How do you know if your AI system falls into the high-risk category?

Why work with us:

– We improve your accessibility
– We enhance your customer experience
– We increase your efficiency

Want to know how we’ve been using AI to enhance the customer experience for years?

“With Pegamento, we found not just a supplier, but a true partner in change. Thanks to their expertise and our joint DevOps approach, we have made great strides in a short time. The technology supports our people so they can focus on where they make a difference: personal contact with entrepreneurs.”

Whether your AI system falls into the high-risk category depends on two factors: the sector in which the system is used and the extent to which the system makes decisions that have direct consequences for people. The EU AI Act uses a risk-based classification system with clear criteria for this purpose. In this article, we answer the most frequently asked questions about high-risk AI, so you know exactly where you stand.

What criteria determine whether an AI system is high-risk?

An AI system is considered high-risk if it falls within one of the categories listed in Annex III of the EU AI Act, or if it functions as a safety component in a regulated product listed in Annex I. The core of the assessment is whether the system poses significant risks to people’s health, safety, or fundamental rights.

Specifically, the law takes the following factors into account when determining the risk level:

  • The system’s purpose: Is it used in decisions that directly affect people, such as granting benefits or evaluating a job applicant?
  • The degree of autonomy: Does the system make decisions on its own, or does it merely support a human decision-maker?
  • The vulnerability of those affected: Are there groups that deserve extra protection, such as children, patients, or job seekers?
  • The reversibility of the consequences: Are the effects of an error easy to correct, or can they cause structural damage?

Important to know: it’s not just about the technology itself, but also about the context. The same AI model can be high-risk in one application and fall completely outside that category in another. A chatbot that provides general product information is very different from a system that assesses creditworthiness.

Which sectors and applications are on the high-risk list?

The high-risk list in Annex III of the EU AI Act covers eight specific domains. Systems that operate within these domains and have a direct impact on decision-making are automatically considered high-risk.

  1. Biometric Identification and Categorization of People
  2. Management of critical infrastructure, such as energy, water, and transportation
  3. Education and vocational training, such as systems that assess learning outcomes or determine access to training programs
  4. Employment and Human Resources Management, including recruitment and selection tools
  5. Access to essential services, such as credit scoring, social benefits, and health care
  6. Law enforcement, including risk profiling and evidence analysis
  7. Migration, Asylum, and Border Control
  8. The administration of justice and democratic processes, including systems that assist judges or administrators in making decisions

For organizations in the public sector, healthcare, education, or financial services, there is a good chance that AI applications fall into at least one of these categories. It is advisable to assess the purpose of each system and determine whether that purpose overlaps with any of the above domains.

What is the difference between high-risk and prohibited AI systems?

Prohibited AI systems are applications that the EU has completely banned, regardless of the context or intended purpose. High-risk systems are not prohibited, but may only be deployed if strict requirements are met. The distinction, therefore, lies not in whether or not they may be used, but in the difference between an absolute ban and conditional authorization.

Examples of prohibited practices that will take effect on February 2, 2025:

  • Systems that manipulate people’s behavior in a way that undermines their free will
  • Social scoring by governments based on personal behavior
  • Real-time biometric identification in public spaces for law enforcement (with very limited exceptions)
  • Emotion Recognition in the Workplace or in Education
  • AI systems that exploit the vulnerabilities of specific groups

High-risk AI falls into a different category: its use is permitted, but only if you, as a provider or user, can demonstrate that you meet all legal requirements. These include documentation, transparency, and human oversight. So it is not a ban, but a system of accountability.

What obligations apply to providers of high-risk AI?

Providers of high-risk AI systems must comply with a comprehensive set of obligations before their systems may be placed on the market. As of August 2, 2026, these requirements will apply in full to systems covered by Annex III.

The main obligations are:

  • Risk Management System: an ongoing process that identifies, assesses, and mitigates risks throughout the system’s entire lifecycle
  • Technical documentation: detailed description of the system, training dates, operation, and measures taken
  • Data Quality Management: Training and test data must be representative, relevant, and free of unacceptable bias
  • Transparency and user information: Users must understand what the system does and what its limitations are
  • Human oversight: The system must be designed so that a person can monitor its operation, understand it, and intervene
  • Accuracy, robustness, and cybersecurity: proven performance under normal and abnormal conditions
  • Conformity Assessment and CE Marking: For many high-risk systems, an external assessment is required
  • Registration in the EU database: high-risk systems must be registered in a central European database

Organizations that do not develop a high-risk AI system themselves but do deploy it as a deployer also have obligations. Among other things, they must ensure appropriate use, establish human oversight, and report incidents.

How can you verify that your AI provider complies with the regulations?

You can verify whether an AI vendor complies with the EU AI Act by asking specific questions about documentation, conformity assessments, and risk management procedures. As a deployer, you share responsibility for the proper use of the system, so you cannot blindly trust a vendor’s claims.

Be sure to ask your supplier at least the following questions:

  • Has a conformity assessment been conducted, and does the product bear the CE marking?
  • Is there technical documentation available that describes the operation, training data, and risk management measures?
  • Is the system registered in the EU database for high-risk AI?
  • How is human oversight organized, and who is responsible for what?
  • What procedures are in place for reporting incidents and serious malfunctions?
  • How are updates or changes that substantially alter the system handled?

Also pay attention to contractual agreements. The EU AI Act stipulates that a distributor, importer, or deployer becomes a provider in their own right—with all the associated obligations—if they affix their name to a system, make a substantial modification to it, or alter its intended purpose in such a way that the system becomes high-risk. Therefore, ensure that contracts clearly specify who bears which responsibilities.

What are the consequences of deploying a high-risk AI system in a non-compliant manner?

If you deploy a high-risk AI system without complying with the requirements of the EU AI Act, you risk fines of up to 15 million euros or 3% of your global annual revenue, whichever is higher. In addition to financial penalties, the regulator may also suspend or prohibit the use of the system.

The penalty structure has three levels:

  • Violations of prohibited practices (Article 5): up to 35 million euros or 7% of global annual revenue
  • Non-compliance with other obligations: up to 15 million euros or 3% of revenue
  • Inaccurate or misleading information provided to authorities: up to 7.5 million euros or 1% of revenue

For small and medium-sized enterprises, the lower of the percentage or the fixed maximum amount applies in each case. This offers some protection, but does not exempt you from the obligation to operate in compliance.

As of August 2, 2026, most of the requirements for high-risk Annex III systems will take effect. In January 2026, Finland became the first Member State to formally grant enforcement powers to its national authority, indicating that enforcement is being taken seriously. Other Member States are expected to follow suit soon.

In addition to the legal risks, there are also reputational risks. Non-compliance with the EU AI Act can lead to negative publicity, a loss of customer trust, and exclusion from procurement procedures, particularly in the public sector.

How Pegamento Helps with AI Compliance in Customer Interactions

We understand that the EU AI Act is a complex puzzle for many organizations, especially if you use AI in customer-facing and customer service environments. Our Agentic AI for customer service was developed with compliance as a core principle, not as an afterthought.

What we do for you:

  • Risk Analysis of Existing AI Applications: We identify which systems are high-risk and determine the resulting obligations
  • Implementing human oversight: Our solutions are designed so that employees always retain control and can intervene
  • Documentation and transparency: We provide the technical documentation required for conformity assessments
  • Everything under one roof: from development to management and support, without having to manage multiple vendors
  • No costly custom development, but a smart combination of proven modules: this way, you stay flexible and compliant without unnecessary complexity

Our Agentic AI goes beyond traditional automation. Whereas traditional bots merely followed instructions, our self-thinking assistants take the initiative on their own and act proactively, within the parameters set by your organization. We are ISO 27001-certified (information security), supplemented by ISO 9001 and ISO 26000, so you can be sure that privacy and security are guaranteed.

Would you like to know how your current AI applications measure up against the requirements of the EU AI Act? Contact us, and we’d be happy to help you figure it out.

Frequently Asked Questions

Does the high-risk classification also apply to AI systems that were already in use before the EU AI Act took effect?

Yes, but with a transition period. Existing high-risk AI systems that were already in use before August 2026 must fully comply with the requirements of the EU AI Act by August 2, 2027, at the latest. This gives organizations some time to assess and adapt existing systems, but it’s wise to start taking stock now. Don’t wait until the deadline, because implementing a comprehensive risk management system and preparing technical documentation takes more time than you might think.

What should I do if I’m not sure whether my AI system is high-risk?

Start with a structured risk analysis based on the criteria in Annex III of the EU AI Act: in which sector is the system used, what decisions does it support or make, and who are the affected parties? If you’re still unsure after this analysis, it’s advisable to seek legal or technical advice from a specialist in AI regulation. The European Commission has also made an interactive tool available to help organizations classify their systems.

Can an AI system change risk categories if it is used in a different way?

Absolutely, and this is one of the most underestimated risks in practice. If you deploy an AI system for a purpose that differs from its originally intended use—or if you substantially modify the system—this can change the risk category. In that case, as the deployer or modifier, you legally become the provider of the system, with all the associated obligations. Therefore, always specify contractually the specific purpose for which a system is being used and inform your supplier of any changes in its use.

How do I implement human oversight in practice for a high-risk AI system?

In concrete terms, human oversight means that there is always an authorized employee who can understand, assess, and, if necessary, correct or override the system’s output. This requires three things: technical measures (such as a ‘human-in-the-loop’ mechanism or a stop function), organizational measures (clear procedures on when and how a human intervenes), and competency development (employees must be sufficiently AI-literate to critically assess the output). Document these agreements in policy and ensure that compliance is verifiable.

What is the difference between a provider and a deployer under the EU AI Act, and why does it matter?

A provider is the party that develops and places an AI system on the market, while a deployer purchases the system from a provider and deploys it within its own organization. This distinction is crucial because both parties have their own obligations: providers are responsible for technical compliance and documentation, while deployers are responsible for proper use, human oversight, and incident reporting. Furthermore, under certain circumstances—such as changing the intended purpose or adding their own name to the system—a deployer may acquire the legal status of a provider, with all the more stringent obligations that entails.

What steps can I take now to prepare my organization for the obligations taking effect in August 2026?

Start by conducting a comprehensive inventory of all AI systems your organization uses or plans to use, and classify each system based on the Annex III criteria. Next, set priorities: systems that are likely to be high-risk require immediate action regarding documentation, risk management, and supplier contracts. Designate an internal point person for AI compliance and ensure that contracts with suppliers clearly define the division of responsibilities. The sooner you start, the more leeway you’ll have to resolve any issues without time pressure.

Do the obligations of the EU AI Act also apply to organizations outside the EU that offer AI systems to European users?

Yes. The EU AI Act has extraterritorial effect, similar to the GDPR. If an AI system is deployed in the EU or its output affects people in the EU, the rules apply—regardless of where the provider or deployer is based. Organizations outside the EU that supply systems to European customers must therefore also comply with the requirements for high-risk AI. In practice, this means they must appoint an authorized representative in the EU.

More blogs

Download the white paper here

Deepen your knowledge with Pegamento’s white papers.

Joost Schaap-Account manager Pegamento

Joost Schaap

Senoir Account Manager

When a customer contacts an organization because they have a complaint, it is crucial that the employee of the organization begin by listening carefully. What does this complaint mean for the customer and also for their own organization? How can this complaint be resolved? After listening carefully the employee needs the right information so that a solution can be offered.

This piece was written by Joost Schaap, working as an Account Manager at Pegamento.

Tim Treurniet-AI developer Pegamento

Tim Treurniet

Designer of Intelligent Systems

Real childhood heroes I never had. But in retrospect, I believe figures like Willie Carrot or Dexter’s lab may have had an influence on me. I get energy from actually making innovative and useful products myself. Nothing like seeing the effect of a project that automates a boring task, or makes a complex process suddenly accessible.

A nice bridge to my photograph is the physical aspect of my work. By working with image recognition, I am often very directly connected to the physical world and my work is more than just programming. For example, our image recognition software ensures safety on bridges, tracks players on a soccer field or uses your own smartphone to accurately measure yourself. This combination between physical and digital provides variety and extra challenge. For me, these are the main reasons for my interest and enthusiasm in what I do!

This piece was written by Tim Treurniet, employed Designer of intelligent systems at Pegamento.

Vera van der Plas-UI-UX designer

Vera van der Plas

UI/UX Designer

As a UX/UI designer, I deal daily with transforming complex data into user-friendly visualizations. All of this topped off with a digital lick of paint which should attract the visitor’s attention to take action.

One of the interesting aspects of this field I find the effects that small tweaks, both textual and visual, can have on conversion. The psychological impact that a simple background color of a CTA button has on our behavior is huge. After all, that color can determine whether or not you are going to buy that product.

What we see and how our brains process and interpret this information fascinates me. The possibilities of subconsciously pointing potential customers in your chosen direction are endless. I hope to apply my expertise more often within our solutions in the future.

This piece was written by Vera van der Plas, working as a UX/UI Designer at Pegamento.

Fouad Rahaoui-Finance Pegamento

Fouad Rahaoui

Financial Controller

A Financial Controller within a company should not only be an expert in Finance. You must also have knowledge of the latest IT developments. Because these are also moving very quickly in the world of Finance.

At Pegamento, I can learn all about the latest IT developments. Like the latest development in the field of Machine learning and deep learning.

Through these application areas, as Financial Controller, I can further automate the financial business processes within Pegamento and implement improvements for the automatic processing of financial data.

This piece was written by Fouad Rahaoui, working as a Financial Controller at Pegamento.

Ernst Vegter-Business consultant Pegamento

Ernst Vegter

Business Consultant

Hospitality is one of my deepest motivations.
Not surprisingly, of course, customer service is a common thread in my career. Aspects of hospitality is being able to connect, to facilitate but mainly to make someone feel genuinely welcome. My intuition is my greatest asset to be able to put myself in the shoes of a guest. A customer is my guest.

Fed by various senses, an image forms around the client. I listen to what is being said, watch facial expressions, taste the underlying tone and get a feel for the challenge to be addressed. An image literally forms on my retina. I have to be able to see it. If I can see it, I can create it.

In this, the trick is to pursue simplicity, give the client a warm feeling that the problem is understood, receive good advice, facilitated and carefully guided to the solution. Trust, connect and unburden.

The feeling when a guest arrives at your hotel after a long tiring journey, can sit in front of the fireplace, be handed a good glass of wine and stare carefree at the fire. My guest knows it will be okay.

This piece was written by Ernst Vegter, working as a Business Consultant at Pegamento.

Gunisch-AI developer Pegamento

Gunish Alag

AI Developer

A picture is worth a thousand words, is an expression most of us have heard. We see a lot of things around us on a daily basis and subconciously have the ability to recognize and understand them. This ability of humans to me seems bizarre.

As a computer vision developer at Pegamento that is what I do, break down complex problems and turn them into solutions using images by meticulously extracting useful data.
With the world moving forward and new technologies emerging, complicated problems which were difficult to solve a decade earlier suddenly seem possible and viable. The future is full of new challenges and I look forward to them.

This story is written by Gunish, working as an AI developer at Pegamento.

Ewold Jansen-Service engineer Pegamento

Ewold Jansen

Service & Support Engineer

Hearing the wishes a customer has or the problems a customer is facing is important in order to then be able to help them properly. In both cases, I help find the right solution.

When the customer comes to us with a desire, they don’t know what all the options are. In this I advise them to make the right choices. When problems arise, listening to them is important. For example, a problem arises from a wrong action. By communicating well in this, many problems can be solved quickly by explaining it well. Through poor communication, a small problem can become very big.

This piece was written by Ewold Jansen, working as a Service & Support Engineer at Pegamento.

Andre Glasbergen-Scrum master Pegamento

Andre Glasbergen

Scrum Master

After completing my studies, I started working as a developer at a young Pegamento with a lot of ambition and enthusiasm. In the first years I learned all about process automation, now better known as RPA. I often had to rack my brains to convert the work instruction into a logical function, with not too many If-statements, so that the robot could perform the work.

I developed further and went to work as a consultant. Listening well to the customer and supporting in the pre-sales phase of projects. Executing projects and listening suited me very well. It was a small, but logical, step to now work as a Scrum Master and Project Manager. I have been supervising projects for a few years now. Such as RPA, Cloud applications and AI, according to the Human lead agile approach, We build this with a large team of specialists.

This piece was written by André Glasbergen, working as a Scrum Master at Pegamento.

Ensar Ari-IT engineer Pegamento

Ensar Ari

IT Engineer

Good communication between customer and organization is very important. As an organization, you naturally want to be easily accessible to your customers. Either via social media channels or via the old familiar telephone. Often organizations do not know exactly how they want their telephone line set up. That is why I like to help them think along and give them ideas. I believe there is a solution to every problem. But sometimes you just need someone who looks at the situation a little differently.

This piece was written by Ensar Ari, working as an IT Engineer at Pegamento.

Nini Heerings-Chief Happiness Officer Pegamento

Nini Heerings

Chief Happiness Officer

“You get to know someone better by playing for an hour than by talking for a year.”

This quote from Plato is totally hitting home for me. That’s why I like to connect people through play. Because while playing, you are totally on, all your senses at work.
In my great role as Chief Happiness Officer, I want to do that by connecting colleagues with each other and with the organization. In a creative and playful way that suits Pegamento.

When I’m not at work, I also enjoy connecting people. I do this by organizing The Playground, where adults play games you used to play in the schoolyard, gymnasium or neighborhood playground. The pure feeling of fun, total relaxation and no thoughts of anything but playing. That feeling is the goal.

This piece was written by Nini, working as Chief Happiness Officer at Pegamento.

Ger Koedam-Communication & Marketing Pegamento

Ger Koedam

Marketing & Communications

How can I help you? That’s pretty much the first question I ask when talking to people who are curious about our services. In such a conversation, the use of senses is very important. Because not everyone is the same. One person thinks in images, while for another words are important or how something feels. For me, sight and hearing are the most beautiful senses, because both eyes and ears absorb information and can convey or process emotions.

Why hearing? Because listening is essential in contact. And it’s the key to unlocking valuable insights.

I developed this skill early on. As a child, I enjoyed radio plays on the radio, bringing the stories to life in my head.

Pim Ritmijer-Software developer Pegamento

Pim Ritmeijer

Software Developer

Programming is more than just “code knocking. For me, listening to what the customer wants and visualizing that is an important part of software development.

Actively listening to a customer to understand the customer’s full story is crucial before building a solution. When you understand a customer’s story, you can think together about a solution that truly helps the customer.

Visualizing solutions is the next step for me. What will be the route we will climb to get to a solution? What challenges are we going to face to get to the top?

Like climbing, good preparation is valuable. Even though you can’t prepare for everything, preparation helps make the application fit the client’s needs as well as possible.

What a beautiful and fascinating profession programming is.

This piece was written by Pim Ritmeijer, working as a Software Developer at Pegamento.

Denise Verhoef-Software developer Pegamento

Denise Verhoef

Software Developer

Hearing is something you do a lot of as a programmer but also thinking, for example, when you are tasked with putting together a customer need. If the customer wants a function for his application, it is important that as a programmer you think carefully about which functions are functional and which functions are not. In this way, you will put together the most functional application possible and the customer will have a good end product. Turning needs into code into functionality is something I find interesting.

I am currently doing an internship at Pegamento and studying Software Developer. I get a lot of information that you have to process and apply. The nice thing about this is that you can learn new things but also that you can experience how it works in real business. I started this training last year and knew nothing about programming beforehand. Now I can find my own way with programming and I enjoy working with it. That you can get from a blank page to a functional application through code is cool!

This piece was written by Denise Verhoef, working as a Software Developer intern at Pegamento.

Remco Pabst-Business consultant Pegamento

Remco Pabst

Computer Vision & AI Lead

Using innovative software technology for people or business to make “things” easier and smarter is really a driving force. That’s why the connection between the senses appeals to me the most. Our brains connect the senses just like a business process connects people, systems (data) and logic. They register and trigger an action, exactly how it should be in an optimal workflow. Very cool what is already possible today when we add a lot of computational power to that as well.

Hearing also means a lot. Not because I like to listen to Jazz, Soul, Deep House or Focus-like music every day AND have to be able to listen well to interpret a wish or pain point, but more because not everyone can have all the senses at their disposal. Think of him or her with a visual impairment. The fact that in close cooperation we were able to apply AI, TTS/STT technology (which is still in development) for this often underserved group of people in today’s digital world and to improve the interaction and experience with it gives me a lot of energy and meaning to what I try to do with technology; create value.

This piece was written by Remco, working as a Business Consultant at Pegamento.

Thomas de Wolf-Vision Engineer Pegamento

Thomas de Wolf

R&D Director

Once when I had to choose which study I was going to do, I had a hard time making that choice. I was interested in engineering, but what I most wanted to do was just work with a team toward a common goal.

To this day, that is still what I love doing most. The technology has become image recognition and the team the computer vision department of Pegamento. So it’s logical that in terms of sense, I end up with “seeing. By using our image recognition solutions to see things in the real world, our entire team solves relevant problems for our customers. And because of the variation in customers, the places where our solutions end up are never the same. For example, one moment I am in the control room of a bridge and the next day I am on a production line for sandwiches or between the fences of a TBS clinic.

This piece was written by Thomas de Wolf, working as a Computer Vision & AI Lead at Pegamento.

Rob Roode-Research Development

Rob Roode

Research & Development

Recognizing and automating patterns. Tasks we are constantly working on when implementing our robots at Pegamento. My 2 Drentsche Patrijshonden are hunting dogs and certainly not robots. The hunting instinct and intuition is basically in their genes. Continuing to offer new forms of training has taught them to recognize and act independently in hunting situations. Even “unsupervised,” even if I’m not around.

But when you try to teach a brain something, it also starts to see things you don’t expect. Dogs pick up on the slightest deviation in your voice or directions. To start recognizing that and correcting it again is perhaps the most complex challenge. But in our work, for the wonderful clients for whom we get to work, it often yields the most beautiful new insights!

This piece was written by Rob, founder of Pegamento and in charge of Marketing and R&D.

Serge Poppes-CEO Pegamento

Serge Poppes

CEO

Feeling. That’s the best thing Pegamento stands for. Feeling for technology in the broadest sense of the word. Not only feeling for the exciting stuff like AI, but also for the basics of communication.

The very best part of my job is selling, listening, translating and thinking about what really matters. We bring the digital transformation with a great team!
The diversity of our team, how sharp we are, but especially the wonderful things we get to make makes me feel extremely good. Hence, I intuitively chose the sense of “feeling.

Feeling gives life and differentiation!