High-risk AI systems are the focal point of the European AI Regulation (Regulation (EU) 2024/1689), commonly referred to as the AI Act, which introduces a risk-based framework for developing, supplying and using artificial intelligence (AI) systems. The higher the risk to health, safety and fundamental rights, the heavier the obligations.
For organisations, compliance therefore does not begin with drafting technical documentation, but with correct classification. First establish which AI systems are developed, purchased or used within the organisation. Then assess whether a system is prohibited, high-risk, subject to transparency obligations, or outside any specific obligations.
This article sets out when an AI system may qualify as high-risk, which obligations apply to providers and deployers, and which steps organisations can take now. It also sets out the timeline as it now stands, after the deferral of the high-risk obligations under the Digital Omnibus.
When is an AI system high-risk?
The assessment of high-risk AI systems is made principally under Article 6 and Annexes I and III of the AI Act. There are two routes.
The first route concerns AI systems that form part of products covered by the European product legislation listed in Annex I and requiring third-party conformity assessment. Think of certain medical devices, machinery, lifts and toys. For these systems the AI Act builds on the existing conformity assessment procedure.
The second route concerns AI systems used in the domains listed in Annex III: biometrics, critical infrastructure, education and vocational training, employment and workforce management, access to essential private and public services, law enforcement, migration, asylum and border control, and the administration of justice and democratic processes. Not every use within such a domain automatically results in classification among high-risk AI systems: the specific function of the system and the conditions of Article 6 must also be assessed.
The exception in Article 6(3)
A system falling within an Annex III domain is not automatically counted among high-risk AI systems: that classification is excluded where it poses no significant risk to the health, safety or fundamental rights of persons and does not materially influence the outcome of decision-making. That may be the case where the system performs only a narrow procedural task, merely improves an activity already carried out by a human, only flags deviations from earlier human decision-making without replacing that assessment, or performs solely a preparatory task.
Reliance on this exception must be carefully reasoned and documented. The organisation records not only the conclusion, but also the facts and the assessment on which that conclusion rests. A provider who considers that an Annex III system does not belong among high-risk AI systems must document that assessment before the system is placed on the market or put into service, and is additionally subject to the registration obligation in Article 49(2).
On one point the Regulation is absolute. Article 6(3) provides that an AI system referred to in Annex III is always counted among high-risk AI systems where it performs profiling of natural persons. The exception cannot be invoked in that case.
What role does your organisation have?
The AI Act distinguishes several roles in the chain. Two of them matter for most organisations. A party that develops an AI system, or places it on the market under its own name or trademark, qualifies as a provider. A party that uses an AI system in the course of its own business without having developed it generally qualifies as a deployer.
That allocation of roles is not static. An organisation that substantially modifies a purchased system, supplies it onward under its own name or trademark, or changes its intended purpose, may still be regarded as a provider and thereby fall under the heavier set of obligations. Establish for each system which role you fulfil, and record that assessment.
The principal obligations
Providers of high-risk AI systems are subject to obligations including those in Articles 8 to 17, 43 and 47 to 49:
- a risk management system covering the entire lifecycle
- data governance, including detecting and correcting bias in the data used, including training, validation and testing data
- technical documentation in accordance with Annex IV, and event logging
- clear instructions for use for deployers
- a design enabling effective human oversight
- requirements on accuracy, robustness and cybersecurity
- a quality management system, a conformity assessment, an EU declaration of conformity, CE marking and registration in the EU database
For high-risk AI systems used for remote biometric identification as referred to in Annex III, point 1(a), Article 14(5) imposes an additional requirement on human oversight: no action or decision may be taken on the basis of the identification unless it has been separately verified and confirmed by at least two natural persons with the necessary competence, training and authority. This is known as the four-eyes principle.
Deployers are subject to the lighter but no less important obligations of Articles 26 and 27: use in accordance with the instructions for use, competent human oversight, monitoring of the system’s operation, reporting of risks and serious incidents, and retention of the logs for at least six months. Employees who will work with the system, and the persons to whom it is applied, must be informed in advance.
Certain deployers must also carry out a fundamental rights impact assessment, the Fundamental Rights Impact Assessment under Article 27. This applies in any event to bodies governed by public law, to private providers of public services, and to deployers using systems for credit scoring or for assessing insurance risks in life and health insurance.
Timeline and current status
The AI Act entered into force on 1 August 2024 and becomes applicable in phases. In practice it is important to distinguish between obligations that already apply, obligations with a future application date, and announced amendments whose formal entry into force has not yet been completed.
Prohibited practices (Article 5): Applicable since 2 February 2025
AI literacy (Article 4): Applicable since 2 February 2025
General purpose AI models: Applicable since 2 August 2025
Transparency obligations (Article 50): applicable since 2 August 2026; not deferred
High-risk via Annex III: applicable from 2 December 2027, following the deferral
High-risk via Annex I: applicable from 2 August 2028, following the same deferral
That deferral is settled law. The European Commission presented the Digital Omnibus package on 19 November 2025 with a proposal to postpone the obligations for high-risk AI systems. The amending regulation, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026.
Only the high-risk regime moved. The obligations under Chapter III for systems classified through Annex III now apply from 2 December 2027, and those for systems classified through Annex I from 2 August 2028. Everything else kept its original date, so the deferral did not create a general pause in the AI Act.
The postponement is not unconditional in the way a simple change of date would be. Application of the high-risk obligations is linked to the availability of the harmonised standards and supporting instruments needed to comply with them, and the new dates operate as the outer limit of that arrangement rather than as a target that can still slip further. Planning on the assumption of another extension is therefore unwise.
Two points deserve separate attention. First, the transparency obligations of Article 50 and the AI literacy obligation of Article 4 were not deferred: Article 50 has applied since 2 August 2026 and Article 4 since 2 February 2025. Second, the package adds a new prohibition to Article 5, aimed at AI applications generating non-consensual intimate imagery and at AI-generated child sexual abuse material.
For organisations this means that December 2027 is the date to plan the high-risk documentation against, while the transparency, literacy and general purpose obligations are matters of present compliance rather than preparation.
Supervision and penalties
In the Netherlands the implementing act for the AI Act is not yet in force. A draft was released for public consultation on 20 April 2026. It gives the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) the role of supervisor for the fields in which no sector supervisor is designated, with a dedicated AI unit, and gives the Dutch Authority for Digital Infrastructure (RDI) a coordinating role, while sector supervisors keep their own domains. Until that act has been passed and brought into force, the precise allocation of powers and the national penalty regime are not settled.
Article 99 of the AI Act provides for several maximum penalty categories. The level depends on the nature of the infringement and, where relevant, on the undertaking’s worldwide annual turnover. The highest maximum applies to infringement of the prohibited practices in Article 5; a lower maximum applies to infringement of the other obligations, including those for providers and deployers of high-risk AI systems; and the lowest applies to supplying incorrect, incomplete or misleading information to authorities. A more favourable regime applies to small and medium-sized enterprises (SMEs), including start-ups. The actual penalty is determined having regard to the applicable rules on penalties and the circumstances of the case.
Practical roadmap
- Inventory all AI systems your organisation develops, purchases or uses.
- Establish for each system which role you fulfil: provider or deployer.
- Determine the risk category for each system and document that assessment, including any reliance on the exception in Article 6(3).
- Set up AI governance and appoint a responsible officer.
- Ensure AI literacy among staff working with these systems; that obligation already applies.
- Implement the transparency measures under Article 50; they have applied since 2 August 2026.
- Begin the technical documentation and, where required, the fundamental rights impact assessment in good time.
- Review supplier contracts on the allocation of roles, information provision and audit rights.
- Plan the high-risk documentation against 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems.
What the AI Act asks of your organisation
The AI Act fundamentally affects how organisations develop, purchase and use AI. The deferral of the high-risk obligations buys time for the heaviest part of the regime, but it leaves everything else in place: the prohibitions of Article 5, the AI literacy obligation, the rules for general purpose AI models and the transparency obligations of Article 50 all apply today. The time gained is best spent on classification and documentation, because those are the steps that cannot be compressed later. For a broader overview of the regulation, see our Complete Guide to the EU AI Act, which complements this article’s focus on high-risk AI systems.
Law & More helps organisations inventory and classify their AI systems, determine their role as provider or deployer, review and draft contracts with AI suppliers, and set up AI governance. If you would like to know which obligations currently apply to your organisation and which steps should take priority? please feel free to contact us.
Frequently asked questions
Below we answer the questions we are asked most often on this subject.
What is the AI Act?
The European AI Regulation (Regulation (EU) 2024/1689). It entered into force on 1 August 2024 and becomes applicable in phases, with obligations that grow heavier as the risk posed by an AI system increases.
When is an AI system high-risk?
Through two routes: as part of a product covered by the product legislation listed in Annex I, or through use within one of the domains listed in Annex III. In the latter case the domain alone is not decisive; the specific function and the conditions of Article 6 also count.
Can an Annex III system nonetheless fall outside the high-risk category?
Yes, where it poses no significant risk and does not materially influence decision-making, for instance where it performs a narrow procedural or purely preparatory task. That assessment must be documented. Where the system performs profiling of natural persons, the exception never applies.
Am I a provider or a deployer?
You are a provider if you develop the system or place it on the market under your own name or trademark, and generally a deployer if you use a purchased system. If you substantially modify a purchased system or supply it onward under your own name, you may still become a provider.
What obligations apply to providers?
Among others risk management, data governance, technical documentation, logging, instructions for use, human oversight, requirements on accuracy and cybersecurity, a quality management system, a conformity assessment, CE marking and registration in the EU database.
What obligations apply to deployers?
Use in accordance with the instructions, competent human oversight, monitoring, reporting of risks and serious incidents, and retention of logs for at least six months. Employees involved and the persons to whom the system is applied must be informed in advance.
When must a fundamental rights impact assessment be carried out?
Article 27 requires this of, among others, bodies governed by public law, private providers of public services, and deployers using systems for credit scoring or for assessing insurance risks in life and health insurance.
Have the high-risk obligations been deferred?
Yes. Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026, moved application to 2 December 2027 for Annex III and 2 August 2028 for Annex I. Only the high-risk regime was deferred.
What already applies today?
The prohibited practices of Article 5 and the AI literacy obligation since 2 February 2025, and the rules for general purpose AI models since 2 August 2025. The transparency obligations of Article 50 have applied since 2 August 2026 and were not deferred.
Who supervises the AI Act in the Netherlands?
The Dutch implementing act is not yet in force. A draft went out for consultation on 20 April 2026, giving the Autoriteit Persoonsgegevens the residual supervisory role and the RDI a coordinating one, alongside the sector supervisors. The final allocation of powers follows from that act.
What should my organisation do now?
Start with an inventory of all AI systems you develop, purchase or use. Record for each system which role you have, which risk category applies and which obligations follow. Also set up AI governance, ensure AI literacy, and review supplier contracts on the allocation of roles, information provision and audit rights.

