What makes an AI system 'high-risk' under the EU AI Act?
Under the EU AI Act, a system is classified high-risk if it falls within one of Annex III's eight domains (and doesn't qualify for the Article 6(3) narrow-task exception), or if it's a safety component of a product already regulated under EU product safety legislation requiring third-party conformity assessment.
What follows from high-risk classification
A high-risk classification triggers several obligations: Annex IV technical documentation, a risk-management system maintained across the system's lifecycle, data governance requirements, human oversight measures, a conformity assessment (internal control or notified-body, depending on the category), registration in the EU database, and post-market monitoring.
Not the same as prohibited
High-risk is a distinct, separate category from Article 5's prohibited practices. A prohibited practice has no compliance pathway — it must stop. A high-risk system is legal to operate, provided the obligations above are met.