The European Commission has published, as of [date], draft guidelines on the classification of AI systems (AIS) as high-risk AI systems (HRAIS) pursuant to Article 6 of the AI Act published. The guidelines consist of several documents:
- Draft Commission Guidelines on the Classification of High-Risk AI Systems Under Article 6 of Regulation (EU) 2024/1689 (AI Act)
- 2 – Draft Guidelines on the Classification of High-Risk AI Systems: Annex I of the AI Act
- 3 – Draft Guidelines on the Classification of High-Risk AI Systems: Annex III of the AI Act
The draft is available for consultation and will be further coordinated with the European AI Board before adoption; the examples are expressly not exhaustive and are intended to be updated on an ongoing basis.
Classification of AIS as HRAIS
General
In the first part, the Commission explains several principles („Horizontal Issues“) that form the basis of its understanding of individual cases.
We should proceed on the basis of the distinction set forth in Article 6 of the AI Act: HRAIS are systems that
- a Product listed in Annex I or are safety components thereof (Art. 6, para. 1, Annex I); or
- one of the eight Areas According to Annex III correspond to:
- Biometrics
- Critical infrastructure
- Education and vocational training
- Employment, Workforce Management, and Access to Self-Employment
- Access to and use of essential private services, as well as essential public services and benefits
- Prosecution
- Migration, Asylum, and Border Control Management
- The Administration of Justice and Democratic Processes
Use Cases According to Annex III
Annex III is of particular practical relevance. When classifying materials, the following applies first and foremost:
- „Significant risk“: Annex III covers only systems that, by their intended purpose, are a significant risk to health, safety, or fundamental rights entail. The final list and the filter are both expressions of this proportionate, risk-based approach. According to Recital 53 of the AI Act, a substantial risk is absent if the system does not influence the substance and thus the outcome of the decision:
(53) It is also important to clarify that there may be specific cases in which AI systems referred to in predefined areas specified in this Regulation do not pose a significant risk of harm to the legal interests protected under those areas because they do not materially influence decision-making or do not substantially harm those interests. For the purposes of this Regulation, an AI system that does not materially influence the outcome of decision-making should be understood to be an AI system that does not affect the substance — and thus the outcome — of decision-making, whether human or automated. An AI system that does not materially influence the outcome of decision-making could include situations in which one or more of the following conditions are met. […]
- Intended Use as a Standard: The only determining factor is whether the intended use of the AIS falls under a use case listed in Annex III. This classification must be made before the product is placed on the market or put into service.
- Human Involvement That, in and of itself, does not change anything, because human oversight under Article 14 of the AI Act is a compliance requirement for a high-risk system and not a factor in its classification.
Low-risk exceptions
Article 6(3) of the AI Act addresses the principle that insignificant risks should not result in a classification as high-risk under Annex III. An AIS that would otherwise fall under Annex III is, exceptionally, not considered high-risk if at least one of the following conditions is met (the Commission refers to this as the „filter.“ Here, the “human-in-the-loop” factor may well be relevant to the final classification as an HRAIS).
The following rules apply to the application of this exception — which applies only to Annex III, not to product-specific classification under Annex I:
- Interpretation: The conditions listed are exhaustive but alternative. As exceptions relevant to fundamental rights, they must be interpreted narrowly. They all apply only to the extent that the AIS does not significantly influence the outcome of a decision.
- Profiling: If the system engages in profiling as defined in Article 4(4) of the GDPR, no exception applies. Therefore, if personal data is processed to evaluate personal aspects, the low-risk exception does not apply.
- Agent-based systems: Distributed and agent-based architectures are evaluated as a single system as soon as their shared tasks significantly influence a decision in a specific case. The fact that individual components, taken on their own, fall under an exception does not change this:
(75) Where several AI systems form part of a more complex AI system, such that their combined intended purpose or joint outputs materially influence an individual decision, the combined configuration is treated as a single AI system for the purpose of high-risk classification. To prevent circumvention of the high-risk classification rules through system design, split architectures are assessed as a whole.
(76) By contrast, strictly procedural or preparatory functions of an AI system that are linked to a high-risk system remain eligible for exemption from high-risk classification under Article 6(3) of the AI Act where they are genuinely separable from the AI system […]
Self-Assessment and Registration: The application of an exception must be reviewed prior to placing the product on the market and, if applicable, documented. The AIS must also be registered in the relevant database (Art. 6(4), Art. 71 AI Act). Market surveillance authorities may reclassify the AIS (Art. 80 of the AI Act) and may impose sanctions in cases of circumvention (Art. 99 of the AI Act).
All of this can be summarized as follows:
Narrow procedural task (lit. a; „narrow procedural task“)
This involves, for example, reformatting, structuring, or categorizing data; making value judgments; classifying data as „useful“ or „less useful“; and scoring or ranking.
The Commission illustrates this with two examples:
- An exception applies: Sorting incoming applications for admission to schools or universities based on the required grade or educational level, because — or when — such systems classify applications into predefined categories (e.g., elementary school, secondary school, high school, or specific classes) based on defined information, without assessing suitability or making admission decisions (an interesting example because it involves minimal risk).
- The exception does not apply:
Improvement of a human outcome (lit. b; „improve the result of a previously completed human activity“)
This exception applies to refinements or quality assurance that do not involve a material revaluation. For this to apply, the following conditions must be met:
- A human review or decision has been completed, and
- led to a result and
- This is improved by the AIS without changing the result—
Here are two examples of this as well:
- An exception applies:
- Identifying errors or inconsistencies in the results
- Supplementing Human Decisions with Additional Evidence
- Conversion of Human-Generated Content
- The exception does not apply: An AIS checks a result and provides a significantly different solution.
Identifying decision-making patterns or deviations (lit. c)
This involves purely ex post reviews, without influencing the decision itself. Unlike the other “low-risk” exceptions, this exception can certainly cover somewhat more complex systems and also serve to prepare the ground for a human decision. However, three conditions must be met:
- The human review must already be complete;
- The AIS conducts only an ex-post analysis, without predetermining future decisions;
- The AIS must not be designed to replace or influence human decision-making. If such influence occurs, it must be followed by a genuine human review.
There is also an example of this. An AIS would likely fall under the “low risk” exception if it analyzes previous classifications made by a public administration for the purposes of quality assurance — through pattern recognition that also identifies deviations in individual decisions — and reporting, but without proposing solutions for future cases or evaluating employee performance.
Preparatory Task (lit. d)
In contrast to the narrow procedural exception (subparagraph (a)), this concerns tasks performed in preparation for a human decision (although such preparation may fall under both subparagraphs (a) and (d) at the same time). In this context, the output of the AIS may only be a general factor that supports decision-making, without the AIS contributing a recommendation or an assessment of an individual case.
One example is an AIS that provides users with references to relevant legal provisions, information on case law, and internal guidelines. The AIS neither analyzes individual cases nor generates a result that significantly influences the decision.
Reservation Regarding Profiling
All “low-risk” exceptions are subject to profiling as defined in Article 4(4) of the GDPR, that is, the automated processing of personal data for the purpose of evaluating personal characteristics.
For example, when a customs authority uses an AIS to assess the risk that goods may violate legal regulations upon import, this does not involve the evaluation of personal characteristics. Such a risk assessment of shipments or goods does not constitute profiling. This is different from an AIS that, in the context of recruitment, identifies deviations from internal recruitment guidelines and, for this purpose, evaluates the decisions of recruiters and personal characteristics in connection with job interviews. While this could in itself constitute a case falling under Article 6(3)(c), the processing of personal data for the purpose of profiling the recruiters precludes this.
Specific Annex III Use Cases
Biometrics (Annex III, No. 1)
This group of cases includes three use cases:
- Section 1(a): remote biometric identification;
- Section 1(b): Biometric categorization based on sensitive characteristics within the meaning of Article 9(1) of the GDPR (special-category personal data). However, age and gender are not included in this definition (the interpretation under the GDPR is sometimes broader and, according to some opinions, may extend to all unchangeable physical characteristics).
- Section 1(c): Emotion recognition, to the extent that it is not already prohibited under Article 5 of the AI Act (emotion recognition in the workplace and in educational institutions).
The definition of biometric data is not provided by the GDPR, but rather by Article 3, No. 34 of the AI Act:
- no biometric data: tracking a person in a store based on their clothing; emotion recognition based on written text; license plate recognition;
- biometric data: Emotion recognition based on keystrokes, facial expressions, body posture, or movements.
Recorded According to the Commission, these include, for example, the following operations:
- Comparing photos or the voices of living individuals with archival material for identification purposes;
- Comparison of footage from sports stadiums to identify troublemakers;
- Detection of diseases based on movement patterns;
- Categorization of airline passengers using facial recognition;
Not recorded include, for example, the following applications:
- Biometric verification used solely as a means of matching data to confirm identity (such as unlocking a device or granting access)
- Locating a person without biometric matching;
- Categorizing customers by gender;
- AI for content moderation.
Specifically with regard to the Emotion recognition (to the extent that AI is used in this context):
Recorded:
- Use of body cameras to identify aggressive individuals;
- Emotion recognition in video games to enhance gameplay, based, among other things, on facial expressions and eye movements;
- Identifying potential sources of conflict at concerts;
- Voice-based emotion recognition of customers in call centers.
Not recorded:
- Detection of fatigue in drivers;
- Recognition of simple facial expressions (smiles, etc.).
Critical Infrastructure (Annex III, No. 2)
This category includes only AIS that serve as a safety component within the meaning of Art. 3, No. 14 of the AI Act, a direct protective function that ensure the physical integrity of infrastructure in the sectors of digital infrastructure, road transportation, and the supply of water, gas, heat, or electricity.
Recorded are for example:
- Traffic light control to prevent physical damage
- Fire Alarm System in a Data Center
Not recorded On the other hand, examples include:
- Pure analysis of traffic flow without direct control intervention
- Ticket Management and Network Load Forecasts
- pure cybersecurity components
- systems that merely optimize, provide information, or organize
Education and Vocational Training (Annex III, No. 3)
Four use cases are listed here, each of which applies to all levels of education, including on-the-job and vocational training and continuing education:
- Section 3(a): Determination of Admission, Enrollment, or Placement in Institutions and Programs
- Section 3(b): Assessment of learning outcomes, but only summative (affecting grades or qualifications), not formative (to support learning)
- Section 3(c): Assessment of the appropriate level of education that a person receives or can attain
- Section 3(d): Monitoring and Detection of Prohibited Behavior During Exams
The Commission explains its understanding as follows:
Access and Allocation (lit. a)
Recorded:
- automated admissions systems that evaluate applications, transcripts, and test scores
- Tools for assigning learners to a program or course
- Systems that match job seekers or employees with professional development programs
Not included:
- Recommendation tools that suggest degree programs to prospective students based on their own preferences and are intended solely to support their decision-making
- Information chatbots about admission requirements, without personalized recommendations.
Low-Risk Exception:
- A simple data organizer that extracts and categorizes job applications (narrow scope of the task)
- Tool for the ex post review of authorization decisions that have already been made (pattern recognition)
Profiling (the low-risk exception does not apply):
- Systems whose data analysis constitutes profiling, such as automated school assignment based on place of residence and personal characteristics
- Matching for Continuing Education Programs
Assessment of Learning Outcomes (lit. b)
Recorded:
- Grading and assessment systems that contribute to the final or interim grade, even if a formative feedback system simultaneously informs the teacher’s grading
Not included:
- adaptive learning systems, intelligent tutoring systems, learning analytics platforms
- Tools to Support Neurodivergent Learners
- Language or pronunciation practice apps used solely by learners
Low-Risk Exception:
- Simple Grade Average Calculator (narrow-scope problem)
- A system that checks teachers’ grading patterns for anomalies and flags them for human review (pattern recognition)
Level of education (lit. c)
Recorded:
- adaptive placement tests
- Systems that assign learners with special needs to a program and level of support
Not included:
- Aggregated trend analyses of educational trajectories without reference to specific individuals
Exam Proctoring (lit. d)
Recorded:
- Proctoring systems used during proctored exams, such as those that use facial recognition, keyboard, screen, or audio/video analysis
Not included:
- Plagiarism and collaboration checks on submitted assignments that take place outside of the supervised, real-time exam setting and after the assignment has been turned in
Employment (Annex III, No. 4)
Here, a distinction must be made between two scenarios, both of which should be interpreted broadly and functionally. The personal scope of application extends beyond employees; freelancers, self-employed individuals, service providers, and platform workers also fall under this scenario — regardless of the type of contract — as soon as an AUS facilitates or conditions their access to work:
- Section 4(a): Recruitment and selection of individuals, including targeted job postings, reviewing and screening applications, and evaluating candidates.
- Section 4(b): Control over employment relationships, specifically decisions regarding contract terms, promotions, and termination; assignment of tasks based on behavior or characteristics; and monitoring and evaluation of performance and behavior.
Recruitment and Selection (lit. a)
The following are included here
- preliminary steps (targeted outreach to candidates, pre-screening) and
- the actual selection process (shortlisting, scoring, ranking, testing).
This includes, for example:
- the AI-based creation of job postings, unless they fall under the “low risk” exception (see below);
- Systems that analyze and filter resumes and generate scores, rankings („Top 5“), or suitability categories („high fit“)
- Sourcing tools that search for profiles and create shortlists
- Camera-based aptitude testing (such as assessing the visual abilities of pilot candidates); evaluation of responses in online assessments
- Apprentice Recruitment
- Employment Agency Placement Systems
Not included:
- Tools for job seekers that the individual controls themselves (resume optimization, job recommendations for the candidate)
- Employer branding not tied to a specific job opening
- Anonymized reputation monitoring of the employer
- Tools that check job postings only for problematic wording
- Onboarding information chatbots after hiring (though these may fall under subparagraph b if they Supply or Monitor Power)
Low-Risk Exception:
- A job description generator that creates a job posting based on tasks and qualifications provided by a user
- Verification of a vocational diploma with a binary result („confirmed / not confirmed“) (narrow procedural task)
- Organizing incoming applications in a searchable database (preparatory work)
- Scheduling interviews, including accessibility options (purely logistical)
- Ex-post bias audit using anonymized data (pattern recognition).
Systems that flag and pre-screen applicants as „high risk“ are being introduced Profiling continue to be highly risky.
Regulation of Employment Relationships (lit. b)
„Decision“ should be understood in a functional sense and also includes cases in which a person formally makes a decision but relies primarily on the output. Only decisions that exceed a materiality threshold are included; not every day-to-day operational decision counts.
Recorded:
- Decisions regarding key terms of the contract (compensation, working hours, vacation), promotions, and termination (including the non-renewal of fixed-term contracts and the permanent suspension of platform accounts)
- Assigning tasks based on behavior or personal characteristics (punctuality, response time, reliability scores; withholding delivery slots for low acceptance rates; ranking freelancers by rating)
- systematic monitoring of performance and conduct, the results of which are included in the personnel file
Not included:
- Assignment of tasks based on objective, neutral, external criteria (availability according to the work schedule, required qualifications such as a forklift operator’s license or a law license, geographic proximity)
- Systems used exclusively to comply with external legal obligations (such as transaction logging to prevent market abuse), for purely medical or security purposes, or to protect company property
- Systems that only alert the affected individual to potential errors, without pressuring them to perform better and without notifying the employer; day-to-day operational decisions that do not alter contractual rights (assignment of office space, scheduling of breaks during a shift)
Low-Risk Exception:
- a system that simply indicates when a fixed-term contract is set to expire, without providing an evaluation
For the record: Emotion recognition in the workplace is prohibited under Article 5(1)(f) of the AI Act.
Access to Essential Services (Annex III, No. 5)
There are four use cases to distinguish here:
- Section 5(a): Eligibility review for essential public benefits conducted by or on behalf of government agencies, including the granting, reduction, withdrawal, or recovery of such benefits
- Section 5(b): Assessment of creditworthiness or calculation of a credit score for individuals
- Section 5(c): Risk Assessment and Pricing in Life and Health Insurance
- Section 5(d): Assessment and Classification of Emergency Calls, Dispatch of Emergency Medical Services, Patient Triage
Creditworthiness and Credit Score (lit. b)
This covers both the assessment of creditworthiness and the calculation of a credit score, each considered separately. The decisive factor in each case is the connection to access to credit or to an essential private service:
- Key Services These include, for example, housing, electricity supply, and telecommunications services, as well as other services of comparable importance to natural persons. Furthermore, exclusion from access to such services must be capable of having comparably serious consequences for the life, health, livelihood, or social participation of the individuals concerned. According to the Commission, these include, in particular, health and long-term care services, other utility services such as gas and water supply, and transportation services.
- At Finance Department Access to the following services, for example, is essential:
- Provision of a bank account;
- Payment services;
- Granting of loans and credit;
- Increase in a credit line or credit card limit;
- Granting of mortgage loans;
- public financial services.
- Not significant These include the following services:
- Acquisition of stocks and securities;
- Access to margin trading (trading on credit or with leverage);
- Access to complex financial instruments;
- Premium credit cards;
- specialized loan products, such as leisure or travel loans.
Cases not included:
- Customer Classification and Segmentation for Information or Marketing Purposes
- Pricing Simulations Without Creditworthiness Considerations
- Customer support in filling out the application
- Appeal Processing Following the Decision
- Internal prudential monitoring of credit exposure after loan origination
Fraud Detection
As mentioned, a high-risk AIS can be a credit assessment. This does not apply to systems used primarily to detect financial fraud, even if their output is also incorporated into a credit assessment.
Insurance (lit. c)
- This covers risk assessment and pricing for life and health insurance, including private long-term care insurance, certain retirement savings insurance policies, and residual debt life insurance policies
- Insurance lines such as auto and home contents insurance are not included
Judiciary, including arbitration (Annex III, No. 8)
This involves providing support to judicial authorities or even to Arbitration Proceedings in determining and interpreting the facts and the law, as well as in applying the law
Recorded:
- Interpretation of meaning; application of precedents to the specific facts of the case
- Preparation of draft decisions, including supporting rationale.
Not recorded:
- support functions such as anonymization, transcription, scheduling, or task assignment
- Pure research and keyword search
- Systems operated by parties or their legal representatives who are not acting „on behalf of“ a judicial authority
Other Areas
The Commission also comments on other use cases, which are not discussed in detail here:
- Criminal Prosecution (Annex III, No. 6)
- Migration, Asylum, and Border Control (Annex III, No. 7)
- Democratic Processes (Annex III, No. 8)
