Article 6: Classification rules for high-risk AI systems
Application dates
- : Article 6(2) and systems listed in Annex III
- : Article 6(1) and systems linked to Annex I
Article 6 determines when an AI system falls under the high-risk regime. The practical question is whether the system is covered by Annex I, Annex III or a limited Article 6(3) exception.
Implementation timeline
Official text
Source: EUR-Lex, Regulation (EU) 2024/1689. Text reproduced verbatim.
Download AI Act (PDF)→Official guidance on this article
7- Regulation (EU) 2026/1744, Digital Omnibus on AIAnchors through Article 113 the two fixed routes: 2 December 2027 for Article 6(2) and Annex III and 2 August 2028 for Article 6(1) and Annex I.PublishedRegulationEuropean Parliament and Council of the European Union24 Jul 2026
- AIB 2025-1 / MDCG 2025-6 Interplay between the Medical Devices Regulation (MDR) and In vitro Diagnostic Medical Devices Regulation (IVDR) and the Artificial Intelligence Act (AIA)Clarifies when AI in a medical device via the Annex I route is high-risk because the device already undergoes conformity assessment by a notified body.PublishedGuidelinesAI Board (AIB) and Medical Device Coordination Group (MDCG), European Commission
- AI PactEncourages organisations to inventory now which systems will later qualify as high-risk, in anticipation of the application datesPublishedCode of practiceEuropean Commission / AI Office7 Aug 2026
- Navigating the AI Act (Questions and Answers)Explains via which two routes, embedded safety component and Annex III application, a system is designated as high-riskPublishedQ&AEuropean Commission, DG CONNECT7 Aug 2026
- Draft Commission Guidelines on the classification of high-risk AI systems under the AI ActExplains how the two routes to high-risk work: safety component in a product under Annex I with third-party conformity assessment, or a use case from Annex III, and when the exceptions in Article 6, paragraph 3, applyConsultationGuidelinesEuropean Commission (AI Office)19 May 2026
- EU AI Act Compliance CheckerGoes through the classification questions with which you test whether a system qualifies as high-riskDraftQ&AEuropean Commission (AI Act Service Desk)
- EDPB-EDPS Joint Opinion 1/2026 on the Proposal for a Regulation as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)Assesses the proposal to postpone the application of high-risk classification and warns that postponement without additional safeguards creates a protection gap for people exposed to Annex III systems.PublishedOpinionEDPB and EDPS jointly21 Jan 2026
Governance
Provider
- •Classifies the AI system as high-risk or not
- •Performs conformity assessment (Art. 43)
- •Registers in EU database (Art. 49)
- •Can claim Art. 6(3) exception with documentation
Deployer
- •Verifies provider's classification
- •Uses AI system within intended purpose
- •Deviating use: reclassification required
Supervisory Authority
- •Market surveillance on correct classification
- •Can challenge Art. 6(3) exception
- •Access to EU database
European Commission
- •Publishes guidelines on classification (⚠️ deadline missed)
- •Can update Annex III via delegated acts
- •Establishes standard templates
What does this mean for you?
Provider+
Deployer+
SME / Startup+
Public Sector+
Overlap with other legislation
High-risk classification under the AI Act often also requires a DPIA under the GDPR. The risk assessment for high-risk AI systems overlaps with the DPIA obligation, but they are not identical — the AI Act focuses on AI-specific risks, the GDPR on privacy risks.
High-risk AI systems must meet cybersecurity requirements (Art. 15 AI Act). If the AI system is part of an essential or important entity under NIS2, additional security obligations apply. Measures can be combined.
AI systems placed on the market as products also fall under product liability. The new PLD (2024/2853) explicitly names software as a product. A high-risk AI system that does not comply with the AI Act may be considered a 'defective product'. The previously proposed AI Liability Directive has been withdrawn — the PLD is now the primary route for AI damage claims.
AI systems that are safety components of machinery (Annex I, section A) automatically fall under high-risk (Art. 6(1)). The conformity assessment of the machinery and the AI system must be aligned.
Regulation (EU) 2026/1744 has applied since 27 July 2026 and amends the AI Act. For Art. 6, the core obligations for Annex III systems apply from 2 December 2027 and those for product-based Annex I systems from 2 August 2028. Registration under Art. 49(2) remains but is simplified. Proportionate rules are extended to small mid-caps.
Art. 6(1) explicitly refers to Annex I — 21 pieces of EU harmonisation legislation. If an AI system is a safety component of a product covered by this legislation AND requires third-party conformity assessment, it is automatically high-risk.
Related recitals
AI systems could have an adverse impact on the health and safety of persons, in particular when such systems operate as safety components of products. Consistent with the objectives of Union harmonisa…
The extent of the adverse impact caused by the AI system on the fundamental rights protected by the Charter is of particular relevance when classifying an AI system as high risk. Those rights include …
As regards high-risk AI systems that are safety components of products or systems, or which are themselves products or systems falling within the scope of Regulation (EC) No 300/2008 of the European P…
As regards AI systems that are safety components of products, or which are themselves products, falling within the scope of certain Union harmonisation legislation listed in an annex to this Regulatio…
Related tools
Related enforcement
- •
- •