EU AI Act article explainer · Last verified 2026-08-02

EU AI Act Art. 6Classification rules for high-risk AI systems

Article 6 is the gateway to the Act's heaviest obligations. It sets out the rules for deciding whether an AI system is high-risk — through Annex I (regulated products) or Annex III (eight areas of fundamental-rights concern).

Regulation (EU) 2024/1689Plain-English explainer · Not legal advice

At a glance

What this article requires

  • An AI system is high-risk if it is a safety component of a product governed by Annex I harmonisation legislation, or is itself such a product requiring third-party assessment.
  • It is also high-risk if it falls in one of the eight Annex III areas (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice).
  • Annex III classification only bites if the system poses a significant risk to health, safety, or fundamental rights.
  • Providers can claim a carve-out where the Annex III system does not pose significant risk — but they must document the reasoning.
  • Real-world examples that typically land in Annex III: hiring/recruitment AI, credit scoring, medical triage, exam proctoring, and some biometric verification.

Scope

Who this applies to

Providers (developers) who classify their systems, and deployers who must verify the classification they are buying into. The classification decides which obligations in Articles 8–27 apply.

Obligations

What you must actually do

Run the two-step Annex III test

A system in an Annex III area is high-risk only if it is used for a purpose in that area AND poses a significant risk of harm to health, safety, or fundamental rights. A borderline system with documented justification can fall outside.

Document the classification decision

Whether you conclude high-risk or carve-out, you should record the reasoning: intended purpose, Annex III category engaged, significant-risk analysis, and any mitigations relied on.

Keep up with the Commission's classification guidance

The Commission and the AI Office publish guidance and databases to help apply Article 6 consistently. Use them when your system sits near a boundary.

Action plan

Practical first steps

  1. 1

    Identify your system's intended purpose in one sentence — classification hangs off it.

  2. 2

    Check Annex I first (regulated products), then walk the eight Annex III categories.

  3. 3

    Run the significant-risk test honestly; a carve-out needs a written rationale, not a hope.

  4. 4

    Record the outcome and revisit it whenever the system's intended purpose changes.

Penalty exposure

Misclassification that leads to missing high-risk obligations is usually penalised at the general tier: up to €15 million or 3% of global annual turnover.

FAQ

Questions about Art. 6

Is my recruitment AI automatically high-risk?

AI used to recruit or evaluate job applicants falls in Annex III, §4 (employment). It is high-risk unless you can substantiate that it poses no significant risk to health, safety, or fundamental rights — a hard argument for most recruitment decisions.

What is the difference between Annex I and Annex III?

Annex I covers products already regulated by EU harmonisation law (e.g. medical devices under MDR, machinery, toys). Annex III covers eight areas where AI itself can affect fundamental rights (e.g. education, employment, essential services). Both routes lead to the same high-risk obligations.

Can I self-certify as not high-risk?

Providers can rely on the Article 6(3) carve-out for Annex III systems, but they must document their reasoning and be ready to justify it to market surveillance authorities. Annex I high-risk systems have no such escape.

Sources

Citations & further reading

Related

More article explainers

Wondering which articles apply to your AI?

Describe your system in the free Risk Scanner and get a preliminary risk read with the obligations that likely apply — in seconds.

Check my use case

Preliminary EU AI Act clarity summary. Not legal advice.