AAI Compliance Atlas
FrameworksState lawsIndustriesToolsNews
GuidesMap my obligations →
AAI Compliance Atlas

Structured, continuously verified reference for US AI compliance — federal frameworks, state laws, and the obligations that connect them.

Atlas

  • Frameworks
  • State laws
  • Industries
  • By role
  • Comparisons

Tools

  • Compliance Checker
  • Penalty Calculator
  • Impact Assessment
  • Vendor Questionnaire

Resources

  • Guides
  • News
  • Blog
  • Methodology

Company

  • About
  • Contact
  • Privacy
  • Terms
© 2026 AI Compliance Atlas. Informational only — not legal advice. Consult qualified counsel before making compliance decisions.Verified Jul 28, 2026
  1. Home/
  2. Guides/
  3. High-Risk AI System Explained

High-Risk AI System Explained

The term high-risk AI system sits at the center of most modern AI regulation. The Colorado AI Act, EU AI Act, NIST AI RMF, and ISO/IEC 42001 all use a version of the concept — though with different definitions and scopes.

Colorado AI Act (the U.S. anchor)

Under C.R.S. § 6-1-1701, a high-risk artificial intelligence system is an AI system that, when deployed, makes — or is a substantial factor in making — a consequential decision.

A consequential decision is one that has a material legal or similarly significant effect on a consumer's access to or terms of:

  • Education enrollment or opportunity
  • Employment or employment opportunity
  • Financial or lending services
  • Essential government services
  • Healthcare services — pair the high-risk analysis with the HIPAA compliance for AI guide when PHI or ePHI is in the workflow
  • Housing
  • Insurance
  • Legal services

Not every AI system is high-risk. The Colorado Act explicitly excludes from "high-risk" several categories where the AI is performing narrow procedural tasks — anti-fraud, anti-cybersecurity, calculator/spreadsheet-style functions, and a list of others enumerated in § 6-1-1701(7)(b).

Parallel concepts

EU AI Act

The EU AI Act defines high-risk AI in Annex III by enumerated categories: biometric ID, critical infrastructure, education, employment, essential public/private services, law enforcement, migration, and democratic processes. The structural overlap with the Colorado Act is significant — both target consumer-affecting decisions in similar domains — though the EU's prohibitions and conformity-assessment regime go further than Colorado's.

NIST AI RMF

NIST AI RMF does not use the term "high-risk" as a binary classifier. Instead, the MAP function asks the organization to characterize impact severity per system. Organizations operationalize this by applying more stringent controls (more frequent measurement, more rigorous oversight) where impact severity is higher.

ISO/IEC 42001

ISO/IEC 42001 follows a similar approach via Annex A.5 (AI system impact assessment) — the standard requires the organization to assess each system's impact on individuals, groups, and society, and apply controls proportionate to assessed risk. The standard does not impose a high-risk binary.

Why the binary matters in U.S. law

Under the Colorado AI Act as originally enacted in SB 24-205, high-risk classification triggered:

  • Annual impact assessments (§ 6-1-1703(3))
  • Mandatory consumer disclosure when used in a consequential decision (§ 6-1-1703(4))
  • Right-to-correct and right-to-appeal for affected consumers
  • Developer documentation obligations (§ 6-1-1702)
  • AG notification on discovery of algorithmic discrimination

Status update (verified 2026-06-27): A federal court stayed SB 24-205 on April 27, 2026, and Colorado repealed and reenacted the framework as SB 26-189 (retrieved 2026-06-27), a covered automated-decision-making-technology (ADMT) regime effective January 1, 2027. SB 26-189 keeps developer documentation and consumer-notice duties but drops SB 24-205's standalone annual impact-assessment mandate; see the Colorado AI Act detail for the current obligations.

If a system is not high-risk, most of these obligations do not apply. So the threshold determination is a critical compliance choice.

How to determine if your system is high-risk (Colorado test)

  1. Does the system make or substantially factor into a decision? Substantial-factor analysis — does the AI's output materially drive the human decision-maker, or merely inform?
  2. Is the decision "consequential" — affecting access to one of the 8 enumerated areas (education, employment, finance, government services, healthcare, housing, insurance, legal)?
  3. Does an exception apply? Anti-fraud, cybersecurity, narrow technical functions, and other carve-outs in § 6-1-1701(7)(b) may exempt the system.

If yes-yes-no, the system is high-risk.

Practical implications

  • Fine-tuning a foundation model for credit decisions → high-risk
  • Using GPT-style chat for internal documentation → not high-risk
  • Resume screening tool that ranks candidates → high-risk for employment
  • Spam filter on customer support email → not high-risk (narrow technical function)

Documentation expectations

For every high-risk system, expect to document these items in an AI compliance framework register:

  • Intended uses and out-of-scope uses
  • Data sources and retention
  • Performance metrics by demographic slice
  • Bias-test methodology and results
  • Human-review trigger conditions
  • Post-deployment monitoring plan

Use the Impact Assessment Generator to produce a baseline document.

Cross-references

  • Colorado AI Act detail — the source of the U.S. anchor definition
  • Federal vs state pillar — how state high-risk concepts interact with federal frameworks
  • EU AI Act vs US state laws — comparison of high-risk taxonomies

Related reading

Continue with the frameworks, laws, and companion guides most relevant to this topic.

  • NIST AI Risk Management Framework — the risk-tiering logic underpinning most high-risk definitions.
  • NIST AI RMF Playbook — suggested actions for MAP, MEASURE, and MANAGE risk work.
  • Colorado AI Act — defines high-risk "consequential decision" AI systems in statute.
  • ISO/IEC 42001 — the AI management-system standard for governing high-risk AI.
  • Deployer vs developer obligations — who carries which duty once a system is classed high-risk.

Last reviewed July 27, 2026. Reviewed by the AI Compliance Atlas editorial process against primary sources. Source selection, retrieval dates, and update rules are documented in the Atlas methodology.

Legal disclaimer

This content is informational only and does not constitute legal advice. Laws change frequently and vary by jurisdiction. Consult qualified legal counsel before making compliance decisions. Information accuracy not guaranteed as of any specific date.