πŸ‡ͺπŸ‡Ί European Union

Is my AI system high-risk under the EU AI Act?

A step-by-step EU AI Act risk check: work out whether your AI system is prohibited, high-risk, subject to transparency rules, or minimal risk.

Reviewed 11 Oct 2026·3 min read

Whether your AI system counts as high-risk decides how much work the EU AI Act creates for you. This step-by-step check helps you place your system. It is a guide, not legal advice, and borderline cases deserve a lawyer's opinion.

Step 1: Is it an AI system under the Act?

The Act defines an AI system as a machine-based system that operates with some autonomy and infers from the input it receives how to produce outputs such as predictions, content, recommendations or decisions. Ordinary software that only follows fixed rules written by people is generally outside this definition. If your product uses machine learning or a general-purpose model to produce outputs, assume it is in scope.

Step 2: Is the use prohibited?

Some uses are banned outright, for example manipulative techniques that cause harm and social scoring. These bans have applied since 2 February 2025, and the 2026 Omnibus added further bans. If your use is on the list, it cannot be placed on the EU market.

Step 3: Is it part of a regulated product?

If your AI is a safety component of a product covered by EU product-safety law (such as medical devices or machinery), or is itself such a product, it may be high-risk through Annex I. These obligations apply from 2 August 2028.

Step 4: Is it used in an Annex III area?

Check the eight areas in Annex III: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and border control, and justice and democratic processes. If your use matches, it is presumed high-risk, with obligations applying from 2 December 2027.

Step 5: Does an exception apply?

An Annex III system can fall outside high-risk if it poses no significant risk of harm, for example a narrow procedural task or a purely preparatory task. A system that profiles people never qualifies for the exception. If you rely on it, document your reasoning and register the system.

Step 6: What is your role?

Step 7: Do transparency rules apply anyway?

Even if a system is not high-risk, Article 50 transparency rules can apply. These include telling people they are interacting with an AI system and labelling AI-generated content. They have applied since 2 August 2026, with a grace period to 2 December 2026 for marking AI-generated content from systems already on the market.

What your result means

Want a quick automated first pass? Attestly (our product) has an EU AI Act risk checker. Treat any tool result as a starting point and confirm it against the official text.

This article is general information, not legal advice. Rules change often, so check official sources before you rely on it.
Our network

More from our team

Other products built by the team behind ActAI Compliance.