Is your system high-risk? Reading Annex III without a lawyer
Almost everything about your AI Act workload depends on one classification: is your system high-risk? Teams either panic (assuming everything is) or hand-wave (assuming nothing is). Both are expensive. High-risk is a defined category, and you can do a credible first read yourself.
High-risk is a category, not a feeling
The Act doesn't ask whether your AI feels risky. It defines high-risk in two main ways: AI used as a safety component of products already regulated under EU law, and AI used in the specific areas listed in Annex III — think biometrics, critical infrastructure, education access, employment and worker management, access to essential services and credit, law enforcement, migration, and administration of justice. If your use doesn't map to one of those, it is very likely not high-risk, however sophisticated it is.
Start with the use case, not the technology
The classification turns on what the system is used for, not how clever it is. A large language model writing marketing copy is not high-risk; the same model screening job applicants likely is, because employment is an Annex III area. So classify per use case, per system. The same underlying model can be minimal-risk in one deployment and high-risk in another — the deployment is what the Act cares about.
Watch the exceptions both ways
There are nuances that cut both directions. Some systems that fall within an Annex III area may not be high-risk if they perform only a narrow, preparatory task and don't materially influence the outcome — but you have to be able to justify that, and profiling generally keeps you in. Equally, don't assume a consumer-facing chatbot is high-risk just because it's visible; it's more likely a transparency (Article 50) obligation than a high-risk one. Precision here saves enormous effort.
Write down the answer and why
Whatever you conclude, record it: this system, this use, this tier, this reasoning. That short justification is the foundation an auditor, a buyer, or your own future self will rely on — and if you later change the system's purpose, it's the trigger to re-check. Classification isn't a one-time gate; it's a decision you revisit whenever the use changes.
Educational orientation, not legal advice. EU AI Act references current as of September 2026. For binding interpretation of your obligations, consult qualified counsel.