A high-risk AI system is one that Article 6 of Regulation EU 2024/1689 places under the AI Act's heaviest obligations. It opens two classification routes: Annex I products and Annex III use cases, whose obligations apply from 2 December 2027.
Read the full guide
EU AI Act 2026: The Complete Compliance Guide for SMEs and Nonprofits
Answer a few questions and get a personalized assessment with recommendations tailored to your industry.
Assess my AI maturityRelated articles
Dive deeper with these complementary articles.
The EU AI Act (Regulation 2024/1689) applies to your SME or nonprofit as soon as you use an AI tool, even a simple ChatGPT subscription. Since February 2025 you must train your teams; on 2 August 2026 the transparency obligations and the penalty regime take effect.
A high-risk AI system is one that Article 6 of Regulation EU 2024/1689 places under the AI Act's heaviest obligations. Article 6 opens two classification routes: products covered by Annex I, and the use cases listed in Annex III. For Annex III systems, those obligations apply from 2 December 2027. The real question is whether your tools actually fall in scope, because most of what an SME uses does not. That question sits at the heart of our AI Act compliance guide, and this article breaks down exactly how Article 6 works.
Article 6 does not describe a specific tool, it sets out a classification method. It answers one question: does your AI system tip into the "high-risk" category or not? The answer has direct consequences, because high-risk triggers most of the AI Act's technical obligations, whereas everyday uses such as a drafting assistant or an internal chatbot stay under simple transparency rules.
In practice, a system classified as high-risk must go through a conformity assessment, keep full technical documentation and be subject to human oversight. That is the difference between "I must inform my users" and "I must prove, with a file to back it up, that my system is under control." Understanding Article 6 therefore means knowing which regime you are playing in before you even talk about obligations.
A system becomes high-risk through one of two doors, never by accident. Article 6 draws a line between two independent mechanisms.
The first route, Article 6(1), covers AI built into already regulated products. If your AI system is a safety component of a product covered by the Annex I harmonisation legislation (machinery, medical devices, toys, lifts, radio equipment and so on), or is itself such a product, and that product must undergo a third-party conformity assessment, then the AI is classified as high-risk. This route mainly affects industrial manufacturers and medical device makers.
The second route, Article 6(2), points to the use cases listed in Annex III. This is the one that concerns the most SMEs, because it targets cross-cutting functions: recruitment, credit scoring, access to essential services. A CV-screening tool is nothing like a medical device, yet it can fall under high-risk through this second door.
Annex III lists eight sensitive areas where AI can weigh on people's rights. A system is in scope only if it matches a precise use case within one of these areas, not simply because it operates near the sector.
| Area (Annex III) | Example systems in scope | Typical SME relevance |
|---|---|---|
| Biometrics | Remote biometric identification, categorisation, emotion recognition | Low, except biometric access control |
| Critical infrastructure | Safety management of water, gas, electricity, traffic | Low |
| Education and training | Admission, assessment of learning outcomes, exam fraud detection | Medium for training bodies |
| Employment and worker management | CV screening, evaluation, promotion or dismissal decisions | High |
| Essential services | Creditworthiness and credit scoring, health and life insurance pricing, emergency call triage | High for financial activities |
| Law enforcement | Recidivism risk assessment, evidence analysis | None outside police forces |
| Migration and border control | Review of asylum claims, visas | None outside government bodies |
For a typical SME, two rows concentrate the real risk: employment (a recruitment-support tool) and essential services (a credit score or insurance pricing). The other six areas belong to very specific players. Our article on who the AI Act applies to sets out who, from provider to deployer, carries which responsibility.
A system can match an Annex III use case without being classified as high-risk. This is the least understood filter in the AI Act, and the most useful one for an SME. Article 6(3) provides that a system listed in Annex III is not high-risk if it does not pose a significant risk to health, safety or fundamental rights, in particular because it does not materially influence the outcome of a decision.
This filter applies where the system meets at least one of these four conditions: it performs a narrow procedural task; it improves the result of a previously completed human activity; it detects decision patterns or deviations from prior patterns without replacing or influencing the human assessment absent proper review; or it performs a preparatory task for an assessment relevant to an Annex III use case.
Watch the trap. A system that carries out profiling of natural persons always stays classified as high-risk, with no possible exception. And above all, claiming the exception is not free: the provider must document the analysis before placing the system on the market, and keeps the obligation to register it in the European database. That registration obligation was explicitly kept during the 2026 adjustments. In other words, the exception is not a box you tick, it is a position you justify in writing.
High-risk imposes a chain of technical requirements split between the provider and the deployer. These are not vague principles but precise articles of the regulation.
On the provider side, seven requirements structure the system: a risk management system (Article 9), governance of training data (Article 10), full technical documentation (Article 11), automatic logging of events (Article 12), transparency and clear instructions for use (Article 13), effective human oversight (Article 14), and accuracy, robustness and cybersecurity (Article 15). On top of that come the conformity assessment (Article 43), the CE marking (Article 48) and registration in the European database. All provider obligations are grouped under Article 16.
On the deployer side, meaning the company that uses the system, the Article 26 obligations are lighter but real: use the system in line with the instructions, ensure human oversight by competent people, monitor how it runs and keep the logs. An SME that buys a recruitment tool classified as high-risk is a deployer, not a provider: it does not have to produce the technical documentation, but it must guarantee that a human keeps control over decisions. This staff competence ties back to the AI literacy obligation we cover in our article on the mandatory training under Article 4.
Obligations for high-risk Annex III systems now apply from 2 December 2027. This is the main change in the adjustment package known as the "Digital Omnibus", agreed in 2026: the deadline, first set for 2 August 2026, was pushed back. For systems tied to Annex I products, application is set for 2 August 2028.
This postponement is not a suspension. On 19 May 2026 the European Commission published draft guidelines on classifying high-risk systems under Article 6, open for consultation until 23 July 2026, and must publish its final guidelines by 1 August 2027 at the latest. Companies therefore have a window to prepare, not a reason to ignore the topic. The full schedule appears in our complete AI Act timeline.
The right first step is not to become compliant, but to check whether you are in scope. Three steps are enough to clarify your situation.
First, inventory your AI systems and test each one against the eight Annex III areas. Then, for any system touching one of those areas, apply the Article 6(3) filter: does the system really decide, or does it simply assist a human who makes the call? Finally, document that analysis in writing, even when you conclude that the system is not high-risk. It is precisely that record that will protect you.
Note that the most dangerous practices do not fall under high-risk but under an outright ban, a regime we cover in our article on the prohibited AI practices of Article 5.
Is my company chatbot a high-risk system? No, in almost every case. An internal chatbot or a drafting assistant falls under transparency obligations, not the high-risk regime, unless it makes decisions in an Annex III area such as recruitment.
Is a recruitment-support tool automatically high-risk? It falls in the "employment" area of Annex III, so under the second route. But Article 6(3) can exclude it if it stays limited to a preparatory task without influencing the final decision. It all depends on its actual role, to be documented case by case.
What is the difference between a provider and a deployer? The provider designs or places the system on the market and carries the heaviest obligations (Articles 9 to 15, CE marking). The deployer uses it and carries the Article 26 obligations, centred on human oversight and proper use.
Are associations in scope? Yes. The AI Act provides no exemption based on non-profit status. A social economy organisation using an Annex III system has the same obligations as a company.
What is the penalty for non-compliance? Breaches of the obligations on high-risk systems expose you to fines of up to 15 million euros or 3 percent of total worldwide annual turnover, whichever is higher.
Does the move to 2 December 2027 mean we can wait? No. Bringing a high-risk system into compliance (documentation, assessment, oversight) takes months. The window until the end of 2027 is there to prepare, not to postpone the analysis.
At GrowthPerf, we help SMEs and associations in the Paris region answer one question before any other: do your AI tools fall under high-risk or not? Our approach is concrete: an inventory of your systems, a documented application of the Article 6 filter, and training for your teams so they keep control over sensitive decisions. The overall framework is set out in our AI Act compliance guide.
Want to know whether one of your tools tips into high-risk? Book a free 30-minute audit: we run your AI uses through Article 6 and you leave with a written analysis and a clear action list.
| Justice and democratic processes | Judicial decision support, influence on elections | None outside courts |