High-Risk AI System
A high-risk AI system is an AI application that, because of where and how it is used, could pose significant risks to people's safety, rights, or important interests. In the European Union's AI Act, certain AI systems are treated as high-risk when they are used in sensitive settings or perform functions the law considers especially consequential. The label matters because such systems typically face stricter requirements than lower-risk uses.
Under the EU AI Act, an AI system is classified as high-risk primarily through two pathways described in Article 6: (i) where the system is used as a safety component of a product, or is itself a product, covered by EU harmonisation legislation listed in the Act's annexes; or (ii) where the system falls within the use cases enumerated in Annex III (which, as commonly summarised, includes systems that profile natural persons through automated processing of personal data). More broadly, and outside the EU legal framework, practitioners and analysts sometimes use "high-risk AI" descriptively to characterise capable models deployed in sensitive environments such as clinical workflows, autonomous systems, or software supply chains. Note that the term's precise, binding meaning is tied to the EU AI Act's classification rules and its jurisdiction; the descriptive usage is not equivalent to that legal classification, and the evidence here does not establish the specific annex contents, effective dates, or clause numbering beyond the Article 6 pathways cited.
Why it matters
The high-risk classification is a threshold that determines the intensity of legal obligations an AI system faces. Under the EU AI Act, systems that fall into the high-risk category are subject to substantially stricter requirements than lower-risk uses, so the classification decision is not merely descriptive—it directly shapes what a provider or deployer must do before and after placing a system on the market. Getting the classification wrong in either direction carries consequences: under-classifying may expose an organisation to non-compliance, while treating everything as high-risk can impose disproportionate burden.
The label also matters because it channels attention toward the settings where AI can most affect people's safety, rights, or important interests. As commonly summarised, the EU AI Act ties high-risk status either to AI functioning as a safety component of, or itself being, a product covered by EU harmonisation legislation, or to enumerated use cases in Annex III such as systems that profile natural persons through automated processing of personal data. These are contexts where errors, opacity, or misuse can have serious downstream effects on individuals.
Professionals should be careful not to conflate the EU AI Act's binding legal classification with the looser, descriptive sense in which "high-risk AI" is sometimes used—for example, to characterise capable models deployed in sensitive environments such as clinical workflows, autonomous systems, or software supply chains. That descriptive usage flags where practitioners intuitively expect elevated risk, but it does not carry the specific legal meaning or obligations attached to the EU AI Act's Article 6 pathways, and it is not scoped to the same jurisdiction.
Who it's relevant to
Inside High-Risk AI System
Common questions
Answers to the questions practitioners most commonly ask about High-Risk AI System.