← Glossary

What makes an AI system 'high-risk' under the EU AI Act?

Under the EU AI Act, a system is classified high-risk if it falls within one of Annex III's eight domains (and doesn't qualify for the Article 6(3) narrow-task exception), or if it's a safety component of a product already regulated under EU product safety legislation requiring third-party conformity assessment.

What follows from high-risk classification

A high-risk classification triggers several obligations: Annex IV technical documentation, a risk-management system maintained across the system's lifecycle, data governance requirements, human oversight measures, a conformity assessment (internal control or notified-body, depending on the category), registration in the EU database, and post-market monitoring.

Not the same as prohibited

High-risk is a distinct, separate category from Article 5's prohibited practices. A prohibited practice has no compliance pathway — it must stop. A high-risk system is legal to operate, provided the obligations above are met.

This is general educational information, not legal advice. Regulatory timelines and interpretations have changed multiple times in 2026 — verify current status before making compliance decisions.
Check your system's risk tier →See Attestly's pricing →