
Is this AI system high-risk? The Article 6 decision tree
The EU AI Act does not classify a company, a model family or an industry as high-risk. It classifies an AI system in its intended use. The same general-purpose model can sit outside the high-risk regime when it drafts internal meeting notes and enter it when integrated into recruitment, credit, education, benefits, migration, policing or judicial decision-making.
This page turns Article 6 and Annex III into a decision record a provider, deployer, auditor or regulator can inspect. It reflects the AI Omnibus that entered into force on 27 July 2026: Annex III high-risk obligations now apply from 2 December 2027, while the product-safety systems in Article 6(1) apply from 2 August 2028. Classification work remains necessary before those dates because intended purpose, contracts, technical documentation and system design decide which lane the operator is building toward.
The decision in four lines
1. Is the AI a safety component of, or itself, a regulated Annex I product that needs third-party conformity assessment? Article 6(1) high-risk.
2. Is its intended use listed in Annex III? Presumptively Article 6(2) high-risk.
3. If Annex III applies, does the system qualify for the narrow Article 6(3) derogation because it does not significantly risk health, safety or fundamental rights and does not materially influence a decision? Document that conclusion.
4. If it profiles natural persons, the Annex III system remains high-risk despite the derogation.
Step 0: freeze the intended purpose before classifying
Classification begins with a versioned statement of intended purpose, not a product name. Record:
SYSTEM_ID_AND_VERSION: <stable identifier>
PROVIDER: <legal person developing or marketing under its name>
DEPLOYER: <legal person using the system under its authority>
INPUTS: <data the system receives>
OUTPUTS: <prediction, recommendation, content or decision>
USERS: <roles operating or relying on it>
AFFECTED_PERSONS: <whose rights, access, safety or opportunities can change>
DECISION_POINT: <where output enters an operational decision>
HUMAN_REVIEW: <authority, information, time and ability to reverse>
PRODUCT_INTEGRATION: <standalone or safety component of named product>
JURISDICTION_AND_MARKET: <where placed, put into service or output used>“Assistant,” “copilot” and “decision support” are marketing descriptions. They do not answer whether the system materially influences an outcome. The record must say what the output changes.
Lane A: regulated products under Article 6(1)
An AI system is high-risk under Article 6(1) only when both conditions hold:
- the system is intended as a safety component of a product, or is itself a product, covered by Union harmonisation legislation listed in Annex I; and
- that product or system must undergo a third-party conformity assessment before market placement or service.
The lane covers product regimes such as medical devices, machinery, toys, lifts, personal protective equipment, radio equipment, motor vehicles, rail and civil aviation when the two-part test is met. Merely being embedded in hardware does not satisfy it. Merely touching safety does not identify the Annex I legislation or the third-party assessment.
| Evidence needed | The question it answers |
|---|---|
| Exact Annex I legal instrument | Is the product family actually listed? |
| Manufacturer’s intended-purpose statement | Is the AI the product or a safety component? |
| Applicable conformity route | Is third-party assessment required? |
| Architecture and failure analysis | What safety function does AI perform? |
| Change-control record | Did a later modification create or alter the safety role? |
Lane B: the eight Annex III areas
Article 6(2) treats AI systems in the listed Annex III uses as high-risk, subject to the paragraph 3 derogation. Match the specific use, not merely the sector.
| Annex III area | In-scope examples named by the Act | Frequent boundary question |
|---|---|---|
| Biometrics | Remote identification; sensitive-attribute categorisation; emotion recognition | Is it verification only, or identification/categorisation? |
| Critical infrastructure | Safety components managing digital infrastructure, traffic, water, gas, heating or electricity | Is the AI a safety component or an administrative tool? |
| Education and training | Admission, assignment, learning-outcome evaluation, level assessment, test-behaviour monitoring | Does output change access, progression or evaluation? |
| Employment and self-employment | Recruitment ads, application filtering, candidate evaluation, promotion/termination, task allocation, worker monitoring | Does it influence a person’s work opportunity or conditions? |
| Essential services and benefits | Public benefits, creditworthiness, life/health insurance pricing, emergency dispatch and triage | Is the use explicitly exempted, such as financial-fraud detection? |
| Law enforcement | Victim risk, polygraphs, evidence reliability, offending/reoffending risk and profiling | Is the use lawful, and which exact subparagraph applies? |
| Migration, asylum and borders | Risk assessment, application examination, evidence reliability and person detection | Is it document verification or a substantive assessment? |
| Justice and democracy | Judicial fact/law assistance, application of law to facts, certain election influence | Is it substantive case work or administrative/logistical support? |
Annex III is not an intuition about sensitivity. It is a list of intended uses. A payroll calculator does not become high-risk because employment is sensitive. A résumé-ranking system does not become low-risk because a recruiter clicks the final button.
The Article 6(3) derogation is a documented exception
An Annex III system may be treated as not high-risk only when it does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing decision-making, and at least one statutory condition applies:
- it performs a narrow procedural task;
- it improves the result of a previously completed human activity;
- it detects patterns or deviations without replacing or influencing a completed human assessment, with proper human review; or
- it performs a preparatory task for an Annex III assessment.
The derogation is unavailable where the system profiles natural persons.
A safe paragraph-3 record has two separate proofs
Proof A: impact. Explain why the system does not significantly risk health, safety or fundamental rights and does not materially influence the outcome. Identify the affected decision, dependency on the output, human authority, reversibility and observed override behaviour.
Proof B: statutory condition. Identify one of the four conditions and tie every word to the actual workflow. “Preparatory” is not a label; show that a later assessment remains open, informed and genuinely independent. “Human review” is not the presence of a person; show what that person sees, can change and has time to assess.
Article 6(4) requires the provider to document the assessment before placing the system on the market or putting it into service and to supply it to competent authorities on request. The 2026 Omnibus removed the earlier EU-database registration obligation for exempted systems, but it did not turn an undocumented exemption into a defensible one.
Human review is measured by authority, information and time
A useful review test is operational:
| Dimension | Failing pattern | Evidence of meaningful review |
|---|---|---|
| Authority | Reviewer can recommend but cannot stop or reverse | Named power to reject, change, suspend and escalate |
| Information | Reviewer sees score and conclusion only | Source inputs, uncertainty, limitations and contrary evidence |
| Time | Throughput target makes independent review impossible | Measured review time and staffing fit the case complexity |
| Independence | Reviewer is evaluated for agreement with the model | Overrides are expected, protected and audited |
| Feedback | Overrides disappear into a ticket queue | Outcome and reason feed monitoring and risk management |
This is not an additional statutory definition. It is the evidence needed to make claims such as “proper human review” and “does not materially influence” falsifiable.
Classification is a lifecycle control
Re-run Article 6 whenever any of these changes:
- intended purpose or marketed claims;
- affected persons or decision point;
- integration into a regulated product;
- autonomy, ranking, scoring or recommendation weight;
- human-review authority or staffing;
- data used for profiling;
- customer configuration that moves the system into an Annex III use;
- a substantial modification by a distributor, importer, deployer or third party.
Article 25 can make a downstream actor the provider when it puts its name on a high-risk system, substantially modifies it while it remains high-risk, or changes the intended purpose of a non-high-risk system so it becomes high-risk. The contractual label “customer” does not prevent the legal role from moving.
The classification memorandum
A complete record can fit in one object:
1. SYSTEM AND VERSION
2. INTENDED PURPOSE AND PROHIBITED USES
3. PROVIDER / DEPLOYER / DOWNSTREAM ROLE MAP
4. ARTICLE 6(1) TEST
Annex I instrument: ...
Safety-component or product basis: ...
Third-party assessment basis: ...
5. ARTICLE 6(2) / ANNEX III TEST
Area and exact subparagraph: ...
Workflow evidence: ...
6. ARTICLE 6(3) TEST, IF CLAIMED
Significant-risk and material-influence assessment: ...
Statutory condition: ...
Profiling exclusion: ...
7. HUMAN-REVIEW EVIDENCE
8. CONTRARY CLASSIFICATION AND WHY REJECTED
9. FACT THAT WOULD CHANGE THE RESULT
10. APPROVER, DATE, SOURCES AND NEXT REVIEW TRIGGERThe strongest contrary classification belongs in the record. A memorandum that cannot state what fact would flip its conclusion is advocacy, not classification.
Dates after the July 2026 AI Omnibus
| Obligation family | Current application date |
|---|---|
| Article 50 transparency obligations | 2 August 2026, with specific transitional treatment for older systems/content |
| Annex III high-risk system requirements | 2 December 2027 |
| Article 6(1) high-risk systems embedded in regulated products | 2 August 2028 |
The Commission says the extensions allow standards, common specifications and guidelines to mature. They change the compliance clock. They do not change whether a system’s architecture, records and contracts are being built for the correct classification lane.
A free classification audit
The Object Invocation Protocol will run a documented Article 6 classification exercise without charge for a legislator, regulator, public-interest organisation, company or private party that supplies a bounded system description and the evidence above. The result can include:
- provider/deployer role allocation;
- the Article 6(1) product route;
- the exact Annex III match;
- a paragraph-3 derogation stress test;
- the human-review evidence gap;
- the strongest contrary classification;
- a compliance schematic and record template;
- multiple independent model findings bound to the same facts, with disagreements preserved.
Send the system description to build@miscsubjects.com. A public URL is enough for an initial gap map; non-public evidence can be reduced to a bounded, redacted record. The result is not legal advice or a determination by a competent authority.
Continue the EU AI Act series
The companion pages cover the complete Act, Article 50 machine-readable marking and the model-panel specimen. This classification guide will be updated when the Commission adopts final high-risk guidelines or authorities establish a material interpretation.
The audit offer is now in the market
Sent: Emre Kazim, Holistic AI
Selected because His November 2025 essay argues that compliance alone is the wrong north star, while Holistic AI's Agent Glass Box brief asks operators to capture decision steps and tool interactions. The full letter and tracked send receipt:
Sent: Meeri Haataja, Saidot
Selected because Her AI Pact statement names use-case inventory, quantified model evaluation and tailored AI Act templates as the work that moves governance into operations. The full letter and tracked send receipt:
Sent: Petar Tsankov, LatticeFlow AI
Selected because His July 2025 essay separates vague GPAI questions from implementable high-risk obligations, and COMPL-AI translates the latter into technical evaluation. The full letter and tracked send receipt:
Key evidence
3 more ranked claims
Ask this article · 8 suggested prompts
Text the build (+14245134626) or WhatsApp — slug|question creates a question node. Paste evidence with ingest slug|q:NODE_ID|your paste.