High-risk AI system: definition under the EU AI Act
A high-risk AI system is one covered by Article 6 of the AI Act, via Annex I products or Annex III use cases; its obligations apply from 2 December 2027.
Key takeaways
- Article 6 of the AI Act defines two routes to high-risk status: safety components of products under Annex I legislation, and use cases listed in Annex III.
- The Digital Omnibus (Regulation (EU) 2026/1744) moved the application date to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems.
- Under Article 6(3), an Annex III system is not high-risk if it poses no significant risk of harm, but systems that profile natural persons always remain high-risk.
A high-risk AI system is an AI system that the EU AI Act classifies as high-risk under Article 6, either because it is a safety component of a product covered by the EU legislation listed in Annex I, or because it is used in one of the areas listed in Annex III. For organisations in Luxembourg, the high-risk obligations apply from 2 December 2027 for Annex III systems and from 2 August 2028 for Annex I systems, following the Digital Omnibus on AI.
Two routes to high-risk
Annex I (products). Under Article 6(1), an AI system is high-risk if it is a product, or a safety component of a product, covered by Union harmonisation legislation in Annex I (for example toys, lifts, radio equipment or medical devices) and that product must undergo a third-party conformity assessment.
Annex III (use cases). Under Article 6(2), AI systems used in eight areas are high-risk:
| Area | Example |
|---|---|
| Biometrics | remote biometric identification, emotion recognition |
| Critical infrastructure | safety components for road traffic, water, gas, heating or electricity |
| Education and training | admission decisions, evaluation of learning outcomes |
| Employment | filtering job applications, decisions on promotion or termination |
| Essential services | eligibility for public benefits, life and health insurance pricing |
| Law enforcement | assessing the risk of a person becoming a victim of crime |
| Migration, asylum, border control | risk assessment of persons entering a Member State |
| Justice and democratic processes | assisting judicial authorities, influencing elections |
The Article 6(3) exceptions
An Annex III system is not high-risk if it does not pose a significant risk of harm and only performs a narrow procedural task, improves the result of a previously completed human activity, detects deviations from decision-making patterns without replacing human assessment, or performs a preparatory task. A system that profiles natural persons is always high-risk. Providers relying on an exception must document their assessment and register the system (Article 6(4)).
Supervision in Luxembourg
Draft law No. 8476 designates the Commission nationale pour la protection des données (CNPD) as the default market surveillance authority, alongside sectoral authorities. As of October 2026 the bill was still in committee.
Questions & answers
Is a CV-screening tool a high-risk AI system?
In principle yes. Annex III lists AI systems used for recruitment or selection, in particular to analyse and filter job applications, under the employment area.
Who supervises high-risk AI systems in Luxembourg?
Under draft law No. 8476, still in committee as of October 2026, the CNPD would be the default market surveillance authority, with sectoral authorities such as the CSSF and the CAA for their supervised entities.
Sources
- Regulation (EU) 2024/1689 (AI Act) · EUR-Lex
- Regulation (EU) 2026/1744 (Digital Omnibus on AI) · EUR-Lex
- Article 6: classification rules for high-risk AI systems (consolidated text) · artificialintelligenceact.eu
- Annex III: high-risk AI systems referred to in Article 6(2) · artificialintelligenceact.eu
- Digital Omnibus on AI: amended application dates · artificialintelligenceact.eu
- Projet de loi 8476 – dossier parlementaire · Chambre des Députés
Written and fact-checked against primary sources.