← Back to blog

EU AI Act requirements for high-risk AI systems

EU AI Act requirements for high-risk AI systems

High-risk AI systems carry the heaviest obligations under the EU AI Act. This guide sets out what providers and deployers of high-risk AI must actually do — the controls, the documentation and the conformity assessment. Part of our guide to the EU AI Act.

AramGRC Team·AI Compliance & Assurance·September 11, 2026·9 min read

What counts as high-risk

A system is high-risk if it's used in one of the Annex III areas (employment, credit, education, essential services, biometrics, law enforcement, migration, critical infrastructure) or as a safety component of a regulated product under Annex I. If you're not sure, start with EU AI Act risk categories.

Provider obligations for high-risk AI

The provider must establish and maintain:

  • A risk-management system across the AI lifecycle.
  • Data and data governance — training, validation and testing data that is relevant, representative and appropriately governed.
  • Technical documentation (Annex IV) demonstrating compliance.
  • Automatic record-keeping and logging for traceability.
  • Transparency and clear instructions for use.
  • Human oversight measures built into the system.
  • Appropriate accuracy, robustness and cybersecurity.
  • A quality management system.
  • A conformity assessment, registration in the EU database, and CE marking.
  • Post-market monitoring and serious-incident reporting.

Deployer obligations for high-risk AI

Deployers — organisations using a high-risk system — must use it in line with the instructions, assign competent human oversight, monitor its operation, keep logs, inform affected people where required, and in certain cases (e.g. public bodies and essential services) carry out a fundamental-rights impact assessment.

Conformity assessment: self-assessment vs notified body

Most high-risk systems can be self-assessed against the requirements; some — particularly certain biometric systems — require a third-party notified body. Either way the outcome is a declaration of conformity and CE marking. We cover this in depth in EU AI Act conformity assessment.

When the requirements apply

After the 2026 Digital Omnibus, the high-risk obligations apply from 2 December 2027 for standalone (Annex III) systems and 2 August 2028 for AI embedded in regulated products (Annex I) — a deferral from the original August 2026/2027 dates. See the full timeline.

How ISO 42001 maps to these requirements

The Act's requirements map closely onto an ISO/IEC 42001 management system — risk management, data governance, human oversight, monitoring and documentation are common to both. Building on ISO 42001 is the most efficient path to meeting the high-risk obligations. See ISO 42001 certification.

How AramGRC helps

AramGRC produces the Annex IV technical documentation and conformity readiness the Act requires for high-risk systems, and validates it independently.

Frequently asked questions

What are the EU AI Act requirements for high-risk AI?+

A risk-management system, data governance, technical documentation, logging, transparency, human oversight, accuracy/robustness/cybersecurity, a quality management system, conformity assessment, EU-database registration and CE marking, plus post-market monitoring.

What is Annex IV technical documentation?+

The documentation a provider of a high-risk AI system must prepare to demonstrate the system meets the Act's requirements — covering its design, development, data, and risk controls.

Do I need a notified body for the EU AI Act?+

Most high-risk systems can be self-assessed, but certain systems (particularly some biometric ones) require conformity assessment by a third-party notified body.

When do EU AI Act high-risk requirements apply?+

After the 2026 Digital Omnibus, from 2 December 2027 for standalone (Annex III) systems and 2 August 2028 for AI embedded in regulated products (Annex I).

EU AI ActHigh-Risk AIConformity
WhatsApp