# High-Risk AI Systems, How to Tell If You're In Scope

> When is an AI system high-risk under the EU AI Act? Annex III with examples, the Art. 6(3) derogation and the roles from provider to deployer.

- Source: https://www.sidd.swiss/en/insights/ai-act-high-risk-systems/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-05-24
- Author: Dr. Dr. Nino Jibuti
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## Introduction

"High-risk AI" under Art. 6 of the EU AI Act is the most expensive regulatory status an AI system can have, with a risk management system (Art. 9), data governance (Art. 10), technical documentation (Art. 11), logging (Art. 12), transparency (Art. 13), human oversight (Art. 14), robustness (Art. 15), QMS (Art. 17), conformity assessment (Art. 43) and CE marking (Art. 48). Swiss SMEs deploying a single Annex III system enter the same compliance universe as large corporates. That makes correct initial classification critical: too cautious costs six figures a year, too careless risks fines of up to EUR 15 million or 3 percent of global turnover (Art. 99(4)).

This article sets out the logic for telling whether your AI is high-risk:

- The two paths to high-risk classification: Annex I (product safety) and Annex III (use cases)
- Annex III in detail: eight areas with concrete examples
- The exemption mechanism under Art. 6(3) ("no significant risk")
- The special case: AI as provider vs deployer
- A step-by-step decision tree for Swiss companies
- Which conformity assessment fits which system
- Typical misjudgements from advisory practice

Legal basis: Regulation (EU) 2024/1689, Art. 6 and Annexes I, III, VI, VII; supplementary Commission guidelines C(2025) 884 on prohibited practices and, pending at publication date, guidelines on Annex III under Art. 6(5).

## Two paths to high-risk classification

Art. 6 sets out two alternative paths. Path 1 (Art. 6(1)): an AI system is high-risk if it is intended as a safety component of a product covered by the EU harmonisation legislation listed in Annex I, or if the AI system itself is such a product subject to third-party conformity assessment. Annex I includes twenty acts, the Machinery Regulation 2023/1230, the Medical Devices Regulation 2017/745, IVDR 2017/746, the Toys Directive, radio equipment, lifts, recreational craft, civil aviation, rail, motor vehicles.

Path 2 (Art. 6(2) + Annex III): an AI system is high-risk if it falls into one of the eight areas listed in Annex III. Both paths lead to full high-risk compliance. Path 1 typically applies in the B2B product manufacturer context (medtech, machinery), Path 2 to broad B2B/B2C use cases. A Swiss manufacturer of CE-certified diagnostic devices with an ML component falls into Path 1; a Swiss HR-tech provider with a CV screening AI falls into Path 2. Both need the same compliance dossier but assemble it from different sources.

## Annex III in detail

Annex III lists eight clusters, each with several sub-categories. (1) Biometric systems: remote biometric identification (RBI), biometric categorisation, emotion recognition, where not already prohibited by Art. 5. (2) Critical infrastructure: AI as safety component in road traffic, water, gas, heat and electricity supply. (3) Education and vocational training: admission, assessment, behavioural monitoring during exams. (4) Employment and HR: recruiting (CV screening, job-ad targeting), allocation, promotion, dismissal recommendations, performance evaluation, behaviour monitoring.

(5) Access to essential services: credit scoring (other than for financial fraud detection), risk assessment and pricing in life and health insurance, emergency call prioritisation, public social benefits. (6) Law enforcement: recidivism risk assessment, polygraphs, evidence evaluation, profiling, predictive policing (where not prohibited). (7) Migration, asylum, border control: risk assessment, polygraphs, visa screening. (8) Justice and democratic processes: AI-assisted legal research for adjudication, election interference. In practice, Swiss SMEs most often encounter clusters 4 (HR), 5 (finance/insurance) and occasionally 1 (biometrics for access control).

## The Art. 6(3) exemption mechanism

If a system is classified under Annex III, a high-risk classification can be avoided under narrow conditions. Art. 6(3) allows an exemption where the system "does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons". Four alternative conditions are listed: (a) the system is intended to perform a narrow procedural task; (b) it is intended to improve the result of a previously completed human activity; (c) it is intended to detect decision-making patterns of prior human decisions without replacing them; (d) it performs preparatory tasks for an assessment listed in Annex III.

Crucial caveat: a system that performs profiling of natural persons is always high-risk and never benefits from the exemption. Anyone using the exemption must document the justification before the system is placed on the market or put into service, and register the system in the EU database (Art. 6(4) in conjunction with Art. 49(2)). Market surveillance authorities can review the classification at any time. The exemption is therefore not an informal compliance relief but a documented and reviewable decision, misuse risks reclassification with retroactive obligations.

## Provider, deployer, importer, distributor

The AI Act distributes obligations asymmetrically across four roles. Provider: anyone who develops an AI system and places it on the market under its own name, bears the full high-risk compliance load (Art. 16). Deployer: anyone who uses an AI system under its own authority, bears primarily due-diligence, oversight and documentation duties (Art. 26) and, for certain use cases (public bodies, banks, insurers), the fundamental rights impact assessment under Art. 27. Importer: anyone who brings a third-country system into the EU market; distributor: anyone who further distributes it in the supply chain.

Swiss companies are often classified in multiple ways. A company licensing a white-label CV screening AI from a US vendor and distributing it under its own brand in the EU is a provider (Art. 25 "provider by substantial modification" or rebranding). The same tool used internally for its own recruiting makes it a deployer. The role analysis must be done per system and per use type, not company-wide. An incorrect role assignment shifts the conformity assessment load by a factor of ten.

## Decision tree for Swiss companies

Step 1: check the AI definition (Art. 3 No. 1). A classic rule-based system is not AI within the meaning of the AI Act. "Autonomy" or "adaptive" capability is required. Step 2: prohibited practice under Art. 5? If yes, stop immediately. Step 3: Annex I product (safety component or own product under EU harmonisation law with third-party conformity assessment)? If yes: high-risk (Wave 4, 08/2027). Step 4: Annex III use case? If yes, proceed to step 5.

Step 5: Art. 6(3) exemption applicable? Exclude profiling of natural persons, then check one of the four conditions, document the justification, prepare registration in the EU database. Step 6: if no exemption: high-risk (Wave 3, 08/2026). Step 7: if neither Annex I nor III: check whether Art. 50 transparency duties apply (chatbots, deepfakes, AI-generated content, emotion recognition). Step 8: determine your role (provider / deployer / both). Step 9: choose conformity assessment path (Annex VI internal control vs Annex VII with notified body).

## Typical misjudgements

In advisory practice we see four recurring errors. First: "We are not in the EU.", Art. 2(1)(c) AI Act covers Swiss companies as soon as the output is used in the EU. A Swiss SaaS provider with two German pilot customers is in scope. Second: "We use GPT, so we are not a provider.", Art. 25 turns deployers into providers as soon as they substantially modify the model, change the intended purpose, or distribute it under their own brand.

Third: "Our AI doesn't make decisions, it just supports.", Annex III speaks of "AI systems used to evaluate/select", not of "autonomously deciding" systems. A CV screening tool that produces a shortlist and leaves the final hire/no-hire decision to the recruiter is high-risk. Fourth: "We are using the Art. 6(3) exemption.", Without documented justification, EU database registration and plausibility evidence, the exemption will not survive market surveillance review.

## How SIDD supports you

SIDD performs the initial classification of your AI systems in a structured way: from the AI definition check through the Annex I/III assessment to role analysis and conformity assessment strategy. For each classified system we deliver a documented assessment that holds up to market surveillance review, not just a spreadsheet. For high-risk systems, we support the build-out of the risk management system, the technical documentation under Annex IV, the QMS and the conformity assessment.

More on our AI compliance offering at [Swiss data protection adviser](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland) (DPIA integration under Art. 22 DSG) and [GDPR DPO](https://www.sidd.swiss/en/services/data-protection-officer-eu) (for EU subsidiaries). For parallel information security oversight (Art. 15 AI Act / ISO 27001) we complement with [ISMS mandates](https://www.sidd.swiss/en/services/iso-27001-isms). To request a fast first classification of your AI applications ("Am I high-risk? Which ones?"), reach us via the [contact form](https://www.sidd.swiss/en/contact); for a full programme proposal, use our [quote form](https://www.sidd.swiss/en/quote).

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
