Direct answer
We use AI for creditworthiness or insurance pricing. What applies?
This falls under Annex III: high-risk AI. That obligation applies from 2 December 2027. There is one exception you have to assess yourself.
This could go the other way
- A listed Annex III system may fall outside high-risk under the strict conditions in Article 6(3), except where it profiles. The assessment and registration must be documented.
First step: Justify the Article 6(3) exception against each individual condition.
You describe: AI determining creditworthiness or credit scores, or risk and premium setting for life or health insurance. Likely role: provider (you place the system on the market or into service).
This applies now
- Article 4: AI literacyApplicable
Coming up
- Annex III: high-risk AIfrom 2 December 2027
- Article 27: FRIAfrom 2 December 2027
Then you are the provider. The design and documentation duties sit with you: you build the requirements into the system, record how it works and what it rests on, and declare before deployment that it meets the regulation. Note that you can become a provider without building anything: substantially modifying a purchased system or placing it under your own name takes over that role.
Your first actions
- Justify the Article 6(3) exception against each individual condition. Name which of the four Article 6(3) conditions you invoke, with facts, and separately justify why the system poses no significant risk of harm to health, safety or fundamental rights and does not materially influence the outcome of decision making.
- Map the affected groups and their specific risks of harm. Name the categories of natural persons and groups likely to be affected by the use in this specific context, and work out the specific risks of harm per category, using the information the provider supplied under Article 13.
- Take role- and context-specific AI literacy measures. Determine for each role, system and context which combination of instruction, guidance, practice or training is appropriate.
Record this
- Article 49(2) registration record for the system assessed as not high-risk
- Notification to the market surveillance authority with the completed template
- AI literacy measures record
financial services
Money laundering detection by an accounting firm under its own legal duty
An accounting firm deploys an AI system that detects money laundering, in order to comply with its own obligations under EU anti-money laundering legislation.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.
Check whether you are meeting your own legal duty or taking over a task from a public authority, because only in the second case do you act on its behalf and enter the law enforcement regime.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III
financial services
Company creditworthiness based on corporate financials
A provider develops a system assessing the creditworthiness of companies by evaluating their company data, balance sheets and financial statements. In a variant, the owner of a legal entity is assessed to back a company loan.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.
Decide in advance whether natural persons form part of your intended purpose, because a system that also evaluates their personal finances falls within point 5(b) as a whole, regardless of its corporate focus.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III
financial services
Corporate creditworthiness based on balance sheets and financial statements
A provider develops an AI system that assesses the creditworthiness of companies using company data, balance sheets and financial statements. The situation where the owner of a legal entity is assessed as backing for a company loan is also addressed.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.
An assessment remains corporate as long as the credit accrues to the company, so even an owner backing a company loan does not turn your system into an evaluation of a natural person.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III
financial services
Credit score of a business owner based solely on business data
A provider develops an AI system that establishes the credit score of the owner of a small business or of a company that is not a legal entity. The system uses only business or company data.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.
Limit your system demonstrably to business data if you want to stay outside point 5(b), because the moment it also draws on the owner personal finances you are evaluating a natural person.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III
Article 6 has two separate routes to high-risk
The European Commission's draft guidelines on the classification of high-risk AI of 19 May 2026, which are expressly non-binding, state in paragraph (7) that an AI system is high-risk in two scenarios: first, where it is intended to be used as a safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in Annex I and required to undergo third-party conformity assessment; and second, where it falls within one of the use cases in the areas listed in Annex III. Paragraph (448) of those same draft guidelines notes that the Article 113 application dates have been postponed by the AI Omnibus to 2 December 2027 for the Article 6(2) route and 2 August 2028 for the Article 6(1) route.
Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II, paragraph (7); section V, paragraph (448)
Broadly positioned and general purpose AI systems: a disclaimer is not enough
According to the non-binding draft guidelines of 19 May 2026 on the classification of high-risk AI, paragraph (12) provides that where the instructions for use, contractual arrangements, terms of service, usage policy, promotional and sales materials or technical documentation present the AI system as broadly applicable across a generality of contexts and functions, and do not consistently limit its application or exclude high-risk uses, the system's intended purpose will be deemed to also encompass high-risk use cases and therefore qualify as high-risk. Under these draft guidelines this applies in particular where such uses are feasible and reasonably foreseeable given the system's functionalities and capabilities. The same paragraph states that merely asserting, for example in the terms of service, that high-risk uses are excluded is insufficient where the provider's overall presentation, examples or product positioning effectively provides for or promotes such uses, and that any limitations of use must be described clearly, concretely and coherently across all materials.
Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraph (12)
High-risk does not mean prohibited, and not high-risk does not mean permitted
The draft guidelines of 19 May 2026 on the classification of high-risk AI, which are not binding, state in paragraph (3) that the fact an AI system is listed as an example in these guidelines does not mean its use should automatically be considered lawful, since such use would still need to comply with other applicable legislation, and in paragraph (4) that the scope of these guidelines is limited to whether an AI system is high-risk or not. In the Annex III chapter of this draft, paragraph (68) states that classifying systems as high-risk under Article 6(2) does not mean their use is prohibited, but that those systems are subject to appropriate requirements. Paragraphs (82) and (83) of this draft explain the wording in so far as their use is permitted under relevant Union or national law and state that falling within a use case does not necessarily mean the system may lawfully be used in those cases, that in addition to the prohibitions other provisions of Union or national law may restrict use, and that under Article 2(9) the AI Act applies without prejudice to rules on consumer protection, product safety and data protection.
Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, paragraphs (3) and (4); Annex III chapter, paragraph (68) and section 2.6, paragraphs (82) and (83)
Split and agentic architectures are assessed as a whole
The non-binding draft guidelines of 19 May 2026 provide in paragraphs 75, 76 and 90 that where several AI systems form part of a more complex whole and their combined intended purpose or joint outputs materially influence an individual decision, that configuration is treated as a single AI system for classification. The draft expressly states that split architectures are assessed as a whole to prevent circumvention by system design, that exemptions for individual modules do not apply where the overall configuration influences key aspects of the decision, and that this also extends to complex interconnected setups such as agentic AI systems whose linked actions jointly serve a high-risk purpose. Under the same draft, strictly procedural or preparatory functions do remain eligible for exemption where they are genuinely separable from the system and do not structure or feed outputs that materially influence the examination of an individual case.
Section IV.2.3, paragraphs 75 and 76, and section IV.2.7.1 paragraph 90
General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.
Full map for your situationExecution
Record the classification in an AI register
A classification without a register and ownership is not demonstrable. Embed AI guides classification, register and reassessment in a fixed approach.
See the Embed AI approach