How do you classify your AI system under the EU AI Act?
Updated 9 August 2026 for Regulation (EU) 2026/1744.
Work out which tier your AI system falls in by going through five checks in a fixed order, writing down the answer at each one. The order is not a preference: an earlier check can settle the question and stop the later ones from applying. Rule out the Article 5 prohibitions, check the Article 6(1) product-safety route, check Annex III under Article 6(2), test the Article 6(3) exemption, then apply Article 50 transparency — and document the conclusion at every step.
Before step one, settle the prior question: whether the thing is an AI system at all under Article 3, point (1), and how many systems you are holding. What counts as an AI system is where that test is set out.
Quick answer
- Run Article 5 first. A prohibited practice cannot be classified into compliance — the capability has to go.
- Two routes lead to high-risk: Article 6(1) for safety components of Annex I regulated products, and Article 6(2) for the Annex III use cases.
- Article 6(3) can take an Annex III system out of high-risk — four exhaustive conditions, all voided by profiling of natural persons.
- The exemption is not informal. Article 6(4) requires a documented assessment before market placement, plus Article 49(2) registration.
- Write the reasoning down at every tier. Under Article 80 an authority can re-evaluate a "not high-risk" call — the documentation is your answer.
Is the practice prohibited under Article 5?
Before any risk tier, check the ten practices Article 5(1) bans outright. Eight have applied since 2 February 2025 under Article 113, third paragraph, point (a); points (ba) and (bb), inserted by Regulation (EU) 2026/1744 and read with the new Article 5(1a) (both points) and 5(1b) (point (ba) only), apply from 2 December 2026 (Article 113, third paragraph, point (a), as amended). If one catches your system, stop: no conformity route, exemption or registration makes it lawful. See which AI practices are prohibited.
Is it a product — or the safety component of one — under Article 6(1)?
Article 6(1) classifies a system as high-risk where both conditions hold: the AI system "is intended to be used as a safety component of a product, or the AI system is itself a product" covered by the Union harmonisation legislation listed in Annex I, and that product "is required to undergo a third-party conformity assessment" under that same legislation. Annex I covers product-safety law — machinery, toys, lifts and medical devices among it. The device route is worked through in is healthcare AI high-risk.
Both limbs must be met — a safety component whose product only needs self-assessment is not caught. Regulation (EU) 2026/1744 narrowed both. Article 6(1a) takes out of "safety component" AI systems "solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control"; Article 6(1b) then provides that, notwithstanding 6(1a), systems "the failure or malfunctioning of which would endanger health and safety" do qualify. Article 6(1c) defeats the second limb where the product needs third-party assessment "solely due to risks other than risks to health and safety", naming radio-spectrum and electromagnetic-interference risks that do not affect health and safety.
Timing: Chapter III, Sections 1, 2 and 3 apply to Article 6(1) and Annex I systems from 2 August 2028 (Article 113, third paragraph, point (c), as amended by Regulation (EU) 2026/1744) — every date is in the full timeline.
Does it fall under an Annex III use case (Article 6(2))?
If Article 6(1) doesn't apply, check Annex III. Under Article 6(2), the AI systems referred to in Annex III "shall be considered to be high-risk." Annex III lists eight areas: biometrics; critical infrastructure; education and vocational training; employment, workers' management and access to self-employment; access to and enjoyment of essential private services and essential public services and benefits (including credit scoring and life and health insurance pricing); law enforcement; migration, asylum and border control management; and the administration of justice and democratic processes.
The match happens at specific points and letters, not area headings — "we do something with employment data" is not a classification; "we analyse and filter job applications, point 4(a) of Annex III" is. Read the exact wording, including carve-outs — biometric verification (point 1(a)) and, within credit scoring, financial-fraud detection (point 5(b)) are expressly excluded. These obligations apply from 2 December 2027 (Article 113, third paragraph, point (c), as amended) — see what high-risk status triggers.
When we built our own deterministic classifier against the source text, the first version over-classified identity verification: every biometric function landed in point 1(a) of Annex III until we modelled its exclusion — point 1(a) expressly does not cover biometric verification whose sole purpose is confirming that a person is who they claim to be. Read what that exclusion does and does not do: it takes the system out of point 1(a), not out of Annex III and not out of high-risk. The same tool can still be caught by another point — biometric categorisation, emotion recognition, or a use in an employment flow — or by Article 6(1) as a safety component. The miss ran the other way on profiling: an Annex III system that performs profiling is always high-risk, and that override is the easiest thing to drop when summarising Article 6(3) — our own drafts dropped it twice before verification caught it.
Can you use the Article 6(3) exemption?
Article 6(3) is a derogation from Article 6(2): an Annex III system "shall not be considered to be high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making." That test is gated — it applies only where one of four exhaustive conditions in the second subparagraph is fulfilled — and it is voided outright where the system "performs profiling of natural persons", whichever condition you rely on.
Claiming it is not informal. Article 6(4) requires a documented assessment before market placement, Article 49(2) requires registration in the EU database, and Article 80 gives market surveillance authorities a dedicated procedure to overturn the call, with fines under Article 99 attached. The four conditions one by one, the profiling override, and what the 2026 amendment changed about the registration — and what it deliberately left alone — are in the Article 6(3) exemption in full.
What applies below the high-risk tier?
Article 50 transparency. Whatever the tier: systems that interact directly with people must disclose that (Article 50(1)); providers of systems generating synthetic audio, image, video or text must mark outputs as artificially generated in a machine-readable way (Article 50(2)); deployers of emotion recognition or biometric categorisation systems must inform exposed persons (Article 50(3)); and deep fakes must be disclosed (Article 50(4)). Under Article 50(6) these duties do not affect Chapter III — Article 50 is a layer, not an alternative classification, so a high-risk chatbot carries both sets.
Minimal risk. The Act never defines a "minimal risk" category — it is the residual: not prohibited, not high-risk on either route, no Article 50 trigger. No article obliges you to document that conclusion; record it anyway, with the provisions you checked and why each came out negative — the cheapest artefact in your compliance file. What minimal risk does and does not require is its own guide.
None of this classifies a general-purpose AI model: models follow their own track under Article 51, with systemic risk presumed above 10^25 training FLOPs (Article 51(2)) — see GPAI obligations.
What this means for you
If you're a provider: Classification is your call and your liability, per system and per intended purpose. Run the five steps in order and produce the artefact each tier demands: removal for Article 5, conformity work for high-risk, the Article 6(4) assessment and Article 49(2) registration for an exemption, a recorded negative for minimal risk. Complipath's guided risk classification returns the risk level with the provisions and reasoning it rests on, so the artefact exists the moment the call is made.
If you're a deployer: Verify the provider's classification before deployment — your obligations flow from it, and your intended use can differ from the provider's. Where a vendor claims an Annex III system is exempt, ask for the Article 6(4) assessment. Who counts as provider and who as deployer determines which duties are yours.
Run it on a system of yours
Classify your system now — 7 questions on the main line, plus follow-ups where they apply, no account, and the classification runs in your browser: answers stay there unless you choose to keep the result.
FAQ
Can I just decide my Annex III system is not high-risk? No. Article 6(3) only applies through one of its four conditions, never where the system profiles natural persons, and Article 6(4) requires you to document the assessment and register under Article 49(2) before market placement. Article 80(7) attaches fines to misclassification aimed at circumventing the requirements.
Does profiling always make an AI system high-risk? Within Annex III, yes: Article 6(3) states that an Annex III system is "always" high-risk where it performs profiling of natural persons, so the exemption never applies. Outside Annex III, profiling alone does not classify a system — though GDPR rules on profiling still apply independently.
When do the classification rules start to apply? Eight Article 5 prohibitions have applied since 2 February 2025; points (ba) and (bb) apply from 2 December 2026. Annex III high-risk obligations apply from 2 December 2027 and Article 6(1) product-safety ones from 2 August 2028 (Article 113, third paragraph, points (a) and (c), as amended by Regulation (EU) 2026/1744).
Is Article 50 transparency a separate risk class? Not really. Article 50 imposes disclosure and marking duties on specific system types — chatbots, synthetic content, emotion recognition, deep fakes — whatever their tier. Article 50(6) says these duties do not affect Chapter III, so a high-risk system with a conversational interface carries both sets of obligations.
Sources: Regulation (EU) 2024/1689 (EUR-Lex), Articles 5, 6, 49, 50, 51, 80 and 113, and Annexes I, III and VIII, as amended by Regulation (EU) 2026/1744 (EUR-Lex) — in force 27 July 2026 — which inserted Article 5(1), first subparagraph, points (ba) and (bb), Article 5(1a) and (1b) and Article 6(1a), (1b) and (1c), replaced Article 113, third paragraph, points (a) and (c), and moved the Machinery legislation from point 1 of Section A of Annex I (Directive 2006/42/EC, deleted) to point 21 of Section B (Regulation (EU) 2023/1230). That move has a consequence this guide does not yet work through: under Article 2(2), as also replaced by Regulation (EU) 2026/1744, "for AI systems classified as high-risk AI systems in accordance with Article 6(1) related to products covered by the Union harmonisation legislation listed in Section B of Annex I, only Article 6(1), Article 60a and Articles 102 to 112 shall apply" — so an AI safety component of machinery is still high-risk under Article 6(1) but carries a reduced obligation set. The Article 6(5) Commission guidelines were due by 2 February 2026 and are not in our source corpus as of 12 August 2026 — verify their publication status and content before relying on an Article 6(3) exemption.