Back to glossaryLaw & regulation

High-risk system

The central category of the AI Act, gathering the AI systems subject to binding obligations because of their potential impact on people's safety or rights.

Definition

The high-risk system is the cornerstone of the AI Act, Regulation (EU) 2024/1689. The text's architecture rests on a risk pyramid, from prohibited uses at the top to minimal risk at the base, and it is on the intermediate high-risk category that most of the constraint concentrates. A system reaches it by two routes: Annex I, when embedded as a safety component in an already regulated product, and Annex III, which targets eight sensitive standalone-use domains such as biometric identification, employment, critical infrastructure or access to essential services. The classification triggers an arsenal of obligations: risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy, robustness and cybersecurity, validated by a conformity assessment. For insurance, point 5(c) of Annex III is decisive, as it explicitly classifies as high-risk the AI used for risk assessment and pricing in life and health insurance, placing the insurer's pricing engine under direct regulatory supervision.

Example

A health insurer using a model to price its individual contracts deploys a high-risk system within the meaning of Annex III, point 5(c), and must therefore document its data governance and ensure human oversight of its algorithm.

Related terms
Related articles
Also known as

IA à haut risque, haut risque, système d'IA à haut risque, high-risk AI system