Chapter 4 of 25
How the Act Identifies High-Risk AI
High-risk status turns on both a general classification logic and a detailed set of sensitive use areas. The recitals show how product components, stand-alone systems, profiling and decision influence determine whether demanding obligations attach.
1. The High-Risk Idea: Harm, Not a Label of Approval
The market condition
Recital (46) says high-risk systems should only be placed on the Union market, put into service, or used if they comply with certain mandatory requirements. Keep the recital's should; do not rewrite it as must.
A limited category
The text limits high-risk identification to systems with a significant harmful impact on health, safety, and fundamental rights of persons in the Union. It also says the limitation should minimise potential trade restrictions.
Multiple product regimes can apply
Under the New Legislative Framework, one product can fall under more than one Union harmonisation act. Making it available or putting it into service can occur only when it complies with every applicable act.
What counts as harm
Recitals (47)-(48) connect risk to product safety and Charter rights. Health, safety, discrimination, privacy, education, workers' rights, fair trial, children's vulnerabilities, and environmental protection all matter.
2. Two Routes to Classification: Products and Stand-Alone Systems
Route 1: product-related AI
For listed products or safety components, Recital (50) uses the relevant product's third-party conformity-assessment procedure as the classification trigger. This is not a general statement about every AI-enabled product.
The third-party trigger
The recital expressly names machinery, toys, lifts, medical devices, in vitro diagnostic medical devices, automotive, aviation, and other listed product areas as examples of the product-related route.
Do not confuse two meanings of high-risk
AI Act high-risk status does not necessarily mean the product is high-risk under sectoral product law. Recital (51) especially warns against that inference for medical-device and IVD regimes.
Route 2: stand-alone AI
A stand-alone system is classified through intended purpose, a high risk of harm, severity and probability of possible harm, and use in specifically pre-defined areas. All parts of that description matter.
3. The Exceptional Non-High-Risk Logic and the Profiling Override
What “not materially influence” means
It means no impact on the substance and therefore the outcome of decision-making, whether human or automated. A system merely appearing in a workflow is not enough; its actual influence matters.
Four possible conditions
The recital identifies narrow procedural tasks, improvement of a completed human activity, ex post pattern or deviation detection, and tasks only preparatory to an assessment. These are possible exceptional conditions.
Examples are not the rule itself
Duplicate detection, document classification, style improvement, checking grading anomalies, search, indexing, and translation illustrate the conditions. The controlling issue remains whether the system materially influences the outcome.
Profiling changes the analysis
In an Annex high-risk use-case, a system that implies profiling should be considered to pose significant risks. Providers claiming the exception should document their assessment before market placement or service and register it.
4. Worked Classification Exercise: Admissions Document Assistant
Tool A: extract and classify
A tool that converts application PDFs into structured fields may resemble Recital (53)'s narrow procedural examples. That conclusion depends on it not affecting the substance or outcome of the admissions decision.
Tool B: rank and recommend
A ranking tool that recommends offers can materially influence access to education. Recital (56) treats systems determining access or admission as high-risk because they can shape educational and professional life.
Tool C: check completed scoring
A tool that flags deviations from a completed human scoring pattern resembles the recital's ex post pattern-detection example. It is not meant to replace or influence the assessment without proper human review.
The profiling checkpoint
If a system in a listed high-risk use-case implies profiling, Recital (53) says it should be considered to pose significant risks. Do not omit this condition when using the non-material-influence analysis.
5. Sensitive Use Areas I: Biometrics, Infrastructure, Education, and Work
Biometric distinctions
Remote biometric identification should be high-risk because inaccuracy can create biased and discriminatory results. By contrast, verification or authentication solely confirming identity for access is excluded from this classification.
Critical infrastructure
The concern is large-scale danger to life and health and major disruption to ordinary social and economic activity. A safety component directly protects infrastructure or people, yet is not needed for the system to function.
Education affects life paths
Admissions, institutional assignment, learning evaluation, materially influential level assessment, and test-behaviour monitoring should be high-risk because they can affect education, work prospects, and livelihood.
Workplace AI
Recruitment, promotion, termination, work allocation, monitoring, and evaluation can affect careers, livelihoods, workers' rights, privacy, and data protection. The recital also includes platform-service relationships in a meaningful sense.
6. Sensitive Use Areas II: Services, State Power, Justice, and Democracy
Essential services and credit
Benefit-entitlement decisions can affect livelihood and rights. Credit scoring or creditworthiness assessment of natural persons should be high-risk because it can determine access to money, housing, electricity, and telecommunications.
Law enforcement and migration
These contexts involve power imbalance and vulnerable people. The recitals stress accuracy, reliability, transparency, non-discrimination, accountability, redress, defence rights, international protection, and non-refoulement.
Justice: support, not replacement
AI may support judicial decision-making, but the final decision-making must remain human-driven. Ancillary administration that does not affect individual cases, such as anonymisation, is outside this stated classification.
High-risk is not lawful-use approval
Classification does not establish lawfulness under data-protection law or other Union or compatible national law. It also does not itself supply a legal ground for processing personal data, including special-category data.
7. Decision Map Activity: Sort the Systems
Instructions
For each scenario, choose the best path using only the recitals studied. Ask these questions in order:
- Is it an AI safety component of a listed product, or itself such a product?
- If so, does the relevant product undergo third-party conformity assessment?
- If it is stand-alone, does its intended purpose create a high risk considering severity and probability and is it in a pre-defined area?
- Could Recital (53)'s non-material-influence logic apply?
- Does the system imply profiling in a listed high-risk use-case?
Scenario A: Cloud-centre fire alarm control
A system controls fire alarms in a cloud computing centre. It directly protects people and property. This closely matches Recital (55)'s example of a critical-infrastructure safety component.
Scenario B: Password-login face match
A phone uses facial matching only to verify that the person unlocking it is the enrolled user. This matches the biometric verification or authentication exclusion described in Recital (54), provided the sole purpose is confirming identity for access.
Scenario C: Job candidate ranking
An employer ranks candidates by predicted job performance before deciding whom to interview. This falls within recruitment and selection, an employment context described in Recital (57), and may affect career prospects and livelihoods.
Scenario D: Court-document anonymiser
A court tool removes names from already issued decisions before publication. Recital (61) describes anonymisation or pseudonymisation of judicial decisions, documents, or data as purely ancillary administrative activity that does not affect actual administration of justice in individual cases.
Scenario E: Benefits duplicate detector that profiles claimants
A public-authority tool detects duplicate benefit applications but also profiles applicants. Narrow procedural work might initially resemble Recital (53). However, because it operates in a listed high-risk use-case and implies profiling, Recital (53)'s profiling statement becomes central.
Write a one-sentence conclusion for each scenario and identify the recital number supporting it.
8. Quiz: Material Influence and Profiling
Choose the best answer
A university uses an AI tool only to translate initial application documents. It does not score, rank, or recommend outcomes. However, the tool profiles applicants in an Annex-listed high-risk use-case. Which answer best reflects Recital (53)?
Which conclusion best follows from Recital (53)?
- It is automatically non-high-risk because translation is a preparatory task.
- It should be considered to pose significant risks because it implies profiling in a listed high-risk use-case.
- It is non-high-risk if the university gives an oral explanation to applicants.
- It is high-risk only if it makes the final admissions decision without a human.
Show Answer
Answer: B) It should be considered to pose significant risks because it implies profiling in a listed high-risk use-case.
Translation of initial documents is an example of a preparatory task, but Recital (53) separately says that AI systems used in high-risk use-cases listed in an annex should be considered to pose significant risks if the AI system implies profiling. The profiling qualifier cannot be ignored.
9. Flashcards: High-Risk Classification Vocabulary
Flip each card and explain the distinction aloud before checking the answer.
- Product-related high-risk trigger
- Under Recital (50), classification is appropriate where the relevant product undergoes a conformity-assessment procedure with a third-party conformity assessment body under the relevant Union harmonisation legislation.
- Stand-alone AI route
- Under Recital (52), intended purpose must pose a high risk of harm to health and safety or fundamental rights, considering severity and probability, and the system must be used in specifically pre-defined areas.
- Material influence
- An AI system does not materially influence a decision where it does not affect the substance, and thereby the outcome, of human or automated decision-making.
- Profiling qualifier
- In high-risk use-cases listed in an annex, Recital (53) says a system should be considered to pose significant risks if it implies profiling under the referenced data-protection definitions.
- Biometric verification exclusion
- Biometric verification, including authentication, is excluded where its sole purpose is confirming a specific person is who they claim to be and confirming identity solely for access to a service, device, or premises.
- Critical-infrastructure safety component
- A component used directly to protect physical integrity of critical infrastructure or health and safety of persons and property, but not necessary for the system to function. Cybersecurity-only components do not qualify.
- Justice boundary
- AI can support judges or judicial independence, but the final decision-making must remain a human-driven activity. Purely ancillary administration does not fall within the stated classification.
- No presumption of lawfulness
- High-risk classification does not mean use is lawful under other Union law or compatible national law, and it does not itself provide a legal ground for personal-data processing unless specifically otherwise provided.
10. Final Check: High-Risk Does Not Mean Lawful
Choose the most accurate statement
A vendor says: "Our system is classified as high-risk under the Regulation, so we are legally allowed to use it for any purpose, including processing special-category personal data." Evaluate this claim using Recital (63).
What is the best answer?
- Correct: high-risk classification is a complete authorisation for the system's use.
- Correct only for law-enforcement and migration systems.
- Incorrect: high-risk classification does not indicate that use is lawful under other applicable Union or national law, and the Regulation does not itself provide a personal-data processing legal ground unless specifically otherwise provided.
- Incorrect only when the system is used in education or employment.
Show Answer
Answer: C) Incorrect: high-risk classification does not indicate that use is lawful under other applicable Union or national law, and the Regulation does not itself provide a personal-data processing legal ground unless specifically otherwise provided.
Recital (63) expressly rejects the idea that high-risk status establishes legal use. Applicable Charter rights, secondary Union law, and compatible national law still govern. The recital also says the Regulation should not be understood as providing the legal ground for personal-data processing, including special-category personal data, unless specifically otherwise provided.
Key Terms
- profiling
- A term referenced in Recital (53) by cross-reference to EU data-protection instruments; in an Annex-listed high-risk use-case, its presence means the system should be considered to pose significant risks.
- Union market
- The market context referred to in Recital (46), where high-risk AI systems should only be placed, put into service, or used if they comply with certain mandatory requirements.
- non-refoulement
- The principle Recital (60) says AI in migration, asylum, and border control management should not infringe.
- intended purpose
- The use-oriented basis on which Recital (52) assesses whether a stand-alone AI system poses a high risk of harm.
- safety component
- For critical infrastructure in Recital (55), a system directly protecting the physical integrity of infrastructure or the health and safety of persons and property, while not being necessary for the system to function.
- material influence
- An impact on the substance and thereby the outcome of human or automated decision-making; its absence is central to Recital (53)'s exceptional logic.
- high-risk AI system
- In these recitals, a category limited to AI systems with a significant harmful impact on health, safety, or fundamental rights of persons in the Union, assessed through product-related or stand-alone classification logic.
- stand-alone AI system
- A high-risk AI system other than one that is a safety component of a product or is itself a product, as described in Recital (52).
- biometric verification
- Biometric use, including authentication, solely to confirm that a specific person is who they claim to be and for access to a service, device, or premises; Recital (54) excludes it from the stated high-risk classification.
- third-party conformity assessment body
- An external body involved in the relevant product conformity-assessment procedure; Recital (50) uses this procedure as the product-related high-risk classification trigger.