How should teams handle High Risk AI under ISO/IEC 42001?
Run two separate decisions. For the AIMS decision, apply documented criteria that distinguish acceptable from unacceptable risk. Identify consequences for the organisation, individuals, and societies; assess realistic likelihood where applicable; determine the risk level; compare it with the criteria; and prioritise treatment. Use the to account for intended use, foreseeable misuse, affected people, deployment context, and applicable jurisdictions.
For an EU AI Act decision, first confirm territorial and material scope under Article 2 and determine the operator role. The Act can reach providers placing systems on the Union market, EU deployers, and certain third-country providers or deployers where output is used in the Union. It excludes specified military, defence, national-security, scientific-research, pre-market research and testing, purely personal non-professional, and some free and open-source circumstances; each exclusion has conditions.
Then test Article 6. The product route requires both an Annex I product or safety-component link and a third-party conformity assessment under the listed product law. The listed-use route requires an intended purpose in , such as recruiting or filtering job applicants, evaluating students, credit scoring of natural persons other than fraud detection, emergency healthcare triage, or specified remote biometric identification. These are examples, and the exact Annex wording and facts control.
For an use, test the limited Article 6(3) derogation. The system must not pose a significant risk of harm to health, safety, or fundamental rights, including by not materially influencing decision-making, and must perform a narrow procedural task, improve a completed human activity, detect patterns without replacing or influencing the completed assessment without proper review, or perform a preparatory task. Profiling of natural persons remains high-risk. A provider relying on the derogation must document the assessment before placing the system on the market or putting it into service and must register it.
The published AI Act text sets 2 August 2026 for the route and 2 August 2027 for the Article 6(1) product route. The Council gave final approval to the Digital Omnibus on AI on 29 June 2026; the adopted amendment moves those dates to 2 December 2027 and 2 August 2028 respectively. The amending act must still be published in the Official Journal and enter into force, so record which legal text and effective date support the classification plan. Article 111 has separate transition rules for systems already placed on the market or put into service, including rules for specified large-scale IT systems and high-risk systems intended for public-authority use. None of these dates delays ISO/IEC 42001 risk and impact work or other applicable law.
- Record the AIMS risk level, EU AI Act classification, operator role, scope facts, Article 6 route, Annex entry, assumptions, derogation analysis, and applicable date in separate fields.
- Identify affected people, deployment context, intended use, foreseeable misuse, decision influence, and whether profiling occurs.
- Do not infer legal high-risk status from an internal score, model capability, vendor label, or the fact that a human reviews the output.
- Route residual-risk acceptance and legal classification to their respective owners; neither decision can override binding law.
ISO/IEC 42001:2023 Clauses 6.1.1-6.1.4 require organisation-specific AI risk criteria, risk assessment, treatment, and impact assessment; the standard does not create the EU AI Act's legal high-risk category.
Binding EU source for the Article 6 classification test, Annex I and Annex III routes, the limited Article 6(3) exclusion, the Article 111 transition rules, and Article 113 application dates.
Official Council source for the 29 June 2026 final approval, the delayed high-risk dates, and the amendment's pending publication and entry into force.