The Article 6(3) exemption is a two-part test, not a menu
Landing in one of the eight Annex III areas does not settle the classification. Article 6(3) is the off-ramp, and it stays shut unless two separate things are true at the same time. Art 6(3)
First, the system must not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making. Second, it must meet at least one of four listed conditions. The two limbs fail in different ways, and the second is the easier one to argue: a provider picks whichever condition sounds closest and never seriously tests whether the system moves outcomes for real people. On the text, the first limb has to be cleared first.
Two structural points before the conditions. The derogation exists only on the Annex III route. If your system is high-risk because it is, or is a safety component of, a product covered by Annex I harmonisation legislation requiring third-party conformity assessment, there is no Article 6(3) counterpart on that route. The only relief the Digital Omnibus added is a targeted carve-out for AI embedded in Machinery Regulation products, which routes the AI-specific requirements through the Machinery Regulation rather than removing them; medical devices and toys stay fully in scope. See how the Annex I and Annex III routes are tested. And the derogation is a self-assessment. Nobody signs it off before you rely on it. You make the call against the text of Regulation (EU) 2024/1689, you document it, and you carry it.
The four conditions that can lift an Annex III system out of high-risk
You need one of the four, not all of them. Each is narrower than it first reads, and each has a failure mode that shows up in real products.
(a) The system performs a narrow procedural task
Both words are load-bearing. A procedural task is one whose output follows from the process rather than from a judgement about a person: converting a scanned form into structured fields, deduplicating records against an identifier, routing a request to a queue by document type. Picture a CV parser that lifts employer names, job titles and start and end dates verbatim into fields a recruiter then reads in full. Nothing has been decided about the candidate. Now picture the same parser deciding which entries count as skills and how senior each one is. That is evaluation, and evaluation of a person is not procedure, however narrow the code path looks.
(b) The system improves the result of a previously completed human activity
The human activity has to be finished before the system touches it, and the system has to improve the result rather than produce it. A tool that flags non-inclusive wording in a job advert a human has already drafted sits here comfortably: the advert exists, a person wrote it, the tool tightens it, and no candidate has been evaluated. The condition breaks when the improvement is really authorship. A system that drafts a candidate assessment and offers a human an accept button has not improved a completed human activity, it has completed the activity and left a signature block.
(c) The system detects decision-making patterns or deviations from prior patterns
This condition carries its own defeat clause in the text: the detection must not replace or influence the previously completed human assessment without proper human review. Picture a quality-assurance tool that samples closed hiring decisions and flags cases where a manager departed from how comparable cases were handled before, so a person can review them. It is auditing decisions that already happened. Feed the same signal forward into live decisions, or wire a flag to an automatic action, and the condition is gone.
(d) The system performs a preparatory task to an assessment
Preparatory means before the assessment and outside it. An interview scheduler that matches free slots to free rooms prepares an assessment without touching its merits. Indexing, format conversion and collating a file for a human to read are the same shape. The failure mode is treating narrowing as preparation. A tool that hands a recruiter 20 of 200 candidates is not preparing an assessment, it is performing most of one: the 180 it removed were assessed, by the system, and no human ever saw them.
Profiling of natural persons is always high-risk, with no derogation
The four conditions sit under an absolute override. An Annex III system that performs profiling of natural persons is always high-risk. Not presumed high-risk, not high-risk unless rebutted: the two-part test is never reached, and the best-drafted condition argument in the world does not survive it. Art 6(3)
This reaches further than the drafting suggests, because profiling catches a lot of products that would otherwise have a plausible condition to point at. Scoring, segmenting, predicting behaviour, inferring reliability or suitability, ranking people against a target: once a system evaluates personal aspects of identifiable people by automated means, the live question stops being which condition applies and becomes whether this is profiling at all. Where that boundary sits in a given product is genuinely contested, and the Commission guidance that would have drawn it has not been published.
Answer the profiling question first and in writing, before anyone drafts a condition argument. If your system evaluates or predicts something about identifiable people - performance, reliability, preferences, risk, fit - assume a regulator reads that as profiling and assume the off-ramp is closed. Building the high-risk file you probably need is cheaper than defending a derogation record that never had a route through.
Filtering, ranking and scoring are not narrow procedural tasks
The over-claim has a signature. A vendor describes the product by its mechanism - it only matches keywords, it only extracts text, it only sorts - and the buyer reads the mechanism as though it were the legal test. It is not. Article 6(3) asks what the system does to the outcome for a natural person, and three verbs almost always answer that question the wrong way.
Filtering removes people. Whatever a filter does mechanically, its effect is that some candidates, applicants or claimants stop existing for the decision maker. Ranking orders people, and an order is a judgement about relative merit even when it is produced by a similarity score. Scoring attaches a number to a person, and the number is the assessment. None of the three is a narrow procedural task, none of the three is preparatory in any useful sense, and all three tend to trip the profiling override on the way past.
Extraction is the harder case, because it can genuinely go either way, and the dividing line is evaluation. Reading a date off a page is transcription. Deciding what counts as a skill on a CV is a judgement about a candidate, and that judgement is what the recruiter then relies on. A useful working test: if a human would have had to exercise judgement to produce the same output, the system is not performing a procedural task, it is performing the assessment earlier and faster.
A human in the loop does not cure material influence. If the reviewer sees only what the system passed forward, or accepts the ranking in almost every case, the system is materially influencing the outcome and the first limb of Article 6(3) fails before you reach the conditions. Treat a reviewer who cannot see the full population, or who departs from the output only rarely, as evidence of material influence rather than as a cure for it. Note that Article 6(3) uses the phrase proper human review in condition (c), not in the first limb.
Worked contrasts: which systems clear the Annex III exemption
These are hypotheticals, not Commission examples, because no Commission examples exist yet. They are drawn along the line the text actually draws: does the system evaluate a person, and does it move the outcome. Employment is the Annex III area where this comes up most, so most of the contrasts sit there, and the same reasoning carries across the recruitment and HR use cases in Annex III point 4.
| Hypothetical system | Article 6(3) | Deciding factor |
|---|---|---|
| CV parser extracting employer, title and dates verbatim | May qualify, condition (a) | Transcription only; recruiter still reads every application |
| CV parser inferring skills and seniority from free text | Does not qualify | Extraction that involves evaluation of the candidate |
| Interview scheduler matching availability to rooms | May qualify, condition (a) or (d) | Prepares the assessment without touching its merits |
| Shortlisting tool sending a recruiter 20 of 200 candidates | Does not qualify | 180 people never reach a human; outcome materially influenced |
| Tool flagging non-inclusive wording in a drafted job advert | Not high-risk | Improves a completed human draft; evaluates no candidate |
| Automated job-matching or candidate-ranking engine | High-risk, no derogation | Ranks people against opportunities; profiling override |
| Audit tool flagging deviations in closed hiring decisions | May qualify, condition (c) | Only if it does not feed live decisions and review is real |
| Any of the above once it scores or segments individuals | Treat as high-risk | Scoring is profiling on any reading; segmentation is contested, so assume the override bites |
Read the middle column as a starting position, not a conclusion. Two products with the same description can land on opposite sides of the line depending on what the human actually sees, how often the human departs from the output, and whether the vendor quietly added a relevance score in a later release.
Article 6(4) documentation, and the registration that survives
Claiming the derogation is not a decision you get to make quietly. Article 6(4) requires the provider to document the assessment before the system is placed on the market or put into service. A record written after a market surveillance authority asks is not the record the article requires, and its date says so. Art 6(4)
A record that will hold up answers all of this, on the page:
- which Annex III point the system engages, and why that one;
- whether the system poses a significant risk to health, safety or fundamental rights, argued on evidence rather than asserted;
- whether it materially influences the outcome of decision making, including what the human reviewer sees and how often the reviewer departs from the output;
- which of the four conditions you rely on, applied to this system rather than to the product category;
- the profiling question, answered explicitly rather than passed over;
- who took the decision, on what date, and what change would force a re-run.
Registration survives the derogation. The Commission proposed dropping the requirement for systems self-assessed as non-high-risk; that proposal did not survive negotiations and the duty was reinstated in simplified form. So a successful derogation is not an exit from visibility: you still enter the system in the EU database and, in effect, publish the claim that Article 6(3) applies to it.
Two penalty tiers meet at this record. The high-risk regime sits in the €15M or 3% of worldwide annual turnover tier, and supplying incorrect, incomplete or misleading information to authorities sits in the €7.5M or 1% tier. A thin derogation record filed alongside a database entry can expose you to both at once. For companies the higher of the fixed sum and the percentage applies, while under Article 99(6) SMEs and start-ups pay the lower: see how the three Article 99 tiers are structured.
No Commission guidelines, so the conservative posture is the default
Article 6 carried a statutory deadline of February 2026 for Commission guidelines on high-risk classification. It passed without them. As at the July 2026 review date on this page there is still no authoritative worked example of a successful Article 6(3) derogation.
Two consequences follow. Your record has to carry itself, because there is nothing external to cite and the reasoning on your own page is the whole of your position. And any derogation claimed now will eventually be read against guidelines written later, by people who never saw your product. That asymmetry is the entire argument for the conservative default: document thoroughly, register, and assume profiling forecloses the off-ramp. If you are wrong in the cautious direction you have built documentation you did not strictly owe. If you are wrong in the other direction you have shipped an unassessed high-risk system.
There is runway, and it is worth using deliberately. The Digital Omnibus moved the high-risk application dates and kept the registration duty; it was signed on 8 July 2026 and, at the review date, was still awaiting publication in the Official Journal, entering into force on the third day after publication.
If the derogation fails, the work waiting on the other side is the full high-risk file: nine documentation blocks under the Annex IV technical documentation guide, a risk management system under Article 9, and a conformity assessment, all drawn up before market placement and kept current. Starting that in 2026 is a different exercise from starting it in late 2027, and the dates behind it are set out in the full application timeline. Commission guidelines, when they arrive, will land on the Commission AI policy pages.
If you would rather walk the test than read it, run your system through the free triage. Stage four is this article in order, with the profiling question asked before the four conditions, and it tells you which limb your system fails rather than only that it failed.