The central category of the AI Act, gathering the AI systems subject to binding obligations because of their potential impact on people's safety or rights.
The high-risk system is the cornerstone of the AI Act, Regulation (EU) 2024/1689. The text's architecture rests on a risk pyramid, from prohibited uses at the top to minimal risk at the base, and it is on the intermediate high-risk category that most of the constraint concentrates. A system reaches it by two routes: Annex I, when embedded as a safety component in an already regulated product, and Annex III, which targets eight sensitive standalone-use domains such as biometric identification, employment, critical infrastructure or access to essential services. The classification triggers an arsenal of obligations: risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy, robustness and cybersecurity, validated by a conformity assessment. For insurance, point 5(c) of Annex III is decisive, as it explicitly classifies as high-risk the AI used for risk assessment and pricing in life and health insurance, placing the insurer's pricing engine under direct regulatory supervision.
A health insurer using a model to price its individual contracts deploys a high-risk system within the meaning of Annex III, point 5(c), and must therefore document its data governance and ensure human oversight of its algorithm.
IA à haut risque, haut risque, système d'IA à haut risque, high-risk AI system