The AI act identifies “high risk” AI systems through two main routes: first, AI systems that are products or safety components of products covered by certain union harmonization legislation (Article 6(1)); and second, AI systems listed in Annex III because of their intended use case (Article 6(2)).
Part 1: Regulated Product or Safety Component High-Risk AI (Article 6(1) AI Act)
An AI system is high-risk under Article 6(1) where the following cumulative conditions are met:
1) It is a product or it is intended to be used as a safety component of such a product.
An AI system is the product itself where it is independently placed on the market, has its own intended purpose that is directly regulated by the Union harmonization legislation listed in Annex I of the AI Act. Such systems can include stand-alone AI systems, or AI systems that are embedded in other products.
Following Regulation (EU) 2026/1744 (“AI Omnibus”), which amended the AI Act and entered into force on 27 July 2026, AI systems used solely for non-safety aspects of user assistance, performance optimization, service efficiency, or automation shall not qualify as safety component.
See details below.
2) That product is required by that legislation to undergo a third-party conformity assessment
Products subject to third-party assessment solely in relation to risks other than health and safety risks, shall not be considered as fulfilling this last condition.
Following the AI Omnibus, some high-risk AI systems under Article 6(1) will benefit from a limited application of certain High-Risk AI systems obligations. The AI Omnibus introduced an obligation on the EU Commission to adopt delegated acts by August 2, 2027, that will specify the high-risk AI concerned, the limited requirements, the conditions and the scope of those limitations.
Annex I to the AI Act
Products covered by Annex I legislation present significant risks to health, safety and fundamental rights.
Section A (“New Legislative Framework”)
Section B (other Union harmonization legislation)
AI systems that will be subject to the legislation listed in Section B of Annex I are not subject to the high-risk AI system obligations set out it in Chapter III, Section 2 of the AI Act, and elsewhere. Instead, to avoid duplication of obligations on manufacturers of covered products Article 2(2) limits the obligations of the AI Act that will be applicable, with the effect that compliance obligations for these AI systems are primarily imposed through their existing sectoral regimes.
Part 2: Designated High-Risk AI System Based on Use Case (Article 6(2) AI Act)
An AI system is high-risk under Article 6(2) where it is identified in Annex III to the Act.
Annex III to the AI Act
REMOTE BIOMETRIC IDENTIFICATION AI
AI systems intended for identifying individuals without their active involvement, typically at a distance, through the comparison of an individual’s biometric data with the biometric data contained in a reference database.
BIOMETRICS
AI systems intended to be used for remote biometric identification or biometric categorization, according to sensitive or protected attributes or characteristics based on the inference of those attributes or characteristics.
EMOTION RECOGNITION AI
AI systems intended to be used for emotion recognition. An “emotion recognition system” is defined as means an AI system for the purpose of identifying or inferring emotions or intentions of natural persons on the basis of their biometric data.
CRITICAL INFRASTRUCTURE AI
AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, or in the supply of water, gas, heating or electricity.
“Critical infrastructure” is defined by Directive (EU) 2022/2557 as an asset, a facility, equipment, a network or a system, or a part of an asset, a facility, equipment, a network or a system, which is necessary for the provision of an essential service.
“Digital infrastructure” includes providers of cloud computing services, providers of data centre services, trust services and publicly available electronic communications services.
EDUCATION & TRAINING AI
AI systems intended to be used to:
-
- Determine access or admission or to assign individuals to educational and vocational training institutions
- Evaluate learning outcomes, including when those outcomes are used to steer the learning process of individuals in educational and vocational training institutions
- Assess the appropriate level of education that an individual will receive or will be able to access, in the context of or within educational and vocational training institutions
- Monitor and detect prohibited behavior of students during tests in the context of or within educational and vocational training institutions
EMPLOYMENT DECISIONS AI
AI systems intended to be used to:
-
- Recruit or select individuals, including to place targeted job advertisements, analyze and filter job applications and to evaluate candidates
- Make decisions affecting terms of work-related relationships, or the promotion or termination of work-related contractual relationships
- Allocate tasks based on individual behavior or personal traits or characteristics of persons in work-related relationships
- Monitor and evaluate the performance and behavior of persons in work-related relationships
INSURANCE RISK / PRICING AI
AI systems intended to be used for risk assessment and pricing in relation to individuals in the case of life and health insurance.
ESSENTIAL SERVICES AI
AI systems intended to:
-
- Be used by public authorities or on their behalf to evaluate the eligibility of individuals for essential public assistance benefits and services, including healthcare services, as well as to grant, reduce, revoke, or reclaim such benefits and services
- Be used to evaluate the creditworthiness of individuals or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud
- Evaluate and classify emergency calls by individuals or to be used to dispatch, or to establish priority in the dispatching of, emergency first response services, including by police, firefighters and medical aid, as well as of emergency healthcare patient triage systems
LAW ENFORCEMENT AI
AI systems intended to be used by or on behalf of law enforcement authorities, or by Union institutions, bodies, offices or agencies in support of law enforcement authorities:
-
- As polygraphs or similar tools
- To assess the risk of an individual becoming the victim of criminal offences
- To evaluate the reliability of evidence in the course of the investigation or prosecution of criminal offences
- To assess the risk of an individual offending or re-offending not solely on the basis of the profiling of natural persons as referred to in Article 3(4) of the Data Protection Law Enforcement Directive
- To assess personality traits and characteristics or past criminal behavior of individuals or groups
- To profile natural persons as referred to in the Data Protection Law Enforcement Directive in the course of the detection, investigation or prosecution of criminal offences
MIGRATION / BORDER CONTROL AI
AI systems intended to be used by or on behalf of competent public authorities or by Union institutions, bodies, offices or agencies:
-
- As polygraphs or similar tools
- To assess a risk, including a security risk, a risk of irregular migration, or a health risk, posed by an individual who intends to enter or who has entered into the territory of a Member State
- To assist competent public authorities for the examination of applications for asylum, visa or residence permits and for associated complaints with regard to the eligibility of the individuals applying for a status, including related assessments of the reliability of evidence
- In the context of migration, asylum or border control management, for the purpose of detecting, recognizing or identifying individuals, with the exception of the verification of travel documents
ADMINISTRATION OF JUSTICE AI
AI systems intended to be used by a judicial authority or on their behalf to assist a judicial authority in researching and interpreting facts and the law and in applying the law to a concrete set of facts, or to be used in a similar way in alternative dispute resolution.
DEMOCRATIC PROCESS AI
AI systems intended to be used for influencing the outcome of an election or referendum or the voting behavior of individuals in the exercise of their vote in elections or referenda. This does not include AI systems to the output of which individuals are not directly exposed, such as tools used to organize, optimize or structure political campaigns from an administrative or logistical point of view.
The Act contains an important derogation from the classification as “high risk” at Article 6(3). An AI system referred to in Annex III shall not be considered to be high-risk under Annex III if it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making. The provision sets out conditions relevant to the application of the derogation. Providers that rely on the derogation need to document their analysis and register their AI system.