Is your AI use case 'high-risk' under the EU AI Act?

The EU AI Act sorts AI by risk, and "high-risk" systems — those used in areas that significantly affect people's rights or safety, like employment, credit, education, critical infrastructure and law enforcement — carry the heaviest obligations. If your use case falls in one of these areas, factor the requirements into scope, budget and timeline from the start.

General information for buyers, not legal advice, and a simplified overview of an evolving framework. Confirm your classification with qualified counsel.

The four risk tiers, briefly

The Act runs from unacceptable-risk (prohibited), through high-risk (heavy obligations), to limited-risk (transparency duties) and minimal-risk (few obligations). Most business AI sits in the lower tiers — but if yours is high-risk, the difference is significant.

Common high-risk categories

Employment and workers

AI used to recruit, screen, evaluate, promote or terminate — decisions that materially affect someone's livelihood.

Essential services and credit

AI that decides access to essential private and public services, including creditworthiness and some insurance decisions.

Education

AI used to determine access to education, or to score exams and assessments.

Critical infrastructure

AI as a safety component in the management and operation of critical infrastructure (e.g. utilities, transport).

Law enforcement, migration, justice

AI used in policing, border and migration management, or the administration of justice.

Safety components of regulated products

AI built into products already covered by EU safety legislation, as a safety component.

What to do if you might be high-risk

Classify early, take specialist advice, and build the requirements into the project rather than bolting them on later. A capable agency should help you classify and produce the documentation. For the wider picture, see what the EU AI Act means when you're buying AI and EU AI Act vs GDPR.

Agencies that can handle high-risk AI

NorthBridge AI connects you with vetted agencies experienced in European compliance, with a Statement of Work that can document risk classification and the obligations that follow. See how it works.

Frequently asked questions

What counts as high-risk under the EU AI Act?

The EU AI Act treats AI as high-risk when it's used in areas that can significantly affect people's rights or safety — examples include AI used in employment decisions (hiring, promotion), access to essential services like credit and insurance, education and exam scoring, critical infrastructure, law enforcement, migration, and certain safety components of regulated products. High-risk systems carry the heaviest obligations. This is general information, not legal advice; confirm your classification with qualified counsel.

What are the EU AI Act risk tiers?

There are four broad tiers: unacceptable-risk uses that are prohibited outright; high-risk systems that carry heavy obligations around risk management, data governance, human oversight, transparency and record-keeping; limited-risk systems with transparency duties (such as telling users they're dealing with AI); and minimal-risk systems with few obligations. Your duties scale sharply as you move up the tiers.

What happens if my AI system is high-risk?

High-risk systems carry substantial obligations, which can include risk management, data governance, technical documentation, human oversight, transparency, and record-keeping. As a deployer you may have your own duties on top of the provider's. If your use case is potentially high-risk, factor these requirements into scope, budget and timeline from the start, and take specialist legal advice.

Build high-risk AI with the right agency

Vetted, European-ready agencies with compliance built into the SOW.

Browse verified agencies