High-risk AI systems: what the AI Act requires of your organisation

Professionals reviewing a high-risk AI systems compliance dashboard in a meeting

High-risk AI systems are the focal point of the European AI Regulation (Regulation (EU) 2024/1689), commonly referred to as the AI Act, which introduces a risk-based framework for developing, supplying and using artificial intelligence (AI) systems. The higher the risk to health, safety and fundamental rights, the heavier the obligations.

For organisations, compliance therefore does not begin with drafting technical documentation, but with correct classification. First establish which AI systems are developed, purchased or used within the organisation. Then assess whether a system is prohibited, high-risk, subject to transparency obligations, or outside any specific obligations.

This article sets out when an AI system may qualify as high-risk, which obligations apply to providers and deployers, and which steps organisations can take now. It also covers the current timeline, including the changes under the Digital Omnibus process. The reference date for this article is 25 July 2026.

When is an AI system high-risk?

The assessment of high-risk AI systems is made principally under Article 6 and Annexes I and III of the AI Act. There are two routes.

The first route concerns AI systems that form part of products covered by the European product legislation listed in Annex I and requiring third-party conformity assessment. Think of certain medical devices, machinery, lifts and toys. For these systems the AI Act builds on the existing conformity assessment procedure.

The second route concerns AI systems used in the domains listed in Annex III: biometrics, critical infrastructure, education and vocational training, employment and workforce management, access to essential private and public services, law enforcement, migration, asylum and border control, and the administration of justice and democratic processes. Not every use within such a domain automatically results in classification among high-risk AI systems: the specific function of the system and the conditions of Article 6 must also be assessed.

The exception in Article 6(3)

A system falling within an Annex III domain is not automatically counted among high-risk AI systems: that classification is excluded where it poses no significant risk to the health, safety or fundamental rights of persons and does not materially influence the outcome of decision-making. That may be the case where the system performs only a narrow procedural task, merely improves an activity already carried out by a human, only flags deviations from earlier human decision-making without replacing that assessment, or performs solely a preparatory task.

Reliance on this exception must be carefully reasoned and documented. The organisation records not only the conclusion, but also the facts and the assessment on which that conclusion rests. A provider who considers that an Annex III system does not belong among high-risk AI systems must document that assessment before the system is placed on the market or put into service, and is additionally subject to the registration obligation in Article 49(2).

On one point the Regulation is absolute. Article 6(3) provides that an AI system referred to in Annex III is always counted among high-risk AI systems where it performs profiling of natural persons. The exception cannot be invoked in that case.

What role does your organisation have?

The AI Act distinguishes several roles in the chain. Two of them matter for most organisations. A party that develops an AI system, or places it on the market under its own name or trademark, qualifies as a provider. A party that uses an AI system in the course of its own business without having developed it generally qualifies as a deployer.

That allocation of roles is not static. An organisation that substantially modifies a purchased system, supplies it onward under its own name or trademark, or changes its intended purpose, may still be regarded as a provider and thereby fall under the heavier set of obligations. Establish for each system which role you fulfil, and record that assessment.

The principal obligations

Providers of high-risk AI systems are subject to obligations including those in Articles 8 to 17, 43 and 47 to 49:

  • a risk management system covering the entire lifecycle
  • data governance, including detecting and correcting bias in the data used, including training, validation and testing data
  • technical documentation in accordance with Annex IV, and event logging
  • clear instructions for use for deployers
  • a design enabling effective human oversight
  • requirements on accuracy, robustness and cybersecurity
  • a quality management system, a conformity assessment, an EU declaration of conformity, CE marking and registration in the EU database

For high-risk AI systems used for remote biometric identification as referred to in Annex III, point 1(a), Article 14(5) imposes an additional requirement on human oversight: no action or decision may be taken on the basis of the identification unless it has been separately verified and confirmed by at least two natural persons with the necessary competence, training and authority. This is known as the four-eyes principle.

Deployers are subject to the lighter but no less important obligations of Articles 26 and 27: use in accordance with the instructions for use, competent human oversight, monitoring of the system’s operation, reporting of risks and serious incidents, and retention of the logs for at least six months. Employees who will work with the system, and the persons to whom it is applied, must be informed in advance.

Certain deployers must also carry out a fundamental rights impact assessment, the Fundamental Rights Impact Assessment under Article 27. This applies in any event to bodies governed by public law, to private providers of public services, and to deployers using systems for credit scoring or for assessing insurance risks in life and health insurance.

Timeline and current status

The AI Act entered into force on 1 August 2024 and becomes applicable in phases. In practice it is important to distinguish between obligations that already apply, obligations with a future application date, and announced amendments whose formal entry into force has not yet been completed.

Prohibited practices (Article 5): Applicable since 2 February 2025

AI literacy (Article 4): Applicable since 2 February 2025

General purpose AI models: Applicable since 2 August 2025

Transparency obligations (Article 50): Applicable from 2 August 2026; not deferred

High-risk via Annex III: Formally still 2 August 2026; once the Omnibus enters into force, 2 December 2027 at the latest

High-risk via Annex I: Formally still 2 August 2027; once the Omnibus enters into force, 2 August 2028 at the latest

On 19 November 2025 the European Commission published the Digital Omnibus package, proposing to defer the application of the obligations for high-risk AI systems. A provisional political agreement was reached on 7 May 2026. The European Parliament gave its endorsement on 16 June 2026 and the Council gave its final approval on 29 June 2026.

As at the reference date of this article, however, publication in the Official Journal of the European Union has not yet been completed. The amendment enters into force on the third day following that publication. Until then the original AI Act timeline remains the applicable law, with 2 August 2026 as the application date for the high-risk obligations under Annex III. Publication before that date is widely expected, but is not yet confirmed.

The deferral is moreover structured conditionally. Application of the obligations for high-risk AI systems is tied to a Commission decision establishing that the necessary harmonised standards and supporting instruments are available, followed by a transitional period. The dates of 2 December 2027 and 2 August 2028 function as backstop dates rather than as a simple postponement.

Two points deserve separate attention. First, the transparency obligations of Article 50 and the AI literacy obligation of Article 4 have not been deferred: they remain on their original timeline. Second, the package adds a new prohibition to Article 5, aimed at AI applications generating non-consensual intimate imagery and at AI-generated child sexual abuse material.

For organisations this means that planning against December 2027 is sensible, but that record-keeping should for now be arranged as if August 2026 still binds, until the Official Journal says otherwise.

Supervision and penalties

In the Netherlands, implementing legislation for the AI Act is still lacking as at the reference date of this article. The Dutch Authority for Digital Infrastructure and the Dutch Data Protection Authority are expected to take a central, coordinating role, with sectoral supervisors remaining responsible within their own domains. The precise allocation of powers and its statutory basis must, however, be determined on the basis of the final Dutch implementing legislation.

Article 99 of the AI Act provides for several maximum penalty categories. The level depends on the nature of the infringement and, where relevant, on the undertaking’s worldwide annual turnover. The highest maximum applies to infringement of the prohibited practices in Article 5; a lower maximum applies to infringement of the other obligations, including those for providers and deployers of high-risk AI systems; and the lowest applies to supplying incorrect, incomplete or misleading information to authorities. A more favourable regime applies to small and medium-sized enterprises (SMEs), including start-ups. The actual penalty is determined having regard to the applicable rules on penalties and the circumstances of the case.

Practical roadmap

  • Inventory all AI systems your organisation develops, purchases or uses.
  • Establish for each system which role you fulfil: provider or deployer.
  • Determine the risk category for each system and document that assessment, including any reliance on the exception in Article 6(3).
  • Set up AI governance and appoint a responsible officer.
  • Ensure AI literacy among staff working with these systems; that obligation already applies.
  • Prepare the transparency measures under Article 50 with a view to 2 August 2026.
  • Begin the technical documentation and, where required, the fundamental rights impact assessment in good time.
  • Review supplier contracts on the allocation of roles, information provision and audit rights.
  • Monitor publication of the Omnibus package in the Official Journal and adjust your planning accordingly.

Conclusion

The AI Act fundamentally affects how organisations develop, purchase and use AI. The announced deferral of the high-risk obligations provides extra time, but is not yet applicable law, and the obligations that already apply or take effect on 2 August 2026 are unaffected by it. A prudent approach is therefore to plan against the new dates while remaining prepared for the old ones. For a broader overview of the regulation, see our Complete Guide to the EU AI Act, which complements this article’s focus on high-risk AI systems.

Law & More helps organisations inventory and classify their AI systems, determine their role as provider or deployer, review and draft contracts with AI suppliers, and set up AI governance. Would you like to know which obligations currently apply to your organisation and which steps should take priority? Please feel free to contact us for a no-obligation discussion.

Frequently asked questions

Below we answer the questions we are asked most often on this subject.

What is the AI Act?

The European AI Regulation (Regulation (EU) 2024/1689). It entered into force on 1 August 2024 and becomes applicable in phases, with obligations that grow heavier as the risk posed by an AI system increases.

When is an AI system high-risk?

Through two routes: as part of a product covered by the product legislation listed in Annex I, or through use within one of the domains listed in Annex III. In the latter case the domain alone is not decisive; the specific function and the conditions of Article 6 also count.

Can an Annex III system nonetheless fall outside the high-risk category?

Yes, where it poses no significant risk and does not materially influence decision-making, for instance where it performs a narrow procedural or purely preparatory task. That assessment must be documented. Where the system performs profiling of natural persons, the exception never applies.

Am I a provider or a deployer?

You are a provider if you develop the system or place it on the market under your own name or trademark, and generally a deployer if you use a purchased system. If you substantially modify a purchased system or supply it onward under your own name, you may still become a provider.

What obligations apply to providers?

Among others risk management, data governance, technical documentation, logging, instructions for use, human oversight, requirements on accuracy and cybersecurity, a quality management system, a conformity assessment, CE marking and registration in the EU database.

What obligations apply to deployers?

Use in accordance with the instructions, competent human oversight, monitoring, reporting of risks and serious incidents, and retention of logs for at least six months. Employees involved and the persons to whom the system is applied must be informed in advance.

When must a fundamental rights impact assessment be carried out?

Article 27 requires this of, among others, bodies governed by public law, private providers of public services, and deployers using systems for credit scoring or for assessing insurance risks in life and health insurance.

Have the high-risk obligations been deferred?

An adopted amendment defers application to 2 December 2027 at the latest for Annex III and 2 August 2028 for Annex I. As at the reference date of this article that amendment has not yet been published in the Official Journal, so the original date of 2 August 2026 formally still applies.

What already applies today?

The prohibited practices of Article 5 and the AI literacy obligation since 2 February 2025, and the rules for general purpose AI models since 2 August 2025. The transparency obligations of Article 50 take effect on 2 August 2026 and have not been deferred.

Who supervises the AI Act in the Netherlands?

Implementing legislation is still lacking. The Dutch Authority for Digital Infrastructure and the Dutch Data Protection Authority are expected to take a central, coordinating role, alongside sectoral supervisors. The final allocation of powers will follow from the Dutch implementing legislation.

What should my organisation do now?

Start with an inventory of all AI systems you develop, purchase or use. Record for each system which role you have, which risk category applies and which obligations follow. Also set up AI governance, ensure AI literacy, and review supplier contracts on the allocation of roles, information provision and audit rights.

Need Legal Assistance?

Contact Law & More for expert guidance on your legal matters. Our multilingual team is ready to help.

Related articles

Cyberattacks such as ransomware, phishing, DDoS attacks and computer intrusion rarely affect only the organisation
Cybersecurity is no longer purely a technical matter. It is also a legal and governance
An IT lawyer helps businesses with IT contracts, GDPR compliance, the AI Act, cybersecurity and

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.