A high-risk AI system is one that the AI Act, Regulation (EU) 2024/1689, subjects to its most demanding regime. It does so because of the system’s impact on people’s health, safety or fundamental rights. There are two routes to that status. The first is being a safety component of a regulated product in Annex I that requires third-party assessment. The second is being used in one of the eight areas of Annex III, such as employment, credit or education. Following the Digital Omnibus on AI, the obligations apply from 2 December 2027 for Annex III. For Annex I, they apply from 2 August 2028. An Annex III system may fall outside if it does not materially influence the decision, but never if it profiles people. Classifying correctly is the first compliance decision, because documentation, conformity assessment and registration all depend on it.
If you need an AI lawyer in Spain for your business, request a free initial assessment.
Article 6 of Regulation (EU) 2024/1689 sets two independent classification rules. Meeting either one is enough for a system to be high-risk.
| Route | What it requires | Applies from |
|---|---|---|
| Article 6(1), Annex I products | That the system is a safety component of a regulated product, or is the product itself, and that the product requires a third-party conformity assessment | 2 August 2028 |
| Article 6(2), Annex III uses | That the system is intended for one of the uses listed in Annex III | 2 December 2027 |
Annex I lists Union product legislation, such as machinery, toys, medical devices, lifts or radio equipment. The Digital Omnibus on AI, Regulation (EU) 2026/1744, has narrowed this route with three new paragraphs in Article 6.
Annex III is the route that affects most software companies. It does not list technologies, but specific uses within eight areas. What counts is the system’s intended purpose, not the technique it uses.
| Area | Uses included, among others |
|---|---|
| 1. Biometrics | Remote biometric identification, categorisation by sensitive attributes and emotion recognition |
| 2. Critical infrastructure | Safety components in digital infrastructure, road traffic or the supply of water, gas or electricity |
| 3. Education | Admission, assessment of learning outcomes and proctoring of exams |
| 4. Employment | Recruitment, decisions on terms, promotion or termination, task allocation and performance evaluation |
| 5. Essential services | Public benefits, creditworthiness and credit scoring, pricing of life and health insurance, emergency triage |
| 6. Law enforcement | Police uses such as evaluating evidence or the risk of reoffending |
| 7. Migration and border control | Risk assessment and examination of asylum or visa applications |
| 8. Justice and democratic processes | Support for judicial decisions and influencing elections |
Area 5 expressly excludes systems used to detect financial fraud. And area 4 covers both access to employment and the day-to-day management of the employment relationship. In Spain, that management carries its own duty since October 2026, algorithmic transparency for workers.
An Annex III system is not high-risk if it does not pose a significant risk to health, safety or fundamental rights. That is the case, for example, when it does not materially influence the decision. Article 6(3) sets out four situations, and meeting one is enough.
The exception has an absolute limit. An Annex III system that profiles natural persons is always high-risk, whether or not it meets one of the four situations.
A provider that considers its system is not high-risk must document that assessment before placing it on the market. In addition, Article 49(2) requires it to register the system in the EU database and to hand over the assessment to the authorities on request. The exception does not avoid paperwork, it avoids the high-risk obligations.
On 19 May 2026 the Commission published draft guidelines on classification, with examples of systems that are and are not high-risk. It put them out to consultation until 23 July.
The obligations are split between whoever develops the system and whoever uses it. The provider carries almost all of them, but the company that uses it, the deployer, has duties of its own.
| Provider | Deployer |
|---|---|
| Risk management system and governance of training data | Use the system in accordance with the provider’s instructions |
| Technical documentation, automatic logs and instructions for use | Assign human oversight to people with the necessary competence, training and authority |
| Design for human oversight, accuracy, robustness and cybersecurity | Monitor operation, keep logs for at least six months and report serious incidents |
| Quality management system, conformity assessment, EU declaration and CE marking | Inform workers and the people affected by decisions |
| Registration in the EU database and post-market monitoring | Fundamental rights impact assessment if it is a public body, provides public services, assesses creditworthiness or prices insurance |
The allocation is not fixed. Under Article 25, a company becomes the provider if it puts its name or trademark on a high-risk system, makes a substantial modification to it or changes its intended purpose. It then takes on all the provider’s obligations.
The Omnibus rewrote Article 111(2). High-risk systems placed on the market before the date of application are only subject to the regulation if their design later undergoes significant changes. The exception does not apply to systems used by public authorities, which must comply by 2 August 2030 at the latest.
This case is fictitious. Credia Finanzas, S.L. is a Madrid startup that grants online microloans. Its in-house model scores each applicant’s creditworthiness from their bank transactions and decides approval automatically. It also uses a third-party system that detects fraudulent transactions.
The scoring model falls under point 5(b) of Annex III and also profiles people, so it is high-risk with no possibility of exception. Credia is its provider and will have to comply with the full regime from 2 December 2027. As it also uses the model to assess creditworthiness, it must carry out the fundamental rights impact assessment in Article 27. The fraud detector, on the other hand, is outside, because Annex III expressly excludes systems used to detect financial fraud.
If Credia placed the model on the market before December 2027 and did not change it, it would not have to adapt it. But a credit model is retrained frequently, and any significant change to its design would bring it within the regulation. The fines for breaching these obligations are explained in our analysis of AI Act penalties. The general framework is in our AI Act compliance guide for businesses.
Two things have to be checked. If it is a safety component of an Annex I product that requires third-party assessment, it is high-risk under Article 6(1). If it is intended for an Annex III use, such as recruitment or credit scoring, it is high-risk under Article 6(2). The exception is that it fits one of the situations in Article 6(3) and does not profile people.
Following the Digital Omnibus on AI, from 2 December 2027 for Annex III and from 2 August 2028 for Annex I. Systems placed on the market earlier are only caught if their design later changes significantly. Those used by public authorities must comply before 2 August 2030.
No. Article 6(3) provides that an Annex III system that profiles natural persons is always considered high-risk, even if it only performs a preparatory or narrow task. The exception is only available to systems that do not profile and do not materially influence the decision.
Yes. As a deployer you must use it in accordance with its instructions, assign competent human oversight, monitor its operation, keep the logs for at least six months and inform workers and affected people. If you put your trademark on it or make a substantial modification, you become the provider.
Yes, if it is in Annex III. A provider relying on the Article 6(3) exception must document its assessment before placing the system on the market. It must also register the system in the EU database, under Article 49(2). The authorities can ask for that documentation at any time.
Classification decides almost all of the cost of complying with the AI Act. A system wrongly classified as limited-risk reaches December 2027 with no documentation and no conformity assessment. And one classified too high carries obligations that do not apply to it. The time until the date of application is useful for mapping systems, deciding who is provider and who is deployer, and documenting exceptions. At Innovatech we classify your systems and prepare the documentation as part of our AI legal advisory service. Write to us and we will give you a free initial assessment.
Marta Suárez-Mansilla is Managing Partner of Innovatech Legal and a Spanish lawyer (abogada), Madrid Bar (ICAM), working in technology law. She completed Harvard Law School's Copyright course and BerkeleyX's Blockchain programme, and has advised technology companies for more than eight years.
