EU AI ActClassification

Is your system high-risk? Reading Annex III without a lawyer

Almost everything about your AI Act workload depends on one classification: is your system high-risk? Teams either panic (assuming everything is) or hand-wave (assuming nothing is). Both are expensive. High-risk is a defined category, and you can do a credible first read yourself.

High-risk is a category, not a feeling

The Act doesn't ask whether your AI feels risky. It defines high-risk in two main ways: AI used as a safety component of products already regulated under EU law, and AI used in the specific areas listed in Annex III — think biometrics, critical infrastructure, education access, employment and worker management, access to essential services and credit, law enforcement, migration, and administration of justice. If your use doesn't map to one of those, it is very likely not high-risk, however sophisticated it is.

Start with the use case, not the technology

The classification turns on what the system is used for, not how clever it is. A large language model writing marketing copy is not high-risk; the same model screening job applicants likely is, because employment is an Annex III area. So classify per use case, per system. The same underlying model can be minimal-risk in one deployment and high-risk in another — the deployment is what the Act cares about.

Watch the exceptions both ways

There are nuances that cut both directions. Some systems that fall within an Annex III area may not be high-risk if they perform only a narrow, preparatory task and don't materially influence the outcome — but you have to be able to justify that, and profiling generally keeps you in. Equally, don't assume a consumer-facing chatbot is high-risk just because it's visible; it's more likely a transparency (Article 50) obligation than a high-risk one. Precision here saves enormous effort.

Write down the answer and why

Whatever you conclude, record it: this system, this use, this tier, this reasoning. That short justification is the foundation an auditor, a buyer, or your own future self will rely on — and if you later change the system's purpose, it's the trigger to re-check. Classification isn't a one-time gate; it's a decision you revisit whenever the use changes.

The shortcut that isn't a shortcut. You can't skip classification, but you can do it quickly and honestly: map each use case to Annex III, apply the exceptions carefully, and write down the reasoning. Get this right and the rest of the Act stops being terrifying and becomes a finite list.
BJ

Former IBM and Deloitte strategy consultant, now advising mid-market companies on AI governance. Founder of Govern42.

Questions about your ISO 42001 or EU AI Act programme? Email me directly: bigjay11@gmail.com

Educational orientation, not legal advice. EU AI Act references current as of September 2026. For binding interpretation of your obligations, consult qualified counsel.