An EU AI Act high-risk system is not simply an advanced model, an autonomous agent, or software handling confidential data. Article 6 connects high-risk status to specified product-safety contexts and intended purposes listed in Annex III.

The same language model can sit inside a low-consequence drafting assistant and an employment system that ranks candidates. The upstream component is similar. The downstream purpose changes the analysis.

This distinction deserves legal review. The Commission published draft high-risk classification guidelines in 2026, and the amended application dates now extend into 2027 and 2028. Confirm the final guidance and consolidated legislation before relying on any example.

Article 6 contains two main routes

The first route concerns AI systems that are products, or safety components of products, covered by specified EU harmonization legislation where a third-party conformity assessment is required. Examples can include regulated machinery or medical-device contexts, subject to the exact product law.

The second route concerns use cases listed in Annex III. The categories include certain biometric uses, critical infrastructure, education, employment and worker management, access to essential private or public services, law enforcement, migration, and administration of justice or democratic processes.

An Annex III label still requires careful analysis of the actual intended purpose and any applicable conditions or exclusions. Marketing language is weak evidence. Product instructions, contracts, configured behavior, user training, and actual use all help show what the system is for.

Model capability does not decide the category

A general-purpose AI model can perform many tasks. The AI Act therefore gives GPAI models a separate track, including specific provider obligations. A business that integrates a GPAI model into an application must still assess the resulting AI system.

Consider a model that can summarize a CV, a project brief, or a safety report. The capability to process all three says little about the legal category. An application ranking applicants for recruitment raises a listed employment use. An internal assistant condensing approved project notes for the assigned manager has a different intended purpose.

Record both layers:

  1. the upstream model, provider, version, terms, and documentation.
  2. the downstream system, intended purpose, users, affected people, data, output, and authority.

Human approval changes control, not intended purpose

Our first internal Skybridge AI Act tracker leaned too heavily on human approval as evidence that a system was outside high-risk classification. That was a useful mistake to catch.

Article 14 makes effective human oversight an important requirement for high-risk systems. Article 26 also requires deployers of high-risk systems to assign oversight to people with suitable competence, training, authority, and support. Those provisions would make little sense if the presence of a person always removed the high-risk category.

Human approval can reduce consequence when it is real. The reviewer needs the relevant context, authority to refuse or override, enough time, and a system that records the decision. Approval theatre changes none of that. Classification still begins with intended purpose.

Use a five-part classification card

Complete this card for every candidate system:

FieldQuestion
Intended purposeWhat result is the system designed and offered to produce?
Decision relationshipDoes it make, materially inform, rank, recommend, identify, evaluate, or allocate?
Affected peopleWhose employment, education, service access, safety, rights, or legal position may be affected?
Product and sector contextIs it a product or safety component covered by Annex I legislation, or a use listed in Annex III?
Conditions and evidenceWhich exclusions, conditions, guidance, instructions, tests, and legal opinions support the conclusion?

Add the deployment version and review date. A later change to the purpose, user group, data, output, or action can invalidate the card.

Skybridge can connect approved sources, retrieve context, prepare an output, and route a proposed action for review. Those capabilities have no single legal category in isolation.

A hypothetical event-company system could prepare a morning brief of project changes for production managers. Its release record can prohibit staffing evaluation and keep the output advisory. Another team could ask the same technical components to score freelance crew members, allocate work based on behavior, or recommend contract termination. Those intended purposes may engage the employment and worker-management category in Annex III.

Compsia must therefore qualify the use before selecting components. A prohibited-use statement belongs in the system instructions, contract, access design, acceptance tests, and monitoring. A sentence on a sales page cannot carry that boundary alone.

Prepare now without claiming the conclusion too early

For a potentially high-risk system, preserve the intended-purpose record and complete legal and technical review. Map provider and deployer roles. Ask the provider for instructions, technical information, logs, performance limits, and change notices needed for your duties.

Then compare present engineering evidence with the applicable requirements. Skybridge provides versioned changes, production promotion, traces, scoped connections, approval states, and a production cockpit that binds retrieval scope, provenance, approval history, and recovery evidence to the exact release.

The correct near-term decision may be to narrow the use. A system can prepare factual logistics without ranking workers. A tool can draft a decision record without making the decision. The business result and the legal consequence should decide whether that narrower design is useful.

The EU AI Act compliance checklist shows where classification sits inside the larger review.

High-risk classification questions

Is every AI system used by HR high-risk?

No universal answer follows from the department name. Annex III identifies specific employment and worker-management uses. Assess the intended purpose, the system's relationship to decisions, and the current legal guidance.

Does keeping a human in the loop avoid high-risk status?

Human oversight can be required and valuable. It does not automatically change a classification driven by intended purpose.

Are high-risk duties already fully applicable?

The 2026 AI Omnibus amended the timetable. The Commission currently identifies 2 December 2027 for specified high-risk systems and 2 August 2028 for AI embedded in covered physical products. Verify the date and transitional provisions for the exact system.

Primary references

  1. Regulation (EU) 2024/1689, the Artificial Intelligence ActEUR-Lex
  2. Regulation (EU) 2026/1744, the 2026 AI OmnibusEUR-Lex
  3. AI Act regulatory framework and implementation timelineEuropean Commission
  4. Guidelines for providers and deployers of AI high-risk systemsEuropean Commission

Continue reading: EU AI Act 2026: What Businesses Must Do Now.