Skip to content
AIRAS Cloud

Classification

What counts as a high-risk AI system?

Most organisations already deploy at least one candidate. The difficulty is not finding them, it is defending the classification.

Short answer

Under Article 6 of the EU AI Act, an AI system is high-risk either because it is a safety component of a product covered by Union harmonisation legislation, or because it falls within one of the Annex III use cases, which include biometrics, critical infrastructure, education, employment and worker management, access to essential public and private services including creditworthiness, law enforcement, migration and the administration of justice. Article 6(3) allows a narrow derogation where a system does not pose a significant risk of harm, but the assessment must be documented before deployment.

Reviewed 2026-08-02. General information for governance planning, not legal advice.

Key points

  • Two routes to high-risk: product safety components, and Annex III use cases
  • Employment, credit and essential services capture ordinary commercial systems
  • The Article 6(3) derogation is narrow and must be documented, not assumed
  • Profiling of natural persons generally defeats the derogation
  • Providers and deployers carry different, complementary obligations
  • Classification must be reproducible, not a one-off judgement call

The Annex III categories in plain terms

  • Biometrics, including remote identification and categorisation
  • Critical infrastructure management and operation
  • Education and vocational training, including admission and assessment
  • Employment, worker management and access to self-employment
  • Access to essential private and public services, including creditworthiness
  • Law enforcement, migration and asylum, and administration of justice

Where classification actually goes wrong

Two failure patterns dominate. The first is under-classification by description: a CV-ranking tool is recorded as productivity software, so the employment category is never reached. The second is over-classification by caution: everything is marked high-risk, controls become undifferentiated, and genuine high-risk systems receive no more attention than a meeting summariser.

Both are symptoms of the same gap. The organisation recorded a conclusion without recording the reasoning that produced it.

What a defensible classification contains

  • The system's actual function, not its marketing description
  • The Annex III category considered, and why it applies or does not
  • Whether profiling of natural persons occurs
  • The Article 6(3) derogation reasoning where relied on
  • The ruleset version used, so the decision can be reproduced
  • The named assessor, the approver, and the date of decision

Deployer obligations are not lighter, only different

Deployers of high-risk systems must use them in accordance with instructions, assign human oversight to people with the competence and authority to act, ensure input data is relevant, monitor operation, keep logs, and inform workers where a system is used in the workplace. Some deployers must also carry out a fundamental rights impact assessment.

None of this can be evidenced retrospectively. It has to be captured while the system is running.

Frequently asked questions

Is a CV screening tool high-risk?
AI used for recruitment, selection, or evaluation of candidates falls within the Annex III employment category, so it is generally high-risk unless a documented Article 6(3) assessment establishes otherwise.
Does a chatbot count as high-risk?
Not by default. A general assistant is usually subject to Article 50 transparency duties rather than the high-risk regime, but a chatbot that triages access to a service or influences an employment or credit outcome may be captured.
Can we rely on the Article 6(3) derogation?
Only with a documented assessment showing the system performs a narrow procedural or preparatory task and does not materially influence the outcome. Systems that profile natural persons are excluded from the derogation.
Who classifies, the vendor or us?
A vendor's statement is useful input but not a substitute. The deploying organisation must reach and record its own position, because it is the deployer that answers for how the system is used in its own context.

Primary sources

How AIRAS Cloud supports this

Complete AI inventory, including embedded vendor AI
Role and applicability determination per system
Deterministic, versioned classification reasoning
Append-only audit record of every decision

Related answers

Turn the regulation into an operating record

AIRAS Cloud gives Irish and EU organisations one accountable place to discover AI, determine scope, classify defensibly, assign controls and evidence every decision.

No pricing commitment. No confidential information required.