Skip to content
AIAC AI ASSURANCE COUNCIL

EU AI Act

Article 6 — Classification rules for high-risk AI systems

Article 6 decides whether the high-risk regime applies to you at all. There are two routes in: a product route with two cumulative conditions, and a listed route through Annex III. Almost every other obligation in the Regulation presupposes the answer, and the Digital Omnibus narrowed both routes.

§ 1 — Who it binds

Who has to answer this question

ProviderDeployerImporterDistributor

Every AI system a provider places on the market or puts into service, because Article 6 is the question asked of all of them. It binds the provider directly — the duty to document a not-high-risk conclusion sits there — and reaches deployers, importers and distributors through the value-chain rule, under which any of them that puts its name on a system, substantially modifies it, or changes its intended purpose so that a non-high-risk system becomes high-risk takes on the provider obligations.

§ 2 — In practice

Two routes in, and where systems fall out of each

The product route is two conditions, not one, and the second is where systems escape. A system is high-risk under Article 6(1) where it is a safety component of — or is itself — a product covered by the Union harmonisation legislation in Annex I, and that product is required to undergo third-party conformity assessment. The common error is "our device falls under sectoral legislation, therefore the AI in it is high-risk". It is high-risk only if that product needs a third-party assessment, and the Digital Omnibus added that a product assessed by a third party solely for risks other than health and safety — radio spectrum, electromagnetic interference — does not satisfy the second condition.

The Omnibus also narrowed what counts as a safety component at all. A system used solely for non-safety aspects of user assistance, performance optimisation, service efficiency, automation, convenience or quality control no longer qualifies. But there is a hard floor immediately after it: a system whose failure or malfunctioning would endanger health and safety qualifies regardless. Read together, the intended-purpose limb narrowed and the failure-mode limb survived intact — so an optimisation system still has to be run through the failure analysis before the exclusion is claimed.

The listed route is Annex III membership, subject to a derogation that is not self-executing. A provider may conclude a listed system is not high-risk where it performs a narrow procedural task, improves a completed human activity, detects decision patterns without replacing human assessment, or performs a preparatory task. Two things bind that conclusion. The derogation is unavailable, absolutely, where the system performs profiling of natural persons. And claiming it requires a positive act: the assessment must be documented before the system is placed on the market, and the system registered in the public database. Deciding quietly is not deciding.

One consequence of getting this wrong is easy to underestimate, because Article 6 carries almost no direct exposure of its own. Misclassifying downward does not produce an Article 6 fine — it produces failure of everything downstream, since a provider that concluded wrongly has no conformity assessment, no declaration, no CE marking and no registration. Each of those is separately fineable through the provider obligations. The classification decision is therefore the cheapest control in the Regulation to get right and among the most expensive to get wrong, which is the argument for writing it down even when the answer looks obvious. Our note on building an AI risk profile sets out one way to structure that record.

There is a further split most readers never reach. Annex I is divided into two sections, and under the amended scope provision a Section B system — vehicles, aviation, rail, marine, and now machinery, which the Omnibus moved there — is still classified high-risk under Article 6(1) and yet carries none of the Chapter III requirements, no deployer duties under Article 26, and no post-market monitoring. The protection is intended to be reinstated through the sectoral instrument instead. A page or a programme that says "your machinery AI is high-risk, here are the requirements" is now wrong on the second half.

§ 3 — What a weak answer looks like

The determination nobody wrote down

A classification that exists only as a conclusion. Someone decided, the programme was scoped from the decision, and no record shows which route was considered or which conditions were tested. It survives until a supervisor, an acquirer or a customer asks — at which point the organisation cannot demonstrate that the second condition of the product route was ever reached, or that profiling was ruled out before a derogation was claimed. Where the conclusion was "not high-risk", the Regulation requires that record to exist, so its absence is itself the breach.

§ 4 — What discharges it

What a defensible classification looks like

The artefacts an assessor asks to see, and what makes each one sufficient rather than merely present.

  1. 01

    A dated classification determination per system

    Naming the route considered, the conditions tested, and the conclusion. This is required by the Regulation only where the conclusion is "not high-risk", but an assessor asks for it either way — it is the record that shows the question was asked before the answer was needed.

  2. 02

    For the product route, evidence on both conditions separately

    Which Annex I instrument covers the product, and whether that instrument requires third-party conformity assessment for it. A determination that addresses only the first condition has answered half the test.

  3. 03

    The safety-component analysis, where an exclusion is relied on

    The intended-purpose question and the failure-mode question are separate, and the second is not disposed of by the first. A system claimed as optimisation still needs a recorded answer to what happens when it fails.

  4. 04

    For a claimed Annex III derogation, the filing that goes with it

    Which of the four conditions is relied on, a record that profiling is not performed, and the registration in the public database. The reasoning no longer has to be published, which raises rather than lowers the value of holding it.

  5. 05

    A re-review trigger tied to change

    Classification is a determination about an intended purpose, and intended purpose moves. The artefact is what causes the question to be re-asked — a new market, a new customer segment, a retrained model, a changed interface.

§ 5 — Worked example

Worked example — a weld inspection system

A manufacturer builds a vision system that inspects welds on a production line and halts the line when it detects a defect. The line is machinery. The company’s counsel has advised that machinery is Annex I, the system is a safety component, and the full high-risk regime therefore applies from August 2028. A programme has been scoped on that basis.

Is the scoping right, and what turns on it?

The classification is probably right and the scoping probably is not, which is an uncomfortable combination. Two questions come before the conclusion. Is it a safety component — a system halting a line on defect detection is protecting product quality, and quality control is named in the Omnibus exclusion, but a weld failure endangering people brings the failure-mode floor back into play, so the analysis has to be done rather than assumed. And does the machinery in question require third-party conformity assessment, because self-assessed machinery fails the second condition outright. If both are satisfied the system is high-risk under Article 6(1) — but machinery now sits in Section B of Annex I, and a Section B system carries only classification and a narrow set of provisions, not Articles 9 to 15. The programme has been scoped against requirements that do not apply to it, while the obligations that do apply arrive through the machinery legislation. The cost of not writing the classification down is visible here: nobody can reconstruct which of the two conditions was ever tested.

§ 6 — Elsewhere

The same requirement elsewhere

Where another instrument addresses the same obligation. These are correspondences, not comparisons — the Council does not rank one framework against another.

  • ISO/IEC 42001

    ISO/IEC 42001 Annex A carries controls for an AI system impact assessment process and for documenting its results — the management-system home for a recorded classification determination. Cited by number and title so the reference stays checkable against the standard.

A correspondence indicates that two instruments address the same underlying obligation. It is not a mapping endorsed by either body, not a statement that one satisfies the other, and not a judgement about which is more demanding.

§ 7 — When it applies

When classification starts to matter

  1. 2 December 2027

    Annex III standalone high-risk systems. Moved from 2 August 2026 by the Digital Omnibus — a sixteen-month extension driven by undesignated national authorities and the absence of harmonised standards, not by any relaxation of the Section 2 requirements themselves.

  2. 2 August 2028

    Annex I embedded high-risk systems — medical devices, machinery, vehicles — where AI Act requirements fold into the existing sectoral conformity assessment. Moved from 2 August 2027.

§ 8 — Exposure

Exposure — derivative, and larger for it

No direct ceiling; exposure is derivative

Article 6 is not enumerated anywhere in Article 99. Misclassifying a system downward is fined through the provider obligations it causes to be missed — no conformity assessment, no declaration, no CE marking, no registration — each reachable at €15 million or 3% under Article 99(4)(a). The duties in Article 6(4) itself, to document a not-high-risk assessment and register it, sit outside the enumerated provider obligations and fall to the penalties Member States lay down under Article 99(1). Stating a Union-level ceiling for an Article 6 breach would assert an exposure the Regulation does not create.

Certification

Assessed on the same standard of evidence

Every Council credential is examined on applied judgement against a published anchor, set out the way the obligations on this page are. The free AI Literacy Certificate is open to any adult today, and the register lists what is open for enrolment.