Artificial IntelligenceRegulations

High-risk systems

AI used in consequential decisions: hiring, credit, health, and public services.

Most comprehensive AI laws reserve their strongest obligations for systems that make or heavily influence consequential decisions about people. The EU AI Act's Annex III names eight areas: biometrics, critical infrastructure, education, employment, access to essential services and credit, law enforcement, migration and border control, and administration of justice. South Korea's AI Basic Act uses a parallel 'high-impact' category. Several US states target the same decisions through anti-discrimination and automated-decision-making rules. Typical duties include risk management, data governance, human oversight, logging, and conformity assessment before deployment.

Why it matters

This is where the compliance cost sits. If a system touches jobs, money, housing, health, or liberty, assume the high-risk rules are the ones that will govern it.

How each jurisdiction handles it

FlagJurisdictionHow it is handledStatus
European UnionComprehensive, horizontal, risk-based statutePhasing inSouth KoreaComprehensive risk-based act with a light enforcement postureIn forceUnited KingdomSectoral, principles-based; no horizontal AI act by designNo comprehensive lawUnited States (Federal)No comprehensive law; deregulatory posture and state preemption pushNo comprehensive lawAustraliaNo AI act; existing laws plus voluntary guidance, by explicit choiceNo comprehensive lawBrazilComprehensive EU-style bill advancing through the legislatureProposedCanadaProposed federal act lapsed; voluntary code plus provincial rulesLapsed / failedCouncil of Europe (international treaty)First binding international AI treaty (framework convention)Partially in forcePeruFirst AI law in Latin America; promotional statute with risk-based regulationIn forceSaudi ArabiaCentralized governance through SDAIA; principles and drafts, no AI actNo comprehensive lawSwitzerlandDeliberate counter-model to the EU: sectoral, with a treaty-implementation bill dueProposedUnited Arab EmiratesLayered model: charters and strategy federally, binding rules in zones and financePartially in forceUnited States: ColoradoRepealed comprehensive act; replaced with a narrower ADMT lawRepealed / replacedUnited States: TexasIntent-based statute with a NIST safe harborIn forceVietnamComprehensive, risk-based AI law with extraterritorial reachIn forceChileEU-inspired risk-based bill in Congress; updated national policyProposedKenyaAI Bill tabled 2026: classification, high-risk duties, and a registerProposedNigeriaBinding framework in motion: risk-based bill with licensing for high-risk AIProposedSingaporeVoluntary frameworks and testing tools; no binding AI lawNo comprehensive law

Recent developments

July 9, 2026
European Commission

Digital Omnibus receives final green light, locking in high-risk delay

The AI Act simplification package cleared its final approval. It confirms the deferral of stand-alone high-risk obligations to December 2, 2027 and product-embedded ones to August 2, 2028, narrows the 'safety component' test, and adds the nudifier and CSAM prohibition taking effect in December 2026.

July 6, 2026
Skadden

Illinois signs the third frontier AI law, the first anywhere to mandate independent audits

Governor Pritzker signed the Artificial Intelligence Safety Measures Act (SB 315), putting Illinois beside California and New York with the same frontier template: models trained past 10^26 operations, developers above 500 million dollars in revenue, safety frameworks, transparency reports, and incident reporting. Illinois goes one step further than either coast: from January 1, 2028, large frontier developers must retain an independent third party to audit their compliance annually and publish the results. The act takes effect January 1, 2027, enforced exclusively by the attorney general, with no private right of action, and it preempts local AI regulation inside the state.

June 14, 2026
BD Emerson

UAE approves a federal Artificial Intelligence and Data Authority

The UAE consolidated its AI, data, and digital-government functions under a single federal authority, the clearest signal yet that its layered governance model is formalizing. The move follows the DIFC's AI-specific regulation reaching full enforcement in January and binding-in-practice central bank guidance for financial institutions in February.

May 19, 2026
Travers Smith / European Commission

EU draft guidelines work through all eight high-risk categories

Draft Commission guidelines on high-risk classification walk through each Annex III area with examples. They clarify that intended purpose is judged from instructions, marketing, and documentation together, so a provider cannot dodge high-risk status by omitting a use from the manual.

Common questions

What does high-risk systems mean in AI regulation?
Most comprehensive AI laws reserve their strongest obligations for systems that make or heavily influence consequential decisions about people. The EU AI Act's Annex III names eight areas: biometrics, critical infrastructure, education, employment, access to essential services and credit, law enforcement, migration and border control, and administration of justice. South Korea's AI Basic Act uses a parallel 'high-impact' category. Several US states target the same decisions through anti-discrimination and automated-decision-making rules. Typical duties include risk management, data governance, human oversight, logging, and conformity assessment before deployment.
Why does high-risk systems matter for compliance?
This is where the compliance cost sits. If a system touches jobs, money, housing, health, or liberty, assume the high-risk rules are the ones that will govern it.
Cite this page

Artificial Intelligence Regulations, "High-risk systems in AI Regulation," reviewed July 28, 2026, https://artificialintelligenceregulations.com/topics/high-risk-systems.html.

Entries state the position as of the review date and link to the primary text for verification.