Your CV screening tool is probably high-risk. Your credit scoring model almost certainly is. Your employee performance monitoring system likely is too — and if you haven't classified it yet, August 2, 2026 is closer than you think. Work through the 7-step SME compliance checklist once you know which tools are in scope. This article shows you exactly what high-risk looks like in practice, with real examples built for SMEs who are figuring out where they actually stand.

Not sure about your tools? Run a free Attestia scan →

What Makes an AI System "High-Risk"?

The EU AI Act does not classify AI by how sophisticated it is. A simple rules-based algorithm can be high-risk. A complex neural network can be minimal risk. What determines risk level is the use case — specifically, what domain the system operates in and what decisions it influences.

There are four risk categories:

Risk LevelDefinitionWhat Applies
UnacceptableAI that poses fundamental threats to rights or safetyProhibited outright — must be removed immediately
High riskAI in critical sectors or uses involving consequential decisions about peopleFull compliance obligations: documentation, oversight, registration, conformity assessment
Limited riskAI that interacts with users or generates contentTransparency disclosures only (must tell users they're talking to AI)
Minimal riskEverything elseNo specific obligations — but document your classification reasoning

High-risk status is triggered by Annex III of the Act — a list of eight domains where AI use automatically attracts the full compliance burden. If your AI system operates in any of these domains, the obligations apply to you as a deployer, regardless of whether you built the system.

The eight Annex III domains are: biometric identification, critical infrastructure, education and training, employment, access to essential services, law enforcement, migration and border control, and administration of justice. Once you know which domain applies, see what EU AI Act compliance actually costs SMEs so you can plan your budget.

Real High-Risk AI Examples for SMEs

Here is where theory becomes practice. These are the tools SMEs are already using — and the ones most likely to trigger compliance obligations they haven't planned for.

Employment and HR: The Biggest SME Blind Spot

Employment is the Annex III domain where SMEs are most commonly caught off guard. The regulation covers any AI used in "recruitment or selection of natural persons" and "decisions affecting employment or working conditions." That is an extremely broad scope.

CV Screening Tools

Any AI system that parses CVs, ranks candidates, or filters applicants before a human sees them is high-risk. This includes:

The test: if the AI's output influences which humans get seen and which don't, it is high-risk. "It's just sorting" is not a classification defence.

Job Interview Analysis Tools

AI that analyses video interviews — assessing communication style, engagement, or predicting job fit from speech and facial expressions — is high-risk. These tools are particularly common in volume hiring contexts. If your company uses them for any role affecting EU applicants, full obligations apply.

Employee Performance Monitoring

AI systems that score employee productivity, flag underperformance, or generate automated assessments that managers use in promotion or termination decisions are high-risk. This includes:

Task Assignment and Shift Scheduling AI

AI that determines what work individuals are assigned, or when they work, falls under the employment domain. Gig economy platforms using AI dispatching are the obvious case — but so is internal workforce management software that automatically allocates workload across employees using AI-driven scoring.

Access to Essential Services: Credit, Insurance, and Finance

Annex III covers AI used to evaluate creditworthiness or establish credit scores, and AI used in life and health insurance risk assessment. For SMEs in financial services or fintech, this is the primary exposure zone.

Credit Scoring Models

Any AI that produces a credit score, creditworthiness assessment, or loan eligibility decision is high-risk. This applies whether you are:

Insurance Risk Assessment

AI that scores risk for health, life, or disability insurance purposes is high-risk. If your insurance product or pricing engine uses AI inputs to determine individual premiums or coverage eligibility, you are in scope.

Property and Rental AI

AI used to evaluate applicants for rental housing — ranking tenants, scoring affordability, or flagging risk — falls under "access to essential private and public services." If your property management platform uses AI to score prospective tenants, it is high-risk.

Biometric Systems: The Identification Tripwire

Biometric identification is one of the most strictly regulated domains. The prohibited uses are well-known (real-time facial recognition in public spaces), but the high-risk obligations are broader.

Facial Recognition for Access Control

If you use facial recognition to grant or deny access to a workplace, building, or system, this is generally high-risk. It involves AI that identifies natural persons using biometric data — a category the Act treats with particular strictness.

Emotion Recognition in Professional Settings

AI that infers emotional states — in interview assessment, customer service monitoring, or workplace productivity tools — falls into high-risk biometric territory. "Emotion AI" that claims to detect stress, engagement, or deception from facial or voice data is under particular regulatory scrutiny.

Fingerprint and Biometric Attendance Systems

Biometric time-and-attendance systems (fingerprint readers, palm vein scanners) that use AI to identify employees are high-risk. The biometric identification classification applies regardless of whether identification is one-to-one verification or one-to-many recognition.

Education and Training

AI in education is high-risk when it determines access to educational opportunities or evaluates individuals in ways that affect their futures.

Automated Grading and Assessment

AI that automatically grades exams, essays, or assessments without human review of individual decisions is high-risk. If an AI produces a score that goes directly on a student's transcript without educator validation, the deployer has full compliance obligations.

Student Monitoring Systems

AI that monitors student behaviour during online exams (proctoring tools), flags "cheating" behaviour, or tracks engagement patterns in ways that affect grades or disciplinary outcomes is high-risk. The combination of biometric-adjacent monitoring and consequential decision-making puts these squarely in scope.

Adaptive Learning Platforms with Access Implications

If an adaptive learning platform uses AI to determine what educational track students are placed on — and that placement affects their future opportunities — the access-to-education dimension makes it high-risk.

Critical Infrastructure

Most SMEs are not operating energy grids or water treatment facilities. But the critical infrastructure domain catches some companies by surprise.

AI in Building Management Systems

If you develop or deploy AI that manages energy systems in critical facilities — hospitals, data centres, emergency services infrastructure — the critical infrastructure classification may apply. "Critical" follows sector-specific definitions; when in doubt, check whether your end customer is itself classified as critical infrastructure.

Industrial Safety Monitoring

AI that monitors equipment in manufacturing or industrial contexts for safety-critical failures, where failure could cause serious harm, is typically high-risk even when not in a formally designated critical infrastructure sector.

Prohibited Practices: The AI You Must Remove Now

These are not high-risk — they are banned. If you use any of these, the obligation is not compliance; it is removal.

Social Scoring

AI that scores individuals based on social behaviour and uses those scores to treat them differentially — in access to services, pricing, or treatment — is prohibited. This includes loyalty or "trust score" systems that affect customers in ways they cannot meaningfully contest or understand.

Subliminal Manipulation

AI that uses techniques operating below conscious awareness to influence decisions or behaviour in ways harmful to users is banned. Dark-pattern AI in e-commerce — urgency manipulation, pricing opacity, manufactured social proof — is under direct regulatory scrutiny here.

Exploitation of Vulnerabilities

AI that targets individuals based on age, disability, or social or economic situation to influence them against their own interests is prohibited. Predatory lending AI, AI that targets struggling consumers with harmful financial products, and systems designed to exploit addiction are squarely in this category.

Real-Time Remote Biometric Identification in Public Spaces

Private companies are prohibited from using real-time facial recognition or similar biometric identification in publicly accessible areas. "For security reasons" is not a legal exception for private actors under the Act.

The High-Risk Compliance Burden: What Actually Changes

If you determine that a system you use is high-risk, here is what changes. These are not aspirational — they are mandatory for deployers.

Risk Management System

You must establish and maintain a risk management system for each high-risk AI system. This means: identifying foreseeable risks, evaluating risks that materialise based on data, adopting measures to address them, and testing against those measures. It is a living document, not a one-time checklist.

Technical Documentation and Vendor Records

You need documentation from your provider covering: the system's design and architecture, its capabilities and limitations, its performance metrics including on relevant subgroups, and the data it was trained on. Providers of high-risk AI must supply this. If they cannot, they are not compliant — and your use of their system creates liability.

Mandatory Human Oversight

High-risk AI systems must allow qualified humans to understand, monitor, and override their outputs before those outputs produce consequential effects. This is the operational requirement with the most day-to-day impact. Your workflows must change. The AI's recommendation cannot be the final word without a human in the loop who actually has authority and time to review it.

Logging and Record-Keeping

High-risk systems must maintain logs sufficient to ensure traceability of outputs. Deployers must retain these logs for at least six months, or longer if required by sector-specific rules. This means: the AI system must be producing logs, you must be retaining them, and you must be able to produce them for a regulator who asks.

EU Registration (for some categories)

Certain high-risk AI systems must be registered in the EU AI database before deployment. This requirement primarily falls on providers — but deployers must verify that the systems they use are registered where required.

Fundamental Rights Impact Assessment

Deployers in certain contexts (public authorities and private actors performing public functions) must conduct fundamental rights impact assessments before deploying high-risk AI. If your company operates in a quasi-public role — providing services on behalf of government, managing social housing, running licensed financial services — check whether this applies.

How to Determine Your Risk Level

The Annex III classification process is not as complex as it sounds. Follow these four questions in order:

  1. Is the AI's primary purpose biometric identification? If yes, high-risk (unless it's for very narrow exceptions like device unlock).
  2. Is the AI deployed in one of the eight Annex III domains (employment, credit, education, infrastructure, law enforcement, migration, justice, biometrics)?
  3. Does the AI's output directly influence a consequential decision about an individual? Not just inform — actually drive or determine an outcome affecting them.
  4. Is there an exception that applies? The Act carves out AI used for narrow safety components, AI used for research purposes only, and certain administrative uses.

If questions 1–3 are yes and no exception applies: high-risk. If question 2 is yes but the AI only provides a general capability that humans then apply to decisions in those domains, the classification requires more careful analysis — this is where legal review adds value.

The most reliable first step is an inventory of your AI tools mapped against these four questions. Attestia's scanner does this classification for you, in under two minutes, at no cost.

Run your free AI risk classification scan →

The Practical Takeaway

High-risk classification is not about the sophistication of the AI. It is about the domain and the consequentiality of the decisions it influences. A simple scoring algorithm used in hiring decisions is high-risk. A complex generative AI used for internal content drafting is probably not.

The SMEs most at risk are in: HR and recruiting, financial services and lending, insurance, property management, education technology, and any company that uses biometric data for identity or attendance. If your company falls in any of these categories, your first step is a complete AI inventory classified against Annex III.

August 2, 2026 is the compliance deadline for high-risk systems under Annex III. That is under 90 days away. A vendor audit, human oversight workflow redesign, and documentation gap analysis each take time. Start the inventory now — everything else follows from knowing what you have and where it sits.


This article provides general educational information about the EU AI Act and does not constitute legal advice. For advice specific to your situation, consult a qualified legal professional.