Direct answer
When are you a provider under the AI Act?
18 obligations under the AI Act bear on this, of which 4 apply today.
First step: Justify the Article 6(3) exception against each individual condition.
Whether you are a provider is not a matter of what you call yourself but of what you do with the system. Across the 18 obligations there are 39 conditions and exceptions that decide it. Below they are listed per provision, with the official source. Likely role: provider of an ai system.
This applies now
- Article 4: AI literacyApplicable
- Article 5: prohibited practicesApplicable
- Article 50: transparencyApplicable
- Article 60: testing in real world conditions outside a sandboxApplicable
Coming up
- Annex III: high-risk AIfrom 2 December 2027
- Article 10: data and data governancefrom 2 December 2027
- Article 11: technical documentationfrom 2 December 2027
- Article 12: logging and traceabilityfrom 2 December 2027
- Article 13: transparency towards deployersfrom 2 December 2027
- Article 14: human oversightfrom 2 December 2027
- Article 15: accuracy, robustness and cybersecurityfrom 2 December 2027
- Article 16: the twelve duties of a provider of a high-risk AI systemfrom 2 December 2027
- Article 17: quality management systemfrom 2 December 2027
- Article 72: post-market monitoringfrom 2 December 2027
- Article 73: serious incident reportingfrom 2 December 2027
- Article 9: risk management systemfrom 2 December 2027
- Articles 43-49: conformity assessment, CE and registrationfrom 2 December 2027
- Articles 22-25: value chain and authorised representativefrom 2 December 2027
What decides whether this is about you
- Applies when: The intended purpose falls within a use case listed in Annex III.
- Applies when: Classification follows Article 6(2).
- Unless: A listed Annex III system may fall outside high-risk under the strict conditions in Article 6(3), except where it profiles. The assessment and registration must be documented.
- Applies when: The high-risk system is trained with data; the provider composes the datasets, the deployer controls relevant input data.
- Unless: For special categories of personal data the strict exception of Article 10(5) applies (bias detection and correction under conditions).
- Applies when: The provider places a high-risk AI system on the market or puts it into service.
- Unless: Small providers (SMEs) may provide the documentation in the simplified form established by the Commission.
- Applies when: The system is high-risk; the provider designs the logging, provider and deployer retain the logs under their control.
- Unless: The retention period may be limited by Union or national law, including data protection.
- Applies when: The provider supplies a high-risk system; the deployer uses it according to the instructions.
- Unless: The level of detail may match the intended deployer’s knowledge; trade secrets need not be disclosed.
- Applies when: The system is high-risk; the provider builds in oversight measures, the deployer assigns oversight to competent persons.
- Unless: For remote biometric identification the reinforced requirement of verification by at least two authorised persons applies (Article 14(5)), with the exceptions listed there.
- Applies when: The provider places a high-risk AI system on the market or puts it into service.
- Unless: Systems that continue learning after deployment carry additional requirements to control feedback loops and drift.
- Applies when: Applies to providers of high-risk AI systems. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027. For systems embedded as a safety component in products covered by the Annex I harmonisation legislation (Article 6(1)) the date is 2 August 2028.
- Unless: A provider that considers an Annex III system not to be high-risk must document that assessment before placing it on the market and remains subject to the registration obligation of Article 49(2) (Article 6(4)). Where an AI system referred to in Annex III performs profiling of natural persons it is always considered high-risk (Article 6(3), final subparagraph).
- Applies when: The provider places high-risk AI systems on the market or puts them into service.
- Unless: Providers already under sectoral quality regimes may integrate the AI elements into that existing system; SMEs may implement elements in simplified form.
- Applies when: The organisation is a provider or deployer of an AI system within scope.
- Unless: The provision does not require a specific individual level to be guaranteed.
- Applies when: Placing on the market, putting into service or using AI falls under one of the practices in Article 5(1), including harmful manipulation or exploitation of vulnerabilities, social scoring, predicting criminal offences based on profiling, untargeted scraping of facial images, emotion recognition in the workplace or education, biometric categorisation by sensitive characteristics and real-time remote biometric identification in publicly accessible spaces for law enforcement.
- Unless: The exceptions are narrow: among others, emotion recognition for medical or safety reasons, and the exhaustively defined law-enforcement situations with authorisation for real-time remote biometric identification in Article 5(2) to (7). The exception must be established and documented in advance.
- Applies when: An AI system is intended to interact directly with natural persons.
- Applies when: The system generates or manipulates synthetic audio, image, video or text, or the use concerns a specifically listed deployer scenario.
- Unless: The direct-interaction disclosure is not required where this is obvious to a reasonably well-informed, observant and circumspect person, considering circumstances and context.
- Unless: Only Article 50(2) has a transition until 2 December 2026 for systems placed on the market before 2 August 2026.
- Applies when: Applies where you are a provider or prospective provider of an Annex III high-risk AI system and you want to test it in real world conditions outside an AI regulatory sandbox, before placing it on the market or putting it into service. If you are established outside the Union, Article 60(4), point (d), requires you to appoint a legal representative established in the Union; that is a different figure from the authorised representative under Article 22.
- Unless: Article 60(1), third subparagraph, leaves Union and national law on real-world testing of high-risk systems related to products under the Annex I harmonisation legislation unaffected. Article 60(4), point (i), contains a law enforcement carve-out: where seeking informed consent would prevent the system from being tested, testing may proceed without consent, provided the testing and its outcome have no negative effect on the subjects and their personal data are deleted after the test. For the systems referred to in Annex III, points 1, 6 and 7, in law enforcement, migration, asylum and border control, registration runs through the secure non-public section of the EU database under Article 49(4), point (d). For the systems referred to in Annex III, point 2, Article 49(5) requires registration at national level.
- Applies when: The provider has a high-risk system on the market; deployers supply the real-world data via monitoring and signals.
- Unless: The plan may be proportionate to the nature of the system and align with existing sectoral monitoring regimes.
- Applies when: A serious incident occurs with a high-risk system: death or serious harm to health, serious and irreversible disruption of critical infrastructure, infringement of fundamental-rights protections or serious damage to property or environment.
- Unless: For systems under sectoral reporting regimes with equivalent duties, reporting may run through that regime to avoid duplication.
- Applies when: The system is high-risk under Article 6 and the provider places it on the market or puts it into service.
- Unless: Risks arising only from misuse beyond any reasonably foreseeable use fall outside the mandatory scope.
- Applies when: The provider places a high-risk system on the market; public deployers also register their use.
- Unless: For most Annex III systems internal control suffices (Annex VI); a notified body is required for certain biometrics and where harmonised standards are lacking.
- Applies when: A high-risk system is supplied, modified, rebranded or placed on the Union market from outside the EU.
- Unless: Those acting solely as distributor or importer without the Article 25 triggers remain in that lighter role, with their own verification duties.
These are the questions you answer yourself. Praxikon shows which condition sits in which provision; whether your system meets it is yours to establish.
recruitment and selection
Candidate recommendation that automatically becomes a decision
An employer uses a system that ranks applicants and recommends a candidate to hire. In one setup a recruiter weighs that recommendation in their own assessment; in the other the outcome is applied automatically and a candidate is rejected without anyone looking at it.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.
Assess a recruitment system on its intended purpose rather than on whether a recruiter reviews the output, because adding or removing human involvement does not change its high-risk classification.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III
biometrics and identification
Face comparison at the border gate: verification or identification
An automated border gate uses biometric facial recognition to compare a traveller’s face with the photo in the passport chip. The same camera could technically also compare against a law-enforcement database, and exactly that difference decides whether this biometrics is high-risk.
Provenance: The Commission draft guidelines of 19 May 2026 state that biometric verification falls outside the high-risk classification: one-to-one comparison of presented biometrics with previously stored biometrics, for the sole purpose of confirming that a person is who they claim to be. Where the same capture is additionally compared against a law-enforcement database, it does become remote biometric identification. The document is a consultation version: non-binding and not yet final.
Test your biometric application on purpose rather than technology: the same camera and the same model stay outside the high-risk route as long as the comparison is one-to-one and only confirms identity, and fall inside it as soon as that same capture is also held against a database. Record per application what the comparison runs against, because that single design choice moves the entire regime.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III, paragraph (136)
recruitment and selection
A CV filter that ranks applicants
An employer has an external recruitment system score and rank every incoming application, after which recruiters only review the top twenty percent by hand. The vendor puts the system on the market under its own name, and the employer uses it in its own selection process.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.
Recruiters keeping the final say does not help you, because once the system scores or ranks applicants and thereby shapes the shortlist it stays high-risk and no exemption applies.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III
education
Application file handling at an educational institution
An educational institution uses AI for application file handling: indexing, searching, text and speech processing, translation of documents submitted with applications, and extracting, transforming and organising the collected data into a usable format.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.
Indexing, searching, translating and reorganising application files remains preparatory work, as long as the system leaves the substantive judgment on the application entirely to the institution.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III
Article 6 has two separate routes to high-risk
The European Commission's draft guidelines on the classification of high-risk AI of 19 May 2026, which are expressly non-binding, state in paragraph (7) that an AI system is high-risk in two scenarios: first, where it is intended to be used as a safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in Annex I and required to undergo third-party conformity assessment; and second, where it falls within one of the use cases in the areas listed in Annex III. Paragraph (448) of those same draft guidelines notes that the Article 113 application dates have been postponed by the AI Omnibus to 2 December 2027 for the Article 6(2) route and 2 August 2028 for the Article 6(1) route.
Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II, paragraph (7); section V, paragraph (448)
Broadly positioned and general purpose AI systems: a disclaimer is not enough
According to the non-binding draft guidelines of 19 May 2026 on the classification of high-risk AI, paragraph (12) provides that where the instructions for use, contractual arrangements, terms of service, usage policy, promotional and sales materials or technical documentation present the AI system as broadly applicable across a generality of contexts and functions, and do not consistently limit its application or exclude high-risk uses, the system's intended purpose will be deemed to also encompass high-risk use cases and therefore qualify as high-risk. Under these draft guidelines this applies in particular where such uses are feasible and reasonably foreseeable given the system's functionalities and capabilities. The same paragraph states that merely asserting, for example in the terms of service, that high-risk uses are excluded is insufficient where the provider's overall presentation, examples or product positioning effectively provides for or promotes such uses, and that any limitations of use must be described clearly, concretely and coherently across all materials.
Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraph (12)
High-risk does not mean prohibited, and not high-risk does not mean permitted
The draft guidelines of 19 May 2026 on the classification of high-risk AI, which are not binding, state in paragraph (3) that the fact an AI system is listed as an example in these guidelines does not mean its use should automatically be considered lawful, since such use would still need to comply with other applicable legislation, and in paragraph (4) that the scope of these guidelines is limited to whether an AI system is high-risk or not. In the Annex III chapter of this draft, paragraph (68) states that classifying systems as high-risk under Article 6(2) does not mean their use is prohibited, but that those systems are subject to appropriate requirements. Paragraphs (82) and (83) of this draft explain the wording in so far as their use is permitted under relevant Union or national law and state that falling within a use case does not necessarily mean the system may lawfully be used in those cases, that in addition to the prohibitions other provisions of Union or national law may restrict use, and that under Article 2(9) the AI Act applies without prejudice to rules on consumer protection, product safety and data protection.
Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, paragraphs (3) and (4); Annex III chapter, paragraph (68) and section 2.6, paragraphs (82) and (83)
Split and agentic architectures are assessed as a whole
The non-binding draft guidelines of 19 May 2026 provide in paragraphs 75, 76 and 90 that where several AI systems form part of a more complex whole and their combined intended purpose or joint outputs materially influence an individual decision, that configuration is treated as a single AI system for classification. The draft expressly states that split architectures are assessed as a whole to prevent circumvention by system design, that exemptions for individual modules do not apply where the overall configuration influences key aspects of the decision, and that this also extends to complex interconnected setups such as agentic AI systems whose linked actions jointly serve a high-risk purpose. Under the same draft, strictly procedural or preparatory functions do remain eligible for exemption where they are genuinely separable from the system and do not structure or feed outputs that materially influence the examination of an individual case.
Section IV.2.3, paragraphs 75 and 76, and section IV.2.7.1 paragraph 90
EN 18286:2026: quality management system for EU AI Act regulatory purposes
EN 18286:2026 (Artificial intelligence: Quality management system for EU AI Act regulatory purposes) was drafted by CEN/CLC/JTC 21 under standardisation request M/613 and approved by CEN-CENELEC on 12 July 2026. It is the first JTC 21 deliverable to reach publication. According to a published coverage statement accompanying the standard, not yet confirmed by a second independent source, it addresses Article 17(1) points (a) to (m) and Article 11(1) first sentence, and expressly not Article 17(2) to (4) or Article 72. The standard is NOT currently cited in the Official Journal. The Article 40 presumption of conformity only attaches after that citation.
EN ISO/IEC 42001: artificial intelligence management system
ISO/IEC 42001:2023 is the first certifiable international standard for an AI management system, published on 18 December 2023 and structured on the plan-do-check-act cycle. The text was adopted unchanged as EN ISO/IEC 42001:2026, approved by CEN on 13 March 2026, with national implementation by the member standards bodies. This adoption is not a deliverable under standardisation request M/613: the standard is not cited in the Official Journal and therefore confers no presumption of conformity under Article 40. For Article 17, the designated deliverable under M/613 is EN 18286:2026; that standard is likewise not cited in the Official Journal.
ISO/IEC 12792: transparency taxonomy of AI systems
ISO/IEC 12792:2025 (Information technology: Artificial intelligence: Transparency taxonomy of AI systems) was published in November 2025 by ISO/IEC JTC 1/SC 42. It specifies a taxonomy of information elements to help stakeholders identify and address transparency needs, and describes the semantics of those elements and their relevance to different stakeholders' objectives. The text was adopted as a European standard as EN ISO/IEC 12792:2025. It is not cited in the Official Journal and therefore confers no presumption of conformity under Article 40. For Article 13 the designated deliverable is prEN 18229-3.
ISO/IEC 23894: guidance on risk management for AI
ISO/IEC 23894:2023 (Information technology: Artificial intelligence: Guidance on risk management) was published in February 2023 and is the first international standard dealing specifically with risk management for AI. It is non-prescriptive and built on the ISO 31000 structure. The text was adopted by CEN-CENELEC as EN ISO/IEC 23894:2024. It is not cited in the Official Journal and therefore confers no presumption of conformity under Article 40 of the AI Act. The deliverable intended to do so for Article 9 is prEN 18228.
General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.
Full map for your situation