Skip to content

Glossary

High-risk AI system

A European legal category for uses that can seriously affect health, safety or people's rights, carrying the heaviest duties before anything is deployed.

In plain terms

A label European law puts on uses of these tools where getting it wrong seriously hurts somebody. It is not about how clever the technology is. It is about what the output decides, so a simple tool making an important decision counts and a sophisticated one writing marketing copy does not.

01

Why it matters

Because the categories cover precisely the work businesses most want to hand over. Screening applicants, managing staff and deciding who gets access to something are all named, so the everyday assumption that this is about robots and weapons rather than about an ordinary office tool is exactly backwards.

02

How it works

The framework sorts systems into four levels: unacceptable, high, limited, and minimal or none. Most ordinary business use sits at the bottom two, which is worth saying plainly, because the point of the category is that a specific and named minority does not.

What lands a use in the top populated tier is the potential for serious harm to health, safety or people's fundamental rights. The test is about consequence rather than complexity, so the sophistication of the tool is not what decides it.

The named examples are ordinary commercial territory. Safety components in critical infrastructure, systems used in education institutions, tools for employment and the management of workers, and certain uses that give access to essential private and public services are all specifically identified.

The requirements attach before deployment rather than after. Risk assessment and mitigation, high-quality data chosen to reduce discriminatory outcomes, activity logging so results can be traced, detailed documentation, clear information to whoever deploys it, human oversight measures, and robustness, security and accuracy: all of that is meant to exist first.

One of those requirements points at your supplier. Clear and adequate information has to reach the organisation deploying the system, which means a buyer in this territory should be receiving documentation rather than asking whether any exists.

The classification is about the use, not the product. The same underlying tool can sit in different tiers depending on what it is pointed at, so an assessment attaches to a deployment and has to be revisited when the deployment changes.

What people expect the line to be, and what it is

What people expect the line to be, and what it isThe gap between the columns explains a specific and common failure. A team adopting a well-known assistant to help sift applications reasons about it as an office tool: it is not autonomous, nobody is calling it a system, and the final decision still sits with a person. All of that is true and none of it is the test. Meanwhile the same organisation may run something genuinely sophisticated on internal document search and worry about it far more, because it feels like the thing regulation would be aimed at. The correction is not to treat everything as though it were in the category, which would be expensive and wrong, but to sort the estate once by consequence rather than by capability: which of these tools touch hiring, staff management, education or access to something people need. That list is usually short, it rarely matches the list of tools people were already worried about, and knowing which is which is most of the work.The expected testHow advanced the system is.Whether it acts on its own.Whether it is called AI at all.The actual testWhat the output can do tosomebody.Whether the setting is a namedone.What this particular deploymentdecides.Every line on the left describesthe technology. Every line onthe right describes theconsequence. Organisationsassess themselves against theleft-hand column, which is whythey conclude they are outside acategory that names the workthey are doing.
The gap between the columns explains a specific and common failure. A team adopting a well-known assistant to help sift applications reasons about it as an office tool: it is not autonomous, nobody is calling it a system, and the final decision still sits with a person. All of that is true and none of it is the test. Meanwhile the same organisation may run something genuinely sophisticated on internal document search and worry about it far more, because it feels like the thing regulation would be aimed at. The correction is not to treat everything as though it were in the category, which would be expensive and wrong, but to sort the estate once by consequence rather than by capability: which of these tools touch hiring, staff management, education or access to something people need. That list is usually short, it rarely matches the list of tools people were already worried about, and knowing which is which is most of the work.
03

Seen in the wild

  • Sorting applicants at the shortlisting stage, which is named territory rather than a grey area.

    LinkedIn Recruiter
  • Pasting CVs into a general assistant to rank them, informally and without an assessment.

    ChatGPT
  • A system used inside an education institution, where the setting itself is named.

    Sana (Workday)
04

Common misconceptions

People assume

It is about advanced or autonomous technology.

In fact

It is about what the output affects. A simple tool ranking job applicants is in named territory, and a far more sophisticated one producing marketing copy is not, because the test is consequence rather than capability.

People assume

A tool is either high risk or it is not.

In fact

The classification attaches to the use rather than the product. The same software can sit in different tiers depending on what it is pointed at, which means the assessment belongs to a deployment and needs revisiting when that changes.

05

Questions

Does using an assistant to help with hiring count?
Employment and the management of workers are named as examples of the category, so this is not an edge case anybody has to argue about. Whether a specific use falls inside it is a legal judgement on your facts, but the territory is explicitly identified rather than debatable.
What does the category actually require?
Risk assessment and mitigation, data quality chosen to reduce discriminatory outcomes, logging so results can be traced, documentation, clear information to whoever deploys it, human oversight, and robustness, security and accuracy. All of it is meant to be in place before deployment rather than added afterwards.
Is most of what we use covered by this?
Almost certainly not. The framework has four levels and ordinary business use sits in the lower two, which is the honest answer. The reason the category matters is that the exceptions are the specific things organisations most want to automate.
06

Key takeaways

  • Four levels; most ordinary use sits in the lower two.
  • The test is what the output affects, not how advanced the tool is.
  • Employment, worker management and access to essential services are named.
  • It attaches to a use, not a product, so it changes when the use does.
08

Tools that use this

Last checked August 2026

All glossary terms