The short answer: your AI system is “high-risk” under the EU AI Act if it’s used in one of the Annex III areas — hiring, credit, education, essential services, biometrics, critical infrastructure, law enforcement, migration, justice — and doesn’t fit the narrow Article 6(3) exceptions for merely preparatory or procedural roles. After the Digital Omnibus, high-risk obligations apply from December 2, 2027 (standalone systems) and August 2, 2028 (AI embedded in regulated products). That’s runway, not a reprieve: proper high-risk compliance takes 9–18 months.
Why classification is the highest-stakes call you’ll make
Everything in the AI Act hangs on this fork. Transparency-only systems (Article 50) need disclosures — days of work. High-risk systems need a risk-management system, data governance, technical documentation, logging, human oversight, accuracy/robustness testing, and a conformity assessment before market — months of work and real money. Misclassify yourself in either direction and you either burn a year on compliance you didn’t owe, or sell a product that becomes unsellable to EU enterprises in 2027.
The Annex III list, translated to startup
Your system is presumptively high-risk if it’s intended to be used for:
| Annex III area | What it looks like in a real product |
|---|---|
| Employment & worker management | CV screening, candidate ranking, interview scoring, promotion/termination recommendations, work allocation |
| Access to essential private/public services | Credit scoring, insurance risk pricing (life/health), emergency-call triage, benefits eligibility |
| Education & vocational training | Admission scoring, exam proctoring, grading, learning-path gating |
| Biometrics | Remote biometric identification, biometric categorisation by sensitive attributes, emotion recognition (where not outright banned) |
| Critical infrastructure | Safety components in energy, water, transport, digital infrastructure |
| Law enforcement / migration / justice / democratic processes | Risk assessments, evidence evaluation, asylum triage, election-influence systems — plus most of this space is public-sector territory |
Being sold to these industries isn’t the trigger — being used for these purposes is. A general writing assistant sold to an HR team isn’t automatically high-risk; a tool that ranks candidates is.
The Article 6(3) escape hatches — read before you panic
A system in an Annex III area is not high-risk if it doesn’t pose a significant risk to health, safety or fundamental rights — concretely, if it only:
- performs a narrow procedural task (e.g., converting unstructured CVs into structured fields — without scoring);
- improves the result of a previously completed human activity (e.g., polishing the wording of a human-written assessment);
- detects decision-making patterns or deviations without replacing or influencing the human assessment;
- performs a preparatory task to an assessment (e.g., document indexing for a human reviewer).
Hard limit: if your system profiles natural persons, it’s high-risk regardless of the exceptions. And if you rely on an exception, you must document that assessment (and be ready to defend it) — the classification memo is itself a compliance artefact. The 2026 Omnibus kept the requirement to register these self-assessed exceptions in the EU database once the high-risk regime applies, so the memo will have an official audience.
Honest warning from practice: founders read these exceptions generously; regulators and enterprise buyers read them narrowly. “We just recommend, a human decides” does not automatically save you — if your score meaningfully influences the human decision, you’re in scope.
What high-risk actually requires (the 2027 workload)
If you land in scope, by December 2, 2027 you’ll need: a documented risk-management system across the lifecycle; data-governance controls on training/validation data; technical documentation (Annex IV); automatic event logging; human-oversight design; declared accuracy, robustness and cybersecurity levels; a quality-management system; conformity assessment and CE marking; registration in the EU database. Non-EU providers additionally appoint an EU authorised representative.
None of this is exotic — it’s product and process work — but it’s sequential and slow. Teams that start by early 2027 give themselves a realistic 10–11 months; teams that wait until mid-2027 are betting the EU market on nothing going wrong.
The high-risk compliance deadline, precisely
- December 2, 2027 — standalone Annex III systems (moved from August 2, 2026 by the Digital Omnibus).
- August 2, 2028 — high-risk AI embedded in products regulated under Annex I (medical devices, machinery, vehicles…).
- Full calendar with what wasn’t delayed: EU AI Act timeline 2026–2028.
A 4-question self-triage (30 minutes)
- Purpose test: does any feature’s intended purpose fall in an Annex III row above?
- Exception test: if yes — does it genuinely fit an Article 6(3) exception, and does it avoid profiling individuals?
- Influence test: does your output materially influence decisions about people (hiring, credit, grades, benefits)?
- Evidence test: is the answer to 1–3 written down with reasoning?
Outcomes: clearly out → do the 10-step checklist and move on; clearly in → calendar a Q1 2027 readiness project; arguable → that’s exactly the case worth a fixed-fee legal classification — the memo costs a fraction of guessing wrong.
FAQ
What is the deadline for EU AI Act high-risk compliance?
December 2, 2027 for standalone Annex III systems; August 2, 2028 for high-risk AI embedded in Annex I regulated products. Both dates were set by the Digital Omnibus — agreed in May 2026, formally adopted in June 2026, and in force since July 2026.
Is my hiring/HR AI automatically high-risk?
If it screens, scores, ranks or influences employment decisions about people — presumptively yes. Purely procedural tasks (parsing, formatting) may fit the Article 6(3) exceptions, if they don’t profile people and you document the assessment.
Does “human in the loop” remove high-risk status?
No. Human oversight is one of the obligations of high-risk systems, not an exemption from classification.
We’re a US company — does the high-risk regime reach us?
Yes, if your system is placed on the EU market or its output is used there. Non-EU providers of high-risk systems also need an EU authorised representative. Details here.
What happens if we misclassify and get caught?
Enforcement exposure (fines up to €15M/3% for non-compliance with high-risk obligations) plus the commercial version: EU enterprise deals now routinely require your classification memo in procurement.

