Bidda Sovereign Intelligence · 10,085 Verified Nodes · 39 Sovereign Pillars

EU AI Act 2026: What High-Risk AI Systems Must Do Now

The EU AI Act became fully enforceable for high-risk AI systems in August 2026. Organisations deploying AI in Annex III use cases - biometric…

· 10 min read · Compliance & Law

Annex III use cases, conformity assessments, and technical documentation requirements - what is actually enforceable this year.

What the EU AI Act Requires in 2026

The EU AI Act (Regulation (EU) 2024/1689) entered into force in August 2024, with a phased implementation timeline. As of August 2026, the requirements for high-risk AI systems are fully enforceable. This means:
  • High-risk AI systems (Annex III) must meet all conformity requirements before being placed on the EU market or put into service.
  • GPAI model providers with systemic risk must comply with Chapters V and VI requirements.
  • Prohibited AI practices (Article 5) have been enforceable since February 2025.
The Act's enforcement is handled by national supervisory authorities in each EU member state, coordinated by the European AI Office. Fines are up to €35M or 7% of global annual turnover for prohibited AI practices, and up to €15M or 3% for high-risk violations.

Annex III: The High-Risk AI Use Cases

The following categories of AI system are automatically classified as high-risk under Annex III. If your AI falls into any of these categories, you have mandatory obligations:
  1. Biometric identification and categorisation - real-time remote biometric ID in public spaces (prohibited for law enforcement except in narrow exceptions), biometric categorisation systems
  2. Critical infrastructure - AI used in management or operation of road traffic, water, gas, heating, electricity supply, or digital infrastructure
  3. Education and vocational training - AI used to determine access to educational institutions, evaluate learning outcomes, or monitor students
  4. Employment and workers management - AI used in recruitment, CV screening, candidate ranking, promotion, task allocation, or monitoring employee performance and behaviour
  5. Essential private and public services - AI used in creditworthiness assessment, insurance risk assessment, or emergency services prioritisation
  6. Law enforcement - AI used for risk assessment of individuals, polygraph testing, emotion recognition, profiling in criminal investigations
  7. Migration, asylum, and border control - AI used for risk assessment, document verification, or examination of asylum applications
  8. Administration of justice and democratic processes - AI used to assist judges in researching facts and law, or AI used to influence elections

The Six Core Obligations for High-Risk AI Providers

1. Technical Documentation (Annex IV)

Before placing a high-risk AI system on the market, providers must produce and maintain technical documentation covering: the system's general description and intended purpose, the design specifications and development process, the training data description and data governance measures, the monitoring and control plan, the risk management methodology, and the accuracy, robustness, and cybersecurity measures implemented. Annex IV specifies the exact contents. This documentation must be updated whenever a substantial modification is made to the system. It must be available to national authorities on request.

2. Conformity Assessment

For most Annex III high-risk systems, providers can self-assess conformity against the EU AI Act requirements. However, for AI systems used by law enforcement (Annex III items 1, 6, 7, and 8), a third-party conformity assessment by a notified body is mandatory. Self-assessment requires checking conformity against all applicable requirements (Articles 8-15) and drawing up an EU Declaration of Conformity (Annex V). The declaration must be kept for 10 years and made available to authorities.

3. EU Database Registration

High-risk AI systems must be registered in the EU database before being placed on the market. The registration entry must include the provider's name and contact details, a description of the system and its intended purpose, the Annex III category it falls under, and the conformity assessment procedure used. The EU database is publicly accessible - this is a transparency mechanism, not just an administrative step.

4. Transparency and User Information Obligations

Providers must supply deployers (the organisations that actually use the AI system in a specific context) with instructions for use containing: information about the intended purpose, the performance metrics, the known limitations and foreseeable misuse cases, the human oversight measures required, and the expected lifespan. Deployers have their own obligations under Article 26 - they cannot simply buy a compliant system and use it however they wish.

5. Human Oversight Measures (Article 14)

High-risk AI systems must be designed to allow effective human oversight by natural persons. This means: the ability for overseers to understand the system's capabilities and limitations, the ability to monitor operations and detect anomalies, the ability to interpret outputs, and the ability to override, interrupt, or shut down the system. Human oversight is not a checkbox - it requires technical implementation (override controls, audit logs, alerting mechanisms) and operational processes (trained oversight staff, escalation procedures).

6. Ongoing Post-Market Monitoring

Once deployed, high-risk AI systems require a post-market monitoring plan that collects and analyses data on performance, incidents, and deviations from expected behaviour. Providers must report serious incidents to national authorities without undue delay. "Serious incident" includes any malfunction that leads to death, serious injury, significant damage to property, or a fundamental rights violation.

GPAI Models with Systemic Risk

General Purpose AI (GPAI) models - including large language models and foundation models - with systemic risk (defined as models trained on a compute threshold exceeding 10^25 FLOPs, i.e., the largest frontier models) have additional obligations under Chapter V: model evaluation, adversarial testing, incident reporting to the AI Office, cybersecurity measures, and energy efficiency reporting. This affects providers of frontier models deployed in EU contexts: OpenAI, Anthropic, Google DeepMind, and Meta's Llama-tier models meet this threshold. Organisations that deploy these models in high-risk contexts inherit obligations from both the GPAI provisions and the Annex III requirements.

How Bidda Supports EU AI Act Compliance

Bidda's 175 EU AI Act nodes cover every Annex, Article, and recital of the Act down to specific paragraph level. Each node provides the exact compliance obligation, the verification method, and the documentary evidence required - structured as deterministic workflow logic that compliance agents can execute programmatically. The Annex IV technical documentation node specifies each required document, the information it must contain, and the update trigger conditions, mapped directly to the regulation text.

Frequently Asked Questions

What is the EU AI Act?The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive AI regulation. It classifies AI systems into risk tiers - prohibited, high-risk, limited risk, and minimal risk - and imposes mandatory conformity assessment, technical documentation, human oversight, and registration requirements on high-risk systems. It became fully enforceable for high-risk AI in August 2026.
What are Annex III high-risk AI use cases?Annex III lists eight categories: (1) biometric identification, (2) critical infrastructure management, (3) education and vocational training, (4) employment and worker management (including CV screening and performance monitoring), (5) essential services access (credit, insurance), (6) law enforcement, (7) migration and border control, and (8) administration of justice. AI systems in any of these categories are automatically high-risk.
What is the EU AI Act conformity assessment process?Most high-risk AI providers can self-assess against EU AI Act requirements (Articles 8-15), draw up an EU Declaration of Conformity (Annex V template), and register in the EU AI database before market placement. Third-party assessment by a notified body is mandatory only for law enforcement and biometric identification use cases under Annex III items 1, 6, 7, and 8.
What are the EU AI Act fines?Prohibited AI practices (Article 5): up to €35M or 7% of global annual turnover. High-risk violations (Articles 8-15): up to €15M or 3% of global turnover. Incorrect or misleading information provided to authorities: up to €7.5M or 1% of global turnover. All figures use the higher of the two thresholds.
Does the EU AI Act apply to companies outside the EU?Yes. The EU AI Act has extraterritorial scope under Article 2. It applies to any AI system placed on the EU market or put into service in the EU, regardless of the provider's location. US, UK, and Asian AI providers deploying to EU users are subject to the Act's requirements for high-risk systems.

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.