ISHIGHRISK AI
The ambiguity hotspot

The Article 6(3) derogation

Four conditions can lift an Annex III system out of the high-risk regime, and profiling forecloses all of them. Where the derogation gets over-claimed.

Reviewed 22 July 2026Regulation (EU) 2024/1689, as amended by the Digital Omnibus
In short

Article 6(3) lifts an Annex III system out of the high-risk regime only when two things hold at once: it poses no significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision making, and it meets at least one of four conditions. A system performing profiling of natural persons is always high-risk, whatever else it does. Article 6(4) requires the assessment to be documented before the system is placed on the market, and under the Digital Omnibus a system self-assessed as non-high-risk still has to be registered in the EU database. The Commission missed its February 2026 deadline for Article 6 classification guidelines, so there is no authoritative worked example and the conservative reading is the safe one.

The Article 6(3) exemption is a two-part test, not a menu

Landing in one of the eight Annex III areas does not settle the classification. Article 6(3) is the off-ramp, and it stays shut unless two separate things are true at the same time. Art 6(3)

First, the system must not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making. Second, it must meet at least one of four listed conditions. The two limbs fail in different ways, and the second is the easier one to argue: a provider picks whichever condition sounds closest and never seriously tests whether the system moves outcomes for real people. On the text, the first limb has to be cleared first.

Two structural points before the conditions. The derogation exists only on the Annex III route. If your system is high-risk because it is, or is a safety component of, a product covered by Annex I harmonisation legislation requiring third-party conformity assessment, there is no Article 6(3) counterpart on that route. The only relief the Digital Omnibus added is a targeted carve-out for AI embedded in Machinery Regulation products, which routes the AI-specific requirements through the Machinery Regulation rather than removing them; medical devices and toys stay fully in scope. See how the Annex I and Annex III routes are tested. And the derogation is a self-assessment. Nobody signs it off before you rely on it. You make the call against the text of Regulation (EU) 2024/1689, you document it, and you carry it.

The four conditions that can lift an Annex III system out of high-risk

You need one of the four, not all of them. Each is narrower than it first reads, and each has a failure mode that shows up in real products.

(a) The system performs a narrow procedural task

Both words are load-bearing. A procedural task is one whose output follows from the process rather than from a judgement about a person: converting a scanned form into structured fields, deduplicating records against an identifier, routing a request to a queue by document type. Picture a CV parser that lifts employer names, job titles and start and end dates verbatim into fields a recruiter then reads in full. Nothing has been decided about the candidate. Now picture the same parser deciding which entries count as skills and how senior each one is. That is evaluation, and evaluation of a person is not procedure, however narrow the code path looks.

(b) The system improves the result of a previously completed human activity

The human activity has to be finished before the system touches it, and the system has to improve the result rather than produce it. A tool that flags non-inclusive wording in a job advert a human has already drafted sits here comfortably: the advert exists, a person wrote it, the tool tightens it, and no candidate has been evaluated. The condition breaks when the improvement is really authorship. A system that drafts a candidate assessment and offers a human an accept button has not improved a completed human activity, it has completed the activity and left a signature block.

(c) The system detects decision-making patterns or deviations from prior patterns

This condition carries its own defeat clause in the text: the detection must not replace or influence the previously completed human assessment without proper human review. Picture a quality-assurance tool that samples closed hiring decisions and flags cases where a manager departed from how comparable cases were handled before, so a person can review them. It is auditing decisions that already happened. Feed the same signal forward into live decisions, or wire a flag to an automatic action, and the condition is gone.

(d) The system performs a preparatory task to an assessment

Preparatory means before the assessment and outside it. An interview scheduler that matches free slots to free rooms prepares an assessment without touching its merits. Indexing, format conversion and collating a file for a human to read are the same shape. The failure mode is treating narrowing as preparation. A tool that hands a recruiter 20 of 200 candidates is not preparing an assessment, it is performing most of one: the 180 it removed were assessed, by the system, and no human ever saw them.

Profiling of natural persons is always high-risk, with no derogation

The four conditions sit under an absolute override. An Annex III system that performs profiling of natural persons is always high-risk. Not presumed high-risk, not high-risk unless rebutted: the two-part test is never reached, and the best-drafted condition argument in the world does not survive it. Art 6(3)

This reaches further than the drafting suggests, because profiling catches a lot of products that would otherwise have a plausible condition to point at. Scoring, segmenting, predicting behaviour, inferring reliability or suitability, ranking people against a target: once a system evaluates personal aspects of identifiable people by automated means, the live question stops being which condition applies and becomes whether this is profiling at all. Where that boundary sits in a given product is genuinely contested, and the Commission guidance that would have drawn it has not been published.

Answer the profiling question first and in writing, before anyone drafts a condition argument. If your system evaluates or predicts something about identifiable people - performance, reliability, preferences, risk, fit - assume a regulator reads that as profiling and assume the off-ramp is closed. Building the high-risk file you probably need is cheaper than defending a derogation record that never had a route through.

Filtering, ranking and scoring are not narrow procedural tasks

The over-claim has a signature. A vendor describes the product by its mechanism - it only matches keywords, it only extracts text, it only sorts - and the buyer reads the mechanism as though it were the legal test. It is not. Article 6(3) asks what the system does to the outcome for a natural person, and three verbs almost always answer that question the wrong way.

Filtering removes people. Whatever a filter does mechanically, its effect is that some candidates, applicants or claimants stop existing for the decision maker. Ranking orders people, and an order is a judgement about relative merit even when it is produced by a similarity score. Scoring attaches a number to a person, and the number is the assessment. None of the three is a narrow procedural task, none of the three is preparatory in any useful sense, and all three tend to trip the profiling override on the way past.

Extraction is the harder case, because it can genuinely go either way, and the dividing line is evaluation. Reading a date off a page is transcription. Deciding what counts as a skill on a CV is a judgement about a candidate, and that judgement is what the recruiter then relies on. A useful working test: if a human would have had to exercise judgement to produce the same output, the system is not performing a procedural task, it is performing the assessment earlier and faster.

A human in the loop does not cure material influence. If the reviewer sees only what the system passed forward, or accepts the ranking in almost every case, the system is materially influencing the outcome and the first limb of Article 6(3) fails before you reach the conditions. Treat a reviewer who cannot see the full population, or who departs from the output only rarely, as evidence of material influence rather than as a cure for it. Note that Article 6(3) uses the phrase proper human review in condition (c), not in the first limb.

Worked contrasts: which systems clear the Annex III exemption

These are hypotheticals, not Commission examples, because no Commission examples exist yet. They are drawn along the line the text actually draws: does the system evaluate a person, and does it move the outcome. Employment is the Annex III area where this comes up most, so most of the contrasts sit there, and the same reasoning carries across the recruitment and HR use cases in Annex III point 4.

Hypothetical systemArticle 6(3)Deciding factor
CV parser extracting employer, title and dates verbatimMay qualify, condition (a)Transcription only; recruiter still reads every application
CV parser inferring skills and seniority from free textDoes not qualifyExtraction that involves evaluation of the candidate
Interview scheduler matching availability to roomsMay qualify, condition (a) or (d)Prepares the assessment without touching its merits
Shortlisting tool sending a recruiter 20 of 200 candidatesDoes not qualify180 people never reach a human; outcome materially influenced
Tool flagging non-inclusive wording in a drafted job advertNot high-riskImproves a completed human draft; evaluates no candidate
Automated job-matching or candidate-ranking engineHigh-risk, no derogationRanks people against opportunities; profiling override
Audit tool flagging deviations in closed hiring decisionsMay qualify, condition (c)Only if it does not feed live decisions and review is real
Any of the above once it scores or segments individualsTreat as high-riskScoring is profiling on any reading; segmentation is contested, so assume the override bites

Read the middle column as a starting position, not a conclusion. Two products with the same description can land on opposite sides of the line depending on what the human actually sees, how often the human departs from the output, and whether the vendor quietly added a relevance score in a later release.

Article 6(4) documentation, and the registration that survives

Claiming the derogation is not a decision you get to make quietly. Article 6(4) requires the provider to document the assessment before the system is placed on the market or put into service. A record written after a market surveillance authority asks is not the record the article requires, and its date says so. Art 6(4)

A record that will hold up answers all of this, on the page:

  • which Annex III point the system engages, and why that one;
  • whether the system poses a significant risk to health, safety or fundamental rights, argued on evidence rather than asserted;
  • whether it materially influences the outcome of decision making, including what the human reviewer sees and how often the reviewer departs from the output;
  • which of the four conditions you rely on, applied to this system rather than to the product category;
  • the profiling question, answered explicitly rather than passed over;
  • who took the decision, on what date, and what change would force a re-run.

Registration survives the derogation. The Commission proposed dropping the requirement for systems self-assessed as non-high-risk; that proposal did not survive negotiations and the duty was reinstated in simplified form. So a successful derogation is not an exit from visibility: you still enter the system in the EU database and, in effect, publish the claim that Article 6(3) applies to it.

Two penalty tiers meet at this record. The high-risk regime sits in the €15M or 3% of worldwide annual turnover tier, and supplying incorrect, incomplete or misleading information to authorities sits in the €7.5M or 1% tier. A thin derogation record filed alongside a database entry can expose you to both at once. For companies the higher of the fixed sum and the percentage applies, while under Article 99(6) SMEs and start-ups pay the lower: see how the three Article 99 tiers are structured.

No Commission guidelines, so the conservative posture is the default

Article 6 carried a statutory deadline of February 2026 for Commission guidelines on high-risk classification. It passed without them. As at the July 2026 review date on this page there is still no authoritative worked example of a successful Article 6(3) derogation.

Two consequences follow. Your record has to carry itself, because there is nothing external to cite and the reasoning on your own page is the whole of your position. And any derogation claimed now will eventually be read against guidelines written later, by people who never saw your product. That asymmetry is the entire argument for the conservative default: document thoroughly, register, and assume profiling forecloses the off-ramp. If you are wrong in the cautious direction you have built documentation you did not strictly owe. If you are wrong in the other direction you have shipped an unassessed high-risk system.

There is runway, and it is worth using deliberately. The Digital Omnibus moved the high-risk application dates and kept the registration duty; it was signed on 8 July 2026 and, at the review date, was still awaiting publication in the Official Journal, entering into force on the third day after publication.

2 Dec 2027High-risk obligations apply to standalone Annex III systems. If the derogation does not hold, this is when the Articles 9 to 15 stack and Article 43 conformity assessment bite.
2 Aug 2028High-risk obligations apply to Annex I embedded-product systems, which never had an Article 6(3) route in the first place.

If the derogation fails, the work waiting on the other side is the full high-risk file: nine documentation blocks under the Annex IV technical documentation guide, a risk management system under Article 9, and a conformity assessment, all drawn up before market placement and kept current. Starting that in 2026 is a different exercise from starting it in late 2027, and the dates behind it are set out in the full application timeline. Commission guidelines, when they arrive, will land on the Commission AI policy pages.

If you would rather walk the test than read it, run your system through the free triage. Stage four is this article in order, with the profiling question asked before the four conditions, and it tells you which limb your system fails rather than only that it failed.

Check your own system

The free classifier walks the same tests in order and tells you which of them your system actually trips, with the article each answer rests on.

Run the triage →

Frequently asked questions

What is the Article 6(3) exemption in the EU AI Act?

Article 6(3) is the derogation that takes an Annex III system out of the high-risk regime. It applies only where two things hold together: the system poses no significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making, and it meets at least one of four conditions - a narrow procedural task, improving the result of a previously completed human activity, detecting decision-making patterns or deviations from prior patterns without replacing or influencing the previously completed human assessment without proper human review, or a preparatory task to an assessment relevant to an Annex III use case. A system that performs profiling of natural persons is always high-risk and never reaches the test.

Does a CV parser qualify for the Article 6(3) derogation?

A CV parser can qualify, but only if it transcribes rather than evaluates. Lifting employer names, job titles and dates verbatim into structured fields looks like a narrow procedural task: the output does not depend on a judgement about the candidate, and a recruiter still reads every application. The moment the same parser decides which entries count as skills, infers seniority, or scores how well a candidate fits a role, it is making an evaluative call about a person and the condition fails. If it also ranks or filters applicants, the profiling override applies and the derogation is closed entirely.

Is filtering or ranking a narrow procedural task under the AI Act?

No. Filtering removes people from a decision, ranking orders them by merit, and scoring attaches a number that is itself the assessment. None of the three is procedural in the sense Article 6(3) uses, however mechanical the implementation looks, because the output is a judgement about natural persons rather than a product of the process. All three also tend to trip the profiling override, which makes an Annex III system high-risk regardless of the four conditions. A shortlisting tool that sends a recruiter 20 of 200 candidates is the clearest case: the other 180 were assessed by the system and never reached a human.

Why does profiling make an Annex III system high-risk automatically?

Because Article 6(3) says so in absolute terms: an Annex III system that performs profiling of natural persons is always high-risk, and the two-part test is never reached. There is no balancing, no rebuttal and no condition that survives it. Practically, this means the profiling question should be answered first and in writing, before anyone spends time drafting a condition argument. Where the boundary of profiling sits for a specific product is genuinely contested, and the Commission guidance that would have drawn it has not been published, so the conservative reading is also the defensible one.

Do I still have to register a system I assessed as not high-risk?

Yes. Under the Digital Omnibus, systems that a provider self-assesses as non-high-risk under Article 6(3) must still be registered in the EU database. The Commission proposed removing that requirement, it did not survive negotiations, and it was reinstated in simplified form. The practical consequence is that a derogation is not an exit from visibility: you enter the system in the database and publish, in effect, the claim that Article 6(3) applies to it. That claim is discoverable by a market surveillance authority, which is one more reason the underlying Article 6(4) documentation has to be real.

When does the Article 6(3) assessment have to be documented?

Before the system is placed on the market or put into service. Article 6(4) puts the documentation duty on the provider and fixes it at that point, so a record produced after an authority asks is not the record the article requires, and its date will say so. A defensible record names the Annex III point engaged, addresses significant risk and material influence on the evidence rather than by assertion, identifies which of the four conditions is relied on and applies it to the specific system, answers the profiling question explicitly, and records who decided and on what date.

Are there official examples of a successful Annex III exemption?

No. The Commission missed its February 2026 statutory deadline for guidelines on Article 6 high-risk classification, so as at July 2026 there is no authoritative worked example of a derogation being accepted. Everything in circulation is interpretation, including the contrasts on this page. Two things follow. Your own documentation has to carry the argument alone, because there is nothing external to cite. And a derogation claimed today will later be read against guidelines written after the fact, which is why the conservative posture - document thoroughly, register, treat profiling as fatal - is the sensible default.

This page is triage guidance, not legal advice. It reflects Regulation (EU) 2024/1689 as amended by the Digital Omnibus, reviewed 22 July 2026, when the Omnibus was adopted and signed but awaiting Official Journal publication. Final classification for ambiguous cases needs qualified counsel.