The AI Regulation doesn't prohibit artificial intelligence. It does something more subtle and more demanding: it categorizes it by risk levels. And there's a category, high-risk AI systems, where almost all the fine print, almost all the obligations, and almost all the headaches are concentrated. The problem is that many companies use systems that could be in that category… without even knowing it.
If you advise companies that use AI—or if you use it yourself—the first question isn't "Do I comply with the Regulation?" but a more basic one: "Is my system high-risk?" Almost everything else depends on the answer.
What does "high risk" mean (and what doesn't)?
High risk doesn't mean prohibited. Prohibited practices are a separate category (manipulation, social scoring, certain biometrics). High risk is the level immediately below: systems that can be used, yes, but which, due to their potential impact on health, safety, or fundamental human rights, come with a serious set of obligations.
Imagine an AI that decides who gets hired, who gets a loan or how a medical emergency is prioritized. They aren't banned; they're monitored.
The Two Entry Points
A system enters the high-risk category through one of two paths:
- By product. When the AI is a product —or a product's safety component—already regulated by the EU and requires a third-party conformity assessment: machinery, medical devices, toys, elevators, vehicles, etc. This is what the Regulation groups in Annex I.
- By use. When the system is intended for any of the sensitive areas that the Regulation lists in Annex III, regardless of the product it's used in.
The List You Really Need to Look At
The second path is the one most systems enter through. The Regulation identifies as high-risk, among others, AI systems used for:
- Biometrics: identification or categorization of people.
- Critical infrastructure: water, energy, traffic.
- Education and training: admissions, exam evaluation.
- Employment: personnel selection, resume screening, promotion or dismissal decisions.
- Access to essential services: credit scoring, health and life insurance, public assistance, emergency prioritization.
- Security and law enforcement.
- Migration, asylum, and border control.
- Administration of justice and democratic processes.
If your system—or your client's—does anything similar to this, it should raise a red flag.
The nuance that could save you
Being on Annex III doesn't automatically condemn you. The Regulation adds a safety valve: a system on that list won't be considered high-risk if it doesn't pose a significant risk to health, safety, or rights. For example, if it only performs a very specific procedural task, if it merely improves the outcome of a completed human activity, or if it detects deviations without replacing human judgment.
However, beware of the exception to the exception: if the system creates profiles of individuals, it is always considered high-risk. No exceptions.
What it means to be involved
If your system is high-risk, it's not enough for it to "work well": you have to demonstrate and document it. Risk management system, data quality control, technical documentation, activity logs, transparency towards users, human oversight that is real, and adequate levels of accuracy, robustness, and cybersecurity. Added to this is conformity assessment, CE marking, and registration in the European database.
And the obligations are divided: it's not the same to be the supplier who develops the system as it is to be the one responsible for the deployment that uses it. It's important to know where you stand.
How to know in practice
To clear up any doubts, ask yourself—or your client—these questions:
- Is the AI in, or integrated into, an already regulated product (healthcare, machine, vehicle, etc.)?
- Is it used in any of the areas in Annex III (employment, credit, education, biometrics, etc.)?
- Does it make or influence decisions that affect people's rights?
- Does it create profiles?
If you answer "yes" to several, be prepared: you're most likely at high risk.
You have less time than it seems
These obligations aren't science fiction or a "someday" problem. For the systems in Annex III, the bulk of the requirements apply from August 2, 2026; for those embedded in regulated products, from August 2, 2027. It seems far off, but adapting a high-risk system—documenting it, auditing it, redesigning its oversight—takes months, not weeks.
Knowing whether your system is high-risk isn't a technicality: it's the question that determines how much of the Regulation applies to you. And like almost everything at the intersection of law and technology, the sooner you ask yourself this question, the cheaper the answer will be.
Sources
- Regulation (EU) 2024/1689 — official text (EUR-Lex): eur-lex.europa.eu
- Official summary "Rules for trustworthy AI in the EU" (EUR-Lex): eur-lex.europa.eu/summary

