EU AI Act

Is your AI system high risk? Article 6 and Annex III, in the Act's own words

If your AI system falls under the EU AI Act, one question decides most of your compliance burden: is it high risk? Article 6 gives two routes to that classification. One runs through EU product safety law, the other through the eight use-case areas in Annex III, and only the second route offers a way out.

Two routes, one label

Article 6 does not define high risk with a single test. It sets two independent routes, and a system that matches either one is high risk.

The first route, in Article 6(1), covers AI tied to products already regulated under EU harmonisation legislation. The second, in Article 6(2), covers AI used in the areas listed in Annex III. The routes work differently. The first has no exceptions. The second has a derogation in Article 6(3), which itself has an override for profiling. You need to hold all four moving parts at once: route one, route two, the derogation, and the override.

Route one: Article 6(1) and product safety law

Article 6(1) classifies a system as high risk where both of the following conditions are met:

  1. The AI system is intended to be used as a safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in Annex I.
  2. That product, or the AI system as a product, is required to undergo a third-party conformity assessment before being placed on the market or put into service under that Annex I legislation.

Two details matter. First, the conditions are cumulative. Coverage by Annex I legislation is not enough on its own. The third-party conformity assessment requirement must also apply. Second, the classification applies irrespective of whether the AI system is placed on the market or put into service independently of the product. You cannot escape route one by selling the AI component separately.

There is no derogation on this route. If both conditions hold, the system is high risk, full stop.

Route two: Article 6(2) and the eight Annex III areas

Article 6(2) adds a second population: AI systems referred to in Annex III are high risk. The annex lists systems "in any of the following areas," in this order:

# Area What it covers
1 Biometrics Remote biometric identification; biometric categorisation by sensitive or protected attributes based on inference of those attributes; emotion recognition. Excludes biometric verification whose sole purpose is confirming a person is who they claim to be.
2 Critical infrastructure Safety components in the management and operation of critical digital infrastructure, road traffic, or the supply of water, gas, heating, or electricity.
3 Education and vocational training Determining access, admission, or assignment to institutions; evaluating learning outcomes, including where they steer the learning process; assessing the level of education a person will receive or access; monitoring and detecting prohibited behavior during tests.
4 Employment, workers' management, and access to self-employment Recruitment or selection, including targeted job ads, filtering applications, and evaluating candidates; decisions on terms of work, promotion, or termination; task allocation based on individual behavior or traits; monitoring and evaluating performance and behavior.
5 Essential private and public services and benefits Public authority evaluation of eligibility for essential public benefits and services, including granting, reducing, revoking, or reclaiming them; creditworthiness evaluation and credit scoring, except systems for detecting financial fraud; risk assessment and pricing for life and health insurance; evaluating and classifying emergency calls and dispatching or prioritizing emergency first response, including patient triage.
6 Law enforcement Assessing the risk of a person becoming a crime victim; polygraphs or similar tools; evaluating the reliability of evidence in investigations or prosecutions; assessing the risk of offending or re-offending not solely on the basis of profiling, or assessing personality traits or past criminal behavior; profiling in the course of detection, investigation, or prosecution of criminal offenses.
7 Migration, asylum, and border control management Polygraphs or similar tools; assessing security, irregular migration, or health risks posed by a person entering or having entered a Member State; assisting the examination of asylum, visa, and residence permit applications and associated complaints; detecting, recognizing, or identifying persons, except verification of travel documents.
8 Administration of justice and democratic processes Assisting a judicial authority in researching and interpreting facts and law and applying the law to a concrete set of facts, or similar use in alternative dispute resolution; influencing the outcome of an election or referendum or voting behavior. Excludes systems whose output people are not directly exposed to, such as tools for the administrative or logistical organization of campaigns.

Note the qualifiers. Areas 1, 6, and 7 apply "in so far as their use is permitted under relevant Union or national law." And several entries carve out specific uses: biometric verification in area 1, financial fraud detection in area 5(b), travel document verification in area 7(d), and campaign logistics tools in area 8(b). These carve-outs mean the system never enters Annex III at all, which is a different thing from qualifying for the derogation below.

The Article 6(3) derogation

Annex III is a list of areas, not a list of automatic verdicts. Article 6(3) opens an exit:

By derogation from paragraph 2, an AI system referred to in Annex III shall not be considered to be high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making.

That is the threshold. The derogation applies where any of the following four conditions is fulfilled:

  • (a) The system is intended to perform a narrow procedural task.
  • (b) The system is intended to improve the result of a previously completed human activity.
  • (c) The system is intended to detect decision-making patterns or deviations from prior decision-making patterns and is not meant to replace or influence the previously completed human assessment, without proper human review.
  • (d) The system is intended to perform a preparatory task to an assessment relevant for the purposes of the use cases listed in Annex III.

One condition is enough. Learn them by intended purpose, because each turns on what the system "is intended to" do, not on what it happens to do in practice.

A clearly hypothetical example: imagine a tool used inside a hiring workflow that only converts uploaded résumés into a standard file format before a recruiter reads them. Hiring sits in Annex III area 4. But if that formatting step is a narrow procedural task under condition (a), or a preparatory task under condition (d), and the threshold in the first subparagraph is met, the derogation can apply.

The profiling override

The derogation has a hard stop, and it is quoted often enough that you should know its exact terms:

Notwithstanding the first subparagraph, an AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons.

The word "always" does the work. If an Annex III system performs profiling of natural persons, none of the four conditions can rescue it. The derogation is off the table before the analysis begins. Check for profiling first. It saves you working through conditions that cannot apply.

Claiming the derogation: Article 6(4)

Deciding your Annex III system is not high risk is not a private judgment call. Article 6(4) attaches two duties to the claim.

First, a provider who considers that an Annex III system is not high risk must document that assessment before the system is placed on the market or put into service. Second, the provider is subject to the registration obligation set out in Article 49(2). On request, the provider must give the documentation of the assessment to national competent authorities.

So the derogation trades one compliance burden for a smaller one. You avoid the high-risk regime, but you take on a documented, registered position that regulators can demand and test. A provider who claims the derogation without paperwork has misunderstood the mechanism.

The parts that can move

Article 6 builds in its own revision machinery, and the dates and mechanisms are fair game for questions.

Under Article 6(5), the Commission must provide guidelines specifying the practical implementation of Article 6, after consulting the European Artificial Intelligence Board, no later than 2 February 2026, in line with Article 96. The guidelines must include a comprehensive list of practical examples of use cases that are high risk and not high risk.

Under Article 6(6), the Commission can adopt delegated acts under Article 97 to add new conditions to the Article 6(3) list or modify the existing ones, where there is concrete and reliable evidence of Annex III systems that do not pose a significant risk of harm to health, safety, or fundamental rights. Under Article 6(7), it must adopt delegated acts deleting conditions where concrete and reliable evidence shows that is necessary to maintain the level of protection. Article 6(8) caps both powers: no amendment may decrease the overall level of protection, and amendments must be consistent with delegated acts adopted under Article 7(1) and take account of market and technological developments.

The takeaway for study purposes: the four derogation conditions you memorize today are the current set, and the Act itself says they can change.

Where this lands on exam day

Classification under Article 6 is a decision procedure, and you should be able to run it without notes. Given a described system, you should be able to say which route applies, whether both Article 6(1) conditions are met, which Annex III area is engaged and whether a carve-out removes the system from the annex, whether one of the four derogation conditions fits the intended purpose, whether profiling kills the derogation, and what Article 6(4) then requires of the provider. Practice running that sequence in order, from route one through the override, until the branching feels mechanical. The classification determines everything that follows in the Act, so the effort pays off across the rest of the syllabus, not just here.

Sources

Every figure, date and quotation above was read from the document itself, not from a summary of it.

Credential Press is not affiliated with, endorsed by or authorized by the IAPP, ISO, the IEC or any other body. This is not legal advice.

We are writing the book on this. The AIGP Exam Guide covers all 4 domains and all 13 competencies, in proportion to the published item weights. Join the first-reader list and you get it free before it goes on sale.