Which AI Tools Fall Under the EU AI Act's High-Risk Rules?
High-risk status usually follows intended use and decision impact—not whether a product is marketed as generative AI.

Bottom line
The EU AI Act treats certain regulated-product safety components and sensitive decision systems as high-risk; ordinary productivity use is usually not enough.
Editorial accountability
Who checked this guide
- Evaluation type
- Research-based verification
- Last materially checked
- Evidence
- 4 listed sources
Hands-on testing is identified explicitly. Research-based coverage uses cited product documentation and other named sources; it does not imply every paid plan was used. Read the full methodology.
Editorial basis
What this guidance is based on
- Editorial basis
- Source-led analysis
- Primary references
- 4
- Products covered
- 0
- Last checked
- 2026-09-10
Important limits
- • Features, availability, and pricing can change after publication; confirm consequential details with the provider.
In this guide
*This classification guide is not legal advice. It reflects Regulation (EU) 2024/1689 and European Commission guidance reviewed September 10, 2026.*
The short answer
An AI tool is high-risk under the EU AI Act when it is a qualifying safety component of a regulated product or is intended for one of the sensitive Annex III uses and materially influences a consequential decision. The same general-purpose model can be low-risk when drafting internal copy and high-risk when configured to rank job applicants.
Common high-risk categories
| Area | Example |
|---|---|
| Biometrics | Remote biometric identification or biometric categorization in covered contexts |
| Critical infrastructure | Safety management of essential digital, energy, water, or transport infrastructure |
| Education | Admission, placement, or exam evaluation |
| Employment | Recruiting, candidate ranking, promotion, termination, or worker monitoring |
| Essential services | Creditworthiness, life/health insurance risk, or access to public benefits |
| Law enforcement | Covered evidence, risk, or profiling uses |
| Migration and borders | Covered risk assessment, application, or identification uses |
| Justice and democracy | Assisting judicial decision research or influencing elections in covered ways |
| Regulated products | AI safety components in products requiring third-party conformity assessment |
What is usually not high-risk?
A general assistant used for brainstorming, translation, formatting, low-stakes customer support, or internal summarization is not automatically high-risk. Article 6 also allows an Annex III system to be treated as not high-risk when it performs a narrow procedural, preparatory, or quality-improvement task and does not materially influence the decision. Profiling people remains high-risk, and a provider claiming an exemption must document it.
Do not confuse “high-risk” with “prohibited.” Some practices are banned rather than managed under the high-risk regime. Nor does a non-high-risk classification eliminate transparency, AI-literacy, privacy, employment, consumer, or sector obligations.
Classify the use, not the brand
Once the category is understood, the [small-business EU AI Act checklist](/articles/eu-ai-act-compliance-checklist-small-businesses) turns the classification into owners, evidence, training, and operating controls.
Write one sentence describing the intended purpose, affected person, input, output, and decision. Ask whether the output determines, recommends, ranks, scores, or materially changes an outcome in a listed area. Record the provider's classification but perform your own deployer assessment.
Bottom line
ChatGPT, Claude, an HR suite, or a spreadsheet plugin is not high-risk by name. A particular configured system and intended use can be. When people may lose work, education, credit, insurance, benefits, liberty, safety, or equal treatment, obtain specialist review before deployment.
Sources and verification
Product details and claims were checked against the following primary sources.
Frequently asked questions
Is ChatGPT high-risk under the EU AI Act?
Not by brand alone. A configured use may be high-risk if it materially influences a listed consequential decision, such as candidate ranking or credit assessment.
Are AI hiring tools high-risk?
Systems intended to recruit, filter, rank, promote, terminate, allocate tasks, or monitor workers can fall within Annex III employment uses.
Are customer-service chatbots high-risk?
Ordinary support chatbots are usually a transparency issue rather than high-risk, unless the system materially influences a listed consequential decision.
Can an Annex III tool be exempt from high-risk status?
Sometimes, for narrow procedural, preparatory, or improvement tasks that do not materially influence the outcome. The assessment must be documented, and profiling remains high-risk.
Found this useful?
Get the next one in your inbox.
One five-minute briefing a week: a meaningful change, a practical workflow, and a clearer tool decision—already filtered for lean teams.
Free · one email a week · unsubscribe any time
Read next
Recommended for you

Arcade Review 2026: Agent Authorization, Tools, and Pricing
A research-based Arcade review covering features, pricing, privacy, limitations, alternatives, and a practical buyer test.
Arcade is an actions runtime for AI agents that manages OAuth, user tokens, tool execution, and policy enforcement across thousands of agent-oriented tools.
Read guide
Daytona Review 2026: AI Code Sandboxes, Security, and Pricing
Gentrace Review 2026: AI Agent Evaluation, Tracing, and Fit
GPT-6 Astra vs Claude for Business: Which Should Your Team Choose?