AI General

EU AI Act 2025: How to Classify and Comply with High-Risk AI Systems

Equip IgeraSolutions
June 17, 2026
11 min read

EU AI Act 2025: How to Classify and Comply with High-Risk AI Systems

The EU AI Act (Regulation (EU) 2024/1689) divides AI systems into four risk tiers. High-risk systems — defined by Annex III or their role as safety components in regulated products — face the most demanding obligations: conformity assessments, mandatory technical documentation, and ongoing post-market monitoring. Providers that deploy these systems in the EU market must be ready to comply by August 2026, regardless of where they are headquartered.

KEY DEFINITION

High-Risk AI System — EU AI Act Art. 6 + Annex III

Article 6 establishes two routes to high-risk classification:

(1) Safety-component route: AI systems that are safety components of products already subject to EU harmonisation legislation (machinery, medical devices, aviation, automotive, rail, lifts, explosives). If that product requires a third-party conformity assessment, the AI component is automatically high-risk.

(2) Standalone Annex III route: AI systems listed directly in Annex III, covering eight domains:

  1. Biometrics — remote biometric identification, emotion recognition, biometric categorisation used for consequential decisions
  2. Critical infrastructure — AI managing road traffic, water, gas, heating, electricity supply
  3. Education and vocational training — systems determining access, admission, assessment outcomes
  4. Employment, workers management and self-employment — recruitment, task allocation, performance monitoring, promotion or termination decisions
  5. Access to essential private and public services — credit scoring, insurance risk assessment, social benefit eligibility, emergency dispatch
  6. Law enforcement — polygraphs, crime risk assessment, analysis of CCTV footage, evidence reliability assessment
  7. Migration, asylum, border control — risk assessment of individuals, verification of travel documents, asylum and visa decisions
  8. Administration of justice and democratic processes — AI assisting courts in case research, fact-finding, law interpretation

MARKET DATA

23%

"Only 23% of European organisations deploying AI systems have conducted a formal risk classification assessment under the EU AI Act, leaving the majority unprepared for the August 2026 deadline."

— IDC European AI Compliance Survey, 2025

Which AI systems fall under Annex III of the EU AI Act?

Annex III is the operative list most organisations should work through first. The eight categories listed above are not exhaustive technology types — they are defined by use case and consequence. An AI system that recommends job candidates is high-risk; one that schedules internal meetings is not. The distinction is whether the output materially affects a natural person's access to education, employment, essential services, or fundamental rights.

The Commission retains the power to update Annex III by delegated act. The EU AI Office published updated guidance in early 2025 clarifying that general-purpose AI models (GPAI) integrated into Annex III applications inherit the high-risk classification of the downstream application — the GPAI provider bears separate transparency and documentation obligations, but the deployer remains responsible for conformity of the complete system.

One important exclusion: Article 6(3) creates a self-assessment exemption for Annex III systems that are "narrow procedural tasks", do not produce profiles of individuals, do not replace human assessment, and whose output is easily reversible. Providers claiming this exemption must document their reasoning — it is not a blanket get-out.

What obligations apply to high-risk AI providers?

Chapter III, Section 2 of the AI Act sets out nine categories of obligation for providers of high-risk systems. These apply from the point of placing a system on the EU market or putting it into service, not from when enforcement begins.

  • Risk management system (Art. 9): A continuous, iterative process spanning the full lifecycle — design through decommissioning. Must identify known and reasonably foreseeable risks, estimate their probability and severity, and document mitigation measures. Not a one-off audit.
  • Data governance (Art. 10): Training, validation, and test datasets must meet quality criteria for relevance, representativeness, and freedom from bias. Providers must document data origins, processing steps, and any known limitations.
  • Technical documentation (Art. 11 + Annex IV): A detailed dossier covering system architecture, training methodology, performance metrics, limitations, and foreseeable misuse scenarios. Must be kept up to date and produced on request for market surveillance authorities.
  • Record-keeping and logging (Art. 12): Automatic logging of events sufficient to trace the system's operation across its lifespan — essential for post-incident investigation.
  • Transparency towards deployers (Art. 13): Providers must supply deployers with clear instructions for use, including intended purpose, known performance limitations, maintenance requirements, and human oversight mechanisms.
  • Human oversight (Art. 14): High-risk systems must be designed so that a natural person can effectively monitor, understand, intervene, override, or halt the system. This cannot be a nominal capability — it must be practically achievable.
  • Accuracy, robustness, and cybersecurity (Art. 15): Systems must achieve declared performance levels under reasonably foreseeable conditions, including adversarial inputs.
  • Quality management system (Art. 17): Providers with more than 10 employees must establish a documented QMS covering development, monitoring, and corrective action procedures.
  • Post-market monitoring (Art. 72): Active collection and analysis of data on system performance in real-world deployment. Serious incidents must be reported to national market surveillance authorities within defined timeframes.

What is the conformity assessment process for high-risk AI?

The conformity assessment is the formal process by which providers demonstrate their high-risk AI system meets the Act's requirements before market placement. The outcome — an EU Declaration of Conformity — is functionally equivalent to CE marking for the AI system.

For most Annex III systems, the AI Act permits internal conformity assessment (Annex VI procedure): the provider conducts and documents its own assessment, registers the system in the EU database for high-risk AI (operational from August 2026), and issues the Declaration of Conformity. Third-party involvement is mandatory only for:

  • Biometric identification systems (except verification with explicit user consent)
  • AI systems that are safety components of products already requiring third-party assessment under sectoral legislation (medical devices, machinery, etc.)

How to Conduct a High-Risk AI Classification Assessment

1

Inventory all AI systems in use

Create a register of every AI-powered tool or component deployed internally or customer-facing. Include third-party SaaS products where AI outputs influence decisions about individuals.

2

Apply the Article 6 two-path test

For each system: (a) Is it a safety component of a regulated product requiring third-party conformity? (b) Does its use case match one of the eight Annex III categories? If either answer is yes, the system is high-risk unless the Article 6(3) exemption applies.

3

Document the classification rationale

Whether classified high-risk or not, record the reasoning. Market surveillance authorities may request justification for non-classification. This documentation also supports any future fundamental rights impact assessment.

4

Gap-assess against Chapter III obligations

For each high-risk system, map current practices against the nine provider obligations. Assign owners and remediation timelines against the August 2026 deadline.

5

Register and monitor

From August 2026, high-risk AI systems must be registered in the EU AI database before deployment. Establish a post-market monitoring programme to capture real-world performance data.

Which sectors face the strictest AI Act enforcement?

Enforcement is risk-proportionate. Financial services, healthcare, and employment are the three sectors expected to attract the earliest enforcement attention. Credit-scoring AI systems fall squarely within Annex III category 5. HR AI tools for CV screening and performance monitoring sit in category 4. Both sectors have existing regulatory frameworks (EBA guidelines, GDPR profiling restrictions) that will interact with AI Act obligations, creating overlapping compliance workstreams from mid-2026.

Obligation High-Risk AI Limited Risk AI Minimal Risk AI
Risk management system Mandatory (Art. 9) Not required Not required
Technical documentation Mandatory (Annex IV) Not required Not required
Conformity assessment Mandatory (Art. 43) Not required Not required
Human oversight Mandatory (Art. 14) Recommended Not required
Post-market monitoring Mandatory (Art. 72) Not required Not required

Does your AI tool meet EU AI Act compliance requirements?

IgeraFincas is designed with AI Act compliance in mind — transparent reasoning, auditable outputs, human oversight built in.

See How IgeraFincas Complies

AI disclosure built in · Auditable logs · Human override controls

How does the AI Act affect property management AI tools?

Property management AI sits, in most configurations, below the high-risk threshold. A tool that answers residents' questions about building rules, generates meeting minutes, or flags maintenance requests does not fall within any of the eight Annex III categories. It does not determine access to housing, employment, or financial services; it does not produce biometric data; it does not assist law enforcement.

This places standard property management AI under the limited risk category (Art. 50), which carries two main obligations: (1) users must be informed they are interacting with an AI system, and (2) the system must not be designed to impersonate natural persons in ways that could deceive users to their detriment. Both are straightforward to implement.

The classification changes if the AI system begins making or substantively influencing binding decisions — for example, AI that produces creditworthiness assessments of tenants for rental applications, or AI used in employment decisions about property management staff. These use cases push into Annex III categories 4 and 5 respectively, triggering the full high-risk compliance programme.

IgeraFincas — AI Compliance Query

Property Manager asks:

"Is an AI chatbot that answers residents' questions about building rules classified as high-risk under the EU AI Act?"

IgeraFincas responds:

No — an AI assistant answering general property management questions falls under 'limited risk' (Art. 50 EU AI Act), not high-risk. You need to (1) disclose it's an AI to users, and (2) ensure it doesn't make binding decisions affecting residents' rights. IgeraFincas includes a mandatory AI disclosure in every interaction and routes decisions to the property manager. Want me to generate a compliance checklist for your deployment?

⏱ Instant response 📄 Art. 50 EU AI Act cited ✅ Flags compliance steps 🚫 0 hallucinations

Ready to make AI Act compliance straightforward?

IgeraFincas provides built-in AI disclosures, auditable conversation logs, and human-override controls — the three pillars of limited-risk AI compliance for property managers.

Explore IgeraFincas

14-day free trial · No card required · Setup in under 24 hours

Key takeaways

  • High-risk classification follows two paths: safety-component of a regulated product, or direct Annex III listing — know which applies to every AI system you deploy or develop.
  • The August 2026 deadline for high-risk AI compliance is a hard enforcement date. Providers without a conformity assessment face fines up to €15 million or 3% of global annual turnover.
  • Most property management AI (question-answering, document summarisation, maintenance triaging) is limited-risk, not high-risk — but you must still disclose AI use to residents and maintain human oversight over binding decisions.
  • The conformity assessment for most Annex III systems can be conducted internally. Third-party notified bodies are mandatory only for biometric identification systems and AI in safety-critical regulated products.
  • GDPR and the AI Act overlap substantially in their data governance requirements — a single unified compliance programme covering both is more efficient than treating them as separate workstreams.

Frequently Asked Questions

What is the EU AI Act compliance timeline for high-risk AI systems?

The AI Act entered into force on 1 August 2024. Prohibited AI practices became unlawful on 2 February 2025. High-risk AI obligations (Chapters III and IV) apply from 2 August 2026. GPAI model obligations applied from 2 August 2025. The EU AI database — where high-risk systems must be registered — was due to be operational by August 2026.

How do GDPR obligations overlap with the EU AI Act?

The overlap is substantial and deliberate. GDPR's data minimisation, purpose limitation, and accuracy principles align closely with the AI Act's data governance requirements (Art. 10). The AI Act's transparency obligations reinforce GDPR's right to explanation for automated decisions (Art. 22 GDPR). The simplest approach is to extend your existing DPIA process to incorporate AI Act classification and risk management documentation simultaneously.

What are the fines for non-compliance with EU AI Act high-risk obligations?

The fine structure is tiered. Violations relating to high-risk AI systems carry fines of up to €15 million or 3% of global annual turnover, whichever is higher. Violations of prohibited practices (Art. 5) carry fines up to €35 million or 7% of global annual turnover. Providing false or misleading information to authorities can result in fines up to €7.5 million or 1.5% of turnover.

Is there a CE marking equivalent under the EU AI Act?

For standalone Annex III AI systems, the equivalent is the EU Declaration of Conformity, issued after completing the conformity assessment under Annex VI. This Declaration must be kept for 10 years after market placement and made available to authorities on request. Registration in the EU AI database functions as the publicly accessible record of compliance.

Does the EU AI Act apply to UK-based organisations post-Brexit?

Yes, in the same way the GDPR applies extraterritorially. If a UK-based organisation places a high-risk AI system on the EU market, or uses a high-risk AI system whose outputs affect individuals located in the EU, the AI Act applies. UK organisations without an EU establishment must appoint an EU-based authorised representative.

What is a fundamental rights impact assessment and when is it required?

Article 27 requires deployers of certain high-risk AI systems — specifically public bodies and private operators providing public services — to conduct a fundamental rights impact assessment (FRIA) before deploying. The FRIA requires the deployer to assess the potential impact on privacy, non-discrimination, freedom of expression, access to justice, and other fundamental rights. The assessment must be registered in the EU AI database.

Editorial Note — June 2026 | Sources: Regulation (EU) 2024/1689 (EU AI Act), Articles 6, 9–17, 43, 50, 72 and Annexes III, IV, VI; EU AI Office published guidance, 2025; IDC European AI Compliance Survey, 2025. This content does not constitute legal advice; organisations should seek qualified EU legal counsel for formal compliance programmes. | IgeraFincas — AI-powered property management built for EU AI Act compliance.

#EU AI Act high risk AI systems#AI Act compliance 2025 2026#Annex III EU AI Act classification#high risk AI obligations#EU AI Act property management

COMPARTIR

Comparte el conocimiento con tu red