High-risk AI system
A high-risk AI system is an AI system that falls within one of the two categories of Art. 6 of the EU AI Act. Under Art. 6(1) and Annex I, an AI system is high-risk if it is intended to be used as a safety component of a product, or is itself a product, covered by listed Union harmonisation legislation and required to undergo third-party conformity assessment; the Medical Device Regulation and the IVDR are on that list, so AI-enabled medical devices and diagnostics above Class I are high-risk. Under Art. 6(2) and Annex III, stand-alone AI systems used in listed areas are high-risk: biometrics, critical infrastructure, education, employment, access to essential private and public services (including systems evaluating eligibility for public healthcare benefits and emergency triage of patients), law enforcement, migration and justice. Art. 6(3) allows a derogation where the system does not pose a significant risk because it performs a narrow procedural task or merely supports human assessment, subject to documentation.
Providers of high-risk systems must implement a risk management system across the lifecycle (Art. 9), apply data governance and quality criteria to training, validation and testing data including examination for bias (Art. 10), draw up technical documentation (Art. 11) and enable automatic logging (Art. 12), provide instructions for use and transparency to deployers (Art. 13), design for effective human oversight (Art. 14), ensure accuracy, robustness and cybersecurity (Art. 15), operate a quality management system, undergo conformity assessment, register the system in the EU database, affix the CE marking and carry out post-market monitoring and serious incident reporting. Deployers must use the system according to instructions, ensure human oversight by competent staff, monitor operation, keep logs, inform affected persons and, where they are public bodies or provide essential services, carry out a fundamental rights impact assessment. Most obligations apply from 2 August 2026 for Annex III systems and from 2 August 2027 for Annex I products, subject to the adjustments proposed in the Commission's digital omnibus.
For life sciences, AI software as a medical device (imaging analysis, diagnostic algorithms, dosing and monitoring tools) is the main high-risk category, with conformity assessment integrated into the notified body's MDR or IVDR review. AI used purely for scientific research and development, or in clinical trials before placing on the market, is largely exempt under Art. 2(6) and 2(8), but the same systems become high-risk when marketed. Where a high-risk system processes personal data, the GDPR applies cumulatively, and the DPIA and the AI Act risk documentation should be prepared together. iliomad's AI compliance services cover classification, gap analysis and documentation.
