All posts23 June 2026

Is your AI system high-risk? Working through Annex III without a lawyer

Most SME software is not high-risk. Annex III lists eight use cases, and if yours is not one of them you can settle the question in an afternoon.

W. Akram10 min readai · regulation

General information, not legal advice. Regulatory duties need your own competent advice.

Probably not. High-risk under the EU AI Act means one of eight use cases listed in Annex III, or an AI system acting as a safety component in a product that already needs third-party safety certification. Ordinary business software rarely lands in either. Checking takes an afternoon, and the output is a document you keep.

What high-risk means, and what it does not

An AI system is high-risk when it is used for one of the purposes listed in Annex III, or when it is a safety component of a product that already requires third-party safety certification. Nothing about the model decides this. Not the size of it, and not whether it makes things up. The Act classifies by what the system is used for (Article 6).

That one fact removes most of the fear in the room. A support assistant built on a frontier model is not high-risk because it is a large language model. A small logistic regression scoring job applicants is high-risk, because scoring job applicants is on the list.

Whichever answer you reach, it lands differently depending on whether you built the system or bought it, which is the provider or deployer question from last week. Providers of high-risk systems carry the conformity assessment and the CE marking. Deployers carry oversight, logging and the duty to tell the people affected.

The eight Annex III categories in plain English

Annex III areaWhat it coversOrdinary business software that lands here
1. BiometricsRemote biometric identification, categorising people by sensitive attributes, emotion recognitionFace recognition on a door; software scoring the mood of a call
2. Critical infrastructureSafety components in digital infrastructure, road traffic, or water, gas, heating and electricity supplyNothing, unless you supply a utility or a traffic operator
3. Education and vocational trainingAdmissions, marking, deciding what level of education someone can access, exam proctoringA learning platform that grades assessments or flags cheating in a test
4. Employment and worker managementTargeted job ads, filtering applications, scoring candidates, promotion and termination decisions, task allocation, performance monitoringApplicant tracking with ranking, interview scoring, shift allocation, productivity monitoring
5. Essential private and public servicesEligibility for public benefits, creditworthiness and credit scoring, risk pricing in life and health insurance, emergency call triageLending decisions, insurance pricing, scoring a claim for public support
6. Law enforcementVictim risk, reliability of evidence, risk of reoffending, profiling in investigationsNothing, unless you sell to police forces
7. Migration, asylum and border controlVisa and asylum applications, risk assessment of arrivals, identificationNothing, unless you build for an immigration or border authority
8. Justice and democratic processesHelping a court research and apply the law; influencing elections or voting behaviourLegal research tools that apply law to facts; campaign tools aimed at voters

Full text at Annex III, and the scoping words matter more than the headings: points 6 and 7 cover systems used by or on behalf of public authorities, so a private company is usually outside them, and the credit scoring entry in point 5 carves out fraud detection.

Six of these eight will never come near a normal SME. The two that do are employment, which catches almost everyone eventually, and essential services, if you lend money or price insurance. One warning on row 1: some biometric and emotion-inference uses are banned outright under Article 5 rather than merely restricted, and that ban has applied since February 2025.

Employment is the category that catches SMEs

Annex III point 4 is wide. It covers recruitment and selection, including placing targeted job advertisements, filtering applications and evaluating candidates. It also covers decisions about the terms of the working relationship, promotion, termination, allocating tasks on the basis of behaviour or personal characteristics, and monitoring or evaluating performance.

Read that against the software a 60-person company already owns. Applicant tracking with a relevance score is in scope, so is an interview tool that ranks recorded answers, a rota tool that allocates shifts by past behaviour, and a productivity dashboard that scores individuals.

The saving grace is your role. If you bought the tool, you are the deployer and the vendor is the provider (Article 26). Your side is operational: use it as the instructions say, keep a competent human in the loop, keep the logs, and tell the workers affected. The engineering sits with the vendor, which makes this a procurement question before it is a compliance one. The sentence worth adding to your next renewal is: will this system be conformity assessed and CE marked before 2 December 2027, and will you say so in writing?

UK readers have a nearer deadline anyway. The Data (Use and Access) Act reforms came into force on 5 February 2026, replacing UK GDPR Article 22 with Articles 22A to 22D. Significant automated decisions are now generally prohibited only where they rest wholly or partly on special category data. Everywhere else explicit consent has gone, but notice that the decision was automated, a route to contest it and human review on request all remain.

The exemption in Article 6(3), and its limits

Being on the Annex III list is not the end of the argument. A system in one of those areas is not high-risk if it does not pose a significant risk of harm to health, safety or fundamental rights, including because it does not materially influence the outcome of decision making, and at least one of these is true:

  • it performs a narrow procedural task
  • it improves the result of a previously completed human activity
  • it detects decision-making patterns or deviations from earlier patterns, and is not meant to replace or influence the human assessment without proper review
  • it performs a preparatory task for an assessment relevant to one of the Annex III uses

Two things stop this becoming a loophole. A system that profiles individuals is always high-risk, whatever else is true of it. And a provider who concludes a system is not high-risk has to document that assessment before placing the system on the market or putting it into service, and register it.

The exemption is narrower than it reads. A parser pulling dates and job titles out of a CV so a human can read them faster is a preparatory task. A model that ranks the same CVs is influencing the decision, and a filter that removes people before anyone sees them is not a narrow procedural task by any honest reading. The trap is writing the assessment against the feature you meant to build rather than the one that shipped.

What the Digital Omnibus moved, and what it did not

ObligationApplies fromMoved?
AI literacy (Article 4)2 February 2025No
Prohibited practices (Article 5)2 February 2025No
General application, including Article 50 transparency2 August 2026No
Member state AI regulatory sandboxes2 August 2027Yes, delayed by a year
Annex III high-risk obligations2 December 2027Yes, from 2 August 2026
High-risk AI inside regulated products (Annex I)2 August 2028Yes

Dates from the European Commission's AI Act page; the moves confirmed by Gibson Dunn, 27 May 2026.

The Omnibus bought high-risk providers and deployers about sixteen extra months. It bought nobody anything on transparency, which still starts on 2 August 2026. Firms still planning around an August 2026 high-risk deadline are over-preparing, and firms that heard the AI Act had been delayed and stopped are about to miss the deadline that applies to almost everybody.

What "not high-risk" still leaves you with

Reaching the answer "not high-risk" removes the conformity assessment, the CE marking, the registration and the technical file. It does not empty the list.

Article 50 transparency starts on 2 August 2026 whatever your risk tier (transparency guide, 14 May 2026). Providers of systems that talk to people have to make sure users know they are dealing with a machine, and providers of generative systems have to mark output in a machine-readable format. Deployers have to disclose deepfakes and label AI-generated text published to inform the public.

Article 4 has bound every provider and deployer since 2 February 2025, at every tier. It asks you to take measures so that staff operating AI on your behalf have a sufficient level of AI literacy. There is no measurement standard and no fine attached directly, which is why it gets ignored. What does attach is civil liability if undertrained staff cause harm (Latham and Watkins). An hour of training and a register of who attended is a proportionate answer.

The afternoon's work, in order

  1. List every AI system you use or ship. Include the ones bought on somebody's card.
  2. Write one sentence per system: what it is used for, and who is affected by the output.
  3. Read each sentence against the eight Annex III areas. Only the purpose counts.
  4. If nothing matches, write down the conclusion, the date and who reached it.
  5. If something matches, settle your role, then test it against Article 6(3) and write that down too.
  6. Redo the sentence whenever the system changes what it decides.

The classification takes twenty minutes. Step one takes the rest of the afternoon, because in a 40-person company one or two systems will have been bought on a personal card by somebody who never thought of them as software. The free Compliance Checker on the Commission's AI Act Service Desk walks the same questions.

A lawyer is not what this needs. It needs somebody willing to write six sentences down and put their name at the bottom, and in every company we have watched do it the argument was about who that person should be rather than about what the sentences said.

Questions we get asked

Is a customer service chatbot high-risk?

No. Annex III lists purposes, and answering questions about your own product is not one of them. The bot is still caught by Article 50 transparency from 2 August 2026, which puts the duty to make the machine obvious on whoever provides the system rather than on the company running it.

Does using an AI CV screener make our system high-risk?

Recruitment and selection sit squarely in Annex III point 4, so yes. You are almost certainly the deployer rather than the provider, so your obligations are oversight, logging, monitoring and informing the people affected, and they begin on 2 December 2027 rather than this year.

We only use AI internally. Does Annex III still apply?

Yes. Classification follows the purpose, not the audience. Putting a system into service for your own use inside the EU counts as putting it into service, so an internal tool that scores staff performance is high-risk even though no customer will ever see it.

What if we think the Article 6(3) exemption covers us?

Document it before you ship. A provider who concludes an Annex III system is not high-risk has to record that assessment and register the system, and produce the reasoning if an authority asks. An exemption nobody wrote down is indistinguishable from never having checked.

Let's talk

Ready to build the thing?

Book a free 30-minute call. We'll dig into your idea, your stack and your timeline, and give you an honest read on what it will take to build and launch. You'll leave with a clearer plan whether or not you hire us.

Free 30-min call. No pitch.