AI GLOSSARY
High-Risk AI
High-risk AI is the second-highest risk category under the EU AI Act—for AI systems with significant impacts on people and fundamental rights. It is subject to strict requirements and is more relevant to many companies than previously thought.
✓ 80+ AI experts ✓ 25+ years of technology expertise ✓ ISO-certified ✓ Made in Germany
Responsibilities
From Risk Management to Documentation
Areas of Application
typically high-risk
Core Components
Governance, Data, Transparency, Oversight
Weeks
Typical preparation time
Why High-Risk AI Is Important for Small and Medium-Sized Businesses
Many companies underestimate which of their AI systems fall under the “high-risk” category—HR recruitment, credit scoring, and audit systems are already included. Addressing these requirements early on helps avoid future roadblocks and fines.
Compliance Requirements
High-risk AI is subject to strict regulatory requirements—violations come at a cost.
Competitive Advantage
Those who prepare early can secure contracts that others are unable to win.
Avoidable Fines
Up to 15 million EUR or 3 percent of global annual revenue—depending on the violation.
Trust in the Market
Compliant AI builds trust among customers, partners, and regulators.
Structured Governance
Requirements strengthen internal AI governance as a whole.
Focus on Quality
High-risk requirements lead to better, more robust AI systems.
What is high-risk AI?
High-risk AI is one of the risk categories defined in the EU AI Act. It encompasses AI systems that can have significant impacts on health, safety, or fundamental rights—for example, in human resources, education, the legal system, border control, or critical infrastructure.
The EU AI Act distinguishes four risk classes: Prohibited (e.g., social scoring), High Risk, Limited Risk (e.g., chatbots subject to transparency requirements), and Minimal Risk.
High-risk AI is subject to numerous obligations: risk management, data quality, technical documentation, transparency, human oversight, robustness, and cybersecurity. Providers and operators share responsibility.
For small and medium-sized enterprises, the classification as high-risk is important—many HR, financial, and credit applications fall into this category. Clarifying this early on saves costly rework.
Requirements for High-Risk AI
Eight Key Requirements for High-Risk AI Systems:
Risk Management System
Data Governance
Technical Documentation
Transparency & Information
Human supervision
Accuracy & Robustness
Cybersecurity
Registration & Conformity Assessment
Best Practices for High-Risk AI
These six principles have proven effective:
- Start early: Compliance takes months—don’t wait until right before the deadline to begin.
- Build cross-functionally: IT, Legal, Compliance, and the business unit must work together.
- Document pragmatically: Use templates and guidelines—don’t reinvent the wheel every time.
- Leverage GDPR synergies: Continue to use existing data protection structures.
- Continuous oversight: Compliance is not a static state, but a process.
- Supplier management: For purchased AI systems, require proof of compliance in the contract.
Risk Class 1
Prohibited
Social scoring, subliminal manipulation. Strictly prohibited in the EU—including for imports.
Prohibited
Risk Class 2
High Risk
HR systems, credit scoring, audit systems, critical infrastructure. Strict requirements.
Strict
Risk Class 3
Limited Risk
Chatbots, deepfakes. Transparency requirement—users must be aware that AI is active.
Transparent
Common Mistakes in High-Risk AI
We frequently encounter these pitfalls:
- Underestimated classification: The system is not identified as high-risk—leading to a rude awakening during the audit.
- IT-Only Perspective: Business units and legal departments are not involved—critical requirements are missing.
- No risk management process: Ad hoc assessments instead of continuous oversight.
- Third-party AI not verified: Responsibility remains with the operator—vendor documentation is mandatory.
- Bias ignored: Data quality and fairness are key requirements—not a minor issue.
Provider vs. Operator vs. User
Three roles in the AI Act with different obligations:
- Provider: Develops and brings an AI system to market. Highest obligations (documentation, conformity assessment).
- Operator: Uses the AI system in their own operations—e.g., HR software with AI. Operational obligations.
- Users: Interact with the system (e.g., job applicants). Right to information and to file a complaint.
Contact Us Now
Frequently Asked Questions About High-Risk AI
-
Is my AI system automatically considered high-risk?
Only if it falls into one of the categories listed in Annex III of the AI Act or is used as a safety component in a regulated product. The vast majority of AI applications pose a limited or minimal risk.
-
When do the high-risk requirements take effect?
For most high-risk systems, starting in August 2026. Different deadlines apply to certain categories (AI in products that are already regulated). Preparations should begin now.
-
What does CE marking mean in the context of AI?
High-risk AI systems must undergo a conformity assessment and bear the CE mark, similar to other regulated products in the EU.
-
Am I a provider or an operator?
Providers: They develop AI or have it developed and bring it to market. Operators: They use purchased AI in their own operations. Both have obligations—providers have more.
-
What happens in the event of violations?
Fines of up to 15 million EUR or 3 percent of global annual revenue (high-risk violations). In addition, market bans, reputational damage, and civil lawsuits.
-
How is high-risk AI related to the GDPR?
Both sets of regulations apply in parallel. The GDPR protects personal data, while the AI Act regulates the system itself. Leverage synergies.
-
How long does the preparation take?
Typically 4–8 months for a single high-risk system. For company-wide compliance, it’s more like 12–24 months. It pays to start early.
Implementing High-Risk AI in Compliance with Regulations
In a free initial consultation, we classify your AI systems and identify compliance gaps—including a concrete roadmap to AI Act compliance.
As an AI partner for small and medium-sized businesses, we bring high-risk AI into productive use in a compliance-ready manner—with governance, documentation, and oversight.
What We Offer
- EU AI Act Glossary — the framework for high-risk AI.
- AI Consulting — Strategy and Governance Development.
- AI Monitoring — Continuous oversight during operation.
- Bias in the Glossary — a key issue in high-risk AI.