A financial company spent three years building an AI credit-scoring system.
It was fast, accurate, and profitable.
Then August 2, 2026 arrived.
A regulator asked one question: “Show me your risk management documentation.”
The company had none. The AI had been making decisions for thousands of customers — but no one had logged how it worked, who it affected, or what happened when it was wrong.
That is a high-risk AI problem. And it is coming for more industries than most people realise.
—
## What Makes an AI System “High-Risk”?
High-risk does not mean dangerous in the traditional sense. Under the EU AI Act, it means the system operates in an area where mistakes have serious consequences for real people.
Annex III of the law lists eight categories. If your AI falls into one of them, your obligations are significantly heavier than for a standard tool.
The eight categories include:
– **Biometric identification** — facial recognition, emotion recognition at work
– **Critical infrastructure** — AI managing energy grids, water, transport
– **Education** — AI that assesses students, grants access, or influences learning paths
– **Employment and HR** — AI that screens CVs, ranks candidates, monitors workers
– **Essential services** — creditworthiness assessment, loan decisions, insurance pricing
– **Law enforcement** — AI used to predict crime, assess risk in criminal proceedings
– **Migration and border control** — document verification, asylum case assessment
– **Justice and democracy** — AI assisting in legal judgments, elections
If you recognise your product in that list, you are in scope.
—
## The Seven Obligations — In Plain Language
The EU AI Act does not just say “be careful.” It sets out specific requirements that providers of high-risk AI systems must meet before deploying and throughout operation. Here is what each one means in practice.
### 1. Risk Management System (Article 9)
You must establish a risk management process that runs across the full lifecycle of the AI system — not just at launch.
What this means: Document known and foreseeable risks. Test the system under real conditions. Update the documentation when the system changes.
A credit scoring model trained in 2022 behaves differently in 2026. That gap is a risk. You need to show you have managed it.
### 2. Data and Data Governance (Article 10)
Training data must be relevant, representative, free from errors, and complete enough to minimise bias.
What this means: You cannot train a hiring AI on historical data that reflects past discrimination and call it compliant. You need to audit your datasets — who is over-represented, who is under-represented, and what effect that has on outputs.
### 3. Technical Documentation (Article 11)
You must produce and maintain technical documentation before the system goes to market. This documentation must allow any competent authority to assess compliance.
What this means: A README file is not documentation. You need a formal record of what the system does, how it was trained, what it cannot do, and how it has been tested.
### 4. Record-Keeping and Logging (Article 12)
High-risk AI systems must automatically log events throughout their operation — to the extent technically possible.
What this means: Every decision the AI makes should leave a trace. Not just the outcome, but the inputs used to reach it. If your credit AI rejects an application, the log should show what data it used and when.
This is not optional. It is the audit trail regulators will ask for first.
### 5. Transparency for Users (Article 13)
The system must be transparent toward the operator — and operators must be transparent toward the individuals affected by decisions.
What this means: If your AI denied someone a loan, that person must be able to understand why — in plain language. Not “the model assigned a score of 0.34.” Something a human can read and challenge.
### 6. Human Oversight (Article 14)
High-risk AI systems must be designed so that natural persons can effectively oversee them.
What this means: A human must be able to intervene, override, or stop the system. And that human must actually understand what they are overriding. A rubber-stamp approval is not human oversight.
Ask yourself honestly: if your AI flagged something wrong, could your team catch it? If the answer is “probably not,” that is a compliance gap.
### 7. Accuracy, Robustness, and Cybersecurity (Article 15)
The system must perform consistently, resist manipulation, and be protected against adversarial attacks.
What this means: You must test for edge cases, adversarial inputs, and failure modes. An AI that works perfectly on clean data but breaks on unusual inputs is not robust. And an AI that can be manipulated by bad data — intentionally or not — is a security risk.
—
## Who Does This Apply To?
The obligations above apply primarily to **providers** — companies that develop and place high-risk AI systems on the market.
But **operators** — companies that deploy and use these systems — also carry responsibilities. They must use the system as instructed, implement human oversight, monitor performance, and report serious incidents.
If you built the AI: provider obligations.
If you bought and deployed the AI: operator obligations.
If you modified the AI significantly: you may become a provider.
That last point catches many companies off guard. Taking a third-party model and fine-tuning it for your specific use case can make you a provider under the law — even if you did not build the original system.
—
## What Does This Look Like in Practice?
**Example — AI in HR:**
A company uses an AI tool to screen incoming CVs and rank candidates before a human recruiter sees them. This falls under Annex III (employment).
The company must: document how the tool works, audit for bias in its outputs, log every ranking decision, and ensure a human makes the final hiring call — not the AI.
If the tool is supplied by a vendor, the vendor must provide the technical documentation. If the company modified it, the company may be considered the provider.
**Example — AI in credit:**
A bank uses AI to assess creditworthiness for personal loans. Under Annex III, this is high-risk AI.
Before 2. August 2026, the bank must have: a risk management system in place, full technical documentation, decision logs, and a process for giving rejected applicants a clear explanation they can act on.
The bank cannot simply say “the AI decided.” That explanation does not exist in a compliant system.
—
## What Should You Do Now?
If you operate or provide high-risk AI, here are five steps that matter before 2. August 2026.
**Step 1 — Classify your AI systems**
Go through Annex III and be honest about where your products land. If you are not sure, assume high-risk and document accordingly. Regulators do not reward ambiguity.
**Step 2 — Audit your documentation**
Do you have technical documentation for each system? If not, start now. This takes weeks, not days.
**Step 3 — Check your logging**
Are your AI systems logging their inputs and outputs? If the answer is “we can reconstruct it if needed,” that is not good enough. Logging needs to happen automatically and continuously.
**Step 4 — Map your human oversight process**
Who in your organisation is responsible for reviewing and overriding AI decisions? Is that person equipped to actually do it — or are they approving outputs they do not understand?
**Step 5 — Talk to your AI vendors**
If you use third-party AI tools, ask them directly: are you compliant with EU AI Act Article 11 technical documentation requirements? Get the answer in writing.
—
## The Real Question
Here is what most organisations are avoiding:
Is the AI system we are running today — right now — one that we could fully explain, justify, and document if someone asked tomorrow?
If the honest answer is no, that is not a technology problem. It is a governance problem.
And governance problems have a deadline: **2. August 2026**.
—
## One Practical Resource
If you are working through Annex III compliance and need a starting framework, the Annex III compliance checklist covers the seven provider obligations with specific documentation questions for each one.
It is built for HR managers, compliance leads, and operations teams who are not lawyers — but need to understand what to prepare.
→ [Link in first comment / Gumroad]
—
*This article references Articles 9–15 of Regulation (EU) 2024/1689 (EU AI Act). For the full legal text, visit artificialintelligenceact.eu.*
—
## POST METADATA (for Gutenberg)
– **Title:** High-Risk AI: What the EU AI Act Actually Requires from Providers
– **Meta description:** If your AI system falls under Annex III, you have seven specific obligations under the EU AI Act. Here is what each one means and what to do before 2. August 2026.
– **Category:** EU AI Act
– **Tags:** high-risk AI, Annex III, EU AI Act compliance, AI providers, Article 9, Article 14
– **Featured image:** POST07_featured_1200x630.png (to create)
– **Internal links:** POST06 (Annex III overview), POST02 (Article 4 AI literacy)
– **External link:** artificialintelligenceact.eu/article/9/ (Article 9 reference)
– **CTA mid-post:** Annex III checklist (Gumroad)
– **CTA end of post:** AI Literacy Kit €49 or Checklist €29

Leave a comment