# High-Risk AI Systems (EU)

The EU Artificial Intelligence Act categorizes high-risk AI systems as applications posing significant threats to health, safety, or fundamental rights, subjecting them to strict obligations including conformity assessments, transparency, human oversight, and fundamental rights impact assessments.

The European Union's Artificial Intelligence Act (AI Act), which entered into force on 1 August 2024, establishes a risk-based regulatory framework for artificial intelligence. Among its four risk categories, high-risk AI systems are those expected to pose significant threats to health, safety, or fundamental rights. These systems face the most stringent obligations under the regulation, including mandatory conformity assessments, transparency requirements, human oversight, and in certain cases, a Fundamental Rights Impact Assessment (FRIA) before deployment. The AI Act was proposed by the European Commission on 21 April 2021, passed the European Parliament on 13 March 2024, and was unanimously approved by the EU Council on 21 May 2024. Its provisions are being phased in gradually over 6 to 36 months from entry into force.

High-risk classification applies to AI systems used in critical sectors such as health, education, recruitment, critical infrastructure management, law enforcement, and justice. These systems must comply with quality, transparency, and safety obligations throughout their lifecycle, from design to deployment. The list of high-risk applications can be expanded over time without amending the AI Act itself, allowing the regulation to adapt to emerging risks. Citizens have the right to submit complaints about high-risk AI systems and to receive explanations of decisions made by such systems that affect their rights.

## Definition and Scope

High-risk AI systems are defined under the AI Act as applications that are likely to cause significant harm to individuals or society. The classification is based on the intended purpose of the system, not its underlying technology. For example, an AI system used for medical diagnosis is high-risk, while the same algorithm used for administrative document sorting may be minimal-risk. The Act covers most AI systems across a wide range of sectors, with exemptions for military, national security, research, and non-professional use. As a form of product regulation, it places duties on providers and deployers, not on individuals.

The high-risk category includes AI systems that are safety components of products, or that are themselves products, subject to EU harmonisation legislation such as the Medical Devices Regulation or the Machinery Regulation. Additionally, standalone AI systems in specific areas are high-risk, including biometric identification, critical infrastructure, education and vocational training, employment and worker management, essential services, law enforcement, migration and asylum, and administration of justice. The scope is broad, reflecting the potential for these systems to affect fundamental rights.

## Obligations for Providers and Deployers

Providers of high-risk AI systems must implement a risk management system that identifies and mitigates risks throughout the system's lifecycle. They must ensure that training, validation, and testing data are relevant, representative, and free from bias. Technical documentation must be drawn up before placing the system on the market, demonstrating compliance with the Act. Logging capabilities must be built in to enable traceability of the system's operations. Human oversight is required, meaning that natural persons must be able to interpret the system's output and override it when necessary.

Deployers, or users, of high-risk AI systems have their own obligations. They must use the system in accordance with the instructions for use, ensure that input data is relevant and sufficiently representative, and monitor the system's operation for signs of risk. They must also inform affected individuals that they are interacting with a high-risk system, and in some cases, conduct a Fundamental Rights Impact Assessment before deployment. This assessment is an ex ante review to identify and mitigate potential impacts on fundamental rights, building on earlier work on algorithmic impact assessments that suggest such tools should identify affected communities, describe possible harms, and provide a basis for public scrutiny.

## Conformity Assessment and Market Surveillance

Before a high-risk AI system can be placed on the EU market, it must undergo a conformity assessment. This process verifies that the system meets the requirements of the AI Act. For many high-risk systems, the provider can self-assess, but for those used in areas like biometric identification or law enforcement, a notified body must be involved. The assessment includes a review of the risk management system, data governance, technical documentation, and human oversight measures. After passing, the system receives a CE marking, indicating conformity.

Market surveillance authorities in each member state monitor compliance after deployment. They can require providers to take corrective action if a system is found to be non-compliant. The European Artificial Intelligence Board, created by the Act, promotes national cooperation and ensures consistent enforcement across the EU. Like the General Data Protection Regulation, the AI Act can apply extraterritorially to providers outside the EU if they have users within the EU, meaning non-European companies must also comply.

## Fundamental Rights Impact Assessment

A Fundamental Rights Impact Assessment (FRIA) is required for high-risk AI systems used in certain sectors, such as public services, law enforcement, and migration. The FRIA must be conducted before deployment and involves a detailed analysis of the system's potential impact on fundamental rights, including non-discrimination, privacy, and data protection. It must describe the system's intended purpose, the categories of individuals affected, and the specific risks to their rights. Mitigation measures must be outlined, and the assessment must be kept up to date.

The FRIA is a key innovation of the AI Act, reflecting a broader trend toward algorithmic impact assessments. Scholars have argued that such assessments should identify which individuals and communities are affected, describe possible harms, and provide a basis for public and institutional scrutiny. The AI Act's FRIA requirement is designed to ensure that high-risk systems are deployed only after careful consideration of their societal implications.

## High-Risk vs. Other Risk Categories

The AI Act classifies AI applications into four levels: unacceptable, high, limited, and minimal risk. Unacceptable risk applications are banned outright, including those that manipulate human behaviour, use real-time remote biometric identification in public spaces, or enable social scoring. High-risk applications, as described, are subject to strict obligations. Limited-risk applications, such as deepfakes, only have transparency obligations, requiring users to be informed that they are interacting with AI. Minimal-risk applications, like video games or spam filters, are not regulated, and member states cannot impose additional restrictions due to maximum harmonisation rules.

This risk-based scheme follows a product-safety model, where regulatory duties increase with potential impact. It is meant to focus oversight on systems likely to create significant risks while allowing lighter approaches for less sensitive uses. Some legal scholars argue that the Act frames 'trustworthy AI' as systems that can demonstrate compliance with these safety and risk thresholds. The European Parliamentary Research Service noted that the Commission's impact assessment drew on stakeholder consultations and existing research when comparing policy options.

## General-Purpose AI and High-Risk Overlap

In 2023, the draft Act was revised to address the rise of generative AI systems, such as ChatGPT, whose general-purpose capabilities did not fit the main framework. A new category for general-purpose AI was added, covering foundation models that can perform a wide range of tasks. These models, like those developed by [openai](https://www.wikiprompt.org/wiki/openai), [anthropic](https://www.wikiprompt.org/wiki/anthropic), and [google-deepmind](https://www.wikiprompt.org/wiki/google-deepmind), are subject to transparency requirements, with reduced obligations for open-source models. High-impact models that pose systemic risks, requiring more than 10^25 floating-point operations to train, must undergo extra evaluation and adversarial testing.

While general-purpose AI is not automatically high-risk, its use in high-risk applications triggers the high-risk obligations. For example, a large language model used in a medical diagnosis tool would be subject to the AI Act's high-risk requirements. The General-Purpose AI Code of Practice, published on 10 July 2025, outlines three main chapters on transparency, copyright, and safety and security to help providers demonstrate compliance. Participation in the code is voluntary, but it provides a framework for meeting the Act's obligations.

## Enforcement and Penalties

Enforcement of the AI Act begins gradually, with prohibitions on unacceptable risk applications applying from February 2025, and high-risk obligations applying from August 2026. Penalties for non-compliance are significant, ranging up to 35 million euros or 7% of global annual turnover, whichever is higher, for violations involving prohibited practices. For other violations, penalties can reach 15 million euros or 3% of turnover. These fines are comparable to those under the General Data Protection Regulation, reflecting the EU's commitment to robust enforcement.

The European Artificial Intelligence Board, composed of representatives from member states and the Commission, plays a key role in coordinating enforcement. It issues guidance and opinions to ensure consistent application of the Act. National supervisory authorities are responsible for investigating complaints and imposing penalties. The extraterritorial reach of the Act means that providers from outside the EU, such as those in the United States or Asia, must also comply if they offer AI systems to EU users.

## Impact on Innovation and Industry

The AI Act's high-risk requirements have significant implications for the AI industry. Companies developing AI systems for healthcare, finance, or public services must invest in compliance measures, including documentation, testing, and human oversight. This can increase development costs, but it also provides a clear regulatory framework that may boost trust in AI technologies. The Act aims to balance innovation with protection, and its risk-based approach is seen as a model for other jurisdictions.

For [artificial-intelligence](https://www.wikiprompt.org/wiki/artificial-intelligence) researchers and developers, the Act encourages the use of techniques like [machine-learning](https://www.wikiprompt.org/wiki/machine-learning) and [deep-learning](https://www.wikiprompt.org/wiki/deep-learning) in a responsible manner. It also promotes transparency, which can help address concerns about bias and accountability. The Act's requirements for data governance and logging are particularly relevant for [neural-network](https://www.wikiprompt.org/wiki/neural-network) and [transformer](https://www.wikiprompt.org/wiki/transformer)-based systems, which are often opaque. By mandating human oversight, the Act seeks to ensure that AI systems remain under human control, even as they become more autonomous.

## Future Developments

The list of high-risk applications can be expanded over time, allowing the EU to respond to new risks. The Act also includes provisions for a voluntary code of conduct for minimal-risk systems, encouraging best practices. As AI technology evolves, the European Commission may propose updates to the Act, and the European Artificial Intelligence Board will continue to provide guidance. The Act's success will depend on effective enforcement and cooperation among member states, as well as international alignment on AI regulation.

In summary, high-risk AI systems under the EU AI Act are subject to some of the most comprehensive regulatory requirements in the world. They must meet strict standards for safety, transparency, and human oversight, and undergo conformity assessments before market entry. The Act represents a major step toward regulating AI in a way that protects fundamental rights while fostering innovation. Its impact will be felt globally, as many companies will need to adapt to its requirements to operate in the EU market.

---
Source: https://www.wikiprompt.org/wiki/high-risk-ai-systems
License: CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0/)
Last updated: 2026-09-13T03:50:14.167823+00:00
