Módulo 4: EU AI Act Deep Dive

3. High-Risk AI: Categorías y Criterios

Descripción de la cápsula

La categoría High-Risk es la más extensa y la que más probablemente aplica a tu sistema. Si tu AI afecta acceso a empleo, educación, servicios esenciales, justicia, o safety, estás aquí.

High-Risk no significa prohibido — significa strict obligations (cápsula 04 las detalla). Es la línea entre "puedes deployar con compliance work substancial" y "no puedes deployar at all" (unacceptable risk).

Esta cápsula:

  1. Annex III: las 8 áreas high-risk del EU AI Act.
  2. Annex I: products con safety components con AI.
  3. Excepciones: cuándo un sistema en area high-risk NO es high-risk.
  4. Casos borderline: gray areas comunes.

Al terminar, vas a poder identificar con precision si tu sistema es high-risk.


Annex III: Las 8 áreas High-Risk

Área 1: Biometric identification y categorization

Sistemas para:

  • Remote biometric identification (no real-time public, eso es prohibited).
  • Categorization based on biometric data.
  • Emotion recognition (cuando no prohibited).

Examples:

  • Sistemas de identificación biométrica para acceso a buildings.
  • Categorization basada en biometric features para marketing.
  • Emotion recognition en consumer apps (medical, safety contexts).

Crítico: real-time public biometric ID es prohibited (cápsula 02). Otros casos biométricos son high-risk.

Área 2: Critical infrastructure

Sistemas que sirven como safety components en management of:

  • Road traffic.
  • Water, gas, heating, electricity supply.
  • Critical digital infrastructure.

Examples:

  • AI controlling traffic light systems.
  • Predictive maintenance for power grid.
  • Autonomous decision making en water treatment.

Crítico: el sistema debe ser safety component (failure causes safety hazard), no just any AI in those sectors.

Área 3: Educación y training profesional

Sistemas usados para:

  • Determine access to educational/vocational institutions.
  • Evaluate learning outcomes o score exams.
  • Assess appropriate level of education.
  • Monitor and detect prohibited behavior during tests.

Examples:

  • AI grading exams or admissions essays.
  • Algorithm matching students with programs.
  • AI-proctoring software during online exams.
  • Predictive system identifying students at risk of dropout (sometimes).

Área 4: Empleo, gestión de trabajadores, y self-employment

Sistemas para:

  • Recruitment: targeted job advertising, screening applications, evaluating candidates.
  • Promotion and termination decisions.
  • Allocate tasks based on individual behavior or personal traits.
  • Monitor and evaluate performance of workers.

Examples:

  • CV screening AI.
  • Performance evaluation algorithms.
  • Schedule optimization considering individual workers.
  • AI generating performance reviews.

Note: Casi cualquier HR-tech con AI cae acá.

Área 5: Servicios esenciales privados y públicos

Sistemas para:

  • Determine eligibility for public benefits y services.
  • Evaluate creditworthiness o establish credit scores.
  • Risk assessment for life and health insurance.
  • Establish priority of dispatch for emergency services.

Examples:

  • Welfare/benefits eligibility decisions.
  • Loan approval algorithms.
  • Insurance underwriting con AI.
  • Emergency services triage AI.

Note: financial services + insurance + government services con AI están heavily covered acá.

Área 6: Law enforcement

Sistemas usados por authorities para:

  • Risk assessment de natural persons (potential victim, recidivism risk).
  • Polygraphs and similar tools (lie detection).
  • Evaluate reliability of evidence.
  • Profile de natural persons (within limited scope acceptable).
  • Crime analytics (para identifying patterns across cases).

Critical: solo profiling alone es unacceptable (cápsula 02). Combined con human review puede ser high-risk.

Área 7: Migration, asylum, y border control

Sistemas para:

  • Polygraphs and similar tools in immigration context.
  • Risk assessment de natural persons in migration contexts.
  • Examination of applications para asylum, visas, residence permits.

Examples:

  • AI assessing visa applications.
  • Risk scoring at border control.
  • Asylum claim evaluation algorithms.

Área 8: Administration of justice y democratic processes

Sistemas para:

  • Assist judicial authority in researching and interpreting facts and law.
  • Assist judicial authority in applying law to facts.
  • Influencing outcome of elections or referenda or voting behavior.

Examples:

  • AI legal research tools used by courts.
  • Sentencing recommendation systems.
  • Algorithms used for political ad targeting (with caveats).

Annex I: Products con AI safety components

Adicional a Annex III, Annex I lists products que están already regulated under EU product safety legislation, donde adding AI safety component triggers high-risk classification.

Examples:

  • Medical devices (Regulation (EU) 2017/745).
  • In vitro diagnostic medical devices (Regulation (EU) 2017/746).
  • Toys con AI (Directive 2009/48/EC).
  • Civil aviation security.
  • Vehicles (some categories).
  • Industrial machinery.
  • Pressure equipment.
  • Lifts.

If your AI is a safety component en cualquiera de estos products, classification is automatic high-risk, regardless de Annex III.


Cuándo un sistema en área high-risk NO es high-risk

Important exception: Art. 6(3) provides exceptions. Sistema may NOT be high-risk si:

  1. Performs narrow procedural task.
  2. Improves the result of previously completed human activity (just enhances, no decides).
  3. Detects decision-making patterns without intending to influence (analysis only, no replacement).
  4. Performs preparatory task to assessment (preparation, no the assessment itself).

Practical examples:

  • Spell-checker en education context: detects spelling errors. Narrow task. NOT high-risk.
  • Resume formatter (formats CVs into standard layout): preparation, not evaluation. NOT high-risk.
  • Sentiment analysis para customer service prioritization queue: prioritization only, no decisions about people. Borderline.
  • Automated email classification para HR department: categorizes incoming emails. Narrow task. NOT high-risk.

Test for exception:

  • Is the AI making decisions about people or just preparing/organizing data?
  • Does the AI's output directly affect outcomes for individuals, or is human still the decision maker?

If decisions about people are made by humans based on AI output, exception may apply. If AI itself is decisive, exception doesn't apply.

Crítico: claiming exception requires risk assessment + documentation. Cannot just assume; must demonstrate.


Casos borderline comunes

Borderline 1: Recommendation engines

Recommending products on Amazon: NOT high-risk (no impact on essential services).

Recommending mortgages on a financial site: borderline. If recommendation is just informational, NOT high-risk. If recommendation directly leads to approval/denial, high-risk.

Borderline 2: Customer support chatbots

General customer support chatbot: typically NOT high-risk.

Chatbot for medical advice: high-risk (impacts health).

Chatbot for legal advice: high-risk (administration of justice context).

Borderline 3: Educational AI

AI tutor providing explanations: typically NOT high-risk.

AI grading homework or exams: high-risk.

AI deciding course placement: high-risk.

Borderline 4: HR systems

AI scheduling shifts based on worker preferences: borderline. If just optimizing schedule = lower risk. If allocating tasks based on individual traits = high-risk.

AI for resume parsing (extract info): borderline. If just extracting structured info from CV = lower risk. If scoring candidates = high-risk.

Resolution approach

For borderline cases:

  1. Conservative default: classify as high-risk.
  2. Document interpretation: argue why exception applies.
  3. Consult legal: high-stakes systems need legal review.
  4. Implement high-risk obligations regardless: prudent defense.

Por qué la classification matters

If your sistema es high-risk, you have:

  • 6 obligations (cápsula 04).
  • Conformity assessment before deploy.
  • Registration en EU database.
  • Human oversight requirements.
  • Documentation extensa.
  • Post-market monitoring.

Effort estimate: months of work + ongoing operations cost.

If you wrongly classify as NOT high-risk and regulator disagrees:

  • Penalties hasta €15M o 3% revenue.
  • Forced compliance retroactivamente.
  • Reputational damage.

If you wrongly classify as high-risk pero realmente eres minimal:

  • Unnecessary cost of compliance.
  • Slower time-to-market.
  • Competitive disadvantage.

Get classification right.


Trampas comunes

1. "It's just an LLM, not high-risk"

The use case determines classification, not the technology. LLM used for hiring decisions is high-risk regardless de que es LLM.

2. Asuming small-scale = not regulated

Scale doesn't matter for classification. A high-risk AI used for 100 people is still high-risk.

3. Treating "support tool" too loosely

If your "support tool" is decisive in practice (humans rubber-stamp), it's effectively the decision maker = high-risk.

4. Ignoring Annex I products

Many engineers focus on Annex III. But Annex I covers many physical products with AI. Check both.

5. Not re-evaluating with feature changes

A system might NOT be high-risk today. Adding feature X changes classification. Re-evaluate when scope changes.


Auto-verificación

1. ¿Cómo distinguís un sistema "high-risk" de uno con la "exception" de Art. 6(3)?

Test concreto: ¿El AI mismo está tomando decisiones sobre personas?

Si SÍ → high-risk.

Si NO (AI prepara data, formats info, performs narrow procedural task, asiste pero humano decide) → potencialmente exception aplica.

Examples:

  • CV scoring algorithm: AI evalúa candidates → high-risk.

  • CV formatter: AI organizes data into standard layout, recruiter evalúa → exception applies.

  • Loan approval algorithm: AI decides approve/deny → high-risk.

  • Loan application data extraction: AI pulls info from forms, human officer decides → exception may apply.

Crítico: claiming exception requires:

  1. Document that AI doesn't make the decision.
  2. Demonstrate humans actually exercise judgment (not rubber-stamp).
  3. Risk assessment showing genuinely lower risk.

If humans rubber-stamp AI output, you don't have exception — you have high-risk system de facto.

2. ¿Cuál es la diferencia entre Annex I y Annex III high-risk?

Annex III: AI systems usados in specific sectors (employment, education, etc.). Classification based on use case.

Annex I: Physical products que están already regulated under EU safety legislation (medical devices, toys, vehicles, etc.). Classification triggers when AI is a safety component of those products.

Implication:

  • Annex III: clasificás tu sistema según qué hace (¿hace decisions de hiring? credit?).
  • Annex I: clasificás tu sistema según el producto en el que está (¿es safety component de a medical device?).

Ambos pueden aplicar a un sistema:

  • An AI for medical diagnosis: Annex III (essential service - health) + Annex I (medical device).

Ambos triggers high-risk classification independently.

Practical: check both Annex I y Annex III when classifying. Many engineers only check Annex III.

3. ¿Por qué "small scale" no exime de high-risk classification?

EU AI Act classification depende de risk type, no scale.

If your AI:

  • Decides who gets a loan, scale 100 people/year → still high-risk.
  • Decides who gets hired, scale 50/year → still high-risk.
  • Helps make medical diagnoses for one clinic → still high-risk.

Reason: risk per individual doesn't scale down con volume. One person wrongly denied loan is still harmed.

What scale does affect:

  • Probability of regulator scrutiny: large impacts more likely investigated.
  • Compliance cost: scaling compliance takes more resources.
  • Penalty severity: percentage-of-revenue penalties hurt large companies more.

But the classification itself is independent de scale. Don't think "we're small, regulation doesn't apply".

4. ¿Qué hacés con un sistema que está in gray area entre high-risk y minimal?

Procedimiento conservador:

  1. Default to high-risk: assume more restrictive classification.

  2. Document your interpretation: why might exception apply, alternative interpretations.

  3. Implement high-risk obligations: even if you believe exception applies, implement obligations:

    • Reduces real risk.
    • Demonstrates due diligence to regulator.
    • Future-proofs against regulation tightening.
  4. Consult legal: para sistemas significant, get formal opinion.

  5. Engage with regulator: AI Office accepts queries. Regulatory sandbox programs may be available para clarification.

  6. Re-evaluate periodically: regulator guidance will clarify over time.

What NOT to do:

  • Assume the most permissive interpretation.
  • Skip compliance hoping regulator won't notice.
  • Wait for enforcement to clarify.

GDPR taught: regulators investigate. Better to comply proactively.


Resumen y siguiente paso

  • High-Risk es la categoría más extensa.
  • Annex III: 8 áreas — biometric, infrastructure, education, employment, essential services, law enforcement, migration, justice.
  • Annex I: products with safety components.
  • Exception (Art. 6(3)): narrow procedural tasks, preparation tasks, etc.
  • Borderline cases: default conservative + document + legal review.
  • Classification matters: 6 obligations vs minimal = months of work difference.

Checkpoint: deberías poder classify cualquier sistema AI con confidence into high-risk vs not.

Puente a la siguiente cápsula: cápsula 04 cubre las 6 obligations de High-Risk: governance, data quality, technical documentation, human oversight, accuracy/robustness/cybersecurity, registration. Las traduce de legal language a engineering action.


Recursos

  1. EU AI Act Art. 6 — Classification of high-risk AI — texto.
  2. Annex III — Specific high-risk areas — list.
  3. Annex I — Products list — list.

Siguiente: 04-high-risk-obligations.md — Las 6 obligations.

Cápsula 03 de 08 — Módulo 4 — AI Ethics & Compliance Guide