TL;DR: Determining whether an AI system is high-risk under the EU AI Act requires assessing Annex III use cases, harmonised product legislation, transparency duties, and extra obligations for general-purpose AI models integrated into high-risk systems, according to Holistic AI. The practical issue is governance readiness: inventory, classification, documentation, oversight, and cybersecurity now determine compliance exposure.
NHIMG editorial — based on content published by Holistic AI: Identify High-Risk AI Systems Under the EU AI Act
Questions worth separating out
Q: How should organisations classify AI systems for EU AI Act compliance?
A: Start with intended use, not technical complexity.
Q: When do AI systems move into high-risk territory under the EU AI Act?
A: AI systems move into high-risk territory when their use case can materially affect health, safety, or fundamental rights, or when they are safety components covered by regulated product rules.
Q: What do security teams get wrong about AI compliance?
A: They often treat AI compliance as a model review exercise and miss the surrounding identity and access layer.
Practitioner guidance
- Create a classified AI system inventory Record every AI system, its business function, deployment context, and whether it may fall under Annex III or harmonised product legislation.
- Document high-risk exception decisions For systems you believe are not high-risk, capture why the system performs only a narrow procedural task, supports rather than replaces human review, or fits another exception.
- Align documentation, oversight, and security controls Make technical documentation, record-keeping, human oversight, and cybersecurity requirements part of the same governance workflow.
What's in the full article
Holistic AI's full blog covers the operational detail this post intentionally leaves for the source:
- Step-by-step AI Act classification examples across Annex III use cases and harmonised product categories
- Detailed breakdown of when the narrow-task and human-review exceptions may apply in practice
- Obligation mapping for providers, deployers, importers, distributors, and authorised representatives
- GPAI-specific documentation and systemic-risk duties for integrated models
👉 Read Holistic AI's guide to identifying high-risk AI systems under the EU AI Act →
EU AI Act high-risk systems: what should AI teams check first?
Explore further
High-risk AI classification is now a governance inventory problem, not a policy memo. The article shows that organisations must identify where AI systems sit in Annex III, where product legislation applies, and where exceptions might remove them from the high-risk category. That means classification is an evidence exercise, not a one-time legal interpretation. AI governance teams should expect regulators to ask for the rationale, not just the label.
A question worth separating out:
Q: How should teams govern GPAI inside regulated AI systems?
A: Treat the model and the application as one governance chain. If a general-purpose AI model is integrated into a high-risk system, the provider must manage both sets of obligations, including documentation, oversight, cybersecurity, and incident handling. Teams should map responsibilities across model owners, deployers, and security functions before go-live.
👉 Read our full editorial: High-risk AI systems under the EU AI Act demand stronger governance