Article 6 • Annex I • Annex III
High-risk AI classification under the EU AI Act
The AI Act has two principal high-risk pathways: product-linked systems under Article 6(1)/Annex I and listed use cases under Article 6(2)/Annex III. The 2026 amendment changed when the main high-risk requirements apply.
Updated and legally reviewed: 26 September 2026.
Two routes
High-risk classification is not one single test.
Article 6(1) / Annex I
AI used as a safety component of, or itself constituting, a product covered by specified EU harmonisation legislation can be high-risk where the product is subject to third-party conformity assessment.
Main amended application date: 2 August 2028.
Article 6(2) / Annex III
AI systems used in listed areas and use cases — including biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration/border control and justice/democratic processes — can be high-risk.
Main amended application date: 2 December 2027.
Annex III nuance
Being mentioned in Annex III does not end the analysis.
Article 6 contains conditions under which certain Annex III systems may not be treated as high-risk if they do not pose a significant risk of harm and satisfy the specified criteria. Profiling of natural persons is treated differently. Providers relying on a non-high-risk assessment must document that assessment.
Narrow procedural task
One statutory pathway concerns systems performing a narrow procedural task.
Improving prior human work
Another pathway can involve improving the result of a previously completed human activity.
Pattern/deviation detection
Certain systems detecting patterns or deviations without replacing/influencing prior human assessment may fall within the statutory criteria.
Preparatory task
A preparatory task to an Annex III assessment can also be relevant, subject to the exact statutory conditions.
Draft 2026 guidance
The Commission's high-risk classification guidance is still draft.
The Commission published draft guidelines in May 2026, including examples for Article 6(1), Article 6(2) and Annex III. The Commission page states that feedback from the consultation is to be incorporated before final adoption. Treat the draft as interpretive material, not binding law or final guidance.
Readiness
What to prepare before 2027/2028
Classification record
Document intended purpose, Annex pathway, use case, exceptions and why the system is or is not high-risk.
Risk management
Build system-level risk identification, evaluation, mitigation, testing and review processes.
Documentation and logs
Prepare technical documentation, instructions/information, record-keeping and evidence architecture early enough to influence product design.
Human oversight & performance
Define human oversight, accuracy, robustness and cybersecurity controls based on system context and risk.