High-Risk AI System

A high-risk AI system is a risk category defined in the EU AI Act for AI applications that can have a significant impact on health, safety or fundamental rights, such as in candidate selection, credit scoring or medicine. These systems are subject to particularly strict obligations that go well beyond the simple transparency obligation.

What is a high-risk AI system?

The EU AI Act classifies AI by risk. The second-highest tier, "high risk", covers AI systems that can significantly affect people's health, safety or fundamental rights. Such systems are not prohibited but are subject to particularly strict requirements.

A note for context: this article is for orientation, not legal advice. Whether a specific system qualifies as high-risk is something to clarify with a lawyer.

Typical examples

Areas where AI can be classified as high-risk include, among others:

  • AI in personnel selection, such as automatically pre-sorting applications.
  • AI in assessing the creditworthiness of individuals.
  • AI in critical infrastructure, medical devices or law enforcement.

An ordinary AI chatbot for customer service usually does not fall into this category, but into the "limited risk" tier with the transparency obligation.

Which obligations apply?

High-risk systems carry far more extensive requirements than just a disclosure. These include, for example, risk management, requirements on data quality, technical documentation, human oversight and logging. The exact catalogue of obligations and the transition periods are set out in the AI Act and partly take effect later than the transparency obligations under Article 50 (which apply from 2 August 2026).

What this means for SMEs

For most small and mid-sized businesses, the high-risk tier is not part of daily life. What matters is the clean classification: a service bot that answers questions and books appointments is usually "limited risk". If, by contrast, you use AI in sensitive decisions such as candidate selection, you should have it reviewed early on whether the high-risk obligations apply.

SendSeven in customer service

SendSeven is a unified messaging platform for WhatsApp, Telegram, SMS, Instagram, Messenger, email, live chat and browser push. The area of use is customer communication, which typically falls under "limited risk". The AI assistant supports you with the relevant obligation: a configurable AI disclosure makes the bot recognisable, with handover to a member of the team at any time. Set up through the AI bots. GDPR-compliant, Made in Germany, Meta Business Partner. Try it free for 14 days, no credit card.