Is your AI system’s intended purpose high-risk under the EU AI Act?
If your organisation provides, or deploys AI systems in high-risk sectors under the EU AI Act, are the intended purpose and organisation’s role defined? Understanding these dimensions is crucial because the requirements differ dependent on where the organisation sits in the value chain. Providers are concerned with classification, conformity, quality management, technical evidence and post-market monitoring. Deployers are concerned with procurement assurance, instructed use, human oversight, AI literacy, input data, monitoring, logging and escalation.
Current European Commission guidance states that rules for AI systems used in certain high-risk areas apply from 2 December 2027, with high-risk AI embedded in physical products following from 2 August 2028. Enterprises are already mobilising, but it is not too late to get started.
This high-level guide is for enterprise boards, executive committees, legal, risk, compliance, data protection, HR, technology and product leaders responsible for AI system lifecycle decisions. It explains how to recognise potential high-risk AI, why discovery requires expert judgment, and how provider and deployer responsibilities connect through the AI supply chain.
High-risk AI intended purpose is a starting point
High-risk AI classification depends on what the system is intended to do, where it is used, who is affected, and how strongly its outputs influence decisions. A general-purpose technology, model or software product may support a relatively low-risk use in one setting and a high-risk use in another.
The intended purpose is shaped by more than internal design intent. Technical documentation, instructions for use, sales material, promotional statements and the expected operating context all form part of the picture. If those materials invite high-risk use, leave high-risk use open, or fail to constrain foreseeable use, it becomes harder to defend a low-risk classification.
Enterprise leaders should be asking whether the AI system influences a consequential decision about a person, a service, a safety function or a legally significant outcome.
Does the intended purpose have consequences?
Many high-risk AI systems share common impacts. They affect access, opportunity, identity, safety, eligibility or legal position. In employment, this may include recruitment, candidate filtering, promotion, termination, task allocation or performance monitoring. In education, it may include admission, assessment, allocation of learning pathways or monitoring during tests. For essential services, it may include public benefits, creditworthiness, credit scoring, and risk assessment and pricing for life and health insurance.
These are decisions that can affect people’s lives and rights, and may create grounds for challenge or redress if handled unlawfully or unfairly. The risk analysis has to look into the decision pathway. What data is used? What output is generated? Who sees it? Where does the human decision-maker sit? Can the affected person challenge the outcome? Is the system monitored after deployment?
Those questions are operational, technical, legal and ethical at the same time. That is the basis of contextual risk modelling -assessing the AI system in the setting where it will actually operate.
Know whether you are provider, deployer or both
The EU AI Act treats providers and deployers differently. A provider develops an AI system, has one developed, places it on the market or puts it into service under its own name or trademark. A deployer uses an AI system under its authority.
This distinction can be more complex inside large enterprises than many organisations expect. A business buying a third-party AI system for recruitment, education, insurance, financial assessment or public-service decision support may be a deployer. A business commissioning, adapting, branding or rolling out an AI system internally may need to consider provider responsibilities as well. Modifying a system, changing its intended purpose or presenting it under the organisation’s name can alter the analysis.
Role classification should happen at the outset alongside decisions about budgeting, procurement route, governance model and assurance plan. Without that step, organisations may prepare for the wrong set of obligations.
High-risk discovery requires the right people in the room
AI discovery provides the evidence base for high-risk classification and regulatory readiness. It should identify the system, intended purpose, technical capability, users, affected persons, data inputs, outputs, decision pathways, human involvement, supplier dependencies, operating environment and foreseeable patterns of use.
Discovery goes beyond inventory administration. A vendor spreadsheet may identify tools, but it rarely explains whether an AI system influences a decision, whether a human relies on its output, whether affected groups can challenge the result, or whether the same capability could be used in a higher-risk context.
A checklist can organise the work. Expert judgement gives it value. The quality of discovery depends on who is in the room, what they are asked, and whether the discussion allows candour. Developers, product owners, legal teams, DPOs, risk teams, HR, procurement, operational leaders and senior sponsors may each hold part of the picture.
This is particularly important where teams have worked within a product specification for months or years. That focus is natural and necessary for delivery. Discovery needs to widen the lens and ask how the system could be used by another function, connected to another dataset, embedded into another workflow or interpreted by a person under pressure with inadequate AI literacy skills. Future high-risk issues often become visible at that point.
Biometrics under the EU AI Act show why precision counts
Biometrics is one of the clearest examples of why high-risk AI assessment requires specialist expertise. Verification asks whether a person is who they claim to be. Identification asks who a person is among a wider set of possible matches. Categorisation may group or infer characteristics. Emotion recognition attempts to infer emotional state. Behavioural analysis may introduce further operational and human-rights concerns depending on context.
These capabilities answer different questions about a person and create different risks. False matches, missed matches, demographic performance variation, environmental conditions, watchlist design, operator interpretation and escalation procedures can all affect people’s rights and safety. Biometric systems also sit at the intersection of AI governance, data protection, security, human rights and operational risk.
For providers, the intended purpose, performance claims, limitations, instructions for use and post-market monitoring plan need careful construction. For deployers, procurement questions, human oversight, operator training, logging, escalation and affected-person safeguards should be designed before operational use begins.
What providers need to evidence
Providers of high-risk AI systems must evidence conformity. In practical terms, this means a clear intended purpose, defensible classification, documented risk management, data governance, technical documentation, testing and validation, human oversight design, instructions for use, change control, post-market monitoring and a quality management system capable of supporting regulatory assurance. This is where EN 18286, once cited in the OJEU and implemented effectively will provide a presumption of conformity for high-risk AI systems which require a conformity assessment. It is a quality management system standard for organisations providing AI systems, with a primary focus on organisations placing on the market or putting into service high-risk AI systems. It covers regulatory strategy, responsibilities, competence, lifecycle controls, data management, supply chain management, change control, post-market monitoring, serious incident reporting, nonconformities and performance evaluation.
For enterprise providers, the organisation must have the governance, evidence and operating discipline to keep the high-risk AI system within its intended purpose throughout its lifecycle.
What deployers need to control
Deployers also have meaningful responsibilities to use high-risk AI systems in accordance with the provider’s instructions, assign competent human oversight, manage input data where it is under their control, monitor operation, retain logs where required, inform affected people in relevant contexts, notify workers where high-risk AI is used in the workplace, and escalate risks or serious incidents through the appropriate channels.
For some deployers, a fundamental rights impact assessment will also be required before first use. This can apply to public bodies, private entities providing public services, and certain essential private services use cases, including creditworthiness and life and health insurance risk assessment and pricing.
For deployers, the work is concentrated in procurement, AI literacy, human oversight, operating procedures, evidence retention, data protection and escalation. Buying a high-risk AI system creates an ongoing governance role in the supply chain.
The supply chain must stay connected
High-risk AI assurance depends on a continuing relationship between provider and deployer. The provider supplies instructions, limitations, oversight requirements and monitoring expectations. The deployer supplies evidence from operational use, including performance issues, misuse, incidents, deviations and concerns raised by users or affected people.
This feedback mechanism is one of the clearest differences between high-risk AI and ordinary software procurement. AI systems may be affected by updates, new data, altered workflows, changed user behaviour or integration with other systems. Operational use may reveal risks that were not visible during development or testing.
A provider without meaningful deployer feedback will struggle to maintain a reliable view of system performance. A deployer without a proper understanding of intended purpose and instructions may create risk through misuse, over-reliance or weak oversight.
Build governance throughout the whole AI estate
ISO/IEC 42001 can support enterprise-wide AI governance by helping organisations define AI policy, governance scope, risk and impact processes, controls, competence, monitoring, audit and management review. It provides a valuable global baseline for organisations operating across jurisdictions, business units and AI risk categories.
EN 18286 supports the provider quality management system required for EU high-risk AI system conformity. The two standards have different jobs. ISO/IEC 42001 supports organisational AI governance. EN 18286 supports specific high-risk AI system conformity. Used intelligently, they can sit together: a global AI governance framework across the enterprise, with specific high-risk AI systems managed for conformity where required.
The action for enterprise leaders
The next step is an evidence-led AI discovery and classification exercise. The output should show which AI systems exist, what they are intended to do, where they are used, who is affected, which systems may be high-risk, whether the organisation is provider, deployer or both, and what action is required.
Providers should focus on classification, conformity planning, quality management, technical evidence, post-market monitoring and supply-chain information flows. Deployers should focus on procurement assurance, AI literacy, human oversight, operational controls, input data, logging, impact assessment and incident escalation.
Anekanta® supports enterprise organisations with AI discovery, EU AI Act high-risk classification, provider and deployer readiness, ISO/IEC 42001 alignment, EN 18286 preparation, AI literacy and human oversight.

The priority is to understand the AI system, its intended purpose, the organisation’s role and the evidence needed

Anekanta®AI and Anekanta®Consulting
AI Strategy | Risk | Literacy | Governance
Contact us | Explore our services | Subscribe to our newsletter | Follow us on LinkedIn
Intellectual Property: © 2016–2026 Anekanta®. All rights reserved. Unless otherwise expressly stated, all materials published on this website, including the Anekanta® AI Governance Framework for Boards, the 12 Principles, and all AI risk and impact evaluation methodologies, software, models, diagrams, text and materials, are proprietary intellectual property of Anekanta®. No reproduction, adaptation, distribution, or commercial exploitation is permitted without prior written authorisation. No rights are granted other than those expressly stated. The Anekanta® AI Governance Framework and 12 Principles are developed, maintained and continuously enhanced as part of Anekanta®’s proprietary governance architecture.
Professional Disclaimer: The information provided on this website is for general informational purposes only and does not constitute legal, regulatory, financial or professional advice. Any reliance placed on the information is strictly at the user’s own risk. Professional advice should be sought in relation to specific circumstances through a formal engagement with Anekanta®.
Use of Generative AI: Generative AI tools may be utilised in research and drafting processes. All published materials are subject to substantive human review, professional judgment and oversight prior to release.
Key EU AI Act Deadlines (updated 27 June 2026)
The EU AI Act – Regulation (EU) 2024/1689 – entered into force from 1 August 2024
2 February 2025: General definitions, AI Literacy and Prohibitions apply.
2 August 2025: Rules for general-purpose AI apply and governance must be in place.
2 August 2026: The majority of rules of the AI Act come into force and enforcement starts for applicable rules.
– Transparency rules (Article 50) start to apply.
– Measures in support of innovation start apply.
– Enforcement of the AI Act starts at national and EU-level concerning general-purpose AI models, prohibitions, transparency rules and AI literacy
2 December 2026: New prohibitions + Article 50(2) transition apply.
2 December 2027: Rules for high-risk AI systems in Annex III apply.
2 December 2028: Rules for high-risk AI embedded in regulated products covered by Annex I apply
Refer to the Commission’s timeline for implementation of the Act.
Find out about our EU AI Act pre-compliance services
Explore our EU AI Act Resource Centre
