Skip to content
All articles
AI regulation and governance

High-risk AI: what the Act actually classifies, and what it does not

"High-risk" is not a description of how worried you are. Article 6 sets out two routes into the category and one route back out of it, and the Annex III rules now apply from 2 December 2027.

By Bastion, Cluj-NapocaPublished 7 min read

"High-risk" is the most misused term in this Regulation. It does not mean an AI system that could cause harm. It means a system that meets the classification rules in Article 6, and those rules are narrower and more mechanical than the phrase suggests.

Route one: embedded in a regulated product

Article 6(1) makes a system high-risk where both of two conditions are met:

(a) the AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I; (b) the product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service of that product pursuant to the Union harmonisation legislation listed in Annex I.

Regulation (EU) 2024/1689, Article 6(1)

This is the machinery, medical device and product safety route. An internal document assistant is not in it.

Route two: the Annex III use cases

Article 6(2) is short: “In addition to the high-risk AI systems referred to in paragraph 1, AI systems referred to in Annex III shall be considered to be high-risk.” Annex III lists use cases, in areas such as employment, education, essential services, law enforcement and the administration of justice.

The classification therefore follows the intended purpose of the system, not the brand of the model and not the size of the company.

The route back out

Article 6(3) is the paragraph most summaries omit. An Annex III system “shall not be considered to be high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making”, where any of four conditions is met:

  • the AI system is intended to perform a narrow procedural task
  • the AI system is intended to improve the result of a previously completed human activity
  • the AI system is intended to detect decision-making patterns or deviations from prior decision-making patterns and is not meant to replace or influence the previously completed human assessment, without proper human review
  • the AI system is intended to perform a preparatory task to an assessment relevant for the purposes of the use cases listed in Annex III

That is why the same underlying model can sit in two different categories in two different applications. Summarising a CV for a human reviewer and ranking candidates for rejection are not the same system in the eyes of the Regulation, even if the weights are identical.

The dates, as they stand

The European Commission records that “the rules for high-risk use cases in certain sensitive areas (Annex III) have been extended to 2 December 2027”, and that “the rules for high-risk AI systems embedded into regulated products (Annex I) have an extended transition period until 2 August 2028”. The extensions come from the AI Omnibus, in force since 27 July 2026, while the Act itself “became applicable on 2 August 2026”.

Do not classify AI by brand, and do not classify it by whether it is cloud or on-premise. Classify it by what the system is used to do, and to whom.

Why private deployment does not change the answer

Moving a model onto an internal server does not alter its intended purpose. If the application falls inside Annex III, it falls inside Annex III on your own hardware, with the same documentation, human oversight and risk controls required.

What changes is how easy those obligations are to evidence. Model version, processing location, access path and update history are facts about your own site rather than answers you have to request from a supplier.

For any deployment that looks close to Annex III, the classification should be reviewed against the current text and applicable guidance, not against a generic checklist, including this one.

With Bastion

What Bastion changes

Bastion is a private AI system delivered as one sealed appliance that runs inside your building. One monthly fee covers the hardware, the model, the hardened operating system and support, and nothing your team types leaves the building.

Bastion is infrastructure. It does not decide whether a use case is high-risk and cannot remove a classification.

Where it helps is the record: which model, which version, where it ran, who reached it and when it was updated, all answerable from the customer's own site.

Questions this article answers

What makes an AI system high-risk under the EU AI Act?
Article 6 gives two routes. Either the system is a safety component of, or is itself, a product covered by the Annex I harmonisation legislation and subject to third-party conformity assessment, or it falls within one of the Annex III use cases.
Can an Annex III system avoid the high-risk classification?
Article 6(3) says yes, where it does not pose a significant risk of harm and meets one of four conditions, such as performing a narrow procedural task or improving the result of a previously completed human activity.
When do the high-risk rules start to apply?
The Commission's current timeline gives 2 December 2027 for the Annex III use cases and 2 August 2028 for high-risk AI embedded in regulated products. Both were extended by the AI Omnibus, in force since 27 July 2026.

On the record

  1. 1
  2. 2

    European Commission

    AI Act. Regulatory framework for AI

    read 2026-09-22