Regulation · Europe

EU AI Act: is your internal knowledge assistant high-risk?

In short

Most internal knowledge assistants are not high-risk under the EU AI Act, because answering staff questions from documents is not a listed use. They become high-risk if used for listed purposes such as decisions about workers or the creditworthiness of individuals. After the Digital Omnibus, Annex III high-risk obligations apply from 2 December 2027, but the classification should be documented now.

The dates, after the Digital Omnibus

The EU AI Act entered into force on 1 August 2024. Prohibited practices have applied since 2 February 2025 and general-purpose AI obligations since 2 August 2025. The Digital Omnibus, published in July 2026, moved later deadlines:

  • 2 December 2026: transparency duties for systems generating synthetic content (Article 50(2)).
  • 2 December 2027: obligations for Annex III high-risk systems.
  • 2 August 2028: obligations for high-risk AI embedded in regulated products (Annex I).

When a knowledge assistant is not high-risk

An assistant that answers employees' questions from policies, manuals and past work, with sources cited and people deciding what to do, is not a listed high-risk use. Most internal deployments fall here.

When it crosses the line

The same technology becomes high-risk when it is used for a purpose in Annex III, for example:

  • Employment: screening CVs, evaluating candidates, or recommending promotions or terminations.
  • Credit: assessing the creditworthiness of individuals.
  • Essential services: decisions on access to certain public benefits or services.
  • Insurance: risk assessment and pricing for individuals in life and health insurance.

It is the use that matters, not the model.

What to do now

  1. List every AI system and the purpose it is used for.
  2. Record the classification and the reasoning behind it.
  3. Keep humans in charge of decisions about people, with approvals logged.
  4. If a use is high-risk, scope it separately: risk management, data governance, documentation and oversight.

Classification must be documented rather than assumed, even when the answer is "not high-risk".

Source: Digital Omnibus summary (Orrick). See also our EU AI Act page.

General information, not legal advice. Questions? Write to sales@deepvox.ai.