High-risk AI: how to recognise the most tightly regulated uses
An AI system is not “high-risk” because it is powerful or generative. It becomes high-risk when it meets the criteria of Article 6 of the AI Act ↗(opens in a new tab), in particular for certain purposes listed in Annex III: recruitment, credit, access to essential services, biometrics, justice, migration or critical infrastructure. The timetable was amended in July 2026.
Law verified as at 16 August 2026. This page is not individualised legal advice.
An AI agent is not “high-risk” merely because it uses a powerful model. The classification depends on its intended purpose and on the categories in Article 6 and Annex III of the AI Act, in particular in employment, education, certain essential services or justice. The deployer must also check the GDPR, the impact assessment, the information given, human oversight and, depending on the case, the fundamental rights assessment. Source: AI Act ↗(opens in a new tab).
Quotable legal markers
What you need to be able to cite
Is every chatbot high-risk?
No. The classification depends on the intended purpose and on the categories in Article 6 and Annex III.
Where a decision based solely on automated processing produces legal effects or significantly affects a person, subject to the conditions and exceptions set out in the text.
The purpose determines the classification. The same model can be unremarkable in one context and high-risk in another.
The list in Annex III of the AI Act ↗(opens in a new tab) covers in particular recruitment, education, credit, life and health insurance, essential benefits, biometrics, justice and migration.
The GDPR already applies.Article 22 ↗(opens in a new tab), the data protection impact assessment and transparency are not postponed by the AI Act timetable.
The deployer must organise genuine human oversight, monitor the system, keep the logs and inform the individuals concerned as the case requires.
French law adds safeguards for administrative decisions and for informing employees.
Our sources
Our official sources
Every statement on this page links to the text or decision it rests on. The links go straight to the official document.
Editorial author and publisher: Blue Lemon Agent, a brand of LINDBERGH FORMATION. Method: texts and decisions verified on EUR-Lex, Légifrance, the CNIL, the courts and the competent authorities. Legal review: Mohamadou Hamady DIA, juriste, on 18/08/2026. Updated on 10/09/2026.
For Annex III ↗(opens in a new tab), certain systems may not be high-risk where they do not present a significant risk to health, safety or fundamental rights and do not materially influence the decision. The AI Act lists cases where the task is narrow and procedural, improves the result of a human activity, detects patterns without replacing the human assessment, or prepares an assessment. That derogation must be documented. A system that carries out profiling of individuals remains high-risk.
The categories most relevant to an agent
Employment and management of workers
Systems intended for recruitment or selection, in particular the targeting of job advertisements, the screening or filtering of applications and the evaluation of candidates; decisions affecting terms of work, promotion, termination, the allocation of tasks on the basis of behaviour or personal traits, and the monitoring and evaluation of performance.
Education and training
Admission, access, assignment, assessment of learning outcomes and the monitoring of examinations, where they determine the path taken or access to it.
Essential private and public services
Assessment of eligibility for essential public benefits and services, creditworthiness assessment or credit scoring of natural persons — other than financial fraud detection — and risk assessment and pricing in life and health insurance.
Biometrics, justice, migration and security
Certain biometric identifications, biometric categorisations, emotion recognition systems, assessments in migration matters, assistance to the judicial authority and systems connected with critical infrastructure also appear in the Annex.
An HR FAQ chatbot is not automatically high-risk. The same agent becomes heavily exposed if it ranks candidates, assesses their emotions or recommends dismissals.
The original prohibitions in Article 5 of the AI Act ↗(opens in a new tab) have applied since 2 February 2025. The new prohibitions and provisions introduced in 2026 at points (ba) and (bb) and at paragraphs 1a and 1b will apply from 2 December 2026.
The general dates of application are set by Article 113 of Regulation (EU) 2024/1689 ↗(opens in a new tab), as amended by Regulation (EU) 2026/1744, and not by Article 111, which governs the treatment of certain systems already placed on the market or put into service.
Regulation (EU) 2026/1744 ↗(opens in a new tab) postpones the application of Chapter III, Sections 1 to 3, until 2 December 2027 for systems classified as high-risk under Article 6(2) and Annex III, and until 2 August 2028 for systems classified under Article 6(1) and Annex I. Article 6(5) — which requires the Commission to provide classification guidelines — is expressly excluded from that postponement; this exclusion is not a derogation from obligations applicable to providers or deployers.
The postponement does not suspend the GDPR, employment law, non-discrimination, sectoral rules or the obligations of the AI Act that already apply. It must be used to prepare for compliance, not to put off the inventory.
The provision in Article 4 of the AI Act ↗(opens in a new tab) on AI literacy has already applied since 2 February 2025. Providers and deployers must take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and the other persons operating the systems on their behalf, taking into account knowledge, experience, the context and the persons affected. Training the human oversight of a future high-risk system therefore begins before 2027.
Deployer obligations — Article 26
For a high-risk system, the deployer must in particular:
follow the instructions for use and adopt technical and organisational measures;
entrust human oversight to persons who are competent, trained, authorised and supported;
check that the input data it controls is relevant and sufficiently representative;
monitor the operation of the system, report risks and incidents and suspend use where necessary;
keep the logs under its control for an appropriate period, at least six months unless another rule provides otherwise;
inform workers and their representatives before use in the workplace;
use the information supplied by the provider to carry out the data protection impact assessment;
Human oversight must guard against automation bias. The person in charge of oversight must understand the limitations, detect anomalies, interpret the output correctly and be able to disregard it, reverse it or stop the system.
Impact assessment, registration and explanation
Fundamental rights impact assessment — Article 27
Before certain deployments of systems in Annex III of the AI Act ↗(opens in a new tab), bodies governed by public law, private entities providing public services and certain deployers in the fields of credit and insurance must analyse the processes, the duration, the persons affected, the risks of harm, human oversight and the corrective measures. The assessment supplements the data protection impact assessment where their elements overlap.
Registration — Article 49
Providers and certain public deployers must register the systems concerned in the EU database or in the registers provided for. A public body that finds that the required registration is missing must not use the system and must inform the provider or the distributor.
Right to an explanation — Article 86
A person who is the subject of a decision taken on the basis of the output of a system in Annex III of the AI Act ↗(opens in a new tab), producing legal effects or a similarly significant adverse effect on health, safety or fundamental rights, may obtain clear and meaningful explanations of the role of the system and the main elements of the decision, subject to the conditions and exceptions set out in the text.
In addition, Article 85 ↗(opens in a new tab) allows any natural or legal person having grounds to consider that a provision of the AI Act has been infringed to lodge a complaint with the relevant market surveillance authority, without prejudice to other remedies.
GDPR: rules that already apply
The rule in Article 22 GDPR ↗(opens in a new tab) applies to decisions based solely on automated processing which produce legal effects or similarly significant effects. Articles 13 to 15 require meaningful information about the existence of the decision, the logic involved and the envisaged consequences. Article 35 requires a data protection impact assessment where a high risk is likely.
CJEU, SCHUFA, C-634/21
Official judgment ↗(opens in a new tab) An automated score can be a decision where the third party gives it a determining role. A recruiter, a lender or a social security body therefore cannot treat a score as mere data if, in practice, the outcome depends on it.
CJEU, 27 February 2025, Dun & Bradstreet Austria, C-203/22
The Court requires a concise, transparent and intelligible explanation of the procedure and of the principles actually applied, enabling the person to understand which data was used and how it weighed. Trade secrecy does not authorise a blanket refusal: the information may be disclosed to the authority or to the court so that the competing interests can be balanced. The judgment does not require the source code to be handed over.
French safeguards for public administration and employment
Administrative decisions
In France, Article 47 of the 1978 Act ↗(opens in a new tab), the French Data Protection Act (loi Informatique et Libertés), governs automated individual administrative decisions. The CRPA, the French code of relations between the public and the administration, at Article L311-3-1, requires an explicit statement where a decision is taken on the basis of algorithmic processing, and allows the rules and the main features of its implementation to be obtained on request. Articles R311-3-1-1 and R311-3-1-2 specify in particular the degree of contribution, the data and its sources, the parameters and their weighting, and the operations carried out.
Conseil constitutionnel, the French constitutional court, decision n° 2018-765 DC.Official commentary. ↗(opens in a new tab) The court accepted certain automated administrative decisions subject to safeguards, ruling out in particular that the administration should base its decision solely on an algorithm whose rules cannot be mastered, such as an uncontrollable self-learning system.
Conseil constitutionnel, decision n° 2020-834 QPC, Parcoursup.Official case file. ↗(opens in a new tab) The court required information to be given after the event on the criteria and on the extent to which algorithmic processing had been used by the institutions, while noting that the decision was not based solely on automated processing.
Employment and recruitment
In employment law, Articles L1222-3 and L1222-4 of the French Labour Code (code du travail) ↗(opens in a new tab) require assessment methods to be relevant and the employee to be informed of the assessment methods and techniques before they are used; no personal information may be collected by a device that has not been brought to the employee’s attention beforehand. Article L2312-8 provides for the information and consultation of the social and economic committee (comité social et économique) on the means or techniques allowing activity to be monitored and, more broadly, on the introduction of new technologies where the statutory conditions are met.
The District Court of The Hague, on 5 February 2020, set aside the Dutch SyRI welfare fraud detection system in the light of Article 8 of the European Convention on Human Rights, in particular because of insufficient transparency and proportionality. The decision is not a French one, nor a judgment of the CJEU, nor an application of Article 22 GDPR ↗(opens in a new tab). It is a comparative illustration of the risks of an opaque public score.
Penalties
Failure to comply with the obligations in Article 26 ↗(opens in a new tab) can fall under Article 99, paragraph 4, of the AI Act: up to 15 million euros or 3% of total worldwide annual turnover, subject to the specific rules for small and medium-sized enterprises and to proportionality. GDPR infringements can reach 20 million euros or 4% for the most serious categories. To that are added discrimination, employment law and administrative law litigation.
Integration checklist
To check before putting the agent into service
Inventory of every system and of the intended purposes.
Workers, representatives and the individuals concerned informed.
Fundamental rights impact assessment prepared where required.
Explanation, challenge and human review procedure in working order.
Discrimination testing and post-deployment monitoring.
Suspension and incident reporting tested.
Frequently asked
What we get asked most
Is every recruitment agent high-risk?
No. A FAQ or appointment-booking tool is not necessarily high-risk. Screening, filtering, the evaluation of candidates and the employment decisions covered by Annex III of the AI Act ↗(opens in a new tab) are high-risk in principle, subject to the full analysis under Article 6.
Do the high-risk obligations already apply?
The main sections of Chapter III have been postponed to 2 December 2027 for Annex III of the AI Act ↗(opens in a new tab) and to 2 August 2028 for Annex I. The GDPR, employment law, non-discrimination and the obligations that have already become applicable continue to apply.
Does a merely indicative score escape Article 22?
Not if the decision-maker gives it a determining role in practice. SCHUFA requires the actual working of the decision chain to be examined.
What does effective human oversight mean?
The person carrying out the oversight must understand the output, have the necessary information, be able to depart from it and have the authority to stop or correct the system. A mechanical approval is not enough.
Are the data protection impact assessment and the fundamental rights assessment the same thing?
No. They can overlap, but Article 27 of the AI Act ↗(opens in a new tab) provides for a specific assessment. Where a data protection impact assessment already covers certain elements, the fundamental rights assessment supplements it.
Must the source code be explained?
In principle, no; the explanation must make it possible to understand the procedure, the data and the specific factors that influenced the decision; the Dun & Bradstreet judgment does not require the source code to be handed over.