AI governance glossary
High-risk AI system
Definition
In the EU AI Act, an AI system that is a safety component of (or is itself) a product covered by the EU product-safety laws listed in Annex I and needing third-party conformity assessment, or one used in an area listed in Annex III, such as biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration and the administration of justice. A provider may document that an Annex III system is not high-risk when it does not pose a significant risk of harm.
Source: EU AI Act (Regulation (EU) 2024/1689). A plain-language explanation for orientation, not the legal text; follow the source for the binding wording.
Risk management duties →EU AI Act role and risk classifier →
Laws and policies on record that use it
- EU AI ActEuropean Union · Partially applicable
- Colorado AI ActColorado (United States) · Repealed
- Royal Decree 817/2023 (AI regulatory sandbox)Spain · In force
- UAE PDPLUnited Arab Emirates · In force
- (Draft) Principles of the Law on Artificial IntelligenceThailand · Under consultation
- Australian mandatory guardrails proposalAustralia · Under consultation
- ICO AI guidanceUnited Kingdom · Guidance
Duties that mention it
- Establish a risk management system for high-risk AIEU AI Act · European Union
- Apply data governance and quality criteria to training, validation and testing dataEU AI Act · European Union
- Design high-risk systems to log events automaticallyEU AI Act · European Union
- Provide deployers with clear instructions for useEU AI Act · European Union
- Achieve appropriate accuracy, robustness and cybersecurityEU AI Act · European Union
- Operate a quality management systemEU AI Act · European Union
- Use high-risk AI as instructed, monitor it and inform affected peopleEU AI Act · European Union
- Report serious incidents to market surveillance authoritiesEU AI Act · European Union
Related terms
- AI systemA machine-based system that operates with some autonomy, may adapt after it is deployed, and infers from the i...
- Conformity assessmentThe process of showing that a high-risk AI system meets the EU AI Act's requirements before it is placed on th...
- Red teaming (AI)Structured adversarial testing in which testers try to make an AI system fail: produce harmful output, leak da...
- Notified bodyAn independent conformity assessment body designated by an EU member state to assess high-risk AI systems wher...
- Quality management system (QMS)The documented policies, procedures and instructions a provider of a high-risk AI system keeps to ensure compl...
- Fundamental rights impact assessment (FRIA)An assessment, before first use, of how a high-risk AI system could affect the people it is used on: who is af...
All glossary terms · Think a definition is off? Tell us; corrections are logged on the corrections page.
Frequently asked questions
What does "High-risk AI system" mean?
In the EU AI Act, an AI system that is a safety component of (or is itself) a product covered by the EU product-safety laws listed in Annex I and needing third-party conformity assessment, or one used in an area listed in Annex III, such as biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration and the administration of justice. A provider may document that an Annex III system is not high-risk when it does not pose a significant risk of harm.
Where does the term High-risk AI system come from?
This explanation follows EU AI Act (Regulation (EU) 2024/1689). It is a plain-language paraphrase for orientation; the source has the binding wording.
Which laws and policies use the term High-risk AI system?
Among the records on this site: EU AI Act (EU); Colorado AI Act (Colorado); Royal Decree 817/2023 (AI regulatory sandbox) (Spain); UAE PDPL (UAE) and (Draft) Principles of the Law on Artificial Intelligence (Thailand).