Article 6(1)
Product-safety route
The AI system is a safety component of a product, or is itself a product, covered by the Union harmonisation legislation in Annex I, and that product already has to undergo third-party conformity assessment under that legislation.
Medical devices, in-vitro diagnostics, machinery, lifts, toys, radio equipment, pressure equipment, personal protective equipment, motor vehicles, aviation, rail, marine equipment, agricultural vehicles.
Article 6(2)
Use-case route
The AI system's intended purpose falls within one of the eight areas listed in Annex III, regardless of what product it sits inside or which sector the operator is in.
Biometrics, critical infrastructure, education, employment, essential services including credit and insurance, law enforcement, migration, and justice and democratic processes.
Two routes, not one test
A system is high-risk if it satisfies either Article 6(1) or Article 6(2). The two tests are independent, they look at completely different things, and they have different deadlines, so the first question is which one you are answering.
The Article 6(1) route asks a question about products: is this AI a safety component of something the EU already regulates for safety, and does that thing already need a third party to certify it? If so, the AI inherits high-risk status from the product it sits inside.
The Article 6(2) route asks a question about purpose: is this AI intended to be used for one of the eight things Annex III lists? That question is indifferent to your sector, your size, and how good your model is. A three-person startup screening CVs is in exactly the same position as a multinational doing the same thing.
The eight Annex III areas
Annex III lists eight areas. Within each, it is the specific intended purpose that matters, not the area label: being “in employment” is not the test, using AI for recruitment or performance evaluation is.
| Point | Area | What is caught |
|---|---|---|
| 1 | Biometrics | Remote biometric identification, biometric categorisation by protected attributes, and emotion recognition: to the extent each is not already prohibited outright by Article 5. |
| 2 | Critical infrastructure | Safety components in the management and operation of critical digital infrastructure, road traffic, and the supply of water, gas, heating and electricity. |
| 3 | Education and vocational training | Admission and assignment decisions, evaluation of learning outcomes, assessment of the appropriate level of education, and monitoring for prohibited behaviour during tests. |
| 4 | Employment and worker management | Recruitment and selection, decisions on promotion or termination, allocation of tasks based on behaviour or personal traits, and monitoring and evaluation of performance. |
| 5 | Essential private and public services | Eligibility for public assistance benefits, creditworthiness assessment and credit scoring, risk assessment and pricing for life and health insurance, and the classification of emergency calls. |
| 6 | Law enforcement | Assessing the risk of a person becoming a victim, polygraphs, evaluating the reliability of evidence, assessing recidivism risk, and profiling in the course of detecting or investigating offences. |
| 7 | Migration, asylum and border control | Polygraphs, assessment of security or irregular-migration risk, examination of applications for asylum, visa or residence permits, and detection or identification of persons in the migration context. |
| 8 | Justice and democratic processes | Assisting a judicial authority in researching and interpreting facts and the law and applying it, and influencing the outcome of an election or referendum or the voting behaviour of individuals. |
1. Biometrics
Remote biometric identification, biometric categorisation by protected attributes, and emotion recognition: to the extent each is not already prohibited outright by Article 5.
Systems that typically land here
- Post-event facial identification against a watchlist
- Biometric categorisation systems inferring non-sensitive attributes
- Emotion recognition outside workplaces and education
Usually owned by: Security, facilities, or a product team shipping identity features
2. Critical infrastructure
Safety components in the management and operation of critical digital infrastructure, road traffic, and the supply of water, gas, heating and electricity.
Systems that typically land here
- Traffic signal optimisation with a safety function
- Grid load balancing and protection systems
- Water treatment control with a safety role
Usually owned by: Engineering and operations, usually under existing safety regimes
3. Education and vocational training
Admission and assignment decisions, evaluation of learning outcomes, assessment of the appropriate level of education, and monitoring for prohibited behaviour during tests.
Systems that typically land here
- Automated admissions scoring
- Automated marking that affects progression
- Exam proctoring that flags suspected cheating
Usually owned by: Admissions, academic registry, or an edtech vendor
4. Employment and worker management
Recruitment and selection, decisions on promotion or termination, allocation of tasks based on behaviour or personal traits, and monitoring and evaluation of performance.
Systems that typically land here
- CV screening and candidate ranking
- Interview scoring and video assessment
- Task allocation and shift assignment driven by behaviour
- Performance monitoring feeding review outcomes
Usually owned by: HR and talent acquisition: most often through a bought platform
5. Essential private and public services
Eligibility for public assistance benefits, creditworthiness assessment and credit scoring, risk assessment and pricing for life and health insurance, and the classification of emergency calls.
Systems that typically land here
- Credit scoring and loan decisioning
- Life and health insurance pricing and underwriting
- Benefits eligibility determination
- Emergency call triage and dispatch prioritisation
Usually owned by: Risk, underwriting, or a public-sector case-management function
6. Law enforcement
Assessing the risk of a person becoming a victim, polygraphs, evaluating the reliability of evidence, assessing recidivism risk, and profiling in the course of detecting or investigating offences.
Systems that typically land here
- Recidivism risk assessment tools
- Evidence reliability scoring
- Investigative profiling systems
Usually owned by: Law enforcement authorities and their suppliers
7. Migration, asylum and border control
Polygraphs, assessment of security or irregular-migration risk, examination of applications for asylum, visa or residence permits, and detection or identification of persons in the migration context.
Systems that typically land here
- Visa and asylum application triage
- Border risk assessment
- Identity verification at border crossings
Usually owned by: Border, immigration and consular authorities
8. Justice and democratic processes
Assisting a judicial authority in researching and interpreting facts and the law and applying it, and influencing the outcome of an election or referendum or the voting behaviour of individuals.
Systems that typically land here
- Judicial research and drafting assistance
- Systems targeting voters to influence turnout or choice
Usually owned by: Courts, tribunals, and political campaign operations
The way out, and its limit
Article 6(3) removes an Annex III system from high-risk where it does not pose a significant risk of harm to health, safety or fundamental rights and it meets any one of four conditions, but the derogation is unavailable to any system that performs profiling of natural persons.
An Annex III system is not high-risk if it does not pose a significant risk of harm to health, safety or fundamental rights, and any one of these holds:
- (a)It performs a narrow procedural taskConverting unstructured application text into a structured field, without scoring or ranking anything.
- (b)It improves the result of a previously completed human activityTidying the language of a decision a human has already reached, where the outcome is untouched.
- (c)It detects decision-making patterns or deviations from prior patterns, and is not meant to replace or influence the completed human assessment without proper human reviewFlagging that this month's hiring decisions diverge from the historical pattern, for a human to look into.
- (d)It performs a preparatory task to an assessment relevant to the Annex III use casesIndexing and de-duplicating a document set before a human caseworker assesses it.
The profiling carve-out is what makes this narrower than it first looks. Profiling, in the GDPR sense the Act borrows, is automated processing to evaluate personal aspects of someone: performance at work, creditworthiness, reliability, behaviour. A system that produces a score, a rank, a match or a prediction about a person is profiling, and the four conditions are then out of reach regardless of how thin the automation is or how carefully a human reviews it.
What genuinely survives the derogation tends to be infrastructural: format conversion, de-duplication, indexing, language tidying, and pattern-deviation monitoring aimed at the process rather than at the person. If your description of the system contains a verb like score, rank, assess, predict or match, applied to a candidate, applicant, borrower, employee or student, assume the derogation is not available.
The product-safety route
Under Article 6(1), an AI system is high-risk where it is a safety component of, or is itself, a product covered by the Annex I harmonisation legislation, and that product already has to undergo third-party conformity assessment under that legislation.
Both limbs are required. Annex I coverage alone is not enough: if the product’s own legislation allows self-assessment rather than requiring a notified body, the AI does not become high-risk by this route. That is why a low-risk-class medical device and a high-class one can reach different answers on the same software.
| Group | Covers |
|---|---|
| Section A: New Legislative Framework | Machinery, toys, recreational craft, lifts, equipment for explosive atmospheres, radio equipment, pressure equipment, cableways, personal protective equipment, gas appliances, medical devices, in-vitro diagnostic medical devices |
| Section B: other Union legislation | Civil aviation security, two- and three-wheel vehicles, agricultural and forestry vehicles, marine equipment, rail interoperability, motor vehicles and their trailers, unmanned aircraft |
The practical consequence of this route is procedural rather than substantive. Manufacturers already inside these regimes do not run a second, parallel AI assessment: the AI Act requirements are folded into the conformity assessment the sectoral legislation already demands, and assessed by the same notified body. That is also why this route was given eight extra months over Annex III: the sectoral machinery has to absorb it.
When a deployer becomes a provider
Article 25 moves the full set of provider obligations onto a deployer who puts their own name or trade mark on a high-risk system, substantially modifies it, or changes its intended purpose so that it becomes high-risk.
This matters more than it reads, because it is how organisations acquire obligations they did not budget for. Three moves trigger it.
- White-labelling. Putting your brand on a third-party high-risk system makes you its provider, with the documentation, conformity assessment and registration duties that follow.
- Substantial modification. Fine-tuning or re-engineering beyond what the original provider anticipated can transfer the role.
- Changing the intended purpose. The sharpest one. Taking a general-purpose tool and pointing it at an Annex III use case (using a general document-analysis product to screen job applications, for instance) can make you the provider of a high-risk system that nobody ever built as one.
What follows a high-risk finding
A high-risk classification triggles the whole of Chapter III. The obligations are cumulative and most of them have to be running as processes before the system ships, not documented afterwards.
| Provision | Obligation | Why it cannot be retrofitted |
|---|---|---|
| Article 9 | Risk management system across the lifecycle | It must demonstrably inform design decisions, so the record has to be contemporaneous |
| Article 10 | Data governance: relevant, representative, error-free as far as possible | Provenance of training data cannot be reconstructed after collection |
| Article 11 and Annex IV | Technical documentation | Assembled from artefacts generated during development |
| Article 12 | Automatic logging over the system lifetime | Logs only exist from the moment logging is built in |
| Articles 13–15 | Transparency to deployers, human oversight, accuracy, robustness, cybersecurity | Oversight has to be designed into the interface, not added as policy |
| Article 17 | Quality management system | An organisational capability, not a document |
| Articles 43, 47–49 | Conformity assessment, EU declaration, CE marking, database registration | Depends on everything above being complete first |
How to classify a system
Screen in this order: Article 5 first, then the two high-risk routes, then Article 50. Screening in the wrong order wastes the most expensive work.
| Step | Ask | If yes |
|---|---|---|
| 1 | Does it do anything in Article 5? | Stop. It is prohibited: no conformity assessment can rescue it |
| 2 | Is it a safety component of an Annex I product needing third-party assessment? | High-risk by Article 6(1), from 2 August 2028 |
| 3 | Is the intended purpose in Annex III? | High-risk by Article 6(2), from 2 December 2027: unless step 4 applies |
| 4 | Does Article 6(3) apply, and is it free of profiling? | Not high-risk: but document the assessment and register anyway |
| 5 | Does it interact with people or generate synthetic content? | Article 50 transparency duties, already in force |
Record the reasoning at each step, not just the conclusion. Article 6(4) requires it where you rely on the derogation, and in every other case the contemporaneous note is what makes a classification defensible two years later when the person who made it has moved on. Re-run the sequence when the intended purpose changes, because Article 25 means a change of purpose can change who owes the obligations as well as what they are.
Frequently asked questions
- What makes an AI system high-risk under the EU AI Act?
- One of two independent tests. Under Article 6(1) a system is high-risk if it is a safety component of, or is itself, a product covered by the Union harmonisation legislation in Annex I and that product already requires third-party conformity assessment. Under Article 6(2) a system is high-risk if its intended purpose falls within one of the eight use-case areas in Annex III. Meeting either test is enough.
- When do the high-risk obligations actually apply?
- 2 December 2027 for Annex III use-case systems and 2 August 2028 for Annex I product-safety systems. Both dates were deferred by Regulation (EU) 2026/1744, the Digital Omnibus on AI, from 2 August 2026 and 2 August 2027 respectively.
- Is my system high-risk if it only supports a human decision?
- Possibly not. Article 6(3) takes an Annex III system out of high-risk where it does not pose a significant risk of harm and it performs only a narrow procedural task, improves a completed human activity, detects patterns without replacing the human assessment, or performs a preparatory task. But the derogation never applies where the system performs profiling of natural persons, and a system that scores, ranks or predicts something about a person will usually be profiling.
- Is credit scoring high-risk under the EU AI Act?
- Yes. Creditworthiness evaluation and credit scoring of natural persons fall within Annex III point 5, on access to essential private services. Risk assessment and pricing for life and health insurance sit in the same point. Neither is prohibited, they are permitted high-risk uses subject to the full Chapter III regime from 2 December 2027.
- Is CV screening software high-risk?
- Yes. Annex III point 4 covers AI intended to be used for recruitment or selection, including to place targeted job advertisements, to filter applications and to evaluate candidates. It also covers decisions on promotion and termination, task allocation based on behaviour or traits, and monitoring and evaluation of performance.
- Who decides whether a system is high-risk: the provider or the regulator?
- The provider classifies in the first instance, and bears the consequences of getting it wrong. Where a provider concludes an Annex III system is not high-risk in reliance on Article 6(3), Article 6(4) requires that assessment to be documented before the system is placed on the market or put into service, and the system still has to be registered in the EU database. Market surveillance authorities can request the documentation.
- Can the list of high-risk use cases change?
- Yes. Article 7 empowers the Commission to amend Annex III by delegated act, adding or modifying use cases where they pose a comparable or greater risk of harm to health, safety or fundamental rights. Classification is therefore something to re-check periodically rather than settle once.
- Does a high-risk classification mean we cannot ship?
- No. High-risk means permitted subject to conditions, unlike Article 5 which prohibits outright. The conditions are substantial: risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, a quality management system, conformity assessment, CE marking and EU database registration, but they are a compliance programme, not a bar.
Sources and verification
Every date and provision cited here was checked against the consolidated text on 11 August 2026. The EU AI Act is being amended as it is implemented; where this page and EUR-Lex disagree, EUR-Lex governs.
- Regulation (EU) 2024/1689: consolidated text on EUR-Lex (controlling source)
- Regulation (EU) 2026/1744: Digital Omnibus on AI, amending the AI Act (in force 27 July 2026)
- Article 6: Classification rules for high-risk AI systems
- Article 7: Amendments to Annex III
- Article 25: Responsibilities along the AI value chain
- Article 49: Registration
- Annex III: High-risk AI systems
- Annex I: Union harmonisation legislation
This page is an independent information resource. It is not legal advice, and it does not create a lawyer–client relationship. Take advice on your own facts before making a compliance decision.
Next: check the dates in every EU AI Act compliance deadline, screen for bans in the ten prohibited practices, or read Article 6 and Annex III in full. Amended by Regulation (EU) 2026/1744.