In a 2025 survey conducted by ENISA, it was revealed that 60% of CTOs misclassified their AI products as being out of scope of the EU AI Act. This misclassification could lead to significant compliance risks and financial penalties. Understanding whether your AI system falls under the high-risk category is crucial as the EU AI Act's high-risk provisions come into effect on 2 August 2026. This article provides a practical decision tree to help CTOs and CISOs determine if their AI systems are high
In a 2025 survey conducted by ENISA, it was revealed that 60% of CTOs misclassified their AI products as being out of scope of the EU AI Act. This misclassification could lead to significant compliance risks and financial penalties. Understanding whether your AI system falls under the high-risk category is crucial as the EU AI Act's high-risk provisions come into effect on 2 August 2026. This article provides a practical decision tree to help CTOs and CISOs determine if their AI systems are high-risk, based on Annex III of the Act.
Understanding Annex III: The Eight Categories of High-Risk AI Systems
The EU AI Act defines high-risk AI systems in Annex III, which outlines eight specific categories. Each category targets different applications of AI that have significant implications on safety and fundamental rights. Here’s a brief summary of each:
1. Biometric Identification and Categorization
AI systems intended for the biometric identification and categorization of natural persons are considered high-risk. This includes systems used for facial recognition, fingerprint scanning, and other biometric data processing.
2. Critical Infrastructure Management
AI systems used in the management and operation of critical infrastructure, such as electricity, water, and transportation, fall into this category. The focus is on systems where failures could pose significant risks to public safety.
3. Education and Vocational Training
AI systems that determine access to education or vocational training, or that assess students in exams, are classified as high-risk. These systems can significantly impact individuals' future opportunities.
4. Employment, Workers Management, and Access to Self-Employment
This category includes AI systems used in recruitment processes, employee management, and systems determining access to self-employment. These systems can affect career trajectories and employment opportunities.
5. Essential Private and Public Services
AI systems that determine access to essential services, such as credit scoring systems, are high-risk. These systems can impact individuals' access to financial services and other essential services.
6. Law Enforcement
AI systems used by law enforcement agencies for purposes such as crime prediction and profiling are considered high-risk. The potential for misuse and impact on civil liberties is significant.
7. Migration, Asylum, and Border Control
AI systems used in managing migration, asylum, and border control processes are included in this category. These systems can affect individuals' rights and freedoms.
8. Administration of Justice and Democratic Processes
AI systems that assist in judicial decision-making or democratic processes are high-risk. The integrity of these systems is crucial for maintaining public trust and fairness.
Decision Tree: Determining High-Risk AI Systems
To assist CTOs and CISOs in determining whether their AI systems fall into the high-risk category, we propose a seven-question decision tree. Answer each question to navigate through the classification process:
Question 1: Does the AI system involve biometric data processing?
- Yes: Proceed to Question 2.
- No: Proceed to Question 3.
Question 2: Is the biometric data used for identification or categorization purposes?
- Yes: High-risk under Biometric Identification and Categorization.
- No: Proceed to Question 3.
Question 3: Is the AI system used in managing critical infrastructure?
- Yes: High-risk under Critical Infrastructure Management.
- No: Proceed to Question 4.
Question 4: Does the AI system determine access to education, training, or employment?
- Yes: High-risk under Education and Vocational Training or Employment.
- No: Proceed to Question 5.
Question 5: Does the AI system determine access to essential services?
- Yes: High-risk under Essential Private and Public Services.
- No: Proceed to Question 6.
Question 6: Is the AI system used by law enforcement or in migration processes?
- Yes: High-risk under Law Enforcement or Migration.
- No: Proceed to Question 7.
Question 7: Does the AI system assist in judicial or democratic processes?
- Yes: High-risk under Administration of Justice and Democratic Processes.
- No: Likely not high-risk, but verify against Annex III.
Documentation and Compliance: Articles 11-15 Explained
Once an AI system is classified as high-risk, compliance with Articles 11-15 of the EU AI Act becomes mandatory. Here's a plain-language breakdown:
Article 11: Risk Management System
High-risk AI systems must implement a comprehensive risk management system. This involves identifying, analyzing, and mitigating risks associated with the AI system throughout its lifecycle.
Article 12: Data and Data Governance
The quality and governance of data used by high-risk AI systems must be ensured. This includes data accuracy, relevance, and representativeness to prevent bias and errors.
Article 13: Technical Documentation
Detailed technical documentation must be maintained for high-risk AI systems. This documentation should cover design, development, and operational details to facilitate compliance checks.
Article 14: Record Keeping
Operators of high-risk AI systems are required to keep detailed logs of system operations. This facilitates accountability and traceability in case of audits or incidents.
Article 15: Transparency and Information to Users
Clear and understandable information must be provided to users of high-risk AI systems. This includes instructions for use and information on the system’s capabilities and limitations.
Next Step with NexCyber
Navigating the complexities of the EU AI Act can be daunting. NexCyber offers an AI Act classifier tool that guides you through the classification process in just four minutes. Ensure your AI systems are compliant and avoid costly misclassifications. Visit [NexCyber AI Act Classifier](https://www.nexcyber.eu/assess?utm_source=editorial&utm_campaign=ai-act-high-risk-decision-tree-cto) to get started.