"High-risk" is the most misused term in this Regulation. It does not mean an AI system that could cause harm. It means a system that meets the classification rules in Article 6, and those rules are narrower and more mechanical than the phrase suggests.
Route one: embedded in a regulated product
Article 6(1) makes a system high-risk where both of two conditions are met:
(a) the AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I; (b) the product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service of that product pursuant to the Union harmonisation legislation listed in Annex I.
Regulation (EU) 2024/1689, Article 6(1)
This is the machinery, medical device and product safety route. An internal document assistant is not in it.
Route two: the Annex III use cases
Article 6(2) is short: “In addition to the high-risk AI systems referred to in paragraph 1, AI systems referred to in Annex III shall be considered to be high-risk.” Annex III lists use cases, in areas such as employment, education, essential services, law enforcement and the administration of justice.
The classification therefore follows the intended purpose of the system, not the brand of the model and not the size of the company.
The route back out
Article 6(3) is the paragraph most summaries omit. An Annex III system “shall not be considered to be high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making”, where any of four conditions is met:
- the AI system is intended to perform a narrow procedural task
- the AI system is intended to improve the result of a previously completed human activity
- the AI system is intended to detect decision-making patterns or deviations from prior decision-making patterns and is not meant to replace or influence the previously completed human assessment, without proper human review
- the AI system is intended to perform a preparatory task to an assessment relevant for the purposes of the use cases listed in Annex III
That is why the same underlying model can sit in two different categories in two different applications. Summarising a CV for a human reviewer and ranking candidates for rejection are not the same system in the eyes of the Regulation, even if the weights are identical.
The dates, as they stand
The European Commission records that “the rules for high-risk use cases in certain sensitive areas (Annex III) have been extended to 2 December 2027”, and that “the rules for high-risk AI systems embedded into regulated products (Annex I) have an extended transition period until 2 August 2028”. The extensions come from the AI Omnibus, in force since 27 July 2026, while the Act itself “became applicable on 2 August 2026”.
Do not classify AI by brand, and do not classify it by whether it is cloud or on-premise. Classify it by what the system is used to do, and to whom.
Why private deployment does not change the answer
Moving a model onto an internal server does not alter its intended purpose. If the application falls inside Annex III, it falls inside Annex III on your own hardware, with the same documentation, human oversight and risk controls required.
What changes is how easy those obligations are to evidence. Model version, processing location, access path and update history are facts about your own site rather than answers you have to request from a supplier.
For any deployment that looks close to Annex III, the classification should be reviewed against the current text and applicable guidance, not against a generic checklist, including this one.
With Bastion
What Bastion changes
Bastion is a private AI system delivered as one sealed appliance that runs inside your building. One monthly fee covers the hardware, the model, the hardened operating system and support, and nothing your team types leaves the building.
Bastion is infrastructure. It does not decide whether a use case is high-risk and cannot remove a classification.
Where it helps is the record: which model, which version, where it ran, who reached it and when it was updated, all answerable from the customer's own site.
Questions this article answers
- What makes an AI system high-risk under the EU AI Act?
- Article 6 gives two routes. Either the system is a safety component of, or is itself, a product covered by the Annex I harmonisation legislation and subject to third-party conformity assessment, or it falls within one of the Annex III use cases.
- Can an Annex III system avoid the high-risk classification?
- Article 6(3) says yes, where it does not pose a significant risk of harm and meets one of four conditions, such as performing a narrow procedural task or improving the result of a previously completed human activity.
- When do the high-risk rules start to apply?
- The Commission's current timeline gives 2 December 2027 for the Annex III use cases and 2 August 2028 for high-risk AI embedded in regulated products. Both were extended by the AI Omnibus, in force since 27 July 2026.
On the record
- 1
EUR-Lex
Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligenceread 2026-09-22
- 2
Read next
- The EU AI Act in 2026: which dates have passed and which have movedA date-by-date reading of what applies to an ordinary company today, what was extended by the AI Omnibus, and why moving a model onto your own server changes none of the classification.Read the article
- Private AI in healthcare: start with the administration, not the diagnosisWhich healthcare workloads are realistic first, what Article 9 and the AI Act's classification rules actually say, and why local processing is an architectural advantage rather than a compliance answer.Read the article