
Three signs your AI tool may count as high-risk
If AI influences access to work, finance or essential services, you need to investigate its classification before scaling it.
In brief
- The system evaluates or ranks people.
- Its output affects access to an important opportunity.
- Operators cannot clearly explain or challenge the result.
Impact is the first signal
Look beyond the model itself. Ask what decision follows, who is affected and whether a wrong output can block someone from work, credit, education or a public service.
The decisive detail often sits in the workflow. A model may only recommend, but if employees routinely accept that recommendation without checking it, the system has substantial influence in practice. Document actual behaviour, not only the process diagram.
Do not wait for certainty
When signals point to high risk, pause expansion and document the system. Early classification gives your team options. Late discovery removes them.
Pausing expansion is not the same as banning innovation. It creates room to involve the supplier, test performance for different groups and design genuine human oversight before more people depend on the outcome.
Three questions for the supplier
Ask what role the supplier believes it has under the AI Act, which intended uses the system was designed for and what evidence supports its performance claims. Then ask which changes, incidents or limitations it will report to you.
Do not accept a generic security page as the complete answer. You need information about the version you use, your configuration and the data flows in your contract. If the supplier cannot provide that, record the uncertainty as a risk rather than silently assuming it is safe.
Make classification a team decision
The process owner understands the decision, IT understands integration and access, privacy understands personal data, and legal understands the regulatory test. None of them has the full picture alone.
Capture the conclusion in plain language, including assumptions and the date for reassessment. Revisit it when the purpose, model, data, user group or degree of automation changes. Classification is a living decision, not a sticker placed on a tool forever.
Sources and further reading
Last reviewed on 29 August 2026. Legislation and official guidance may change.
Not compliant yet?
Start the free AI Compliance Scan and know where you stand in 30 minutes.
Related within this theme