Praxikon
All obligations
Upcomingv1.0.0

Annex III: high-risk AI

Classification route for standalone high-risk AI systems under Article 6(2) and Annex III.

The official source remains authoritative. This general interpretation is not legal advice.

Status
Upcoming
Application date
2 December 2027
Version
1.0.0
Last reviewed
8 August 2026

Who this is relevant to

When this applies

  • Deployer

    An organisation using an AI system under its authority, excluding personal non-professional use.

  • Provider of an AI system

    A party that develops or has an AI system developed and places it on the market under its own name.

  1. 1The intended purpose falls within a use case listed in Annex III.
  2. 2Classification follows Article 6(2).

What the official source establishes

The core rules in Chapter III, Sections 1 to 3, for systems under Article 6(2) and Annex III become applicable on 2 December 2027.

Our interpretation

The later application date does not remove the classification question. An early classification record avoids design and procurement decisions without evidence.

What you can do now

Document now the intended purpose, Annex III point, Article 6(3) assessment, profiling and selected registration path.

  1. 01

    Classify the use case and document the outcome

    Assess Article 5, Article 6 and Annex III in that order and document purpose, context and any Article 6(3) exception.

What to retain

Article 6 and Annex III classification record

Traceable rationale covering intended purpose, Annex III category, Article 6(3) assessment and registration decision.

Control and reassessment

  • Reclassification on purpose or context change

    Reopen classification when intended purpose, use context or system functionality changes materially.

Public tools

Conditions and exceptions

  • A listed Annex III system may fall outside high-risk under the strict conditions in Article 6(3), except where it profiles. The assessment and registration must be documented.

Official sources and locators

  • Digital Omnibus on AI 2026/1744

    European Parliament and Council | official-journal-2026-07-24

    Source locator: Amended Article 113, Article 6(2) and Annex III application date

  • EU Artificial Intelligence Act 2024/1689

    European Parliament and Council | original-oj-2024-07-12

    Source locator: Article 6 and Annex III

  • EU Artificial Intelligence Act 2024/1689

    European Parliament and Council | original-oj-2024-07-12

    Source locator: Article 6(2)-(4), Article 49 and Annex III

What changed in this

Moments when this obligation took effect, moved or received official guidance.

  • 2028-08-02 | upcoming

    High-risk AI embedded in regulated products

    AI as a safety component of products under Annex I follows on 2 August 2028.

  • 2027-12-02 | binding law

    Annex III core rules moved to 2 December 2027

    The amended application date has been binding law since 27 July 2026.

  • 2026-05-19 | guidance

    Draft guidelines on high-risk classification

    The Commission explains in consultation when a system falls under Annex I or Annex III.

  • 2025-07-29 | guidance

    Guidelines on the definition of an AI system

    The Commission draws the line between software that does and does not fall under the regulation.

See the full timeline

What member states are doing with this

Dated signals from the enforcement tracker that refer to this obligation.

  • EU | 2026-07-27 | Europees Parlement en Raad

    Digital Omnibus on AI (Regulation (EU) 2026/1744) enters into force

    The Digital Omnibus on AI, adopted on 8 July 2026 and published in the Official Journal on 24 July 2026, enters into force on 27 July 2026. The regulation defers the obligations for stand-alone high-risk AI systems (Annex III) from 2 August 2026 to 2 December 2027 and for embedded high-risk systems (Annex I) from 2 August 2027 to 2 August 2028, and adds two prohibitions to Article 5 as of 2 December 2026 (non-consensual intimate imagery and AI-generated child sexual abuse material). This recalibrates the enforcement agenda of the Commission and the Member States.

    EUR-Lex

  • France | 2023-12-27 | Commission Nationale de l’Informatique et des Libertés (CNIL)

    CNIL fines Amazon France Logistique 32 million euros for employee monitoring

    The CNIL fined Amazon France Logistique 32 million euros for an excessively intrusive system that tracked warehouse workers’ activity via scanners down to the second. Under the AI Act, algorithmic monitoring of workers is a high-risk use (Annex III, employment), with obligations applying from 2 December 2027.

    CNIL, besluit SAN-2023-021

Open the enforcement tracker

Version history

  1. v1.0.0

    27 July 2026

    Annex III: high-risk AI

    Classification route for standalone high-risk AI systems under Article 6(2) and Annex III.

Execution

Record the classification in an AI register

A classification without a register and ownership is not demonstrable. Embed AI guides classification, register and reassessment in a fixed approach.

See the Embed AI approach

For AI agents and integrations

This page and the machine output derive from the same versioned object. Use the API for deterministic filters by role, topic and time.