What is a high-risk AI system under the EU AI Act? Under the EU AI Act, a high-risk AI system is an AI application that can significantly affect people's health, safety, or fundamental rights and is therefore subject to the strictest rules. Whether a system counts as high-risk depends on its area of use and function; the Annex III list enumerates most of these areas one by one.
This article gives the narrow, practical answer: how the risk classes work, which criteria make a system high-risk, what obligations arise, and how a company serving the EU from Türkiye is affected. It is a specific resource that complements the comprehensive guide covering every dimension of the topic. This content is informational; it is not legal advice and should be applied together with your organization's legal/compliance function.
- High-Risk AI System (EU AI Act)
- Under the EU AI Act, an AI application subject to the strictest obligations because it can significantly affect people's health, safety, or fundamental rights. Whether a system is deemed high-risk depends on its area of use (the Annex III list) and function; risk management, data governance, technical documentation, human oversight, and a conformity assessment are mandatory.
- Also known as: high-risk AI system, high-risk class, EU AI Act high risk, Annex III
The Logic of Risk Classification
The EU AI Act does not treat all AI systems alike; it adopts a risk-based approach. The AI Act risk classes consist of four tiers: unacceptable risk (prohibited), high risk (full compliance), limited risk (transparency), and minimal risk (free). Which tier a system falls into depends on what it does and where it is used; the same technology can be minimal in one context and high-risk in another.
The table below shows the four risk classes together with each class's core obligation:
| Risk class | Example | Core obligation |
|---|---|---|
| Unacceptable risk | Social scoring, manipulative systems | Prohibited |
| High risk | Recruitment, credit scoring, biometrics (Annex III) | Full compliance + conformity assessment |
| Limited risk | Chatbot, generative content | Transparency: the user is informed |
| Minimal risk | Spam filter, in-game AI | No mandatory obligation |
The critical layer of this pyramid is high risk: it is not banned but carries the heaviest obligations. We cover the general framework of the EU AI Act in what is the EU AI Act and the basis of AI in what is AI.
High-Risk AI System Criteria
For an application to count as a high-risk AI system, one of two paths usually applies. First, the system is a safety component of a product covered by EU product-safety law (for example a medical device, machinery, a toy). Second — and more common in practice — the system is used in one of the sensitive areas enumerated in the Annex III list.
The Annex III list covers these areas: biometric identification, critical infrastructure management, education and vocational assessment, recruitment and worker management, access to essential public and private services (e.g. credit scoring), law enforcement, migration and border control, justice and democratic processes. A system operating in these areas can be deemed high-risk whether it decides directly or supports a human decision. For example, a system that screens CVs, scores a credit application, or performs facial recognition are typical high-risk examples.
The Obligation Headings
Once a system falls within the high-risk scope, it must fulfil a set of obligations before market placement and throughout use. The main obligations are:
- Risk management system: continuous risk assessment across the lifecycle.
- Data governance: quality, representativeness, and bias control of training data.
- Technical documentation: records proving how the system works.
- Record-keeping (logging): storing events in a traceable manner.
- Transparency and human oversight: informing users and human supervision.
- Accuracy, robustness, and cybersecurity.
- Conformity assessment: the mandatory conformity assessment done before market placement and evidenced by the CE marking.
These obligations are not one-off but continuous; they are reviewed again as the system is updated. To manage the process at the enterprise level, the AI governance, ISO 42001, and responsible AI frameworks provide guidance. For the explainability of decisions, explainable AI is especially important.
A Company Serving the EU from Türkiye
The most misunderstood aspect of the EU AI Act is its geographic scope. The law binds not only companies established in the EU but also systems whose output is used in the EU. That is, an AI system developed in Türkiye but serving a customer, user, or recruitment process in the EU can fall within scope; just like the extraterritorial effect of the GDPR.
This means a concrete obligation for Turkish companies offering software, services, or HR solutions to Europe. In practice the system's risk class is determined first; if it is high-risk, the above obligations and the conformity assessment are completed. We cover the regulatory picture in Türkiye in Türkiye AI regulation, the data dimension in KVKK and GDPR, and compliant architecture in KVKK-compliant AI.
Common Misinterpretations
- "The law only binds EU companies." Wrong; systems whose output is used in the EU are also in scope.
- "High risk = banned." Wrong; high risk is not banned, it is allowed under obligations. Only the unacceptable-risk class is prohibited.
- "Generative AI is automatically high-risk." Wrong; the class depends on the area of use, not the technology.
- "Comply once and you are done." Wrong; the conformity assessment and risk management are continuous and repeat as the system changes.
Frequently Asked Questions
What is a high-risk AI system?
A high-risk AI system is an AI application subject to the strictest obligations under the EU AI Act because it can significantly affect people's health, safety, or fundamental rights. Systems used in Annex III areas such as recruitment, credit scoring, biometrics, education, and critical infrastructure fall within this scope. The class depends not on the technology but on the area of use.
Is our system within scope, and how do we know?
First look at what the system does and where it is used. If the system is a safety component of a product covered by EU product-safety law, or if it decides or supports a decision in one of the sensitive areas in the Annex III list (e.g. recruitment, credit, biometrics), it is likely high-risk. The definitive determination should be made with your organization's legal and compliance function.
What obligations arise for a high-risk system?
The main obligations are a risk management system, data governance, technical documentation, record-keeping, transparency, human oversight, and accuracy and cybersecurity. In addition, the system must pass a conformity assessment before being placed on the market and, where required, bear the CE marking. These obligations are continuous, not one-off.
What are the AI Act risk classes?
There are four AI Act risk classes: unacceptable risk (prohibited applications), high risk (full compliance obligation), limited risk (transparency obligation, e.g. chatbot disclosure), and minimal risk (no specific obligation). A system's class is determined by its area of use and potential impact; the same technology can fall into different classes in different contexts.
Why must a company in Türkiye comply with the EU AI Act?
Because the law looks not at where the system is developed but at where its output is used. Even if developed in Türkiye, a system serving users or processes in the EU can fall within scope. This resembles the extraterritorial effect of the GDPR and creates direct obligations for Turkish companies serving Europe.
What is the Annex III list?
The Annex III list is the annex enumerating the use areas the EU AI Act deems high-risk. It covers areas such as biometrics, critical infrastructure, education, recruitment and worker management, access to essential services (e.g. credit scoring), law enforcement, migration, and justice. If a system is used in one of these areas, a high-risk assessment is carried out.
In Short and the Next Step
In short, a high-risk AI system is the AI application subject to the strictest obligations of the EU AI Act, affecting people's rights and safety; the class is determined by the Annex III list, and the obligations range from risk management to the conformity assessment. Clarifying early whether your system falls within the high-risk scope is the first step that minimizes both compliance cost and regulatory risk.
To draw up a roadmap tailored to your sector you can review the resource files in the learning center, and to deepen the topic end to end you can read the comprehensive guide. Correct classification is the most practical investment that spares you a late compliance scramble.
Consulting Pathways
Consulting pages closest to this article
For the most logical next step after this article, you can review the most relevant solution, role, and industry landing pages here.
AI Governance, Risk and Security Consulting
A governance framework that makes enterprise AI usage more sustainable across data, access, model behavior and operational risk.
Enterprise RAG Systems Development
Production-grade RAG systems that provide grounded, secure and auditable access to internal knowledge.
Operational AI and Process Automation for COOs
AI-enabled operational systems that reduce repetitive work, accelerate decisions and free teams for higher-value tasks.