Guides
7 min read
Is Your System 'High-Risk'? A Classification Guide
Confusion abounds regarding what constitutes a 'High-Risk' AI system under Annex III. We clarify the categories and the critical 'filter' exception.
By Dr. Marcus Weber
·
Published
Understanding Annex III
The core of the AI Act's regulatory burden falls on "High-Risk" AI systems. But determining if your system falls into this bucket isn't always straightforward.
Key High-Risk Areas
- Biometrics: Remote biometric identification, emotion recognition.
- Critical Infrastructure: Safety components in road traffic, water, gas, heating, and electricity.
- Education & Vocational Training: Systems determining access to education or evaluating students.
- Employment: Recruitment filtering, task allocation, and performance monitoring.
- Essential Private & Public Services: Credit scoring, risk assessment for insurance, dispatching emergency services.
- Law Enforcement & Migration: Polygraphs, risk assessments, border control tools.
The "Filter" Exception (Article 6(2a))
Even if your system falls under Annex III, it might not be high-risk if it does not pose a significant risk of harm to health, safety, or fundamental rights. Specifically, if the AI performs a narrow procedural task, improves a previous human activity, or detects decision-making patterns without replacing the human assessment.
Warning: You must document this assessment thoroughly. If you claim the exception, you better have the receipts.