EU AI Act High-Risk Classification: How to Tell If Your Product Falls Under Annex III

The short answer: your AI system is “high-risk” under the EU AI Act if it’s used in one of the Annex III areas — hiring, credit, education, essential services, biometrics, critical infrastructure, law enforcement, migration, justice — and doesn’t fit the narrow Article 6(3) exceptions for merely preparatory or procedural roles. After the Digital Omnibus, high-risk obligations apply from December 2, 2027 (standalone systems) and August 2, 2028 (AI embedded in regulated products). That’s runway, not a reprieve: proper high-risk compliance takes 9–18 months.

Why classification is the highest-stakes call you’ll make

Everything in the AI Act hangs on this fork. Transparency-only systems (Article 50) need disclosures — days of work. High-risk systems need a risk-management system, data governance, technical documentation, logging, human oversight, accuracy/robustness testing, and a conformity assessment before market — months of work and real money. Misclassify yourself in either direction and you either burn a year on compliance you didn’t owe, or sell a product that becomes unsellable to EU enterprises in 2027.

The Annex III list, translated to startup

Your system is presumptively high-risk if it’s intended to be used for:

Annex III areaWhat it looks like in a real product
Employment & worker managementCV screening, candidate ranking, interview scoring, promotion/termination recommendations, work allocation
Access to essential private/public servicesCredit scoring, insurance risk pricing (life/health), emergency-call triage, benefits eligibility
Education & vocational trainingAdmission scoring, exam proctoring, grading, learning-path gating
BiometricsRemote biometric identification, biometric categorisation by sensitive attributes, emotion recognition (where not outright banned)
Critical infrastructureSafety components in energy, water, transport, digital infrastructure
Law enforcement / migration / justice / democratic processesRisk assessments, evidence evaluation, asylum triage, election-influence systems — plus most of this space is public-sector territory

Being sold to these industries isn’t the trigger — being used for these purposes is. A general writing assistant sold to an HR team isn’t automatically high-risk; a tool that ranks candidates is.

The Article 6(3) escape hatches — read before you panic

A system in an Annex III area is not high-risk if it doesn’t pose a significant risk to health, safety or fundamental rights — concretely, if it only:

  • performs a narrow procedural task (e.g., converting unstructured CVs into structured fields — without scoring);
  • improves the result of a previously completed human activity (e.g., polishing the wording of a human-written assessment);
  • detects decision-making patterns or deviations without replacing or influencing the human assessment;
  • performs a preparatory task to an assessment (e.g., document indexing for a human reviewer).

Hard limit: if your system profiles natural persons, it’s high-risk regardless of the exceptions. And if you rely on an exception, you must document that assessment (and be ready to defend it) — the classification memo is itself a compliance artefact. The 2026 Omnibus kept the requirement to register these self-assessed exceptions in the EU database once the high-risk regime applies, so the memo will have an official audience.

Honest warning from practice: founders read these exceptions generously; regulators and enterprise buyers read them narrowly. “We just recommend, a human decides” does not automatically save you — if your score meaningfully influences the human decision, you’re in scope.

What high-risk actually requires (the 2027 workload)

If you land in scope, by December 2, 2027 you’ll need: a documented risk-management system across the lifecycle; data-governance controls on training/validation data; technical documentation (Annex IV); automatic event logging; human-oversight design; declared accuracy, robustness and cybersecurity levels; a quality-management system; conformity assessment and CE marking; registration in the EU database. Non-EU providers additionally appoint an EU authorised representative.

None of this is exotic — it’s product and process work — but it’s sequential and slow. Teams that start by early 2027 give themselves a realistic 10–11 months; teams that wait until mid-2027 are betting the EU market on nothing going wrong.

The high-risk compliance deadline, precisely

  • December 2, 2027 — standalone Annex III systems (moved from August 2, 2026 by the Digital Omnibus).
  • August 2, 2028 — high-risk AI embedded in products regulated under Annex I (medical devices, machinery, vehicles…).
  • Full calendar with what wasn’t delayed: EU AI Act timeline 2026–2028.

A 4-question self-triage (30 minutes)

  1. Purpose test: does any feature’s intended purpose fall in an Annex III row above?
  2. Exception test: if yes — does it genuinely fit an Article 6(3) exception, and does it avoid profiling individuals?
  3. Influence test: does your output materially influence decisions about people (hiring, credit, grades, benefits)?
  4. Evidence test: is the answer to 1–3 written down with reasoning?

Outcomes: clearly out → do the 10-step checklist and move on; clearly in → calendar a Q1 2027 readiness project; arguable → that’s exactly the case worth a fixed-fee legal classification — the memo costs a fraction of guessing wrong.

FAQ

What is the deadline for EU AI Act high-risk compliance?

December 2, 2027 for standalone Annex III systems; August 2, 2028 for high-risk AI embedded in Annex I regulated products. Both dates were set by the Digital Omnibus — agreed in May 2026, formally adopted in June 2026, and in force since July 2026.

Is my hiring/HR AI automatically high-risk?

If it screens, scores, ranks or influences employment decisions about people — presumptively yes. Purely procedural tasks (parsing, formatting) may fit the Article 6(3) exceptions, if they don’t profile people and you document the assessment.

Does “human in the loop” remove high-risk status?

No. Human oversight is one of the obligations of high-risk systems, not an exemption from classification.

We’re a US company — does the high-risk regime reach us?

Yes, if your system is placed on the EU market or its output is used there. Non-EU providers of high-risk systems also need an EU authorised representative. Details here.

What happens if we misclassify and get caught?

Enforcement exposure (fines up to €15M/3% for non-compliance with high-risk obligations) plus the commercial version: EU enterprise deals now routinely require your classification memo in procurement.

Get a definitive classification in one week

Montaire & Co.’s fixed-fee classification memo: feature-by-feature Annex III analysis, Article 6(3) assessment, and — if you’re in scope — a costed readiness roadmap to December 2027.

30 minutes · senior advisor · no charge, no obligation

General information, not legal advice. Status as of July 16, 2026.