Obligations for high-risk AI systems in regulated sectors are applying on a phased timeline through 2027. Organizations that have deployed AI systems without assessing their classification under the Act are discovering that systems they considered routine automation may be classified as high-risk, that compliance obligations apply retroactively to deployed systems, and that the documentation, transparency, and human oversight requirements the Act imposes require significant changes to how those systems were built and how they are governed.
What the EU AI Act Actually Classifies
The EU AI Act's risk classification creates four tiers. Unacceptable risk systems — social scoring, real-time biometric surveillance in public spaces, systems that exploit vulnerabilities of specific groups — are prohibited. High-risk systems face the most extensive compliance obligations: technical documentation, conformity assessments, registration in the EU AI database, transparency requirements, human oversight obligations, and post-market monitoring. Limited-risk systems have transparency obligations. Minimal-risk systems are largely unregulated.
The high-risk category is defined both by sector — AI systems used in critical infrastructure, employment, credit, education, law enforcement, migration, and administration of justice — and by intended purpose. The definition is broad enough to capture AI systems that organizations may not have considered high-risk: an AI tool used in recruitment decisions is high-risk. An AI system that determines access to essential services is high-risk. An AI component in safety-critical infrastructure is high-risk. The classification does not depend on the organization's internal risk assessment — it depends on the system's function and deployment context.
Organizations that have assessed their AI systems against internal risk frameworks may have classified systems differently than the EU AI Act classifies them. The Act's classification is not the organization's classification to make — it is determined by the regulatory definition. The system that an organization considers low-risk may be high-risk under the Act.
The Compliance Obligations That High-Risk Classification Creates
Technical Documentation
High-risk AI systems must have technical documentation that describes the system's general description, the design specifications, the training, validation, and testing methodologies, the capabilities and limitations, the known risks, and the post-market monitoring plan. This documentation must be created before the system is placed on the market or put into service, and must be updated throughout the system's lifecycle. For systems already deployed without this documentation, the obligation to create it applies retroactively.
Human Oversight
High-risk AI systems must be designed and developed so that they can be effectively overseen by natural persons during the period of use. The oversight must be capable of understanding the AI system's capacities and limitations, monitoring the operation of the system, being able to intervene in or interrupt the system, and being able to decide not to use the system. This is not a procedural requirement — it is a design requirement. Systems that are designed for full automation without meaningful human oversight do not meet this standard regardless of whether a human is nominally in the loop.
Post-Market Monitoring
High-risk AI systems must have a post-market monitoring plan that collects, documents, and analyses data on the system's performance throughout its lifetime. For systems that are used by a large number of users or that operate in high-risk contexts, the monitoring must include proactive collection of data about the system's real-world performance relative to its validated performance. This is an ongoing obligation that continues for as long as the system is deployed.
The Operational Reality of Compliance
EU AI Act compliance for high-risk systems is not a documentation exercise. The technical documentation requirement can produce documentation. The human oversight requirement requires that the system was designed with meaningful oversight capability, which cannot be added to a system that was designed for full automation without significant re-engineering. The post-market monitoring requirement requires ongoing operational investment — not a one-time compliance activity.
Organizations that have deployed AI systems in the high-risk categories without building compliance into the system design are in the position of needing to retrofit compliance into deployed systems. This is expensive for technical documentation — it requires understanding the system well enough to document it accurately in retrospect. It is potentially much more expensive for human oversight — retrofitting oversight capability into fully automated systems may require architectural changes. It is operationally demanding for post-market monitoring — building the data collection and analysis capability the requirement calls for after deployment rather than as part of the design.
The organizations that are best positioned for EU AI Act compliance are those that began the classification assessment early, built compliance requirements into new AI system designs, and have a remediation plan for deployed systems that are high-risk. The organizations least positioned are those that are discovering their high-risk systems at the point of compliance deadlines.
Classify your AI systems against the EU AI Act's criteria, not your internal risk framework. The compliance obligations follow the regulatory classification.
Map your AI deployments against the EU AI Act's high-risk definitions. Identify the systems whose classification creates compliance obligations. Start the remediation planning before the deadline creates the urgency.
Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.
