Skip to main content
Praxikon
All answers

Direct answer

Does our system fall under the definition of an AI system (Article 3)?

This falls under Annex III: high-risk AI. That obligation applies from 2 December 2027. There is one exception you have to assess yourself.

This could go the other way

  • A listed Annex III system may fall outside high-risk under the strict conditions in Article 6(3), except where it profiles. The assessment and registration must be documented.

First step: Justify the Article 6(3) exception against each individual condition.

You describe: You are unsure whether software, a computational model or a rule-based system legally qualifies as an AI system and thus falls under the regulation. Likely role: provider and deployer alike.

The conclusion and your first steps

This applies now

Coming up

Depends on your situation

These provisions only apply once the stated fact is established. The locator says which provision settles it.

The Article 3 definition centres on a machine-based system that, with some autonomy, infers from input how to generate output such as predictions, recommendations or decisions, and that may be adaptive after deployment. Classic software that only executes predefined rules generally falls outside it. Record the assessment per system; the conclusion "not an AI system" belongs in the register too.

Your first actions

  1. Justify the Article 6(3) exception against each individual condition. Name which of the four Article 6(3) conditions you invoke, with facts, and separately justify why the system poses no significant risk of harm to health, safety or fundamental rights and does not materially influence the outcome of decision making.
  2. Take role- and context-specific AI literacy measures. Determine for each role, system and context which combination of instruction, guidance, practice or training is appropriate.
  3. Set and test performance and security levels. Determine appropriate accuracy, test robustness against errors and misuse, and take AI-specific security measures.
Read the official sourceChecked on

General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.

Full map for your situation

Your route

From your situation, via your role, to what applies and when it starts.

1 now · 4 later

Your situation

You are unsure whether software, a computational model or a rule-based system legally qualifies as an AI system and thus falls under the regulation.

Role

Provider and deployer alike

To record: Article 49(2) registration record for the system assessed as not high-risk · AI literacy measures record · Performance and security file

Source and locator

Every statement above rests on these texts. The locator points to the place in the text, the version and the date say which edition was checked.

  • EU Artificial Intelligence Act 2024/1689

    European Parliament and Council, version original-oj-2024-07-12, checked on , ELI http://data.europa.eu/eli/reg/2024/1689/oj

    Locators in this source

    • Article 6 and Annex III
    • Article 6(2)-(4), Article 49 and Annex III
    • Article 15(1)-(5)
    • Article 10(1)-(6)
    • Article 11(1)-(3) and Annex IV
  • Digital Omnibus on AI 2026/1744

    European Parliament and Council, version official-journal-2026-07-24, checked on , ELI http://data.europa.eu/eli/reg/2026/1744/oj

    Locators in this source

    • Amended Article 113, Article 6(2) and Annex III application date
    • Amendment of Article 4; entry into force 27 July 2026
    • Amended Article 113 application dates
  • AI literacy questions and answers

    European Commission, version updated-2026-07-27, checked on

    Locators in this source

    • Questions on measures, formats, certificates and records
    • Implementation examples and evidence guidance

Dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0, schema 1.5.0.

Sharper for your situation

Do you build this system yourself or take it from a vendor?

This flips your role, and with it almost the entire set of obligations.

Execution

Record role and classification for each AI system

The boundary is set out in the rules above. The outcome becomes demonstrable when the facts, role, classification, owner and reassessment are recorded for each system. Embed AI guides that inventory and sets up the AI register. The source interpretation above is separate from this commercial referral by Praxikon to an affiliated brand.

See the AI register approach
Does this answer your question?
Zahed Ashkara, jurist and freelance AI & Privacy Consultant

Behind this page

Zahed Ashkara

Freelance AI & Privacy Consultant, jurist