Not sure where your AI use stands?
Run the free AI compliance checkup to get a practical readiness score, likely risk bucket, missing controls and next actions.
Common high-risk areas
- Critical infrastructure and safety components in regulated products.
- Education and vocational training decisions.
- Employment, worker management and access to self-employment.
- Access to essential private or public services such as credit or certain benefits.
- Certain biometric identification, categorisation and emotion-recognition systems.
- Law enforcement, migration, asylum, border control, justice and democratic processes.
What high-risk readiness usually requires
High-risk readiness is evidence-heavy. Expect to document risk management, data quality, technical documentation, logging, transparency for deployers, human oversight, accuracy, robustness, cybersecurity, post-market monitoring and incident processes. The exact obligations depend on your role and system.
Questions before launch
- Does the system influence access to a job, education, credit, benefits, safety, public service or legal outcome?
- Can a human meaningfully review and override the result?
- What datasets were used, and how were bias and quality risks assessed?
- What documentation would you show to a regulator, customer or auditor?
- How are errors, complaints and incidents handled after launch?
Escalation rule
If a use case may be high-risk, do not rely only on a generic checklist. Escalate to legal, compliance, privacy, security and product leadership before deployment.
FAQ
Is every AI system high-risk?
No. Many AI systems are minimal or low risk, but sensitive use cases require careful classification.
Can HR AI be high-risk?
AI used for recruitment, worker management or access to self-employment can be high-risk depending on the function.
What if a vendor says the tool is compliant?
Collect vendor documentation, but still assess your own use case, role, data and deployment context.
Sources and review method
This page is written as general business guidance, not legal advice. It is maintained from official AI Act materials, European Commission / AI Office updates, the NIST AI Risk Management Framework and practical AI governance controls.