Whether your AI system falls into the high-risk category depends on two factors: the sector in which the system is used and the extent to which the system makes decisions that have direct consequences for people. The EU AI Act uses a risk-based classification system with clear criteria for this purpose. In this article, we answer the most frequently asked questions about high-risk AI, so you know exactly where you stand.
What criteria determine whether an AI system is high-risk?
An AI system is considered high-risk if it falls within one of the categories listed in Annex III of the EU AI Act, or if it functions as a safety component in a regulated product listed in Annex I. The core of the assessment is whether the system poses significant risks to people’s health, safety, or fundamental rights.
Specifically, the law takes the following factors into account when determining the risk level:
- The system’s purpose: Is it used in decisions that directly affect people, such as granting benefits or evaluating a job applicant?
- The degree of autonomy: Does the system make decisions on its own, or does it merely support a human decision-maker?
- The vulnerability of those affected: Are there groups that deserve extra protection, such as children, patients, or job seekers?
- The reversibility of the consequences: Are the effects of an error easy to correct, or can they cause structural damage?
Important to know: it’s not just about the technology itself, but also about the context. The same AI model can be high-risk in one application and fall completely outside that category in another. A chatbot that provides general product information is very different from a system that assesses creditworthiness.
Which sectors and applications are on the high-risk list?
The high-risk list in Annex III of the EU AI Act covers eight specific domains. Systems that operate within these domains and have a direct impact on decision-making are automatically considered high-risk.
- Biometric Identification and Categorization of People
- Management of critical infrastructure, such as energy, water, and transportation
- Education and vocational training, such as systems that assess learning outcomes or determine access to training programs
- Employment and Human Resources Management, including recruitment and selection tools
- Access to essential services, such as credit scoring, social benefits, and health care
- Law enforcement, including risk profiling and evidence analysis
- Migration, Asylum, and Border Control
- The administration of justice and democratic processes, including systems that assist judges or administrators in making decisions
For organizations in the public sector, healthcare, education, or financial services, there is a good chance that AI applications fall into at least one of these categories. It is advisable to assess the purpose of each system and determine whether that purpose overlaps with any of the above domains.
What is the difference between high-risk and prohibited AI systems?
Prohibited AI systems are applications that the EU has completely banned, regardless of the context or intended purpose. High-risk systems are not prohibited, but may only be deployed if strict requirements are met. The distinction, therefore, lies not in whether or not they may be used, but in the difference between an absolute ban and conditional authorization.
Examples of prohibited practices that will take effect on February 2, 2025:
- Systems that manipulate people’s behavior in a way that undermines their free will
- Social scoring by governments based on personal behavior
- Real-time biometric identification in public spaces for law enforcement (with very limited exceptions)
- Emotion Recognition in the Workplace or in Education
- AI systems that exploit the vulnerabilities of specific groups
High-risk AI falls into a different category: its use is permitted, but only if you, as a provider or user, can demonstrate that you meet all legal requirements. These include documentation, transparency, and human oversight. So it is not a ban, but a system of accountability.
What obligations apply to providers of high-risk AI?
Providers of high-risk AI systems must comply with a comprehensive set of obligations before their systems may be placed on the market. As of August 2, 2026, these requirements will apply in full to systems covered by Annex III.
The main obligations are:
- Risk Management System: an ongoing process that identifies, assesses, and mitigates risks throughout the system’s entire lifecycle
- Technical documentation: detailed description of the system, training dates, operation, and measures taken
- Data Quality Management: Training and test data must be representative, relevant, and free of unacceptable bias
- Transparency and user information: Users must understand what the system does and what its limitations are
- Human oversight: The system must be designed so that a person can monitor its operation, understand it, and intervene
- Accuracy, robustness, and cybersecurity: proven performance under normal and abnormal conditions
- Conformity Assessment and CE Marking: For many high-risk systems, an external assessment is required
- Registration in the EU database: high-risk systems must be registered in a central European database
Organizations that do not develop a high-risk AI system themselves but do deploy it as a deployer also have obligations. Among other things, they must ensure appropriate use, establish human oversight, and report incidents.
How can you verify that your AI provider complies with the regulations?
You can verify whether an AI vendor complies with the EU AI Act by asking specific questions about documentation, conformity assessments, and risk management procedures. As a deployer, you share responsibility for the proper use of the system, so you cannot blindly trust a vendor’s claims.
Be sure to ask your supplier at least the following questions:
- Has a conformity assessment been conducted, and does the product bear the CE marking?
- Is there technical documentation available that describes the operation, training data, and risk management measures?
- Is the system registered in the EU database for high-risk AI?
- How is human oversight organized, and who is responsible for what?
- What procedures are in place for reporting incidents and serious malfunctions?
- How are updates or changes that substantially alter the system handled?
Also pay attention to contractual agreements. The EU AI Act stipulates that a distributor, importer, or deployer becomes a provider in their own right—with all the associated obligations—if they affix their name to a system, make a substantial modification to it, or alter its intended purpose in such a way that the system becomes high-risk. Therefore, ensure that contracts clearly specify who bears which responsibilities.
What are the consequences of deploying a high-risk AI system in a non-compliant manner?
If you deploy a high-risk AI system without complying with the requirements of the EU AI Act, you risk fines of up to 15 million euros or 3% of your global annual revenue, whichever is higher. In addition to financial penalties, the regulator may also suspend or prohibit the use of the system.
The penalty structure has three levels:
- Violations of prohibited practices (Article 5): up to 35 million euros or 7% of global annual revenue
- Non-compliance with other obligations: up to 15 million euros or 3% of revenue
- Inaccurate or misleading information provided to authorities: up to 7.5 million euros or 1% of revenue
For small and medium-sized enterprises, the lower of the percentage or the fixed maximum amount applies in each case. This offers some protection, but does not exempt you from the obligation to operate in compliance.
As of August 2, 2026, most of the requirements for high-risk Annex III systems will take effect. In January 2026, Finland became the first Member State to formally grant enforcement powers to its national authority, indicating that enforcement is being taken seriously. Other Member States are expected to follow suit soon.
In addition to the legal risks, there are also reputational risks. Non-compliance with the EU AI Act can lead to negative publicity, a loss of customer trust, and exclusion from procurement procedures, particularly in the public sector.
How Pegamento Helps with AI Compliance in Customer Interactions
We understand that the EU AI Act is a complex puzzle for many organizations, especially if you use AI in customer-facing and customer service environments. Our Agentic AI for customer service was developed with compliance as a core principle, not as an afterthought.
What we do for you:
- Risk Analysis of Existing AI Applications: We identify which systems are high-risk and determine the resulting obligations
- Implementing human oversight: Our solutions are designed so that employees always retain control and can intervene
- Documentation and transparency: We provide the technical documentation required for conformity assessments
- Everything under one roof: from development to management and support, without having to manage multiple vendors
- No costly custom development, but a smart combination of proven modules: this way, you stay flexible and compliant without unnecessary complexity
Our Agentic AI goes beyond traditional automation. Whereas traditional bots merely followed instructions, our self-thinking assistants take the initiative on their own and act proactively, within the parameters set by your organization. We are ISO 27001-certified (information security), supplemented by ISO 9001 and ISO 26000, so you can be sure that privacy and security are guaranteed.
Would you like to know how your current AI applications measure up against the requirements of the EU AI Act? Contact us, and we’d be happy to help you figure it out.
Frequently Asked Questions
Geldt de hoog-risico classificatie ook voor AI-systemen die al in gebruik zijn vóór de inwerkingtreding van de EU AI Act?
Ja, maar met een overgangsperiode. Bestaande hoog-risico AI-systemen die vóór augustus 2026 al in gebruik waren, moeten uiterlijk op 2 augustus 2027 volledig voldoen aan de vereisten van de EU AI Act. Dit geeft organisaties enige tijd om bestaande systemen te beoordelen en aan te passen, maar het is verstandig om nu al te beginnen met een inventarisatie. Wacht niet tot de deadline, want het implementeren van een volledig risicomanagementsysteem en het opstellen van technische documentatie kost meer tijd dan je denkt.
Wat moet ik doen als ik er niet zeker van ben of mijn AI-systeem hoog-risico is?
Begin met een gestructureerde risicoanalyse aan de hand van de criteria in Annex III van de EU AI Act: in welke sector wordt het systeem ingezet, welke beslissingen ondersteunt of neemt het, en wie zijn de betrokkenen? Als je na deze analyse nog twijfelt, is het raadzaam juridisch of technisch advies in te winnen bij een specialist in AI-regelgeving. De Europese Commissie heeft daarnaast een interactieve tool beschikbaar gesteld om organisaties te helpen bij de classificatie van hun systemen.
Kan een AI-systeem van risicocategorie veranderen als het op een andere manier wordt ingezet?
Absoluut, en dit is een van de meest onderschatte risico’s in de praktijk. Als je een AI-systeem inzet voor een doel dat afwijkt van het oorspronkelijk beoogde gebruik — of als je het systeem substantieel wijzigt — kan dit de risicocategorie veranderen. In dat geval word je als deployer of aanpasser juridisch gezien de aanbieder van het systeem, met alle bijbehorende verplichtingen. Leg daarom altijd contractueel vast voor welk specifiek doel een systeem wordt ingezet en informeer je leverancier bij elke wijziging in het gebruik.
Hoe richt ik menselijk toezicht in de praktijk in voor een hoog-risico AI-systeem?
Menselijk toezicht betekent concreet dat er altijd een bevoegde medewerker is die de output van het systeem kan begrijpen, beoordelen en zo nodig corrigeren of overschrijven. Dit vereist drie dingen: technische maatregelen (zoals een ‘human-in-the-loop’ mechanisme of een stop-functie), organisatorische maatregelen (heldere procedures over wanneer en hoe een mens ingrijpt), en competentieontwikkeling (medewerkers moeten voldoende AI-geletterd zijn om de output kritisch te beoordelen). Leg deze afspraken vast in beleid en zorg dat ze aantoonbaar worden nageleefd.
Wat is het verschil tussen een aanbieder en een deployer onder de EU AI Act, en waarom maakt dat uit?
Een aanbieder is de partij die een AI-systeem ontwikkelt en op de markt brengt, terwijl een deployer het systeem van een aanbieder afneemt en in de eigen organisatie inzet. Het onderscheid is cruciaal omdat beide partijen eigen verplichtingen hebben: aanbieders zijn verantwoordelijk voor de technische conformiteit en documentatie, deployers voor het correcte gebruik, menselijk toezicht en incidentmelding. Bovendien kan een deployer onder bepaalde omstandigheden — zoals het wijzigen van het beoogde doel of het toevoegen van de eigen naam aan het systeem — de juridische status van aanbieder krijgen, met alle zwaardere verplichtingen van dien.
Welke stappen kan ik nu al zetten om mijn organisatie voor te bereiden op de verplichtingen per augustus 2026?
Start met een volledige inventarisatie van alle AI-systemen die je organisatie gebruikt of van plan is te gebruiken, en classificeer elk systeem aan de hand van de Annex III-criteria. Stel vervolgens prioriteiten: systemen die waarschijnlijk hoog-risico zijn, vragen directe actie op het gebied van documentatie, risicobeheer en leverancierscontracten. Wijs intern een verantwoordelijke aan voor AI-compliance en zorg dat contracten met leveranciers duidelijk de verantwoordelijkheidsverdeling vastleggen. Hoe eerder je begint, hoe meer ruimte je hebt om eventuele knelpunten op te lossen zonder tijdsdruk.
Gelden de verplichtingen van de EU AI Act ook voor organisaties buiten de EU die AI-systemen aan Europese gebruikers aanbieden?
Ja. De EU AI Act heeft een extraterritoriale werking, vergelijkbaar met de AVG. Als een AI-systeem wordt ingezet in de EU of de output ervan gevolgen heeft voor mensen in de EU, zijn de regels van toepassing — ongeacht waar de aanbieder of deployer gevestigd is. Organisaties buiten de EU die systemen aan Europese klanten leveren, moeten dus eveneens voldoen aan de vereisten voor hoog-risico AI. In de praktijk betekent dit dat zij een gemachtigde vertegenwoordiger in de EU moeten aanwijzen.


