EUAIACTUS.COM

Article 6 • Annex I • Annex III

High-risk AI classification under the EU AI Act

The AI Act has two principal high-risk pathways: product-linked systems under Article 6(1)/Annex I and listed use cases under Article 6(2)/Annex III. The 2026 amendment changed when the main high-risk requirements apply.

Updated and legally reviewed: 26 September 2026.

Two routes

High-risk classification is not one single test.

Article 6(1) / Annex I

AI used as a safety component of, or itself constituting, a product covered by specified EU harmonisation legislation can be high-risk where the product is subject to third-party conformity assessment.

Main amended application date: 2 August 2028.

Article 6(2) / Annex III

AI systems used in listed areas and use cases — including biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration/border control and justice/democratic processes — can be high-risk.

Main amended application date: 2 December 2027.

Annex III nuance

Being mentioned in Annex III does not end the analysis.

Article 6 contains conditions under which certain Annex III systems may not be treated as high-risk if they do not pose a significant risk of harm and satisfy the specified criteria. Profiling of natural persons is treated differently. Providers relying on a non-high-risk assessment must document that assessment.

Narrow procedural task

One statutory pathway concerns systems performing a narrow procedural task.

Improving prior human work

Another pathway can involve improving the result of a previously completed human activity.

Pattern/deviation detection

Certain systems detecting patterns or deviations without replacing/influencing prior human assessment may fall within the statutory criteria.

Preparatory task

A preparatory task to an Annex III assessment can also be relevant, subject to the exact statutory conditions.

Draft 2026 guidance

The Commission's high-risk classification guidance is still draft.

The Commission published draft guidelines in May 2026, including examples for Article 6(1), Article 6(2) and Annex III. The Commission page states that feedback from the consultation is to be incorporated before final adoption. Treat the draft as interpretive material, not binding law or final guidance.

Readiness

What to prepare before 2027/2028

Classification record

Document intended purpose, Annex pathway, use case, exceptions and why the system is or is not high-risk.

Risk management

Build system-level risk identification, evaluation, mitigation, testing and review processes.

Documentation and logs

Prepare technical documentation, instructions/information, record-keeping and evidence architecture early enough to influence product design.

Human oversight & performance

Define human oversight, accuracy, robustness and cybersecurity controls based on system context and risk.