Most of the EU AI Act's heaviest obligations apply to a defined set of high-risk systems. Working out whether yours is one of them is the first governance question, and a recent delay to those duties makes it easy to put off.

Where the line sits

Annex III lists the high-risk categories. They include uses in employment, credit and insurance, education, essential public and private services, law enforcement, and the operation of critical infrastructure. A system that makes or materially shapes decisions in one of these areas is likely to be caught, whether or not it was sold as an AI product.

Time to prepare

EU institutions have agreed to defer the high-risk obligations for standalone Annex III systems to December 2027. The categories themselves are unchanged. The extra room is meant to let standards bodies finish the technical detail that conformity work depends on. Firms that map their systems against Annex III now will face a lighter task later than those that read the new date as permission to wait.

Part of our guide: EU AI Act compliance for UK organisations.

Settle your scope early

HEX 165 checks whether your systems fall within Annex III and how they measure against the duties that apply. Get in touch or read more about HEX 165.