---
title: "High-risk AI systems: how to read Article 6 of the AI Act"
url: https://zerofive.ai/en/blog/compliance/high-risk-ai-systems-article-6-ai-act
canonical: https://zerofive.ai/en/blog/compliance/high-risk-ai-systems-article-6-ai-act
language: en
published: 2026-09-28
updated: 2026-09-28
author: "ZeroFive.AI"
tags: AI Act, high-risk AI, Article 6, Digital Omnibus, ISO IEC 42001
abstract: "Annex I, Annex III, Article 6(3) exceptions and obligations for providers and deployers: how to classify AI systems before 2 December 2027."
---

# High-risk AI systems: how to read Article 6 of the AI Act

**In short.** An AI system becomes high-risk through one of two routes: as a safety component of a product regulated under Annex I, or because its intended purpose falls within one of the eight areas listed in Annex III. The Digital Omnibus has moved the obligations to 2 December 2027 and 2 August 2028, but classification has to happen now, because it determines the cost, contracts and architecture of projects already under way.

On 19 May 2026 the European Commission published its draft guidelines on the classification of high-risk artificial intelligence systems, required by Article 6(5) of Regulation (EU) 2024/1689. They were due by 2 February, arrived more than three months late, the stakeholder consultation closed over the summer and the final version is expected by the end of 2026. In the meantime the Digital Omnibus, published as Regulation (EU) 2026/1744 on 24 July, has reshaped the timeline: obligations for the systems listed in Annex III apply from 2 December 2027, those for AI embedded in the regulated products of Annex I from 2 August 2028.

These weeks the topic is everywhere, in webinars, posts and checklists, and the reaction we see most often in companies is a kind of relief, because fourteen months feel like a lot. In my view that reading is dangerous.

The classification of an AI system decides how much it costs to build, how the contract with the vendor has to be written, which documentation must be produced while the project takes shape, and who in the company has to sign off. The Artificial Intelligence Observatory of Politecnico di Milano, in research presented in February 2026, found that 71% of large Italian companies have active AI projects and only 9% have structured governance: that gap is full of systems nobody has classified yet, and that someone will have to classify in a hurry a year from now.

## The two routes of Article 6

Article 6 opens two separate doors into high-risk status, and mixing them up is the most common mistake.

The first, in paragraph 1, covers AI systems that are themselves a product, or a safety component of a product, covered by the EU harmonisation legislation listed in Annex I, provided that product has to undergo a third-party conformity assessment. The second, in paragraph 2, covers systems whose intended purpose falls within one of the use cases in Annex III, regardless of the product they run in.

These are two different logics. The first reasons about the product and physical safety, inherits the language of the New Legislative Framework and plugs into certification processes that makers of machinery or medical devices have known for years. The second reasons about use and fundamental rights, and reaches companies that have never thought of themselves as "regulated", such as those hiring staff or assessing creditworthiness.

In both cases the decisive variable is the intended purpose, meaning the use the provider declares in its documentation, instructions and commercial material. The draft guidelines insist on this point: the purpose must be described consistently across all documents, and a system presented as general-purpose in the technical sheet but sold for candidate screening on the website will be judged by what it does.

## The regulated products of Annex I

For AI embedded in products, the first question is technical before it is legal. Annex I lists the relevant product legislation: machinery, toys, radio equipment, medical and in vitro diagnostic devices, lifts, pressure equipment, vehicles, civil aviation and more. If the product falls under one of these regimes and requires a notified body, the next step is to establish whether the AI system performs a safety function or whether its failure could endanger the health or safety of people, following the definition of safety component in Article 3(14).

The guidelines make clear that what counts is the function, not the way the AI is delivered: a vision module that stops a press when it detects a hand in the working area is a safety component whether it runs on the machine or arrives as a cloud service. For manufacturers, and Italian industry is full of increasingly intelligent machines, this means classification belongs inside the product's technical file, handled by the same people who manage CE marking today.

## The eight areas of Annex III

Annex III is the list that matters to most service companies. There are eight areas:

- biometrics, including remote identification and emotion recognition where permitted;
- critical infrastructure, such as the management of water, gas, electricity and traffic networks;
- education and vocational training, from admission to the assessment of learning outcomes;
- employment and workers management, from recruitment to decisions on promotion, termination and task allocation;
- access to essential public and private services, including creditworthiness assessment and pricing in life and health insurance;
- law enforcement;
- migration, asylum and border control;
- administration of justice and democratic processes.

Anyone working in a bank, an insurer or an HR department sits inside this list even without building anything in-house, because obligations follow the system along the value chain and fall partly on whoever uses it. The Commission's draft adds a clarification many companies had not anticipated: a system that materially shapes an employment decision stays high-risk even if a person has the final word, because human oversight is an Article 14 obligation and not an exit from classification.

## The exceptions of Article 6(3)

This is where the most heated discussions with market surveillance authorities will concentrate. A system that falls within Annex III may not be considered high-risk if it does not materially influence the outcome of decisions, and Article 6(3) sets out four alternative conditions, so meeting one is enough:

- the system performs a narrow procedural task, such as sorting incoming documents;
- it improves the result of a previously completed human activity, for example by polishing the wording of a text written by a person;
- it detects decision-making patterns or deviations from prior decisions, without replacing human assessment;
- it performs a preparatory task for an assessment that remains human.

With one limit that leaves no room for interpretation: if the system profiles natural persons, none of the four conditions can save it.

Anyone relying on the exception must document the assessment before placing the system on the market and make it available to authorities on request, so the derogation is an active, signed choice that someone must be able to defend. The guidelines also close the architectural shortcut: when several components, possibly separate agents, jointly contribute to a decision within Annex III, the overall configuration is treated as a single system, and splitting the workflow into pieces that look harmless on their own does not change the outcome.

## Obligations for providers and deployers

Once a system is classified as high-risk, the provider carries most of the load. It must set up a risk management system across the whole lifecycle, govern the quality of training, validation and test data, produce technical documentation, ensure automatic event logging, supply understandable instructions for use, design human oversight, and guarantee appropriate levels of accuracy, robustness and cybersecurity. On top of that come a quality management system, conformity assessment with CE marking, registration in the EU database, post-market monitoring and the reporting of serious incidents.

The deployer, meaning the company that uses the system in its own activity, has lighter obligations that are anything but formal. Article 26 requires it to use the system according to the instructions, to assign oversight to people with adequate competence and authority, to check the relevance of the input data under its control, to monitor operation, to keep automatically generated logs for at least six months and to inform workers when the system is used in the workplace. For public bodies, private entities providing public services, and those using creditworthiness assessment or life and health insurance pricing systems, Article 27 adds the fundamental rights impact assessment.

Article 25 provides that a deployer becomes a provider, with all the related obligations, if it substantially modifies a high-risk system, changes its intended purpose so that it becomes high-risk, or places it on the market under its own name. A company that takes a general model and configures it to screen CVs for its clients is crossing that line, often without noticing.

## Classification as a governance decision

Faced with this list, many companies are tempted to treat the whole thing as a legal problem to delegate. That is understandable, and a legal opinion on a borderline case is genuinely useful, but classification starts earlier, at the moment someone in the company defines a system's purpose, chooses a vendor, designs a workflow. Whoever goes to their lawyer with an empty inventory will get an opinion on a hypothesis.

The work we see missing almost everywhere sits upstream: a register of the AI systems in use and in development, recording for each one the declared intended purpose, the company's role (provider, deployer, or both), the Article 6 route that might apply and, where an exception is invoked, the written rationale and the name of whoever approved it. It is the same kind of discipline ISO/IEC 42001 requires for an AI management system, and it is what our AI Rating measures in the Risk dimension, with a gate that cannot be offset by high scores elsewhere: a company that does not know which systems it has cannot be mature on AI, whatever the quality of its models.

The Digital Omnibus timeline leaves time to build documentation, testing, contracts and oversight processes, provided classification is done now. Those who postpone it to 2027 will be classifying systems already in production, with contracts already signed and architectures already fixed, and at that point every uncomfortable answer costs twice as much. The Commission's draft will be revised, examples will change, some interpretations will shift. A register started today will be ready to absorb the final version, and it will tell the company how many of its "support tools" are in fact systems that steer decisions about people.
