← All posts
·7 min read·The DecisionChain Team

High-Risk AI Under the EU AI Act: Who's Actually In Scope

The high-risk list is narrower than the headlines suggest — but wider than most product teams assume. A checklist for scoping.

The obligations that make headlines — conformity assessments, technical documentation, logging — apply to high-risk AI systems. Whether your system is high-risk is a scoping question you must answer early.

Two paths into the high-risk category

1. Annex III use cases. Employment, credit, essential services, education, law enforcement, migration, critical infrastructure, and more. 2. Safety component of a regulated product. If your model is embedded in a product covered by existing EU product safety law, high-risk status may follow the product.

Where teams miss the mark

  • Internal tooling can be in scope if it materially affects an Annex III decision.
  • General-purpose AI models have separate obligations, but *deployers* who put them into a high-risk workflow inherit high-risk duties.
  • "The human makes the final call" does not automatically remove the system from scope.

A one-page scoping checklist

Write down: intended purpose, the decision it materially influences, the affected population, and whether any Annex III category applies. If any of the first three sound consequential and the last one is "yes," treat it as high-risk until legal review says otherwise.