GuideUpdated 2026-09-10

Which AI Tools Fall Under the EU AI Act's High-Risk Rules?

High-risk status usually follows intended use and decision impact—not whether a product is marketed as generative AI.

By DiscoverAI Editorial TeamReviewed by DiscoverAI Editorial Review2 min readWork & OperationsHow we evaluate
Paper-cut illustration sorting AI uses for hiring, education, credit, infrastructure, and office writing into different legal risk paths
Original DiscoverAI editorial illustration. Editorial illustration: legal classification follows the configured use, not the software logo.

Bottom line

The EU AI Act treats certain regulated-product safety components and sensitive decision systems as high-risk; ordinary productivity use is usually not enough.

Editorial accountability

Who checked this guide

Meet the editorial team →
Evaluation type
Research-based verification
Last materially checked
Evidence
4 listed sources

Hands-on testing is identified explicitly. Research-based coverage uses cited product documentation and other named sources; it does not imply every paid plan was used. Read the full methodology.

Editorial basis

What this guidance is based on

Editorial basis
Source-led analysis
Primary references
4
Products covered
0
Last checked
2026-09-10

Important limits

  • Features, availability, and pricing can change after publication; confirm consequential details with the provider.
In this guide
  1. The short answer
  2. Common high-risk categories
  3. What is usually not high-risk?
  4. Classify the use, not the brand
  5. Bottom line

*This classification guide is not legal advice. It reflects Regulation (EU) 2024/1689 and European Commission guidance reviewed September 10, 2026.*

The short answer

An AI tool is high-risk under the EU AI Act when it is a qualifying safety component of a regulated product or is intended for one of the sensitive Annex III uses and materially influences a consequential decision. The same general-purpose model can be low-risk when drafting internal copy and high-risk when configured to rank job applicants.

Common high-risk categories

| Area | Example |
|---|---|

| Biometrics | Remote biometric identification or biometric categorization in covered contexts |

| Critical infrastructure | Safety management of essential digital, energy, water, or transport infrastructure |

| Education | Admission, placement, or exam evaluation |

| Employment | Recruiting, candidate ranking, promotion, termination, or worker monitoring |

| Essential services | Creditworthiness, life/health insurance risk, or access to public benefits |

| Law enforcement | Covered evidence, risk, or profiling uses |

| Migration and borders | Covered risk assessment, application, or identification uses |

| Justice and democracy | Assisting judicial decision research or influencing elections in covered ways |

| Regulated products | AI safety components in products requiring third-party conformity assessment |

What is usually not high-risk?

A general assistant used for brainstorming, translation, formatting, low-stakes customer support, or internal summarization is not automatically high-risk. Article 6 also allows an Annex III system to be treated as not high-risk when it performs a narrow procedural, preparatory, or quality-improvement task and does not materially influence the decision. Profiling people remains high-risk, and a provider claiming an exemption must document it.

Do not confuse “high-risk” with “prohibited.” Some practices are banned rather than managed under the high-risk regime. Nor does a non-high-risk classification eliminate transparency, AI-literacy, privacy, employment, consumer, or sector obligations.

Classify the use, not the brand

Once the category is understood, the [small-business EU AI Act checklist](/articles/eu-ai-act-compliance-checklist-small-businesses) turns the classification into owners, evidence, training, and operating controls.

Write one sentence describing the intended purpose, affected person, input, output, and decision. Ask whether the output determines, recommends, ranks, scores, or materially changes an outcome in a listed area. Record the provider's classification but perform your own deployer assessment.

Bottom line

ChatGPT, Claude, an HR suite, or a spreadsheet plugin is not high-risk by name. A particular configured system and intended use can be. When people may lose work, education, credit, insurance, benefits, liberty, safety, or equal treatment, obtain specialist review before deployment.

Sources and verification

Product details and claims were checked against the following primary sources.

Frequently asked questions

Is ChatGPT high-risk under the EU AI Act?

Not by brand alone. A configured use may be high-risk if it materially influences a listed consequential decision, such as candidate ranking or credit assessment.

Are AI hiring tools high-risk?

Systems intended to recruit, filter, rank, promote, terminate, allocate tasks, or monitor workers can fall within Annex III employment uses.

Are customer-service chatbots high-risk?

Ordinary support chatbots are usually a transparency issue rather than high-risk, unless the system materially influences a listed consequential decision.

Can an Annex III tool be exempt from high-risk status?

Sometimes, for narrow procedural, preparatory, or improvement tasks that do not materially influence the outcome. The assessment must be documented, and profiling remains high-risk.

Found this useful?

Get the next one in your inbox.

One five-minute briefing a week: a meaningful change, a practical workflow, and a clearer tool decision—already filtered for lean teams.

Free · one email a week · unsubscribe any time

Read next

More on Work & Operations