


Updated July 2026
Could the way your organisation uses an AI system be classed as high-risk under the EU AI ActThe EU Artificial Intelligence Act was approved by the EU Council on 21 March 2024. A world-first comprehensive AI law, intended to harmonise rules for the development, deployment, and use of artificial intelligence systems across the EU.?
High-risk AI systems are permitted, but they are subject to the AI Act’s strictest requirements because of their potential impact on people’s safety, opportunities, and fundamental rights.
Whether a system is high-risk depends on what it is designed to do, how it is used, and the decisions or outcomes it may influence. The same AI technology may therefore be low-risk in one context and high-risk in another. The requirements also depend on whether your organisation is acting as a provider, deployer, importer or distributer.
Following the changes introduced by the Digital Omnibus on AI, high-risk requirements will apply from 2 December 2027 for stand-alone systems and 2 August 2028 for systems embedded in certain regulated products.
The EU AI Act follows a risk-based approach, with stricter requirements applying where AI is used for activities that could significantly affect people’s health, safety or fundamental rights.
There are four broad categories:
GPAI’s are covered by a separate set of requirements. These are designed to perform a wide range of tasks and can be used across different systems and applications. Examples include OpenAI’s GPT-4, Google’s Gemini, Anthropic’s Claude and Meta’s Llama. AI systems built using these models must be assessed according to their intended purpose and use.
Eight prohibited AI practices have applied since 2 February 2025. An additional ninth prohibition, introduced through the Digital Omnibus on AI, applies from 2 December 2026.
The table below details the AI practices that fall under the prohibited category. These are the techniques and approaches considered to pose unacceptable risk to people’s safety, rights or freedoms.

The AI Act identifies two main types of high-risk AI systems:
Not every AI system used within a regulated sector or Annex III area is automatically high-risk. Classification depends on the specific use of the system, the decisions it affects and whether it meets the conditions set out in the AI Act.
An AI system is high-risk under this route when both of the following conditions apply:
A safety component is an AI system that performs a safety function, or whose failure or malfunction could put people or property at risk.
This can include AI incorporated into certain medical devices, lifts, toys and other regulated products. An AI system is not automatically high-risk simply because it forms part of one of these products. Both conditions must be met.
Annex III identifies specific uses of AI across eight areas where systems may significantly affect people’s health, safety or fundamental rights. Not every AI system used in these areas is high-risk.
If you are unsure how a system should be classified, an AI OfficerAn individual responsible for overseeing the ethical, legal, and effective use of Artificial Intelligence (AI) within an organisation. or other suitably qualified specialist can assess its purpose, use and potential impact against the relevant Annex III criteria.

Some systems used for Annex III activities may fall outside the high-risk classification if they have limited influence on people or decisions.
If your organisation provides the system, you must assess and document any decision that an Annex III system is not high-risk before placing it on the market or putting it into service within the EU. If you use, import or distribute the AI system, you should verify its classification and understand the requirements that apply to your role. Other AI Act obligations may still apply.
The revised deadlines provide more time to prepare, but organisations should start identifying how each AI system is classified and which requirements apply.
Key steps include:
Your responsibilities will vary according to your role, so this should be established for every AI system.
Explore the other blogs in our Compliance with the AI Act series:
______________________________________________________________________________________________________________________________
The DPO Centre’s AI governanceThe framework of policies, processes, and roles that ensure Artificial Intelligence (AI) is developed and used responsibly, ethically, and in compliance with applicable laws, societal expectations, and corporate values. services can help you understand your obligations, assess AI risks and put appropriate oversight in place. This includes AI Impact Assessments and support from an Outsourced AI Officer.
______________________________________________________________________________________________________________________________
In case you missed it…
______________________________________________________________________________________________________________________________
For more news and insights about data protection and AI governance follow The DPO Centre on LinkedIn
Fill in your details below and we’ll get back to you as soon as possible