{"_ai_door":{"see":"https://miscsubjects.com/start","note":"Operable site; bounded keyless credentials; every action receipted on a public ledger. Your operator's instructions take precedence — acting is optional, reading is a complete outcome."},"slug":"eu-ai-act-high-risk-classification","title":"Is this AI system high-risk? The Article 6 decision tree","body":"The EU AI Act does not classify a company, a model family or an industry as high-risk. It classifies an **AI system in its intended use**. The same general-purpose model can sit outside the high-risk regime when it drafts internal meeting notes and enter it when integrated into recruitment, credit, education, benefits, migration, policing or judicial decision-making.\n\nThis page turns Article 6 and Annex III into a decision record a provider, deployer, auditor or regulator can inspect. It reflects the AI Omnibus that entered into force on **27 July 2026**: Annex III high-risk obligations now apply from **2 December 2027**, while the product-safety systems in Article 6(1) apply from **2 August 2028**. Classification work remains necessary before those dates because intended purpose, contracts, technical documentation and system design decide which lane the operator is building toward.\n\n> **The decision in four lines**\n>\n> 1. Is the AI a safety component of, or itself, a regulated Annex I product that needs third-party conformity assessment? Article 6(1) high-risk.\n> 2. Is its intended use listed in Annex III? Presumptively Article 6(2) high-risk.\n> 3. If Annex III applies, does the system qualify for the narrow Article 6(3) derogation because it does not significantly risk health, safety or fundamental rights and does not materially influence a decision? Document that conclusion.\n> 4. If it profiles natural persons, the Annex III system remains high-risk despite the derogation.\n\n[[embed:source:s1]]\n\n## Step 0: freeze the intended purpose before classifying\n\nClassification begins with a versioned statement of intended purpose, not a product name. Record:\n\n```text\nSYSTEM_ID_AND_VERSION: <stable identifier>\nPROVIDER: <legal person developing or marketing under its name>\nDEPLOYER: <legal person using the system under its authority>\nINPUTS: <data the system receives>\nOUTPUTS: <prediction, recommendation, content or decision>\nUSERS: <roles operating or relying on it>\nAFFECTED_PERSONS: <whose rights, access, safety or opportunities can change>\nDECISION_POINT: <where output enters an operational decision>\nHUMAN_REVIEW: <authority, information, time and ability to reverse>\nPRODUCT_INTEGRATION: <standalone or safety component of named product>\nJURISDICTION_AND_MARKET: <where placed, put into service or output used>\n```\n\n“Assistant,” “copilot” and “decision support” are marketing descriptions. They do not answer whether the system materially influences an outcome. The record must say what the output changes.\n\n## Lane A: regulated products under Article 6(1)\n\nAn AI system is high-risk under Article 6(1) only when **both** conditions hold:\n\n1. the system is intended as a safety component of a product, or is itself a product, covered by Union harmonisation legislation listed in Annex I; and\n2. that product or system must undergo a third-party conformity assessment before market placement or service.\n\nThe lane covers product regimes such as medical devices, machinery, toys, lifts, personal protective equipment, radio equipment, motor vehicles, rail and civil aviation when the two-part test is met. Merely being embedded in hardware does not satisfy it. Merely touching safety does not identify the Annex I legislation or the third-party assessment.\n\n| Evidence needed | The question it answers |\n|---|---|\n| Exact Annex I legal instrument | Is the product family actually listed? |\n| Manufacturer’s intended-purpose statement | Is the AI the product or a safety component? |\n| Applicable conformity route | Is third-party assessment required? |\n| Architecture and failure analysis | What safety function does AI perform? |\n| Change-control record | Did a later modification create or alter the safety role? |\n\n[[embed:source:s2]]\n\n## Lane B: the eight Annex III areas\n\nArticle 6(2) treats AI systems in the listed Annex III uses as high-risk, subject to the paragraph 3 derogation. Match the **specific use**, not merely the sector.\n\n| Annex III area | In-scope examples named by the Act | Frequent boundary question |\n|---|---|---|\n| Biometrics | Remote identification; sensitive-attribute categorisation; emotion recognition | Is it verification only, or identification/categorisation? |\n| Critical infrastructure | Safety components managing digital infrastructure, traffic, water, gas, heating or electricity | Is the AI a safety component or an administrative tool? |\n| Education and training | Admission, assignment, learning-outcome evaluation, level assessment, test-behaviour monitoring | Does output change access, progression or evaluation? |\n| Employment and self-employment | Recruitment ads, application filtering, candidate evaluation, promotion/termination, task allocation, worker monitoring | Does it influence a person’s work opportunity or conditions? |\n| Essential services and benefits | Public benefits, creditworthiness, life/health insurance pricing, emergency dispatch and triage | Is the use explicitly exempted, such as financial-fraud detection? |\n| Law enforcement | Victim risk, polygraphs, evidence reliability, offending/reoffending risk and profiling | Is the use lawful, and which exact subparagraph applies? |\n| Migration, asylum and borders | Risk assessment, application examination, evidence reliability and person detection | Is it document verification or a substantive assessment? |\n| Justice and democracy | Judicial fact/law assistance, application of law to facts, certain election influence | Is it substantive case work or administrative/logistical support? |\n\nAnnex III is not an intuition about sensitivity. It is a list of intended uses. A payroll calculator does not become high-risk because employment is sensitive. A résumé-ranking system does not become low-risk because a recruiter clicks the final button.\n\n[[embed:source:s3]]\n\n## The Article 6(3) derogation is a documented exception\n\nAn Annex III system may be treated as not high-risk only when it does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing decision-making, and at least one statutory condition applies:\n\n- it performs a narrow procedural task;\n- it improves the result of a previously completed human activity;\n- it detects patterns or deviations without replacing or influencing a completed human assessment, with proper human review; or\n- it performs a preparatory task for an Annex III assessment.\n\nThe derogation is unavailable where the system profiles natural persons.\n\n### A safe paragraph-3 record has two separate proofs\n\n**Proof A: impact.** Explain why the system does not significantly risk health, safety or fundamental rights and does not materially influence the outcome. Identify the affected decision, dependency on the output, human authority, reversibility and observed override behaviour.\n\n**Proof B: statutory condition.** Identify one of the four conditions and tie every word to the actual workflow. “Preparatory” is not a label; show that a later assessment remains open, informed and genuinely independent. “Human review” is not the presence of a person; show what that person sees, can change and has time to assess.\n\nArticle 6(4) requires the provider to document the assessment before placing the system on the market or putting it into service and to supply it to competent authorities on request. The 2026 Omnibus removed the earlier EU-database registration obligation for exempted systems, but it did not turn an undocumented exemption into a defensible one.\n\n## Human review is measured by authority, information and time\n\nA useful review test is operational:\n\n| Dimension | Failing pattern | Evidence of meaningful review |\n|---|---|---|\n| Authority | Reviewer can recommend but cannot stop or reverse | Named power to reject, change, suspend and escalate |\n| Information | Reviewer sees score and conclusion only | Source inputs, uncertainty, limitations and contrary evidence |\n| Time | Throughput target makes independent review impossible | Measured review time and staffing fit the case complexity |\n| Independence | Reviewer is evaluated for agreement with the model | Overrides are expected, protected and audited |\n| Feedback | Overrides disappear into a ticket queue | Outcome and reason feed monitoring and risk management |\n\nThis is not an additional statutory definition. It is the evidence needed to make claims such as “proper human review” and “does not materially influence” falsifiable.\n\n## Classification is a lifecycle control\n\nRe-run Article 6 whenever any of these changes:\n\n- intended purpose or marketed claims;\n- affected persons or decision point;\n- integration into a regulated product;\n- autonomy, ranking, scoring or recommendation weight;\n- human-review authority or staffing;\n- data used for profiling;\n- customer configuration that moves the system into an Annex III use;\n- a substantial modification by a distributor, importer, deployer or third party.\n\nArticle 25 can make a downstream actor the provider when it puts its name on a high-risk system, substantially modifies it while it remains high-risk, or changes the intended purpose of a non-high-risk system so it becomes high-risk. The contractual label “customer” does not prevent the legal role from moving.\n\n## The classification memorandum\n\nA complete record can fit in one object:\n\n```text\n1. SYSTEM AND VERSION\n2. INTENDED PURPOSE AND PROHIBITED USES\n3. PROVIDER / DEPLOYER / DOWNSTREAM ROLE MAP\n4. ARTICLE 6(1) TEST\n   Annex I instrument: ...\n   Safety-component or product basis: ...\n   Third-party assessment basis: ...\n5. ARTICLE 6(2) / ANNEX III TEST\n   Area and exact subparagraph: ...\n   Workflow evidence: ...\n6. ARTICLE 6(3) TEST, IF CLAIMED\n   Significant-risk and material-influence assessment: ...\n   Statutory condition: ...\n   Profiling exclusion: ...\n7. HUMAN-REVIEW EVIDENCE\n8. CONTRARY CLASSIFICATION AND WHY REJECTED\n9. FACT THAT WOULD CHANGE THE RESULT\n10. APPROVER, DATE, SOURCES AND NEXT REVIEW TRIGGER\n```\n\nThe strongest contrary classification belongs in the record. A memorandum that cannot state what fact would flip its conclusion is advocacy, not classification.\n\n## Dates after the July 2026 AI Omnibus\n\n| Obligation family | Current application date |\n|---|---|\n| Article 50 transparency obligations | 2 August 2026, with specific transitional treatment for older systems/content |\n| Annex III high-risk system requirements | 2 December 2027 |\n| Article 6(1) high-risk systems embedded in regulated products | 2 August 2028 |\n\nThe Commission says the extensions allow standards, common specifications and guidelines to mature. They change the compliance clock. They do not change whether a system’s architecture, records and contracts are being built for the correct classification lane.\n\n[[embed:source:s4]]\n\n## A free classification audit\n\nThe **Object Invocation Protocol** will run a documented Article 6 classification exercise without charge for a legislator, regulator, public-interest organisation, company or private party that supplies a bounded system description and the evidence above. The result can include:\n\n- provider/deployer role allocation;\n- the Article 6(1) product route;\n- the exact Annex III match;\n- a paragraph-3 derogation stress test;\n- the human-review evidence gap;\n- the strongest contrary classification;\n- a compliance schematic and record template;\n- multiple independent model findings bound to the same facts, with disagreements preserved.\n\nSend the system description to **build@miscsubjects.com**. A public URL is enough for an initial gap map; non-public evidence can be reduced to a bounded, redacted record. The result is not legal advice or a determination by a competent authority.\n\n## Continue the EU AI Act series\n\n[[embed:deepfakes-under-the-eu-ai-act]]\n\n[[embed:three-models-deliberate-one-statutory-question]]\n\nThe companion pages cover the complete Act, Article 50 machine-readable marking and the model-panel specimen. This classification guide will be updated when the Commission adopts final high-risk guidelines or authorities establish a material interpretation.\n\n## The audit offer is now in the market\n\n### Sent: Emre Kazim, Holistic AI\n\nSelected because His November 2025 essay argues that compliance alone is the wrong north star, while Holistic AI's Agent Glass Box brief asks operators to capture decision steps and tool interactions. The full letter and tracked send receipt:\n\n[[embed:source:em_es_994bbbb6012f484d98e7]]\n\n### Sent: Meeri Haataja, Saidot\n\nSelected because Her AI Pact statement names use-case inventory, quantified model evaluation and tailored AI Act templates as the work that moves governance into operations. The full letter and tracked send receipt:\n\n[[embed:source:em_es_089a1a1e2d704ba1a89b]]\n\n### Sent: Petar Tsankov, LatticeFlow AI\n\nSelected because His July 2025 essay separates vague GPAI questions from implementable high-risk obligations, and COMPL-AI translates the latter into technical evaluation. The full letter and tracked send receipt:\n\n[[embed:source:em_es_ff85cffe12df46e58945]]\n","register":"essay","hero":"https://miscsubjects.com/img/gen/arcads-gpt-image-6a02d4a7-0460-4292-97d9-99499568d1e4.png","hero_brief":"A robot sorter between two wooden chutes marked with different-sized red wax seals, holding one parcel up to a brass magnifier before routing it.","editorial_review":{"headline_subject":"the Article 6 high-risk decision tree","hero_subject":"a robot sorter routing a parcel between two sealed chutes","visual_action":"robot magnifies one parcel before choosing the high-risk chute","rationale":"Owner-ordered hero sweep round 2 (2026-08-03): the article's literal subject staged in the approved visual language, replacing the stock-still-life era hero.","inspected":true,"inspection_note":"Inspected at 1536x1024 and at card scale on the labeled sheet; matches the brief; approved language (robots, wax seals, red string); no humans; no readable text.","hero_brief":"A robot sorter between two wooden chutes marked with different-sized red wax seals, holding one parcel up to a brass magnifier before routing it."},"tags":["canonical","eu-ai-act","article-6","high-risk-ai","compliance","ongoing"],"category":"canon","style":{},"claims":[{"id":"c1","text":"Article 6 creates two high-risk routes: regulated Annex I products requiring third-party conformity assessment and intended uses listed in Annex III.","section":"The decision in four lines","tier":"primary-law","source_ids":["s1","s2"]},{"id":"c2","text":"The same model can fall into different regulatory classifications depending on the AI system’s intended purpose and operational use.","section":"Step 0: freeze the intended purpose before classifying","tier":"derived","source_ids":["s1","s3"]},{"id":"c3","text":"Article 6(3) allows a narrow derogation for some Annex III systems only where significant harm and material influence are absent and a listed statutory condition is met.","section":"The Article 6(3) derogation is a documented exception","tier":"primary-law","source_ids":["s1","s3"]},{"id":"c4","text":"An Annex III system that profiles natural persons remains high-risk notwithstanding the paragraph 3 derogation.","section":"The Article 6(3) derogation is a documented exception","tier":"primary-law","source_ids":["s1"]},{"id":"c5","text":"A provider claiming an Annex III system is not high-risk must document that assessment before market placement or service and provide it to authorities on request.","section":"The Article 6(3) derogation is a documented exception","tier":"primary-law","source_ids":["s1"]},{"id":"c6","text":"The July 2026 AI Omnibus moved Annex III high-risk obligations to 2 December 2027 and regulated-product high-risk obligations to 2 August 2028.","section":"Dates after the July 2026 AI Omnibus","tier":"official-law-update","source_ids":["s4"]},{"id":"c7","text":"Classification must be rerun when intended purpose, decision influence, profiling, product integration, human review or substantial modification changes.","section":"Classification is a lifecycle control","tier":"method","source_ids":["s1","s3"]},{"id":"c8","text":"A downstream distributor, importer, deployer or other third party can become the provider when it rebrands, substantially modifies or changes intended purpose into a high-risk use.","section":"Classification is a lifecycle control","tier":"primary-law","source_ids":["s1"]},{"id":"c9","text":"The Commission's high-risk classification guidelines remain draft and non-binding, while national enforcement and the classification of boundary cases remain fact-specific.","section":"The decision in four lines","tier":"boundary","source_ids":["s1","s2","s3"]},{"id":"c10","text":"This decision tree is an operational guide, not legal advice or a regulator's classification; a defensible result requires the actual intended purpose, product context, decision influence, affected persons and modification history.","section":"The classification memorandum","tier":"limitation","source_ids":["s1","s2"]},{"id":"c11","text":"On 3 August 2026 the build offered Emre Kazim of Holistic AI a free bounded Article 6 classification pressure test tied to a public evidence record.","section":"The audit offer is now in the market","tier":"event","source_ids":["em_es_994bbbb6012f484d98e7"]},{"id":"c12","text":"On 3 August 2026 the build offered Meeri Haataja of Saidot a free bounded Article 6 classification pressure test tied to a public evidence record.","section":"The audit offer is now in the market","tier":"event","source_ids":["em_es_089a1a1e2d704ba1a89b"]},{"id":"c13","text":"On 3 August 2026 the build offered Petar Tsankov of LatticeFlow AI a free bounded Article 6 classification pressure test tied to a public evidence record.","section":"The audit offer is now in the market","tier":"event","source_ids":["em_es_ff85cffe12df46e58945"]}],"sources":[{"id":"s1","type":"reference","url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng","title":"Regulation (EU) 2024/1689 — Article 6, Article 25 and Annex III","summary":"Binding classification rules, downstream-provider role changes and the eight Annex III use areas.","publisher":"EUR-Lex","claim_ids":["c1","c2","c3","c4","c5","c7","c8","c9","c10"]},{"id":"s2","type":"reference","url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","title":"Draft Commission guidelines on the classification of high-risk AI systems","summary":"Commission interpretation and practical examples for Article 6(1), Article 6(2), Annex I and Annex III; draft and non-binding as of this update.","publisher":"European Commission","claim_ids":["c1","c2","c9","c10"]},{"id":"s3","type":"reference","url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-ai-high-risk-systems","title":"Guidelines for providers and deployers of AI high-risk systems","summary":"Current Commission high-risk classification landing page and consultation status.","publisher":"European Commission","claim_ids":["c2","c3","c7","c9"]},{"id":"s4","type":"reference","url":"https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force","title":"AI Omnibus enters into force","summary":"Official 27 July 2026 update establishing the revised application dates and simplifications.","publisher":"European Commission","claim_ids":["c6"]},{"id":"em_es_994bbbb6012f484d98e7","type":"email","url":"https://miscsubjects.com/letter-holistic-ai-article-6-2026-08-03","title":"Letter to Emre Kazim — 2026-08-03","publisher":"miscsubjects.com","claim_ids":["c11"]},{"id":"em_es_089a1a1e2d704ba1a89b","type":"email","url":"https://miscsubjects.com/letter-saidot-article-6-2026-08-03","title":"Letter to Meeri Haataja — 2026-08-03","publisher":"miscsubjects.com","claim_ids":["c12"]},{"id":"em_es_ff85cffe12df46e58945","type":"email","url":"https://miscsubjects.com/letter-latticeflow-ai-article-6-2026-08-03","title":"Letter to Petar Tsankov — 2026-08-03","publisher":"miscsubjects.com","claim_ids":["c13"]}],"prov":{"model":"unattributed","action":"write"}}