COMPLIPATHDOC complipath.io/guides/ai-act-article-6-3-exemptionRENDERED 2026-08-23ENGINE 2026-08-09.1CORPUS 2024/1689 + 2026/1744 + Commission guidelines
Guides/Risk classification ·By Yobel Tzegai ·Updated 22 August 2026

Can an Annex III AI system be exempt from high-risk under Article 6(3)?

Updated 9 August 2026 for Regulation (EU) 2026/1744.

An Annex III system can escape high-risk under Article 6(3), but only through one of four exhaustive conditions, and never where the system profiles natural persons. The exemption is not a judgement you keep to yourself: Article 6(4) requires a documented assessment before market placement, and Article 49(2) requires registration in the EU database.

Quick answer

What does Article 6(3) actually say?

Two sentences that have to be read together. The first is the general test: "By derogation from paragraph 2, an AI system referred to in Annex III shall not be considered to be high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making."

The second stops that test from standing on its own: "The first subparagraph shall apply where any of the following conditions is fulfilled".

So the general test is not a free-standing "is this risky?" question. It is gated. A system can be genuinely harmless and still fail Article 6(3), because none of the four conditions describes what it does. That misreading runs in the direction that costs money: a provider who reasons only about risk concludes exemption, and skips conformity work the Regulation still requires.

Which of the four conditions can you rely on?

They are exhaustive, and "any" means one is enough. The AI system is intended to:

Read (c) with its trailing qualifier attached, because the qualifier does the work: the system must not be meant to replace or influence the earlier human assessment without proper human review. Detection feeding a reviewed process is inside the condition; detection that displaces the review is not.

The Regulation defines none of "narrow", "procedural" or "preparatory". When we encoded Article 6(3) into a deterministic classifier, those were the terms we could not automate — whether a task is narrow procedural or preparatory is a judgement about the workflow around the system, not a property of the system. Our engine asks the human and records the answer rather than deciding, because a recorded judgement is defensible and a silent inference is not.

When does profiling take the exemption off the table?

Always, and regardless of which condition you satisfy: "Notwithstanding the first subparagraph, an AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons."

This is an override, not a fifth condition, and it is the limb most often lost when the provision is summarised — our own drafts dropped it twice before verification caught it. A summary listing four conditions and omitting the override is accurate about everything it kept and silent about the thing that decides the case.

Profiling takes its GDPR meaning: Article 3, point (52) of the AI Act points to Article 4, point (4), of Regulation (EU) 2016/679. Where that definition is met, the exemption is unavailable however narrow the task — see how the AI Act and GDPR differ.

What must you document and register?

Article 6(4) attaches three duties to the claim itself. The provider "shall document its assessment before that system is placed on the market or put into service"; "shall be subject to the registration obligation set out in Article 49(2)"; and "upon request of national competent authorities, the provider shall provide the documentation of the assessment".

Registration under Article 49(2) goes into the EU database referred to in Article 71, before placing on the market or putting into service. What you file is set by Section B of Annex VIII — and it got shorter in 2026. Point 6 still requires the condition or conditions under Article 6(3) "based on which the AI system is considered to be not-high-risk". Point 7, which required "a short summary of the grounds", and point 9, which required the Member States concerned, were both deleted by Regulation (EU) 2026/1744, Article 1, point (42).

Note what the deletion did and did not do. It simplified the filing. It did not touch Article 6(4), so the assessment you write, keep and hand over on request is unchanged — the recital accompanying the amendment says a provider applying Article 6(3) "remains obligated to document its assessment". A shorter form is not a lighter duty.

The two duties do not share a date, and this is where most readers will get it wrong. Article 6 sits in Chapter III, Section 1, so the Article 6(4) assessment follows the deferred dates — 2 December 2027 for the Annex III route under Article 113, third paragraph, point (c)(i). Article 49 sits in Section 5, which point (c) does not defer: it lists "Chapter III, Sections 1, 2, and 3" and stops there. Section 5 therefore keeps the general date in Article 113, second paragraph — 2 August 2026 — so the Article 49(2) registration duty is already in application. How a registration duty operates while the classification rules that decide its scope do not yet apply is not answered anywhere in the text. Say so to your counsel rather than assuming either date covers both; the full timeline carries them separately.

What happens if an authority disagrees?

Article 80 exists for this and nothing else. Where a market surveillance authority "has sufficient reason to consider" that a system classified as non-high-risk under Article 6(3) is in fact high-risk, it evaluates the classification "based on the conditions set out in Article 6(3) and the Commission guidelines".

Fines attach at two separate points, worth telling apart. Under Article 80(4), a provider who does not bring the system into compliance within the period the authority prescribes is subject to fines under Article 99 — failure to remediate, requiring no finding about motive. Under Article 80(7), fines follow where the authority establishes the system "was misclassified by the provider as non-high-risk in order to circumvent the application of requirements in Chapter III, Section 2" — that one is about intent. A contemporaneous, registered assessment keeps a borderline call in the first category rather than the second.

The guidelines Article 80(1) measures you against are the ones Article 6(5) required the Commission to provide "no later than 2 February 2026", with "a comprehensive list of practical examples of use cases of AI systems that are high-risk and not high-risk". Whether they have been published, and what they say, cannot be answered from the Regulation's text — this guide is written from that text alone. Check their status before relying on the exemption, because they are half of the standard an authority will apply.

What this means for you

If you're a provider: Work in the order the provision is written — condition first, then the risk test, then the profiling override as a veto over both. Write the assessment before market placement, not after an authority asks: Article 6(4) fixes the timing, and a reconstruction dated later is worth less than a thin note dated correctly. Register under Article 49(2) even though the form is now shorter. Complipath's guided risk classification returns the risk level with the provisions and reasoning behind it, so the Article 6(4) artefact exists the moment the call is made.

If you're a deployer: A vendor's exemption claim is a claim, and your obligations depend on whether it holds. Ask for the Article 6(4) assessment and check which condition it names. For most systems point 6 of Section B of Annex VIII puts that condition on the public record anyway — but not for systems under points 1, 6 and 7 of Annex III, where Article 49(4) files the registration in "a secure non-public section of the EU database" and its point (b) admits only Section B "points 1 to 5, and points 8 and 9", leaving point 6 out. If your intended use differs from the provider's, the classification may not survive the difference; who counts as provider and who as deployer decides whose problem that is, and the decision tree walks the routes in order.

Can your listed system claim the exemption?

Classify your system now — 7 questions on the main line, plus follow-ups where they apply, no account, and the classification runs in your browser: answers stay there unless you choose to keep the result.

FAQ

Is Article 6(3) available to systems outside Annex III? No. It is a derogation from Article 6(2), which is the Annex III route, so it only reaches systems Annex III has already caught. A system high-risk under Article 6(1) as a safety component of an Annex I product cannot use it, and a system outside both routes never needed it.

Does a low-risk system automatically qualify? No, and this is the common error. The general test in the first subparagraph applies only where one of the four conditions in the second subparagraph is fulfilled. A system that poses no significant risk of harm but matches none of the four conditions stays high-risk.

Does the 2026 amendment make the exemption easier to claim? It makes the filing shorter, not the claim easier. Regulation (EU) 2026/1744 deleted points 7 and 9 of Section B of Annex VIII, so the registration no longer carries a summary of grounds or the Member States. Article 6(3) and Article 6(4) are untouched — the conditions and the documented assessment are exactly as before.

What if we profile only some users? Article 6(3) says an Annex III system is "always" high-risk where it performs profiling of natural persons, with no threshold and no proportion attached. If profiling within the GDPR definition is part of what the system does, the exemption is unavailable; the provision offers no partial route.


Sources: Regulation (EU) 2024/1689 (EUR-Lex), Articles 3, 6, 49, 71, 80, 99 and 113, and Annexes III and VIII, as amended by Regulation (EU) 2026/1744 (EUR-Lex) — in force 27 July 2026 — which deleted points 7 and 9 of Section B of Annex VIII (Article 1, point (42)) and replaced Article 113, third paragraph, point (c) (Article 1, point (40)). Article 6(3), Article 6(4) and Article 49(2) were not amended. The Commission guidelines required by Article 6(5) no later than 2 February 2026 — not in our source corpus as of 12 August 2026; verify their publication status before relying, and Article 80(1) makes them half the standard against which an authority evaluates an exemption. The Regulation defines none of "narrow procedural task", "preparatory task" or "significant risk of harm", and no case law interprets them.

← All guides
Complipath

Complipath is EU AI Act compliance software for AI-heavy software companies without a compliance team — an AI system register, deterministic risk classification, the obligations that follow, and the evidence behind every decision.

Complipath is built by Yobel Tzegai in Gothenburg, Sweden.

Complipath provides legal information, not legal advice. Every guide cites its source on EUR-Lex — Regulation (EU) 2024/1689, and Regulation (EU) 2026/1744 where that has amended it; where the law is still settling, the guide says so.

We measure page views with Vercel Web Analytics. It uses no third-party cookies. Visitors are identified by a hash derived from the incoming request, which is discarded after 24 hours, and no identifier is stored that could follow a visitor to another site. What is collected: the time of the visit, the URL, the referring page, filtered query parameters, city-level location, operating system, browser and device type.