Chapter III · Section 1 · Classification of AI systems as high-risk
Article 6 — Classification rules for high-risk AI systems
▼ Primary text, verbatim. Our annotations appear below, visibly separated.
1. Irrespective of whether an AI system is placed on the market or put into service independently of the products referred to in points (a) and (b), that AI system shall be considered to be high-risk where both of the following conditions are fulfilled:
(a) the AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I;
(b) the product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service of that product pursuant to the Union harmonisation legislation listed in Annex I.
1a. For the purposes of this Regulation, including paragraph 1 of this Article, AI systems that are solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control shall not qualify as safety components.
1b. Notwithstanding paragraph 1a, AI systems the failure or malfunctioning of which would endanger health and safety shall qualify as safety components.
1c. A product that is required to undergo a third-party conformity assessment solely due to risks other than risks to health and safety, in particular risks relating to the distribution of radio spectrum or electromagnetic interference that do not affect health and safety, shall not be considered as fulfilling the condition in paragraph 1, point (b).
2. In addition to the high-risk AI systems referred to in paragraph 1, AI systems referred to in Annex III shall be considered to be high-risk.
3. By derogation from paragraph 2, an AI system referred to in Annex III shall not be considered to be high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making.
The first subparagraph shall apply where any of the following conditions is fulfilled:
(a) the AI system is intended to perform a narrow procedural task;
(b) the AI system is intended to improve the result of a previously completed human activity;
(c) the AI system is intended to detect decision-making patterns or deviations from prior decision-making patterns and is not meant to replace or influence the previously completed human assessment, without proper human review; or
(d) the AI system is intended to perform a preparatory task to an assessment relevant for the purposes of the use cases listed in Annex III.
Notwithstanding the first subparagraph, an AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons.
4. A provider who considers that an AI system referred to in Annex III is not high-risk shall document its assessment before that system is placed on the market or put into service. Such provider shall be subject to the registration obligation set out in Article 49(2). Upon request of national competent authorities, the provider shall provide the documentation of the assessment.
5. The Commission shall, after consulting the European Artificial Intelligence Board (the ‘Board’), and no later than 2 February 2026, provide guidelines specifying the practical implementation of this Article in line with Article 96 together with a comprehensive list of practical examples of use cases of AI systems that are high-risk and not high-risk.
6. The Commission is empowered to adopt delegated acts in accordance with Article 97 in order to amend paragraph 3, second subparagraph, of this Article by adding new conditions to those laid down therein, or by modifying them, where there is concrete and reliable evidence of the existence of AI systems that fall under the scope of Annex III, but do not pose a significant risk of harm to the health, safety or fundamental rights of natural persons.
7. The Commission shall adopt delegated acts in accordance with Article 97 in order to amend paragraph 3, second subparagraph, of this Article by deleting any of the conditions laid down therein, where there is concrete and reliable evidence that this is necessary to maintain the level of protection of health, safety and fundamental rights provided for by this Regulation.
8. Any amendment to the conditions laid down in paragraph 3, second subparagraph, adopted in accordance with paragraphs 6 and 7 of this Article shall not decrease the overall level of protection of health, safety and fundamental rights provided for by this Regulation and shall ensure consistency with the delegated acts adopted pursuant to Article 7(1), and take account of market and technological developments.
This text is meant purely as a documentation tool and has no legal effect. The Union's institutions do not assume any liability for its contents. The authentic versions of the relevant acts, including their preambles, are those published in the Official Journal of the European Union and available in EUR-Lex.
Passages marked with the accent edge in the primary text were inserted or replaced by the amendment.
Show the text as adopted, before the amendment
The authentic 2024 text of this provision, shown for comparison. It no longer states the law.
1. Irrespective of whether an AI system is placed on the market or put into service independently of the products referred to in points (a) and (b), that AI system shall be considered to be high-risk where both of the following conditions are fulfilled:
(a) the AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I;
(b) the product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service of that product pursuant to the Union harmonisation legislation listed in Annex I.
2. In addition to the high-risk AI systems referred to in paragraph 1, AI systems referred to in Annex III shall be considered to be high-risk.
3. By derogation from paragraph 2, an AI system referred to in Annex III shall not be considered to be high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making.
The first subparagraph shall apply where any of the following conditions is fulfilled:
(a) the AI system is intended to perform a narrow procedural task;
(b) the AI system is intended to improve the result of a previously completed human activity;
(c) the AI system is intended to detect decision-making patterns or deviations from prior decision-making patterns and is not meant to replace or influence the previously completed human assessment, without proper human review; or
(d) the AI system is intended to perform a preparatory task to an assessment relevant for the purposes of the use cases listed in Annex III.
Notwithstanding the first subparagraph, an AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons.
4. A provider who considers that an AI system referred to in Annex III is not high-risk shall document its assessment before that system is placed on the market or put into service. Such provider shall be subject to the registration obligation set out in Article 49(2). Upon request of national competent authorities, the provider shall provide the documentation of the assessment.
5. The Commission shall, after consulting the European Artificial Intelligence Board (the ‘Board’), and no later than 2 February 2026, provide guidelines specifying the practical implementation of this Article in line with Article 96 together with a comprehensive list of practical examples of use cases of AI systems that are high-risk and not high-risk.
6. The Commission is empowered to adopt delegated acts in accordance with Article 97 in order to amend paragraph 3, second subparagraph, of this Article by adding new conditions to those laid down therein, or by modifying them, where there is concrete and reliable evidence of the existence of AI systems that fall under the scope of Annex III, but do not pose a significant risk of harm to the health, safety or fundamental rights of natural persons.
7. The Commission shall adopt delegated acts in accordance with Article 97 in order to amend paragraph 3, second subparagraph, of this Article by deleting any of the conditions laid down therein, where there is concrete and reliable evidence that this is necessary to maintain the level of protection of health, safety and fundamental rights provided for by this Regulation.
8. Any amendment to the conditions laid down in paragraph 3, second subparagraph, adopted in accordance with paragraphs 6 and 7 of this Article shall not decrease the overall level of protection of health, safety and fundamental rights provided for by this Regulation and shall ensure consistency with the delegated acts adopted pursuant to Article 7(1), and take account of market and technological developments.
Recital 50 — interpretive context
As regards AI systems that are safety components of products, or which are themselves products, falling within the scope of certain Union harmonisation legislation listed in an annex to this Regulation, it is appropriate to classify them as high-risk under this Regulation if the product concerned undergoes the conformity assessment procedure with a third-party conformity assessment body pursuant to that relevant…
Recital 53 — interpretive context
It is also important to clarify that there may be specific cases in which AI systems referred to in pre-defined areas specified in this Regulation do not lead to a significant risk of harm to the legal interests protected under those areas because they do not materially influence the decision-making or do not harm those interests substantially. For the purposes of this Regulation, an AI system that does not…
Commonly misquoted
What gets said
Title IV of the AI Act sets out the high-risk obligations.
What the provision says
The adopted Regulation has no Title IV. It is organized in Chapters: the classification rules for high-risk systems are Chapter III, Section 1, the requirements are Chapter III, Section 2, and the obligations of providers and deployers are Chapter III, Section 3. A reference to a Title belongs to the Commission proposal that preceded this text, and its numbering does not map onto the articles you are reading here.
Scenarios that touch this provision
A CV-screening feature in your product
Illustrative
You are about to ship a feature that ranks and filters job applications for the companies that use your hiring product.
- Your role
- ProviderDeployer
- Where it lands
- High risk 2 Dec 2027
- Decided by
- Annex III, point 4(a): systems intended to be used for the recruitment or selection of natural persons, in particular to analyse and filter job applications and to evaluate candidates.
What applies
- Risk management system
- Data and data governance
- Technical documentation
- Automatic recording of events
- Transparency and instructions for deployers
- Human oversight
- Accuracy, robustness and cybersecurity
- Conformity assessment
- EU declaration of conformity and CE marking
- Registration in the EU database
- Keeping the automatically generated logs
- Post-market monitoring
- Serious incident reporting
What you have to be able to produce
- Adversarial and injection test suite
- Annex IV technical file
- Authority notification runbook
- Bias examination report
- Conformity route decision per system
- Dataset cards with provenance
- Decision-correlation IDs across services
- Declared accuracy levels and metrics
- Doc generation wired into CI
- Documentation format decision on record
- Escalation path for emergent risk
- EU declaration of conformity per system
- Field-data review cadence
- Field-risk signal feed into the register
- Foreseeable-misuse analysis per release
- Incident classification with regulatory branch
- Inference event schema
- Instructions for use per system
- Kill switch and override, with tests
- Living risk register with review cadence
- Model performance SLOs with alerts
- Named reporting roles
- Output metadata deployers can read
- Oversight runbook
- Oversight UX with override path
- Per-run lineage records
- Post-market monitoring plan
- Registration entries per system
- Replay runbook
- Representativeness note for the target population
- Resource, lifetime and maintenance inputs for the instructions
- Restore test on aged logs
- Retention budget and DPO sign-off
- Retention policy meeting the six-month floor
- Risk-to-control mapping in the design docs
- Stated assumptions per data set
- Tamper-evident log storage
- Versioned field telemetry
What would change the answer
- The Article 6(3) derogation is the only way out, and a system that performs profiling of natural persons never qualifies. Ranking candidates is hard to argue as a narrow procedural task.
- Your customers are deployers of this system and carry Article 26 duties, including keeping the logs under their control and telling candidates they are subject to it.
- A customer who puts its own brand on your feature becomes its provider under Article 25(1)(a), and you stop being it.
A product recommender in your storefront
Illustrative
A model ranks what each visitor sees, trained on browsing and purchase history.
- Your role
- ProviderDeployer
- Where it lands
- Not classified In force 2 Feb 2025
- Decided by
- Ranking products is not an Annex III use case and not a safety component. What the system infers about people is what to watch.
What applies
What you have to be able to produce
- Onboarding notes for AI-touching roles
- Team enablement plan for people operating AI systems
What would change the answer
- Price or risk-assess life and health insurance with it and Annex III point 5(c) applies; score creditworthiness and point 5(b) does.
- Article 5 prohibits certain manipulative and exploitative practices outright. A recommender tuned to exploit the vulnerabilities of a specific group is a different object from one tuned to relevance.
- Profiling turns the Article 6(3) escape hatch off for any Annex III system, so it matters what the model infers, not only what it displays.
A RAG assistant over internal documents, on a vendor model
Illustrative
You wrapped a vendor model in a retrieval layer over your own wiki and runbooks, and put it in front of your own staff. Nobody outside the company can reach it.
- Your role
- ProviderDeployer
- Where it lands
- Not classified In force 2 Feb 2025
- Decided by
- No Annex III use case, and not a safety component under Article 6(1). Putting a system into service for your own use still makes you its provider under Article 3(11).
What you have to be able to produce
- Disclosure pattern in the design system
- Onboarding notes for AI-touching roles
- Reusable disclosure component
- Team enablement plan for people operating AI systems
What would change the answer
- Point it at a decision the Act lists. The moment it screens candidates or scores people, Annex III applies and the answer changes completely.
- Article 50(1) asks you to tell people they are interacting with an AI system unless that is obvious. For an internal assistant behind a login it usually is; write down why you concluded that.
- Fine-tune the vendor model and you may become the provider of the modified model, with Chapter V duties for it.
If you would rather not read the law
The basics page explains the Regulation's own categories in order: scope, role, tier, date. The engineering view groups the obligations by the platform capability they demand.