EU AI Act High-Risk AI System

A high-risk AI system under the EU AI Act is an AI system meeting the criteria in Article 6 and Annex III, subject to conformity assessment, risk management, technical documentation, transparency, human oversight, and post-market monitoring obligations.

How High-Risk Systems Are Classified

The EU AI Act defines high-risk AI in two ways. First, AI systems that are safety components of products already regulated under specific EU harmonization legislation (medical devices, machinery, toys) are high-risk. Second, AI systems used in specific areas listed in Annex III are high-risk.

Annex III covers biometric identification, critical infrastructure management, education and vocational training, employment and worker management, access to essential services (credit, public benefits), law enforcement, migration and border control, and administration of justice and democratic processes.

What Obligations Apply

Providers of high-risk AI systems must implement a risk management system, ensure data quality and governance, provide technical documentation, keep automatic logs, deliver transparency to deployers, enable human oversight, and meet accuracy, robustness, and cybersecurity requirements. Systems must undergo conformity assessment before placement on the market. Deployers have their own set of obligations, including fundamental rights impact assessments in certain cases.

When High-Risk Obligations Apply

Obligations for high-risk AI systems listed in Annex III apply from August 2, 2026. Systems that are safety components of already-regulated products fall under a longer transition period, with obligations applying from August 2, 2027.

How Kovrr Approaches High-Risk AI System Compliance

Kovrr's EU AI Act Automated Compliance capability identifies high-risk AI systems in the enterprise environment, maps them to specific EU AI Act obligations, and produces the technical documentation and evidence required for conformity assessment.

Related Terms

Full AI Visibility. Full Control. One Connected Platform.

Enterprise AI is expanding faster than most governance programs can track. Kovrr connects every AI signal across browser, endpoint, network, identity, and vendor systems into a single platform so security, governance, and risk teams work from the same evidence.