Artificial Intelligence in Greece

High-risk AI in Greece

Article 6 of the EU AI Act sets out classification rules for high-risk AI systems, stating that high-risk AI systems fall within two categories: (i) safety components of products or products themselves regulated by existing EU product safety laws (listed in Annex I, e.g., medical devices, automotive AI); or (ii) systems used in specified areas (listed in Annex III), namely:

  • Critical infrastructure: AI systems used as safety components in the management or operation of critical digital infrastructure, road traffic, or the supply of water, gas, heating, or electricity.
  • Education and vocational training: AI systems that determine access to education or training or otherwise impact a person's future opportunities and career development, and AI systems used for monitoring and detecting prohibited behaviour during tests.
  • Employment and worker management: AI systems used in hiring (including the placement of targeted job advertisements), performance evaluation, promotion, or termination decisions.
  • Access to essential private and public services: AI systems that evaluate eligibility for essential public services, such as social security and healthcare, as well as AI systems for evaluating and classifying emergency calls and dispatching emergency services. Additionally, AI systems used to evaluate creditworthiness or during the risk assessment and pricing of life and health insurance.
  • Law enforcement: AI systems used by law enforcement for risk assessments, predicting criminal activities (the risk of individuals becoming victims of crime, risk of (re-)offending, or otherwise during criminal investigations), for polygraphs (i.e., 'lie detectors' or similar tools), and assessing reliability of evidence.
  • Border control and migration: AI systems used to assess visa applications, asylum claims, and border security, including for polygraphs (i.e., 'lie detectors' or similar tools), and for detecting, recognising, or identifying individuals in migration contexts.
  • Judicial and democratic processes: AI systems assisting judicial authorities with researching and interpreting facts and the law and applying the law to a set of facts, as well as AI systems used for influencing the outcome of elections or referendums or voting behaviour.
  • Biometric identification and categorisation: AI systems that perform remote biometric identification, are used to categorise individuals based on biometric data or other sensitive or protected attributes, or are used for emotion recognition purposes.

Chapter III, Section 2 of the EU AI Act (Articles 9 to 15) imposes mandatory requirements on high-risk AI systems, including risk management systems (Article 9), data governance (Article 10), technical documentation (Article 11), record-keeping and logging (Article 12), transparency and information to deployers (Article 13), human oversight measures (Article 14), and accuracy, robustness, and cybersecurity (Article 15). Providers must also implement quality management systems (Article 17) and post-market monitoring (Article 72).

The European Commission has the power to amend the abovementioned categories of high-risk AI systems, including to modify any existing use cases or add new ones (Article 7(1) of the EU AI Act).

The Digital Omnibus for AI clarifies the definition of ‘safety component’ (Article 3(14)), specifying that an AI system fulfils a safety function only where its intended purpose is to prevent or mitigate risks to health and safety. AI systems used solely for non-safety-related functions such as user assistance, performance optimisation, service efficiency, automation, convenience, or quality control do not qualify as safety components.

The 19 May 2026 High-Risk Classification Guidelines are intended to assist providers, deployers, and market surveillance authorities in determining whether an AI system qualifies as high-risk. They provide interpretation of key classification concepts and practical examples.

Where an AI system falls into one of the two abovementioned categories of high-risk AI systems but does not pose significant risk of harm to health, safety, or fundamental rights, the operators of such AI systems are relieved from the requirements imposed for high-risk AI systems (except for the EU database registration). However, to benefit from such exemption, a thorough assessment must be documented and strict conditions must be met (the 19 May 2026 High-Risk Classification Guidelines published in May 2026 provide interpretive guidance). Importantly, providers claiming this exemption under Article 6(3) must still register the AI system in the EU database pursuant to Article 49(2). The Digital Omnibus for AI maintains this mandatory registration requirement for effective market surveillance and public accountability, but simplifies the registration process.

The Digital Omnibus for AI extends the deadlines for high-risk AI system requirements. Specifically:

  • for Annex III high-risk AI systems, the requirements apply from 2 December 2027 (extended from 2 August 2026);
  • for Annex I high-risk AI systems, the requirements apply from 2 August 2028 (extended from 2 August 2027); and
  • for high-risk AI systems intended to be used by public authorities, providers and deployers must comply with the EU AI Act requirements by 2 August 2030.

Continue reading

  • no results

Previous topic
Back to top