NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new
EU AI Act Article 6: High-Risk Classification
Learn

EU AI Act Article 6: High-Risk Classification

·Alexander Sverdlov

Article 6 of the EU AI Act is the whole classification question in one place. There are two ways into the high-risk category and one way back out. Route one, Article 6(1): your AI system is a safety component of a product, or is itself a product, covered by the Union harmonisation legislation in Annex I, and that product needs third-party conformity assessment. Route two, Article 6(2): your system falls in one of the eight areas listed in Annex III. The way out is Article 6(3), and it is narrower than most summaries suggest.

Two things about Article 6 changed in 2026, and both matter more than the classification test itself. Regulation (EU) 2026/1744, the Digital Omnibus on AI, inserted three new paragraphs into Article 6 that narrow what counts as a safety component, and it moved the date on which the high-risk regime applies at all.

QuestionAnswerProvision
What makes a product-embedded system high risk?It is a safety component of, or is itself, an Annex I product, and that product needs third-party conformity assessment. Both conditions.Art. 6(1)
What makes a standalone system high risk?It falls in one of the eight areas of Annex III.Art. 6(2)
Is there a way out?Yes, if the system poses no significant risk of harm and meets one of four conditions. Never if it profiles natural persons.Art. 6(3)
What do you owe if you use the derogation?Document the assessment before placing the system on the market, register it in the EU database, and hand the documentation over on request.Art. 6(4), Art. 49(2)
When do the high-risk rules apply?2 December 2027 for Annex III systems, 2 August 2028 for Annex I systems.Art. 113, as amended
What each paragraph of EU AI Act Article 6 does: the Annex I route, the Annex III route, the derogation, the documentation duty, the Commission guidelines, and the Article 7 power to add use cases

What does Article 6 of the EU AI Act say?

Read it as a sequence of tests rather than a definition.

Article 6(1): the product route

A system is high risk where both conditions are met: it is intended to be used as a safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in Annex I; and that product is required to undergo third-party conformity assessment before being placed on the market. The paragraph applies irrespective of whether the AI system is placed on the market independently of the product it serves, so selling the component separately does not take you out of scope.

Article 6(2): the use-case route

In addition to the systems caught by paragraph 1, AI systems referred to in Annex III are high risk. This route ignores the product entirely and asks only what the system is used for.

Article 6(3): the derogation

By derogation from paragraph 2, an Annex III system is not high risk where it does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision making. That threshold has to be met, and then one of four listed conditions has to be fulfilled on top of it.

Article 6(4): what the derogation costs

A provider who concludes that an Annex III system is not high risk must document that assessment before the system is placed on the market or put into service, is subject to the registration obligation in Article 49(2), and must produce the documentation on request from national competent authorities. The Omnibus simplified what that registration entry has to contain, by deleting two of the fields in Annex VIII Section B, but it left the registration duty itself standing.

The Article 6 classification test in order: Annex I safety component, third party conformity assessment, Annex III area, Article 6(3) condition, and the profiling override

What is on the Annex III list?

Eight areas. The heading is not the test; the lettered points under each heading are, and several of them are narrower than the heading implies.

Annex III areaWhat it actually covers
1. BiometricsRemote biometric identification, biometric categorisation by sensitive or protected attributes, and emotion recognition. Verification that only confirms a person is who they claim to be is excluded.
2. Critical infrastructureSafety components in the management and operation of critical digital infrastructure, road traffic, or the supply of water, gas, heating or electricity.
3. Education and vocational trainingAdmission and assignment, evaluating learning outcomes, assessing the level of education a person will get, and monitoring for prohibited behaviour during tests.
4. Employment and workers' managementRecruitment and selection, including targeted job advertising and filtering applications, plus decisions on promotion, termination, task allocation and performance monitoring.
5. Essential private and public servicesEligibility for public assistance benefits, creditworthiness and credit scoring, risk assessment and pricing for life and health insurance, and emergency call triage and dispatch.
6. Law enforcementVictim risk assessment, polygraphs, evidence reliability, offending and re-offending risk, and profiling in the course of detection, investigation or prosecution.
7. Migration, asylum and border controlPolygraphs, risk assessment of people entering, examination of asylum, visa and residence applications, and detection or identification of people, other than verifying travel documents.
8. Justice and democratic processesAssisting a judicial authority in researching and interpreting facts and law, and systems intended to influence an election, a referendum or voting behaviour.

Two exclusions inside the list are worth holding on to, because they are where a lot of ordinary software lives. Biometric verification whose sole purpose is confirming that a person is who they claim to be is carved out of point 1. Financial fraud detection is carved out of the creditworthiness point in point 5. And in point 8, tools used to organise, optimise or structure political campaigns administratively, where natural persons are not directly exposed to the output, are outside the election point.

The Omnibus did not amend Annex III. The eight areas and their lettered points are unchanged from the 2024 text. What it did add, in a new Annex XIV, is a code list for notified body designation in which the only Annex III codes that exist are the three biometric ones, which is a useful signal about where third-party assessment capacity is actually being built.

When does an Annex III system escape the high-risk label?

Only when the no-significant-risk threshold is met and at least one of these four conditions is fulfilled: the system is intended to perform a narrow procedural task; it is intended to improve the result of a previously completed human activity; it is intended to detect decision-making patterns or deviations from prior patterns and is not meant to replace or influence the previously completed human assessment without proper human review; or it is intended to perform a preparatory task to an assessment relevant to an Annex III use case.

Then the override. Notwithstanding all of the above, an Annex III system is always high risk where it performs profiling of natural persons. There is no balancing test attached to that sentence. If your system profiles people, the derogation is closed, whatever else it does.

The four conditions in EU AI Act Article 6(3): narrow procedural task, improving a completed human activity, detecting decision patterns, and performing a preparatory task

What did the Digital Omnibus change in Article 6?

It inserted paragraphs 1a, 1b and 1c, all aimed at the safety component test in paragraph 1, and all narrowing it.

Paragraph 1a says that AI systems used solely for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation, convenience or quality control do not qualify as safety components. Paragraph 1b immediately puts the floor back: notwithstanding 1a, systems whose failure or malfunctioning would endanger health and safety do qualify. Paragraph 1c addresses the second limb of the test, providing that a product required to undergo third-party conformity assessment solely because of risks other than health and safety, in particular radio spectrum or electromagnetic interference risks that do not affect health and safety, does not satisfy Article 6(1)(b).

The Omnibus also tightened the definition of safety component itself in Article 3(14), adding that a component fulfils a safety function where its intended purpose is to prevent or mitigate risks to the health and safety of persons or property. Taken together, these are the amendments most likely to move a real product out of the high-risk category, and they operate on the Annex I route rather than the Annex III one.

When do the classification rules actually apply?

Chapter III Sections 1, 2 and 3 of the AI Act now apply from 2 December 2027 for systems classified as high risk under Article 6(2) and Annex III, and from 2 August 2028 for systems classified under Article 6(1) and Annex I. Article 6 sits in Section 1, so the classification rules move with the obligations they gate.

One paragraph was carved out of that deferral. The amended Article 113 defers those sections with the exception of Article 6(5), which is the Commission's duty to publish guidelines on the practical implementation of Article 6 together with a list of examples. That duty was originally due by 2 February 2026. The Commission published draft guidelines on 19 May 2026 in three parts, covering general principles, Annex I classification and Annex III classification, and they were still in draft at the time of writing.

Two dates that did not move are worth keeping next to these. The Article 50 transparency obligations still apply from 2 August 2026. And under the amended Article 111(2), providers and deployers of high-risk systems intended to be used by public authorities have until 2 August 2030 for systems already placed on the market. Which of those duties lands on you depends on whether you are the provider or the deployer of the system. The complete set of dates is in our guide to EU AI Act deadlines, and the reasoning behind the postponement is in why the August 2026 high-risk deadline moved.

When each part of the EU AI Act high risk regime applies after the Digital Omnibus: Article 50 transparency in 2026, Annex III in December 2027, Annex I in August 2028, and public sector legacy systems in 2030

What the other results get wrong

The most common error is reproducing the 2024 text of Article 6 without the 2026 amendments. Article 6 now has paragraphs 1a, 1b and 1c that did not exist when most published explainers were written, and they are precisely the paragraphs a manufacturer needs.

The second is describing Article 6(3) as a four-condition test. It is a threshold plus one of four conditions. A system can satisfy condition (a) comfortably and still be high risk because it materially influences the outcome of decision making, and it will be high risk regardless if it profiles people.

The third is treating the deferral as a pause. Classification is the input to everything else: your conformity assessment route, your technical documentation, and your penalty exposure all follow from it, and the notified body capacity that Annex XIV is designed to build up is finite.

Working out your own position

Fill this in per system, not per company. Classification is a property of the system and its intended purpose.

QuestionYour answerWhat it decides
Is the system a safety component of, or itself, an Annex I product?Opens the Article 6(1) route, and with it the 2 August 2028 date.
Does that product need third-party conformity assessment for health and safety reasons?Art. 6(1)(b), as narrowed by the new Art. 6(1c). Spectrum-only assessment does not count.
Which Annex III lettered point does it fall under, if any?The heading is not the test. Name the point or you are not in scope by this route.
Does it profile natural persons?If yes, the Article 6(3) derogation is closed and the answer is high risk.
If you are relying on 6(3), where is the documented assessment?Art. 6(4). It must exist before placing on the market, and registration still applies.

If more than one system is in play, the useful next step is an inventory with a classification decision recorded against each entry, dated and re-runnable as the guidelines firm up. A free compliance check gives you a starting position, and the EU AI Act framework page sets out how the obligations hang off the classification once it is made.

The bottom line on EU AI Act Article 6: Annex III puts a system in scope and Article 6(3) is the only way back out

Frequently asked questions

What is Article 6 of the EU AI Act?

The classification rules for high-risk AI systems. It sets the Annex I product route in paragraph 1, the Annex III use-case route in paragraph 2, the derogation in paragraph 3, and the documentation and registration duty that comes with using the derogation in paragraph 4.

How many high-risk categories are in Annex III?

Eight areas, each with its own lettered points. The Digital Omnibus did not change them.

Does the Article 6(3) derogation mean we have no obligations?

No. You must document the assessment before the system is placed on the market, you remain subject to the Article 49(2) registration obligation, and you must give the documentation to national competent authorities on request. The Omnibus simplified the registration content, not the duty.

Can the Commission add new high-risk use cases?

Yes, under Article 7, by delegated act, where the conditions in that article are met. It can also amend the Article 6(3) conditions under Article 6(6) and (7), but not in a way that decreases the overall level of protection.

Which date applies to a system that is both an Annex I product and an Annex III use case?

The Omnibus added a rule for the overlap: where a high-risk system is covered by Section A Annex I legislation and also falls within an Annex III category, the provider follows the conformity assessment procedure required by that harmonisation legislation. Classification, and therefore the applicable date, needs to be settled system by system.

Primary sources

Article 6 and Annex III as quoted are from Regulation (EU) 2024/1689. The 2026 amendments, including the new Article 6(1a) to (1c), the Article 3(14) definition, the Annex VIII deletions, new Annex XIV and the amended Article 113 application dates, are from Regulation (EU) 2026/1744, the Digital Omnibus on AI, adopted 8 July 2026, published in the Official Journal on 24 July 2026 and in force from 27 July 2026. The draft classification guidelines are the European Commission's own publication of 19 May 2026. Confirm the current consolidated text before relying on a specific paragraph.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

CONTINUE READING