Whether your AI system counts as high-risk decides how much work the EU AI Act creates for you. This step-by-step check helps you place your system. It is a guide, not legal advice, and borderline cases deserve a lawyer's opinion.
Step 1: Is it an AI system under the Act?
The Act defines an AI system as a machine-based system that operates with some autonomy and infers from the input it receives how to produce outputs such as predictions, content, recommendations or decisions. Ordinary software that only follows fixed rules written by people is generally outside this definition. If your product uses machine learning or a general-purpose model to produce outputs, assume it is in scope.
Step 2: Is the use prohibited?
Some uses are banned outright, for example manipulative techniques that cause harm and social scoring. These bans have applied since 2 February 2025, and the 2026 Omnibus added further bans. If your use is on the list, it cannot be placed on the EU market.
Step 3: Is it part of a regulated product?
If your AI is a safety component of a product covered by EU product-safety law (such as medical devices or machinery), or is itself such a product, it may be high-risk through Annex I. These obligations apply from 2 August 2028.
Step 4: Is it used in an Annex III area?
Check the eight areas in Annex III: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and border control, and justice and democratic processes. If your use matches, it is presumed high-risk, with obligations applying from 2 December 2027.
Step 5: Does an exception apply?
An Annex III system can fall outside high-risk if it poses no significant risk of harm, for example a narrow procedural task or a purely preparatory task. A system that profiles people never qualifies for the exception. If you rely on it, document your reasoning and register the system.
Step 6: What is your role?
- Provider: you develop the system or have it developed and place it on the market under your name. You carry most of the duties, including technical documentation and the conformity assessment.
- Deployer: you use someone else's system. You have your own duties, such as human oversight and informing people.
Step 7: Do transparency rules apply anyway?
Even if a system is not high-risk, Article 50 transparency rules can apply. These include telling people they are interacting with an AI system and labelling AI-generated content. They have applied since 2 August 2026, with a grace period to 2 December 2026 for marking AI-generated content from systems already on the market.
What your result means
- Prohibited: stop or redesign.
- High-risk: plan documentation, risk management, human oversight and a conformity assessment.
- Transparency only: make sure users are informed and content is labelled.
- Minimal risk: no specific AI Act duties, though other laws such as GDPR still apply.
Want a quick automated first pass? Attestly (our product) has an EU AI Act risk checker. Treat any tool result as a starting point and confirm it against the official text.