Classification is about the intended use, not the sophistication of the model, so a simple scoring tool used for promotion decisions can be high risk.
Why it matters when the plan changes
Classification decides which regime a system lives under: documentation, risk management, data governance, logging, transparency, human oversight and conformity assessment for high-risk systems under Article 6, and far lighter duties for the rest. Annex III names employment, workers' management and access to self-employment explicitly, so a tool that ranks candidates or evaluates staff sits inside that heavier regime by design, not by accident. A supplier and a deployer both need to know which side of the line they are on before either can say what they owe.
The tension is the exemption for systems that do not materially influence a decision. It is narrow, it is easy to over-read, and a supplier who relies on it for a system that in practice drives outcomes has misclassified. Annex III obligations apply from 2 December 2027, but the defensible posture for anything that evaluates people at work is to build the documentation, traceability and oversight now, treating the system as high risk before any assessment confirms it.
In practice
A vendor describes its candidate-ranking feature as decision support and treats it as outside Annex III. Recruiters follow the ranking in almost every case. The system materially influences the decision whatever the label says, and it has been shipped without the documentation, logging or oversight design the classification would have required.
Evidence
A system is considered high risk where the conditions in Article 6 are met, including the Annex III use cases.
Article 6, European Union Artificial Intelligence Act (2024)Annex III lists employment and worker management, including systems that evaluate candidates, among the high-risk use cases.
Annex III, European Union Artificial Intelligence Act (2024)
What it cannot tell you
Classification tells you which regime applies, not whether the system works well or is fair in practice. A high-risk label does not certify accuracy, and a system that escapes Annex III is not thereby safe. The category is silent on model quality, and on how a deployer actually uses the output day to day.
Questions
Its intended purpose. Article 6 of the European Union Artificial Intelligence Act (2024) sets the high-risk conditions, and Annex III lists employment, workers' management and access to self-employment as one of the covered areas, covering recruitment, evaluation and task allocation of staff.
Often, yes. The Act contains an exemption for systems that do not materially influence the outcome of a decision, but a recommendation people habitually follow does materially influence it. Labelling a system as support does not change how it is used, and use is what the classification follows.
Risk management, data governance, technical documentation, logging, transparency toward deployers, human oversight, accuracy and security, a quality management system and a conformity assessment before the system is placed on the market. Deployers carry their own duties on use, monitoring and informing affected people.
The official timeline set out in the European Union Artificial Intelligence Act (2024) gives 2 December 2027 for Annex III systems. Dates in this area have been adjusted before, so the current official text is the reference rather than a remembered figure. Building toward the requirements ahead of that date is the sensible posture.
A provider makes the initial classification and must document its reasoning. Where it relies on the exemption it has to register the system and be able to defend the judgement. A classification that turns out wrong exposes the provider and leaves deployers using a non-compliant system.