-binding

ip stresser