Most Companies Don’t Know Their AI Risk Category — Here’s Why That’s a Problem

Image AI-generated. All  text human-written.

Before any organisation can build a credible AI governance program, one question has to be answered first: is your AI system classified as “high-risk” under the EU AI Act?

It sounds like a simple compliance checkbox. In practice, it’s the foundation everything else depends on — and most companies get to it late, or skip it entirely.

Why Classification Comes First

The EU AI Act uses a risk-based structure: some AI uses are banned outright, some are tightly regulated as “high-risk,” and the majority face light-touch or no specific obligations. Which bucket a system falls into determines almost everything that follows — what documentation is required, what conformity assessments apply, what a company has to register, and what penalties it’s exposed to if it gets this wrong.

Skip the classification step, and any governance framework built afterward is standing on guesswork. You can’t scope a risk management system, a data governance process, or human oversight controls for a system whose regulatory status hasn’t actually been determined.

The Two Paths to “High-Risk”

Under Article 6 of the Act, a system can become high-risk in one of two ways:

1. Annex I — Regulated products and safety components If an AI system is a safety component of a product covered by existing EU product-safety legislation (things like machinery, medical devices, toys, or radio equipment) — or is itself such a product — and that product legally requires third-party conformity assessment, the AI system is high-risk.

2. Annex III — Specific high-risk domains Annex III lists defined use cases across sectors: biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration and border control, and the administration of justice. If a system’s intended purpose falls into one of these use cases, it’s presumed high-risk — unless the provider can document that it doesn’t pose a significant risk to health, safety, or fundamental rights, and formally records that assessment before the system goes to market.

A key detail many organisations miss: classification is based on intended purpose, not actual use. The European Commission’s draft guidance clarifies that a system doesn’t become high-risk simply because someone uses it in a sensitive way if that wasn’t its documented intended purpose — but conversely, human oversight or review steps layered on top don’t exempt a system that was designed for a high-risk use case.

A Timeline Update Worth Knowing

If your compliance calendar still says “August 2026” for high-risk obligations, it’s out of date. As part of the EU’s Digital Omnibus package, the Commission agreed in May 2026 to defer these deadlines significantly:

  • Annex III (sector-specific) high-risk systems: obligations now apply from 2 December 2027, not August 2026.
  • Annex I (regulated product/safety component) high-risk systems: obligations now apply from 2 August 2028.

The Commission also published draft guidelines on high-risk classification in May 2026, open for stakeholder feedback until 23 June 2026. Once finalized, these guidelines won’t be legally binding, but they’re expected to carry significant weight as the Commission’s official interpretation — and they include practical, sector-by-sector examples of what does and doesn’t qualify.

The extra runway is useful, but it isn’t a reason to wait. Classification work — mapping systems against Annex I and III, documenting the rationale, and identifying gaps — takes real time, especially across a large AI portfolio.

What “Documented Classification Rationale” Actually Means

It’s not enough to informally conclude a system isn’t high-risk. Providers who determine their system falls outside Annex III must document that assessment before placing the system on the market. If a market surveillance authority later disagrees, that documentation is what stands between a defensible position and a scramble.

This also matters for deployers, not just providers. If a company takes a system that wasn’t classified as high-risk and modifies it or repurposes it in a way that shifts its intended purpose into a high-risk use case, it can effectively “step up” into the provider role under the Act — inheriting the full set of provider obligations.

The Practical Takeaway

Every AI governance framework — risk registers, human oversight processes, technical documentation, conformity assessments — is built on top of a classification decision. Get that decision wrong, or skip it, and the structure above it is unreliable no matter how well-designed it looks.

The organisations in the strongest position right now aren’t the ones with the most polished governance documents. They’re the ones that can point to a clear, current, well-documented answer to one question: where does each of our AI systems sit under Annex I and Annex III — and why?

EU AI Act Compliance Disclaimer

This article is provided for general informational and educational purposes only and should not be considered legal, regulatory, or compliance advice. The EU AI Act is evolving, and its requirements can vary depending on the organisation, AI system, role, and specific use case. For professional advice and guidance on EU AI Act compliance, visit www.exclevelai.eu