Praxikon
Article 6 of 1135%
Nederlands

Article 6: Classification rules for high-risk AI systems

EU Official:
UpcomingAnnex III from 2 Dec 2027; Annex I from 2 Aug 2028
Title III: High-Risk AI Systems

Application dates

  • : Article 6(2) and systems listed in Annex III
  • : Article 6(1) and systems linked to Annex I

Article 6 determines when an AI system falls under the high-risk regime. The practical question is whether the system is covered by Annex I, Annex III or a limited Article 6(3) exception.

Implementation timeline

1 Aug 2024
AI Act entered into force
2 Feb 2025
Prohibited practices apply (context for classification)
19 May 2026
Commission draft guidelines published; final version not yet published
2 Dec 2027
Core rules for Article 6(2) and Annex III apply
2 Aug 2028
Core rules for Article 6(1) and Annex I apply

Official text

||

Source: EUR-Lex, Regulation (EU) 2024/1689. Text reproduced verbatim.

Download AI Act (PDF)

Official guidance on this article

7

Governance

Provider

  • Classifies the AI system as high-risk or not
  • Performs conformity assessment (Art. 43)
  • Registers in EU database (Art. 49)
  • Can claim Art. 6(3) exception with documentation

Deployer

  • Verifies provider's classification
  • Uses AI system within intended purpose
  • Deviating use: reclassification required

Supervisory Authority

  • Market surveillance on correct classification
  • Can challenge Art. 6(3) exception
  • Access to EU database

European Commission

  • Publishes guidelines on classification (⚠️ deadline missed)
  • Can update Annex III via delegated acts
  • Establishes standard templates

What does this mean for you?

Provider+
First determine which Article 6 route applies: a safety component or product under Annex I, or a use case listed in Annex III. An Annex III system can fall outside high risk under Article 6(3) only if it poses no significant risk of harm, does not materially influence decision-making and meets one of the four statutory conditions. Profiling blocks this filter. Document the assessment in advance and register the system as required by Article 49(2).
Deployer+
Ask the provider for the intended purpose, classification and supporting reasons. Where Article 6(3) is invoked, check the EU database to see which condition is relied on. If you use the system outside its intended purpose or substantially modify it, separately assess whether Article 25 makes you a provider.
SME / Startup+
There is no general SME exemption from the classification rules. For each system, record its intended purpose, the Annex I or Annex III route, any Article 6(3) reasoning and the allocation of roles with the vendor. The high-risk rules apply from 2 December 2027 for Annex III and from 2 August 2028 for Annex I.
Public Sector+
Government use is not automatically high-risk. The intended purpose must fall within a specific Annex III use case, such as access to essential public services, law enforcement, migration or the administration of justice. Then check Article 6(3), the profiling exclusion, and the applicable registration and FRIA duties.

Overlap with other legislation

Complementary

High-risk classification under the AI Act often also requires a DPIA under the GDPR. The risk assessment for high-risk AI systems overlaps with the DPIA obligation, but they are not identical — the AI Act focuses on AI-specific risks, the GDPR on privacy risks.

NIS2 DirectiveArt. 21 (Cybersecurity)
Complementary

High-risk AI systems must meet cybersecurity requirements (Art. 15 AI Act). If the AI system is part of an essential or important entity under NIS2, additional security obligations apply. Measures can be combined.

Product Liability Directive (EU) 2024/2853Art. 6 (Defective product)
Reinforcing

AI systems placed on the market as products also fall under product liability. The new PLD (2024/2853) explicitly names software as a product. A high-risk AI system that does not comply with the AI Act may be considered a 'defective product'. The previously proposed AI Liability Directive has been withdrawn — the PLD is now the primary route for AI damage claims.

Machinery Regulation (EU) 2023/1230Art. 6 (High-risk machinery)
Integrated

AI systems that are safety components of machinery (Annex I, section A) automatically fall under high-risk (Art. 6(1)). The conformity assessment of the machinery and the AI system must be aligned.

Regulation (EU) 2026/1744Amendments to Art. 6, 49, deadlines
Modifying

Regulation (EU) 2026/1744 has applied since 27 July 2026 and amends the AI Act. For Art. 6, the core obligations for Annex III systems apply from 2 December 2027 and those for product-based Annex I systems from 2 August 2028. Registration under Art. 49(2) remains but is simplified. Proportionate rules are extended to small mid-caps.

Sectoral legislation (Annex I)Various
Integrated

Art. 6(1) explicitly refers to Annex I — 21 pieces of EU harmonisation legislation. If an AI system is a safety component of a product covered by this legislation AND requires third-party conformity assessment, it is automatically high-risk.

Related recitals

Related tools

Related enforcement

  • CNIL fines Amazon €32 million for AI employee monitoringCNIL · Dec 2023
  • Hungarian bank fined for AI-based customer profilingNAIH · Aug 2021

Related blog posts

Cross-references

Frequently asked questions

How do I determine if my AI system is high-risk?+
Article 6 defines two categories of high-risk AI: (1) AI systems used as safety components in products under EU harmonisation legislation (Annex I), and (2) AI systems in specific application areas such as biometrics, critical infrastructure, education, employment and law enforcement (Annex III).
What is the difference between Annex I and Annex III high-risk AI?+
Annex I concerns AI in regulated products (medical devices, machinery, toys). Annex III concerns standalone AI applications in sensitive domains such as credit scoring, recruitment and law enforcement.
When do the rules for high-risk AI apply?+
The core rules apply from 2 December 2027 to systems under Article 6(2) and Annex III, and from 2 August 2028 to systems under Article 6(1) and Annex I.
Do SMEs also need to comply with Article 6 of the AI Act?+
Article 6 of the AI Act does not provide a general exemption for SMEs. However, the AI Act includes supportive measures and potentially lighter obligations for small and medium-sized enterprises, depending on their role in the AI value chain.
How does Article 6 of the AI Act relate to the GDPR?+
Article 6 of the AI Act complements the GDPR. While the GDPR protects personal data, the AI Act focuses on the safety and trustworthiness of AI systems. Organisations must comply with both regulations when their AI system processes personal data.
What are the deadlines for Article 6 of the AI Act?+
Regulation (EU) 2026/1744 sets two routes: 2 December 2027 for Article 6(2) and Annex III and 2 August 2028 for Article 6(1) and Annex I.
Does Article 6 of the AI Act also apply to AI systems I purchase?+
Yes, Article 6 of the AI Act may also be relevant when you purchase AI systems. As a deployer, you have your own obligations under the AI Act, regardless of whether you developed the system yourself or purchased it from a provider.
What is the difference between provider and deployer under Article 6 of the AI Act?+
Under Article 6 of the AI Act, the provider is the entity that develops or places the AI system on the market, while the deployer is the entity that uses the system under its own authority. Both roles carry different obligations.
Can my AI system still be not high-risk even if it's listed in Annex III?+
Only where the system poses no significant risk of harm, does not materially influence decision-making and meets one of the four Article 6(3) conditions. Profiling natural persons blocks this filter.
Do I need to document why my AI system is not high-risk?+
Yes, if you conclude your Annex III AI system is not high-risk based on Article 6(3), you must document this before placing the system on the market and make this documentation available to authorities. You must also register the system in the EU database with an explanation.
What are the practical consequences of a high-risk classification?+
A high-risk classification means you must comply with extensive requirements: establish a risk management system (Art. 9), ensure data governance (Art. 10), prepare technical documentation (Annex IV), implement logging (Art. 12), provide transparency (Art. 13), arrange human oversight (Art. 14), and undergo a conformity assessment.
Will the European Commission publish a list of examples of high-risk and not high-risk AI?+
On 19 May 2026, the Commission published draft guidelines with examples and separate parts for Annex I and Annex III. The targeted consultation is closed, but final guidelines have not yet been published.
How much does compliance with the high-risk AI requirements cost?+
The AI Act sets no fixed cost. The effort depends on the role, classification route, existing management systems, intended purpose, and the technical and organisational measures needed for the specific system.