Annex III lists eight categories of AI systems that are high-risk by virtue
of their use. High-risk systems have strict obligations on data, documentation,
transparency, human oversight, accuracy, robustness, cybersecurity, and conformity assessment.
Administration of justice and democratic processes — judicial decision support, electoral processes.
Obligations for high-risk systems
Risk management — Article 9: continuous risk management across the lifecycle.
Data governance — Article 10: training/validation/test datasets are relevant, representative, and as free of errors as possible.
Technical documentation — Article 11 + Annex IV: kept up to date.
Record-keeping — Article 12: automatic logging.
Transparency — Article 13: instructions for use, deployer information.
Human oversight — Article 14: designed to allow effective oversight by natural persons.
Accuracy, robustness, cybersecurity — Article 15.
Quality management system — Article 17.
Conformity assessment
Before placing a high-risk system on the market, the provider must subject it to a
conformity assessment. Most Annex III systems can use the internal-control route
(Article 43) — see Article 43, with evidence for the
mechanics of credible self-assessment.
Some systems (e.g. remote biometric identification, CNI-critical) require a
notified body assessment. CSOAI is not a notified body.
What CSOAI provides for high-risk systems
Closed-book citation measurement against the published harness.
Provenance survival measurement (ProvBench).
Article 50 transparency measurement.
Signed records that can be handed to a notified body as audit evidence.
What we do not provide
Conformity assessment. Only notified bodies or internal-control can do that.
Risk classification. Whether a system is "high-risk" is a legal question, not a measurement.