Regulation (EU) 2024/1689 — AI Act, Annex III point 2
AI as safety component in management/operation of critical digital infrastructure, road traffic, water, gas, heating, electricity is high-risk.
Cited onEnergy
Regulation (EU) 2024/1689 — AI Act, Annex III point 3
AI for educational-institution access determination, assessment scoring (formative + summative), monitoring during exams is high-risk.
Cited onEdTech
Regulation (EU) 2024/1689 — AI Act, Annex III point 4
AI for recruitment, candidate filtering, evaluation, promotion/termination, task allocation, behaviour monitoring is high-risk.
Cited onHR Tech
Regulation (EU) 2024/1689 — AI Act, Annex III point 5(a)
AI used by (or on behalf of) public authorities to evaluate eligibility for essential public assistance benefits and services is high-risk.
Cited onGovtech
Regulation (EU) 2024/1689 — AI Act, Annex III point 5(b)
AI for evaluating creditworthiness or establishing credit scores is high-risk. Fraud-detection AI is carved out.
Cited onFintech · PropTech
Regulation (EU) 2024/1689 — AI Act, Annex III point 5(c)
AI for risk assessment and pricing in life and health insurance is high-risk.
Cited onInsurTech
Regulation (EU) 2024/1689 — AI Act, Annex III point 5(d)
AI to evaluate/classify emergency calls, dispatch or establish priority in dispatching emergency first-response services (police, firefighters, medical aid) — including emergency healthcare patient triage — is high-risk.
Cited onHealthtech · Govtech
Regulation (EU) 2024/1689 — AI Act, Annex III point 8(a)
AI used by (or on behalf of) judicial authorities to assist in researching, interpreting, applying the law — or in ADR — is high-risk.
Cited onLegalTech
Regulation (EU) 2024/1689 — AI Act, Article 12
High-risk AI systems must technically allow for automatic recording of events (logs). Logs enable post-market monitoring + traceability over the AI system's lifecycle.
Cited onFintech · HR Tech · InsurTech · Govtech · EdTech
Regulation (EU) 2024/1689 — AI Act, Article 13
Providers must design high-risk AI systems to be transparent enough to deployers — instructions for use, system limitations, expected output interpretation.
Cited onGovtech · LegalTech
Regulation (EU) 2024/1689 — AI Act, Article 14
High-risk AI systems must enable effective human oversight by the deployer — meaningful intervention, override capability, monitoring of system outputs.
Cited onHealthtech · Govtech · HR Tech · InsurTech · Energy
Regulation (EU) 2024/1689 — AI Act, Article 15
High-risk AI must achieve appropriate levels of accuracy + robustness + cybersecurity. Fallback to safe defaults under adverse conditions is part of the obligation.
Cited onHealthtech · Fintech · InsurTech
Regulation (EU) 2024/1689 — AI Act, Article 25
Distributors, importers, deployers, and other third parties along the AI value chain are subject to operator obligations when they modify or substantially affect the high-risk AI system.
Cited onCybersecurity
Regulation (EU) 2024/1689 — AI Act, Article 50
Natural persons interacting with an AI system must be informed it is AI. Synthetic content (text, image, audio, video) must be machine-readably marked as AI-generated.
Cited onAdTech · Customer Support · EdTech
Regulation (EU) 2024/1689 — AI Act, Article 53
General-purpose AI model providers must maintain technical documentation, training-data summary, copyright policy. Downstream operators receive transparency information from upstream providers.
Cited onCybersecurity
Regulation (EU) 2024/1689 — AI Act, Article 6 paragraph 1
AI is high-risk when it is (or is a safety component of) a product covered by Annex I Union harmonisation legislation requiring third-party conformity assessment. MDR is on Annex I — so Class IIa+ medical-device software with AI is automatically high-risk.
Cited onHealthtech