Whether an AI counts as high-risk is decided not by its technology but by its purpose — and the list of those purposes is Annex III of the AI Act. What you find there is not science fiction but office routine: pre-sorting applications, assessing creditworthiness. Which is exactly how companies slide into the high-risk category without noticing — usually via a feature in purchased software. The deadlines were postponed to 2 December 2027 — which changes nothing about whether you’re affected.
As always: a technical assessment, not legal advice.
The eight areas — translated into daily life
Annex III (full text at EUR-Lex) covers eight areas. This is what they look like with the legal language stripped off:
| Area | Sounds corporate, but means … |
|---|---|
| Biometrics | face recognition at the factory gate, biometric categorisation |
| Critical infrastructure | AI control in energy, water, transport networks |
| Education | automated exam grading, admission decisions |
| Employment | CV screening, performance evaluation, AI shift allocation |
| Essential services | credit scoring, insurance risk assessment, public benefits |
| Law enforcement | predictive policing, evidence evaluation |
| Migration | asylum and visa decision support |
| Justice and democracy | support for judicial decisions, influencing elections |
For SMEs, the bold rows are the ones that matter. The employment row is the treacherous one, because modern HR suites ship ranking and matching functions as convenience features — switch them on and you’re operating a high-risk system, even with ten employees.
Being a deployer is manageable — becoming a provider is expensive
The heavy end of the AI Act — risk management, technical documentation, conformity assessment — sits with the system’s provider. As a deployer you have the shorter list: use the system per the provider’s instructions, put trained people in charge of oversight, control the input data — for the more sensitive cases that often means running the model in-house instead of at an outside vendor — retain logs, report incidents.
One trap deserves its own paragraph: substantially modifying a purchased system, or reselling it under your own name, can legally turn you into the provider — with the full set of duties. Where exactly that line runs is lawyer territory, but the rule of thumb is simple: configuring is harmless, deep rebuilding and rebadging are not.
What to check now, concretely
The first step is the same as for every AI Act duty: the AI inventory. Walk through it and ask, for each entry, whether it serves an Annex III purpose — especially anything that evaluates people, ranks them, or decides their access to something. For each hit, clarify three things: what does the vendor say about their AI Act preparations? Who at your company exercises the human oversight, and is that person trained for it? And which data classes flow in — the GDPR question doesn’t vanish just because the AI Act arrives.
There’s enough time until December 2027 — if you start. The expensive variant is the usual one: park the topic until the HR software vendor sends a contract amendment in autumn 2027 and nobody can place what’s in it. If you’d rather do the classification properly once, get support for it — it’s a workshop, not a retainer.
Not sure whether your HR, scoring or evaluation tools fall under Annex III? Get in touch — we’ll go through your inventory and sort what is genuinely high-risk from what merely sounds like it.