High-Risk AI under Art. 6: How to Assess It Correctly

Art. 6 AI Act determines whether your AI system is high-risk. An overview of Annex III, carve-outs and the postponed 2 December 2027 deadline.

Whether an AI system qualifies as “high-risk” under the AI Act is not a matter of gut feeling, but follows a clear assessment routine set out in Art. 6. Anyone who carries out this assessment without documenting it risks either unnecessary effort later or an unpleasant surprise during a regulatory enquiry.

Two Routes to a High-Risk Classification

Art. 6 sets out two separate assessment paths. Under paragraph 1, a system is high-risk if it cumulatively (a) is a safety component of a product covered by the harmonisation legislation listed in Annex I, or is itself such a product, and (b) that product is required to undergo a third-party conformity assessment. This is the classic domain of product safety law – machinery, medical devices, lifts and similar products.

The second path, usually more relevant in practice, is set out in paragraph 2: AI systems listed in Annex III are deemed high-risk regardless of product safety law. This is where most real-world use cases – in recruitment, credit lending or public administration – end up.

Annex III: The Practical List

Annex III names six areas in which AI systems are automatically deemed high-risk – provided their use is permitted at all:

  • Biometrics: remote identification, biometric categorisation based on sensitive characteristics, emotion recognition.
  • Critical infrastructure: safety components in road traffic, or in the supply of water, gas, heating or electricity.
  • Education: admission, assessment of learning outcomes, exam monitoring.
  • Employment: candidate selection, evaluation of applications, decisions on promotion, dismissal or performance monitoring.
  • Essential services: access to social benefits, creditworthiness assessment, risk assessment for life and health insurance, prioritisation of emergency calls.
  • Law enforcement: risk assessments, lie detectors, evaluation of evidence – in each case to the extent permitted under Union or national law.

Anyone deploying a system in one of these areas must assume a high-risk classification until the opposite has been documented.

The Carve-Out under Paragraph 3 – and Its Limits

Paragraph 3 opens a loophole: by way of exception, an Annex III system is not deemed high-risk if it does not pose a significant risk to health, safety or fundamental rights – for instance because it does not materially influence the outcome of a decision. Specifically, the exception applies where the system performs a narrowly defined procedural task, merely improves the result of a previously completed human activity, detects deviations from earlier decision-making patterns (without replacing human assessment without proper review), or carries out a preparatory task for a relevant assessment.

The typical gap in practice: this exception is often claimed prematurely – for example when pre-filtering job applications is classified as “mere preparation”, even though the system in fact carries out substantial pre-selection. Paragraph 3, second subparagraph, also draws a hard line: as soon as the system profiles natural persons, the exception does not apply – the system remains high-risk, regardless of any other argument put forward.

The Documentation Obligation under Paragraph 4

Anyone relying on the carve-out cannot avoid one obligation: the provider must document its assessment before the system is placed on the market or put into service, and is at the same time subject to the registration requirement under Art. 49 paragraph 2. This documentation must be produced on request by the competent authority. This is precisely where the most common gap lies: the classification is made informally, in the head of the product owner, without any traceable document existing – so that nothing can be produced if the matter is ever checked.

When the Obligations Apply

The classification rules of Art. 6 itself already apply; the Commission is also due to provide guidelines and example catalogues on high-risk and non-high-risk use cases by 2 February 2026. However, under the Digital Omnibus, the specific obligations arising from an Annex III classification are subject to a postponed deadline: they will only take effect from 2 December 2027 (rather than the originally planned 2 August 2026). For high-risk systems under Annex I product law, the corresponding deadline shifts to 2 August 2028. You should carry out the classification obligation itself – i.e. the assessment under Art. 6 – now, regardless of these deadlines, since preparation time for conformity assessment, risk management and technical documentation tends, in practice, to be tight.

Whether your system falls into one of the Annex III categories, and whether a carve-out genuinely applies, can be checked in a structured way within minutes using our free risk assessment tool at /einstufung.

Factual orientation, not legal advice. Citations refer to the named legal acts and were checked against the official EUR-Lex texts.