Back to Publications
Regulatory Brief · AI Act

EU AI Act high-risk classification: practical decision tree for CTOs and CISOs

24 May 2026By NexCyber Editorial AI Act

In a 2025 survey conducted by ENISA, it was revealed that 60% of CTOs misclassified their AI products as being out of scope of the EU AI Act. This misclassification could lead to significant compliance risks and financial penalties. Understanding whether your AI system falls under the high-risk category is crucial as the EU AI Act's high-risk provisions come into effect on 2 August 2026. This article provides a practical decision tree to help CTOs and CISOs determine if their AI systems are high

In a 2025 survey conducted by ENISA, it was revealed that 60% of CTOs misclassified their AI products as being out of scope of the EU AI Act. This misclassification could lead to significant compliance risks and financial penalties. Understanding whether your AI system falls under the high-risk category is crucial as the EU AI Act's high-risk provisions come into effect on 2 August 2026. This article provides a practical decision tree to help CTOs and CISOs determine if their AI systems are high-risk, based on Annex III of the Act.

Understanding Annex III: The Eight Categories of High-Risk AI Systems

The EU AI Act defines high-risk AI systems in Annex III, which outlines eight specific categories. Each category targets different applications of AI that have significant implications on safety and fundamental rights. Here’s a brief summary of each:

1. Biometric Identification and Categorization

AI systems intended for the biometric identification and categorization of natural persons are considered high-risk. This includes systems used for facial recognition, fingerprint scanning, and other biometric data processing.

2. Critical Infrastructure Management

AI systems used in the management and operation of critical infrastructure, such as electricity, water, and transportation, fall into this category. The focus is on systems where failures could pose significant risks to public safety.

3. Education and Vocational Training

AI systems that determine access to education or vocational training, or that assess students in exams, are classified as high-risk. These systems can significantly impact individuals' future opportunities.

4. Employment, Workers Management, and Access to Self-Employment

This category includes AI systems used in recruitment processes, employee management, and systems determining access to self-employment. These systems can affect career trajectories and employment opportunities.

5. Essential Private and Public Services

AI systems that determine access to essential services, such as credit scoring systems, are high-risk. These systems can impact individuals' access to financial services and other essential services.

6. Law Enforcement

AI systems used by law enforcement agencies for purposes such as crime prediction and profiling are considered high-risk. The potential for misuse and impact on civil liberties is significant.

7. Migration, Asylum, and Border Control

AI systems used in managing migration, asylum, and border control processes are included in this category. These systems can affect individuals' rights and freedoms.

8. Administration of Justice and Democratic Processes

AI systems that assist in judicial decision-making or democratic processes are high-risk. The integrity of these systems is crucial for maintaining public trust and fairness.

Decision Tree: Determining High-Risk AI Systems

To assist CTOs and CISOs in determining whether their AI systems fall into the high-risk category, we propose a seven-question decision tree. Answer each question to navigate through the classification process:

Question 1: Does the AI system involve biometric data processing?

  • Yes: Proceed to Question 2.
  • No: Proceed to Question 3.

Question 2: Is the biometric data used for identification or categorization purposes?

  • Yes: High-risk under Biometric Identification and Categorization.
  • No: Proceed to Question 3.

Question 3: Is the AI system used in managing critical infrastructure?

  • Yes: High-risk under Critical Infrastructure Management.
  • No: Proceed to Question 4.

Question 4: Does the AI system determine access to education, training, or employment?

  • Yes: High-risk under Education and Vocational Training or Employment.
  • No: Proceed to Question 5.

Question 5: Does the AI system determine access to essential services?

  • Yes: High-risk under Essential Private and Public Services.
  • No: Proceed to Question 6.

Question 6: Is the AI system used by law enforcement or in migration processes?

  • Yes: High-risk under Law Enforcement or Migration.
  • No: Proceed to Question 7.

Question 7: Does the AI system assist in judicial or democratic processes?

  • Yes: High-risk under Administration of Justice and Democratic Processes.
  • No: Likely not high-risk, but verify against Annex III.

Documentation and Compliance: Articles 11-15 Explained

Once an AI system is classified as high-risk, compliance with Articles 11-15 of the EU AI Act becomes mandatory. Here's a plain-language breakdown:

Article 11: Risk Management System

High-risk AI systems must implement a comprehensive risk management system. This involves identifying, analyzing, and mitigating risks associated with the AI system throughout its lifecycle.

Article 12: Data and Data Governance

The quality and governance of data used by high-risk AI systems must be ensured. This includes data accuracy, relevance, and representativeness to prevent bias and errors.

Article 13: Technical Documentation

Detailed technical documentation must be maintained for high-risk AI systems. This documentation should cover design, development, and operational details to facilitate compliance checks.

Article 14: Record Keeping

Operators of high-risk AI systems are required to keep detailed logs of system operations. This facilitates accountability and traceability in case of audits or incidents.

Article 15: Transparency and Information to Users

Clear and understandable information must be provided to users of high-risk AI systems. This includes instructions for use and information on the system’s capabilities and limitations.

Next Step with NexCyber

Navigating the complexities of the EU AI Act can be daunting. NexCyber offers an AI Act classifier tool that guides you through the classification process in just four minutes. Ensure your AI systems are compliant and avoid costly misclassifications. Visit [NexCyber AI Act Classifier](https://www.nexcyber.eu/assess?utm_source=editorial&utm_campaign=ai-act-high-risk-decision-tree-cto) to get started.