Classifying an AI system under the EU AI Act is not a yes or a no. It is a chain of checks, and each link has to stand on its own. Skip one and you quickly arrive at a result that feels reassuring and does not survive the first follow-up question. The most common gap concerns high risk.
The chain in six steps
- Determine the role. Is the company a provider or a deployer? Anyone who substantially modifies a purchased system or puts it into service under their own name can become a provider without noticing, with considerably more obligations.
- Define the purpose. What is the system, and what is it intended for? Without a written intended purpose, you can neither classify it nor test it.
- Check prohibited practices. Some applications are not a question of effort but of whether they are allowed at all. Emotion recognition in the workplace is one of them.
- Check high risk, first route. Annex III lists areas in which AI is considered high risk.
- Check high risk, second route. AI as a safety component of a product that is already covered by European product legislation.
- Justify exemptions or derive obligations. Only then is it clear what needs to be done, and what does not.
The first route: Annex III
Annex III is well known. Among other things, it covers critical infrastructure, education, access to essential services and employment. Many industrial companies read the list, do not find their image-based quality inspection on it and conclude that they are not affected.
Image recognition in quality inspection is indeed usually uncritical. The critical point lies elsewhere: anything that affects employees. Shift planning, task allocation and performance assessment by AI fall under employment. These functions often sit inside software that was never bought as an “AI project”, such as workforce scheduling or assistance systems at the workstation. This is where it pays to involve the works council early rather than inform it at the end.
The second route: AI as a safety component
The overlooked route is not in Annex III but in Article 6(1) of the EU AI Act. An AI system is also considered high risk if it serves as a safety component of a product that is already subject to European product legislation and requires a third-party conformity assessment. Machinery and medical devices are typical examples.
For manufacturers, this means: an AI that performs a safety function in a plant, such as a camera that detects people in a danger zone and stops the machine, is a candidate for a high-risk classification. Regardless of whether it appears in Annex III.
Anyone who only checks the first route gives the all-clear too early here.
The exemption has to be documented
Not every system used in an Annex III area is automatically high risk. The EU AI Act allows an exemption if the system only prepares a decision and does not materially influence it.
This exemption is valuable because it saves considerable effort. But it has to be justified and documented. This is exactly where a careful classification pays off: it gives the all-clear where it is warranted, and it holds up under scrutiny.
What follows
- An AI inventory is the starting point. Many companies use more AI than their management knows about, often embedded in purchased software.
- Every relevant system gets a classification with a rationale that covers both high-risk routes.
- Where high risk applies, risk management, technical documentation, logging, human oversight and a quality management system follow. Where it does not, the main remaining duties are transparency and training staff in the use of AI.
Companies in regulated production are well prepared for this. Anyone who masters validation under GAMP 5 already knows intended purpose, risk assessment, traceability and change control. The subject is new; the test is not.
This article is not legal advice. It describes how I prepare a classification so that the legal assessment rests on a solid foundation.