⭐ Star on GitHub

Summary: Two routes into the high-risk tier (product-safety components under Art 6(1), Annex III use cases under Art 6(2)), plus the Art 6(3) derogation that lets an Annex III system escape — with one hard exception.

Sources: raw/AI-regulations/Regulation - EU - 2024_1689.md (Articles 6, 7, Annex III)

Last updated: 2026-07-28


Route 1 — safety components of regulated products (Art 6(1))

A system is high-risk where both:

  • (a) it is “intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I”; and
  • (b) that product “is required to undergo a third-party conformity assessment” under that legislation.

(source: Regulation - EU - 2024_1689.md)

This route applies from 2 August 2027, a year later than the rest (Art 113(c)). See ai-act-timeline.

Route 2 — Annex III use cases (Art 6(2))

Eight areas (source: Regulation - EU - 2024_1689.md, Annex III):

  1. Biometrics (where permitted) — remote biometric identification (excluding pure verification “to confirm that a specific natural person is the person he or she claims to be”); biometric categorisation by sensitive/protected attributes; emotion recognition.
  2. Critical infrastructure — safety components in “the management and operation of critical digital infrastructure, road traffic, or in the supply of water, gas, heating or electricity.”
  3. Education and vocational training — admissions; evaluating learning outcomes; assessing appropriate level of education; “monitoring and detecting prohibited behaviour of students during tests.”
  4. Employment and worker management — recruitment and selection, “in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates”; decisions on promotion, termination, task allocation based on behaviour or traits, and performance/behaviour monitoring.
  5. Access to essential private and public services and benefits.
  6. Law enforcement · 7. Migration, asylum and border control · 8. Administration of justice and democratic processes.

The Art 6(3) derogation — and its limit

An Annex III system is not high-risk if it “does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making,” and any of these hold:

  • (a) it performs “a narrow procedural task”;
  • (b) it improves “the result of a previously completed human activity”;
  • (c) it detects decision-making patterns or deviations and is “not meant to replace or influence the previously completed human assessment, without proper human review”; or
  • (d) it performs “a preparatory task to an assessment.”

The hard exception: “Notwithstanding the first subparagraph, an AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons” (source: Regulation - EU - 2024_1689.md, Art 6(3)).

Profiling defeats the derogation unconditionally. No amount of narrowness, human review, or preparatory framing rescues a profiling system.

Self-assessment carries an audit trail

Art 6(4): a provider claiming the derogation “shall document its assessment before that system is placed on the market or put into service,” is still subject to the registration obligation in Art 49(2), and must produce the documentation on request from national competent authorities.

So the derogation is not an exit from the regime — it is a documented, registered, reviewable claim. Getting it wrong is an Art 16 provider-obligation breach at the 3% / €15M tier. See enforcement-and-penalties.

Guidance that was due

Art 6(5): the Commission “shall, after consulting the… Board, and no later than 2 February 2026, provide guidelines specifying the practical implementation of this Article… together with a comprehensive list of practical examples of use cases of AI systems that are high-risk and not high-risk.”

How Annex III moves

Art 7 empowers the Commission to add, modify or remove Annex III use cases by delegated act. Additions require the risk to be “equivalent to, or greater than” existing entries, assessed against eleven criteria in Art 7(2) — including autonomy and override capability (d), demonstrated prior harm (e), dependence and inability to opt out (g), power imbalance and vulnerability (h), and reversibility, where the text states that outcomes adversely affecting health, safety or fundamental rights “shall not be considered to be easily corrigible or reversible” (i).

Removal requires that the system “no longer poses any significant risks” and that deletion “does not decrease the overall level of protection” (Art 7(3)). Art 6(8) applies the same ratchet to the derogation conditions. The Act is designed so amendments cannot lower protection.

Worked sector example — employment

Annex III(4) makes most HR AI high-risk. A staffing-sector analysis reads this as covering “recruitment, selection, targeted job advertising, candidate evaluation, performance monitoring, and certain decisions about compliance, contract terms or termination,” with both providers and deployers in scope, requiring “mandatory risk assessments, technical documentation, bias testing, human oversight, transparency disclosures, and continuous monitoring” from 2 August 2026 (source: raw/Laws/What the EU AI Act Means for Staffing Businesses...md). See High-risk AI in employment.