Skip to content

GlossaryFloor 4 · The Organisationa mosaic: AI is only one tile among manyFloor 4 · The Organisation

high-risk use

No. 107 · v2026-08FR: usage à haut risque

A high-risk use is a use of an AI system that European law holds liable to weigh heavily on a person’s rights or safety, and that it subjects for that reason to reinforced obligations. Like the same vehicle that does not obey the same rules depending on whether it carries parcels or children: it is the use that commands the regime, not the mechanics.

What it is not

A high-risk use is not a high-risk model. The qualification bears on the use and on its context, so that the same system falls under heavy requirements at an organisation that has it sort job applications and under almost none at one that has it write advertisements: asking “is this model high-risk” is a badly posed question, one that no product sheet can answer. Nor is it a measure of the system’s power or a judgement on its reliability, since a mediocre system used for a harmless task stays outside the category while an excellent system used to decide access to a job enters it. And it is not AI governance: the qualification comes from an outside text and imposes itself, whereas governance is the system of internal decisions that makes it possible to recognise the qualification in time.

In depth

Qualification in two stages

The qualification is read in two steps. First a domain: the European regulation on artificial intelligence lists the fields where a decision engages a person’s life. There you find access to employment and the management of workers, education and the assessment of learners, access to credit and to essential services. To these are added several sovereign fields, from law enforcement to justice, migration and border control included, and certain uses of biometrics. To this are added the cases where an AI system serves as the safety component of a product already regulated elsewhere. Then a role: within those domains, what counts is the place the system occupies in the decision, and an arrangement that prepares, filters or ranks does not sit among the accessories once it steers what the person obtains. The text provides that a listed use may be set aside from the category where its contribution stays narrow and without real influence, but that exclusion has to be demonstrated and documented: it is not a silent self-declaration. The practical consequence is that the question is never answered from a supplier’s catalogue: the real use has to be described.

What it triggers

What the qualification triggers reads better as a set of capabilities to be demonstrated than as a list of forms to be filled in. You have to be able to show that risks have been identified and monitored over time, and not estimated once and for all at launch. You have to be able to account for the data used: where it comes from, what it covers and what it leaves out, which is the direct point of contact with the question of bias. You need technical documentation describing what the system does, what it rests on and within what limits it holds, together with logging that makes it possible to reconstruct a contested case months later. You need effective human oversight, that is to say oversight entrusted to someone who has the time, the information and the authority to interrupt: the wording explicitly targets rubber-stamp approvals, and this is the point at which most arrangements empty of their substance. Finally, the people concerned have to know that a system is involved, and to be able to contest the result when a decision is aimed at them. These requirements are distributed along the chain, whoever supplies not answering for the same things as whoever uses, and that is why compliance announced by a supplier never closes the question for the organisation that deploys.

Internal use

The main trap is believing that an internal use escapes the qualification. The intuition comes from consumer law, where the subject is the product sold, whereas here the starting point is the consequence for the person: uses that affect employees, from recruitment to assignment and appraisal, are among the most heavily regulated. The second trap is the reasoning from the “merely assisted” decision. Filing a system among the aids because a person signs at the end proves nothing: you still have to look at what happens before that signature. An arrangement that discards three quarters of the files before any human sees them does steer the decision. The third is treating the qualification as a state once acquired, when a use drifts, a system changes and a pilot becomes a deployment: the question comes back at every widening. The fourth is confusing the tool with the use, which gives the feeling of having dealt with the subject because a supplier has produced a certificate. The useful conclusion is not legal but organisational: what you must be able to produce is an honest description of the real use, of who is subject to the decision and of what the system changes in it, and then to take that description to whoever knows how to qualify it.

Relations where the neighbours live

Check 3 questions · click your answer

Level 1 · Recognise

The same model is used by two companies: one has it sort job applications, the other has it write advertising copy. Which one is a high-risk use?

Level 2 · Distinguish

An internal department pre-selects benefit applications and an officer signs the final decision. The organisation concludes that the use is “merely assisted”, and therefore outside the category. What should be made of this?

Level 2 · Distinguish

What separates the qualification of a high-risk use from an organisation’s AI governance?

Who works with this 1 role

The roles for which this term is part of the ordinary work.

No. 107 · v2026-08 · first written in · editorial responsibility Anthony Capirchio

Lexigraph, "High-risk use", v2026-08, https://www.lexigraph.org/en/high-risk-use/, CC BY 4.0.

Report

What goes with your message

Entry · High-risk use
No. 107 · v2026-08 · /en/high-risk-use

What is this about
0 / 600

It is used to reply to you, and for nothing else. What is recorded