Let’s skip the legal preamble.
You use software that makes decisions about people. Or helps you make those decisions. Hiring tools, credit checks, customer scoring, content moderation — that’s most modern business software.
The EU AI Act has a name for AI that touches these areas: high-risk.
High-risk does not mean banned. It means the rules are strict and the paperwork is real. Here is what falls into that category — and what it means if your business uses any of it.
What Makes AI “High-Risk”?
The EU AI Act defines high-risk AI in two places. Annex I covers AI built into products already regulated by EU safety law (medical devices, vehicles, machinery). Most businesses don’t encounter this.
Annex III is where most companies need to pay attention. It covers eight areas where AI is used to make or assist decisions about people.
The Eight High-Risk Areas in Annex III
1. Biometric Identification and Categorisation
AI that identifies individuals from their physical or behavioural characteristics, or sorts people into categories based on biometric data.
This covers more than facial recognition. Gait analysis, voice identification, and behavioural profiling all fall here if they’re used to identify or classify individuals.
Real-world example: An access control system that uses face or fingerprint matching is operating in this category.
2. Critical Infrastructure
AI used to manage or operate critical infrastructure — electricity grids, water systems, transport networks, digital infrastructure.
Who this affects: Operators of critical infrastructure and their technology suppliers.
3. Education and Vocational Training
AI that determines access to education, evaluates students, or monitors exam behaviour.
An AI that scores applications to universities, flags students for cheating in online exams, or assesses student performance is high-risk.
Real-world example: Automated essay scoring or online proctoring tools used in schools and universities.
4. Employment and Workers Management
This is the one most private businesses encounter.
Any AI system used to:
- Screen CVs and filter job applicants
- Make or assist hiring decisions
- Evaluate employee performance
- Assign tasks or monitor productivity
If you use AI in your recruitment or HR process — even a third-party tool — this category applies to you.
Real-world example: ATS (Applicant Tracking Systems) that rank candidates, or software that scores employee performance automatically.
5. Access to Essential Private Services and Public Benefits
AI that determines whether someone gets a loan, insurance, credit, or public benefits.
Credit scoring AI, insurance risk models, and social welfare eligibility systems are all covered here.
Real-world example: A bank’s AI model that decides whether to approve a mortgage application.
6. Law Enforcement
AI used by police and justice authorities to assess crime risk, profile individuals, or analyse evidence.
This category is primarily relevant to public authorities rather than private businesses.
7. Migration, Asylum and Border Control
AI used in visa processing, border checks, or asylum decisions.
Again, primarily public-sector territory.
8. Administration of Justice and Democratic Processes
AI that assists courts in applying law or that influences elections.
So What Are the Obligations?
If your AI system falls into a high-risk category, the obligations are significant:
Risk management system — ongoing documentation of risks and mitigation measures throughout the AI system’s lifecycle.
Technical documentation — detailed records of how the system works, what data it was trained on, and how it performs.
Data governance — training data must be relevant, representative, and free of bias where possible.
Transparency to users — the system must provide enough information for human operators to understand and oversee it.
Human oversight — high-risk AI must be designed so a human can monitor, intervene, and override it.
Accuracy and robustness — the system must perform consistently and be resistant to errors or adversarial interference.
Conformity assessment — before going to market, providers must demonstrate the system meets the requirements. For some categories, this requires a third-party audit.
Registration — high-risk AI systems must be registered in the EU database before deployment.
Providers vs Deployers — Who Is Responsible?
This is where many businesses get surprised.
Providers (companies that build or place AI on the market) carry most of the compliance obligations — technical documentation, conformity assessment, registration.
Deployers (businesses that use AI built by someone else) have lighter but still real obligations — they must use the system as intended, implement human oversight, monitor performance, and inform affected individuals when required.
If your HR software vendor uses an AI system that turns out to be high-risk, you — as the deployer — share responsibility for how it’s used. Your vendor contracts should address this now.
Timeline
High-risk AI obligations for Annex III systems apply from 2 August 2026.
That is six weeks away as of this post. If your business uses AI in hiring, credit, education, or customer scoring, the assessment cannot wait.
The Practical Checklist
Ask these questions about every AI tool your business uses that makes or assists decisions about people:
- Does it use biometric data?
- Does it affect hiring, performance management, or employee monitoring?
- Does it affect access to credit, insurance, or services?
- Does it affect education or training access?
If yes to any of these — you are likely in high-risk territory. The next step is a gap assessment against the Annex III obligations list.
Next in this series: what the technical documentation and conformity assessment actually require — and what to ask your AI vendors before August 2026.

Leave a comment