Article 6 sets two routes to high-risk, and they are alternatives
Article 6 of the EU AI Act does not define a high-risk AI system with one test. It sets two independent routes, and a system is high-risk if it satisfies either of them. The product-safety route asks whether the AI is a safety component of, or is itself, a product covered by the Union harmonisation legislation listed in Annex I, where that product has to undergo third-party conformity assessment before it can be placed on the market. The use-case route asks whether the intended purpose of the system falls in one of the eight areas listed in Annex III.
The most common classification error is reading these as a sequence. Teams check whether they build a regulated product, decide they do not, and stop. Annex III catches a large population of pure software that never touches product-safety law at all: CV screening, credit scoring, exam proctoring, benefit eligibility. Ask both questions in parallel. A system can also satisfy both routes at once. Neither Article 6 nor the Digital Omnibus sets a priority rule for that case, so work the requirements and the application date of each route separately rather than assuming one displaces the other.
| Test | Annex I route | Annex III route |
|---|---|---|
| What triggers it | The AI is a safety component of, or is itself, a product covered by Annex I harmonisation legislation | The intended purpose falls in one of the eight Annex III areas |
| Additional condition | That product must undergo third-party conformity assessment under that legislation | None. Falling in the area is enough unless Article 6(3) lifts it out |
| Typical subjects | Medical devices, toys, other regulated physical products | Standalone software: hiring tools, credit models, proctoring, biometric identification |
| Off-ramp available | No. The Article 6(3) derogation is written for Annex III systems only | Article 6(3), unless the system profiles natural persons |
| Obligations apply from | 2 August 2028 | 2 December 2027 |
A system that clears both routes is not high-risk under Article 6. That is not the end of your obligations. It may still be a prohibited practice under Article 5, and it owes the Article 50 transparency duties for chatbots, deepfakes and synthetic content if it interacts directly with people, recognises emotions or categorises biometrics, or generates or manipulates synthetic content. Those duties bind from 2 August 2026 regardless of risk tier, with one carve-out: the Article 50(2) machine-readable marking duty for synthetic content applies from 2 December 2026 to generative systems placed on the market before 2 August 2026, and from placement for systems placed on the market on or after that date.
The Annex I route: AI inside products that already carry safety law
Annex I lists the Union harmonisation legislation that pulls the AI Act along with it, including the medical devices framework, toy safety and the Machinery Regulation. Two conditions have to hold together. First, the AI is a safety component of the product, or the AI system is the product. Second, that product is required under the relevant Annex I legislation to undergo third-party conformity assessment before it goes on the market. If the product only ever needs self-assessment under its sectoral rules, the Annex I route does not close.
The Digital Omnibus changed the picture for one sector. AI embedded in products covered by the Machinery Regulation received a targeted carve-out from the direct high-risk rules of the AI Act, with AI-specific requirements layered in through the Machinery Regulation instead. Medical devices and toys got no equivalent treatment and remain fully in scope of the AI Act high-risk regime.
The machinery carve-out moves the requirements, it does not delete them. A machinery manufacturer that reads the carve-out as a discharge is misreading it. The AI-specific requirements are relocated into the Machinery Regulation, so your engineering and documentation burden survives the change of instrument. What changes is which instrument your notified body assesses you against.
The eight Annex III areas, with examples of high-risk AI systems in each
Annex III is the list most people mean when they ask whether their AI is high-risk. It is organised by area of use, not by technique, so the question is always what the system is intended to do rather than how it was built. The table below walks all eight areas with illustrative systems that land in each.
| Annex III area | Systems that typically land here |
|---|---|
| 1 · Biometrics | Remote biometric identification, biometric categorisation, emotion recognition. Note that several biometric uses are banned outright under Article 5 rather than merely high-risk |
| 2 · Critical infrastructure | Safety components in the management and operation of critical infrastructure, for example load balancing on an electricity network or a signalling control system on a road network |
| 3 · Education and vocational training | Admissions and course-allocation systems, automated exam scoring, systems that evaluate learning outcomes, remote proctoring that monitors candidates during a test |
| 4 · Employment and worker management | Targeted job advertising, application filtering, candidate evaluation, promotion and termination decisions, task allocation and performance monitoring |
| 5 · Essential private and public services | Credit scoring and credit checks, risk assessment and pricing in health and life insurance, and systems that determine eligibility for public benefits |
| 6 · Law enforcement | Risk assessment of natural persons, evaluation of the reliability of evidence, profiling in the course of detection and investigation. Individual predictive criminal-risk assessment based solely on profiling is prohibited under Article 5(d), not high-risk |
| 7 · Migration, asylum and border control | Assessment of visa and asylum applications, verification of travel documents, risk assessment of persons seeking to enter a member state |
| 8 · Justice and democratic processes | Systems assisting a judicial authority in researching and interpreting facts and law, and systems intended to influence the outcome of an election or referendum or the voting behaviour of natural persons |
Where Annex III catches teams who did not expect it
Point 4 is the broadest in practice, because almost every organisation of any size hires, promotes and allocates work. An applicant tracking system that ranks candidates, a scheduling engine that allocates shifts, and a productivity dashboard that scores workers all sit inside it. If you buy rather than build, note that the duties do not stop at the vendor: deployers carry their own obligations, and the sector guide to recruitment and HR AI under the AI Act works through which HR tools land where.
Point 5 is the one that surprises financial services. Credit scoring and credit checks are named expressly, as are risk assessment and pricing in health and life insurance. A pricing model is not exempted because it is actuarially conventional or because a human signs off the final quote. Point 3 catches education technology that most vendors think of as administrative: automated marking and remote proctoring both evaluate people and both steer outcomes.
Intended purpose decides it, not model sophistication
A small gradient-boosted scorer that ranks job applicants is high-risk. A frontier multimodal model used to draft marketing copy is not, on the Article 6 test. Nothing in Annex III turns on parameter count, training compute or autonomy. It turns on what the system is intended to be used for, which is why a change of intended purpose is a classification event rather than a product decision. If you repurpose a general tool into an Annex III use, Article 25 can make you the provider of a high-risk system with the full Article 16 obligation set attached. That mechanism is set out in the guide to provider and deployer roles and the Article 25 flip.
Falling in Annex III does not settle it: the Article 6(3) off-ramp
Article 6(3) lets a provider conclude that an Annex III system is not high-risk after all. Two things have to be true. The system must not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making. And it must meet at least one of four conditions: it performs a narrow procedural task; it improves the result of a previously completed human activity; it detects decision-making patterns or deviations from prior patterns without replacing or influencing the previously completed human assessment without proper human review; or it performs a preparatory task to an assessment relevant to an Annex III use case.
Profiling closes the off-ramp absolutely. A system that performs profiling of natural persons is always high-risk, whatever else it does and however narrow the task looks. There is no balancing exercise and no significant-risk argument to be had. Test profiling first, because a positive answer ends the analysis.
Two duties survive a successful derogation. Article 6(4) requires the provider to document the assessment before placing the system on the market, and under the Digital Omnibus a system self-assessed as not high-risk must still be registered in the EU database. The Commission proposed dropping that registration duty and it did not survive negotiations, so it was reinstated in simplified form. The Commission also missed its February 2026 statutory deadline for Article 6 classification guidelines, so authoritative worked examples of a successful derogation are scarce and the conservative posture is the default: document thoroughly, register, and assume profiling forecloses the exit. The full walkthrough of the Article 6(3) derogation and where it gets over-claimed sets out the four conditions against worked contrasts.
What attaches once a system is high-risk: Articles 9 to 15, 43 and 49
The substantive requirements sit in Articles 9 to 15. Article 9 requires a risk management system running across the whole lifecycle, established, implemented, documented and maintained rather than produced once for an audit. Article 11 requires technical documentation drawn up before the system is placed on the market, against the nine Annex IV documentation blocks, with a simplified form available to SMEs under Article 11(2). Alongside them, Articles 9 to 15 impose data and data governance requirements on training, validation and testing sets, automatic logging, information and instructions for use directed at deployers, human oversight designed into the system, and an appropriate level of accuracy, robustness and cybersecurity.
Then the conformity layer:
- Article 43 conformity assessment. Either the Annex VI internal control procedure, which you run yourself, or the Annex VII route through a notified body. Which one applies depends on the system, and the Annex VII route adds a third party to your critical path. Art 43
- Article 47 EU declaration of conformity. A signed statement that the system meets the Chapter III requirements, retained and kept current. Art 47
- Article 49 registration. Registration in the EU database before the system is placed on the market or put into service, and, for Annex III systems the provider has self-assessed as not high-risk, a registration duty that the Digital Omnibus retained in simplified form after the Commission proposal to drop it failed in negotiations. Art 49
Breach of the high-risk regime sits in the middle Article 99 tier at €15,000,000 or 3% of total worldwide annual turnover, the higher figure for companies and the lower for SMEs and start-ups under Article 99(6). The breakdown of the three penalty tiers and who enforces them covers how that is split between national market surveillance authorities and the AI Office.
When high-risk obligations apply: 2 December 2027 and 2 August 2028
The Digital Omnibus split the original single date by route. Standalone Annex III systems get a seventeen-month extension from 2 August 2026, and embedded Annex I products get longer still.
A later date is not a stand-down. A risk management system, an Annex IV file, a data governance regime and a notified-body assessment are multi-quarter projects, and the Annex VII route puts a third party on your critical path. Teams that paused their programmes on the headline that deadlines moved have less runway than the calendar suggests. Article 50 transparency is untouched by the extension and still applies from 2 August 2026, except that the Article 50(2) marking duty applies from 2 December 2026 to generative systems placed on the market before 2 August 2026.
One caveat on the dates themselves. The Digital Omnibus was adopted by the European Parliament on 16 June 2026 by 423 votes to 57 with 174 abstentions, adopted by the Council on 29 June 2026 and signed on 8 July 2026, but it had not been published in the Official Journal as at the 22 July 2026 review date, and it enters into force on the third day after publication. The amended dates are agreed and final in substance, but the consolidated text and the final regulation number are not yet authoritative. Track that against the full application timeline as amended and the text of Regulation (EU) 2024/1689 on EUR-Lex.
How to run the Article 6 test on your own system
Classification is an ordered exercise, and running the steps out of order produces answers you cannot defend later.
- Write down the intended purpose. One paragraph, specific, describing what the system is intended to be used for and by whom. Every step below reads from it, and a vague purpose statement is the single most common cause of a wrong classification.
- Confirm scope. Article 2 excludes exclusive military, defence and national-security use, scientific research and development before market placement (note that real-world testing is not excluded), and purely personal non-professional use. Free and open-source AI systems are excluded too, but not where they are high-risk, prohibited or caught by Article 50. The territorial hook reaches you if the system is placed on the market, put into service or used in the EU, or if its output is used in the EU.
- Screen Article 5 before Article 6. A prohibited practice is not a high-risk system with extra paperwork, it is banned, and it carries the €35,000,000 or 7% tier.
- Run both Article 6 routes in parallel. Annex I product plus third-party conformity assessment, and the eight Annex III areas. Record the answer to each.
- If Annex III bites, test profiling, then Article 6(3). Profiling ends the analysis. Otherwise work the significant-risk gate and the four conditions, and document the assessment under Article 6(4) before you place the system on the market.
- Fix your role. Provider, deployer, importer, distributor, product manufacturer or authorised representative, and you can hold several at once. Check whether anything you do triggers the Article 25 flip into provider status.
The free classifier walks these stages in order and returns the article each determination rests on, which gives you the skeleton of the record you will need under Article 6(4) either way. It is triage, not legal advice: for a genuinely contested classification, the Commission guidance gap means you want counsel and a paper trail rather than a confident answer. Commission material as it is published sits on the European Commission AI policy page.