COMPLIPATHDOC complipath.io/guides/classify-ai-system-eu-ai-actRENDERED 2026-08-23ENGINE 2026-08-09.1CORPUS 2024/1689 + 2026/1744 + Commission guidelines
Guides/Risk classification ·By Yobel Tzegai ·Updated 23 August 2026

How do you classify your AI system under the EU AI Act?

Updated 9 August 2026 for Regulation (EU) 2026/1744.

Work out which tier your AI system falls in by going through five checks in a fixed order, writing down the answer at each one. The order is not a preference: an earlier check can settle the question and stop the later ones from applying. Rule out the Article 5 prohibitions, check the Article 6(1) product-safety route, check Annex III under Article 6(2), test the Article 6(3) exemption, then apply Article 50 transparency — and document the conclusion at every step.

Before step one, settle the prior question: whether the thing is an AI system at all under Article 3, point (1), and how many systems you are holding. What counts as an AI system is where that test is set out.

Quick answer

Is the practice prohibited under Article 5?

Before any risk tier, check the ten practices Article 5(1) bans outright. Eight have applied since 2 February 2025 under Article 113, third paragraph, point (a); points (ba) and (bb), inserted by Regulation (EU) 2026/1744 and read with the new Article 5(1a) (both points) and 5(1b) (point (ba) only), apply from 2 December 2026 (Article 113, third paragraph, point (a), as amended). If one catches your system, stop: no conformity route, exemption or registration makes it lawful. See which AI practices are prohibited.

Is it a product — or the safety component of one — under Article 6(1)?

Article 6(1) classifies a system as high-risk where both conditions hold: the AI system "is intended to be used as a safety component of a product, or the AI system is itself a product" covered by the Union harmonisation legislation listed in Annex I, and that product "is required to undergo a third-party conformity assessment" under that same legislation. Annex I covers product-safety law — machinery, toys, lifts and medical devices among it. The device route is worked through in is healthcare AI high-risk.

Both limbs must be met — a safety component whose product only needs self-assessment is not caught. Regulation (EU) 2026/1744 narrowed both. Article 6(1a) takes out of "safety component" AI systems "solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control"; Article 6(1b) then provides that, notwithstanding 6(1a), systems "the failure or malfunctioning of which would endanger health and safety" do qualify. Article 6(1c) defeats the second limb where the product needs third-party assessment "solely due to risks other than risks to health and safety", naming radio-spectrum and electromagnetic-interference risks that do not affect health and safety.

Timing: Chapter III, Sections 1, 2 and 3 apply to Article 6(1) and Annex I systems from 2 August 2028 (Article 113, third paragraph, point (c), as amended by Regulation (EU) 2026/1744) — every date is in the full timeline.

Does it fall under an Annex III use case (Article 6(2))?

If Article 6(1) doesn't apply, check Annex III. Under Article 6(2), the AI systems referred to in Annex III "shall be considered to be high-risk." Annex III lists eight areas: biometrics; critical infrastructure; education and vocational training; employment, workers' management and access to self-employment; access to and enjoyment of essential private services and essential public services and benefits (including credit scoring and life and health insurance pricing); law enforcement; migration, asylum and border control management; and the administration of justice and democratic processes.

The match happens at specific points and letters, not area headings — "we do something with employment data" is not a classification; "we analyse and filter job applications, point 4(a) of Annex III" is. Read the exact wording, including carve-outs — biometric verification (point 1(a)) and, within credit scoring, financial-fraud detection (point 5(b)) are expressly excluded. These obligations apply from 2 December 2027 (Article 113, third paragraph, point (c), as amended) — see what high-risk status triggers.

When we built our own deterministic classifier against the source text, the first version over-classified identity verification: every biometric function landed in point 1(a) of Annex III until we modelled its exclusion — point 1(a) expressly does not cover biometric verification whose sole purpose is confirming that a person is who they claim to be. Read what that exclusion does and does not do: it takes the system out of point 1(a), not out of Annex III and not out of high-risk. The same tool can still be caught by another point — biometric categorisation, emotion recognition, or a use in an employment flow — or by Article 6(1) as a safety component. The miss ran the other way on profiling: an Annex III system that performs profiling is always high-risk, and that override is the easiest thing to drop when summarising Article 6(3) — our own drafts dropped it twice before verification caught it.

Can you use the Article 6(3) exemption?

Article 6(3) is a derogation from Article 6(2): an Annex III system "shall not be considered to be high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making." That test is gated — it applies only where one of four exhaustive conditions in the second subparagraph is fulfilled — and it is voided outright where the system "performs profiling of natural persons", whichever condition you rely on.

Claiming it is not informal. Article 6(4) requires a documented assessment before market placement, Article 49(2) requires registration in the EU database, and Article 80 gives market surveillance authorities a dedicated procedure to overturn the call, with fines under Article 99 attached. The four conditions one by one, the profiling override, and what the 2026 amendment changed about the registration — and what it deliberately left alone — are in the Article 6(3) exemption in full.

What applies below the high-risk tier?

Article 50 transparency. Whatever the tier: systems that interact directly with people must disclose that (Article 50(1)); providers of systems generating synthetic audio, image, video or text must mark outputs as artificially generated in a machine-readable way (Article 50(2)); deployers of emotion recognition or biometric categorisation systems must inform exposed persons (Article 50(3)); and deep fakes must be disclosed (Article 50(4)). Under Article 50(6) these duties do not affect Chapter III — Article 50 is a layer, not an alternative classification, so a high-risk chatbot carries both sets.

Minimal risk. The Act never defines a "minimal risk" category — it is the residual: not prohibited, not high-risk on either route, no Article 50 trigger. No article obliges you to document that conclusion; record it anyway, with the provisions you checked and why each came out negative — the cheapest artefact in your compliance file. What minimal risk does and does not require is its own guide.

None of this classifies a general-purpose AI model: models follow their own track under Article 51, with systemic risk presumed above 10^25 training FLOPs (Article 51(2)) — see GPAI obligations.

What this means for you

If you're a provider: Classification is your call and your liability, per system and per intended purpose. Run the five steps in order and produce the artefact each tier demands: removal for Article 5, conformity work for high-risk, the Article 6(4) assessment and Article 49(2) registration for an exemption, a recorded negative for minimal risk. Complipath's guided risk classification returns the risk level with the provisions and reasoning it rests on, so the artefact exists the moment the call is made.

If you're a deployer: Verify the provider's classification before deployment — your obligations flow from it, and your intended use can differ from the provider's. Where a vendor claims an Annex III system is exempt, ask for the Article 6(4) assessment. Who counts as provider and who as deployer determines which duties are yours.

Run it on a system of yours

Classify your system now — 7 questions on the main line, plus follow-ups where they apply, no account, and the classification runs in your browser: answers stay there unless you choose to keep the result.

FAQ

Can I just decide my Annex III system is not high-risk? No. Article 6(3) only applies through one of its four conditions, never where the system profiles natural persons, and Article 6(4) requires you to document the assessment and register under Article 49(2) before market placement. Article 80(7) attaches fines to misclassification aimed at circumventing the requirements.

Does profiling always make an AI system high-risk? Within Annex III, yes: Article 6(3) states that an Annex III system is "always" high-risk where it performs profiling of natural persons, so the exemption never applies. Outside Annex III, profiling alone does not classify a system — though GDPR rules on profiling still apply independently.

When do the classification rules start to apply? Eight Article 5 prohibitions have applied since 2 February 2025; points (ba) and (bb) apply from 2 December 2026. Annex III high-risk obligations apply from 2 December 2027 and Article 6(1) product-safety ones from 2 August 2028 (Article 113, third paragraph, points (a) and (c), as amended by Regulation (EU) 2026/1744).

Is Article 50 transparency a separate risk class? Not really. Article 50 imposes disclosure and marking duties on specific system types — chatbots, synthetic content, emotion recognition, deep fakes — whatever their tier. Article 50(6) says these duties do not affect Chapter III, so a high-risk system with a conversational interface carries both sets of obligations.


Sources: Regulation (EU) 2024/1689 (EUR-Lex), Articles 5, 6, 49, 50, 51, 80 and 113, and Annexes I, III and VIII, as amended by Regulation (EU) 2026/1744 (EUR-Lex) — in force 27 July 2026 — which inserted Article 5(1), first subparagraph, points (ba) and (bb), Article 5(1a) and (1b) and Article 6(1a), (1b) and (1c), replaced Article 113, third paragraph, points (a) and (c), and moved the Machinery legislation from point 1 of Section A of Annex I (Directive 2006/42/EC, deleted) to point 21 of Section B (Regulation (EU) 2023/1230). That move has a consequence this guide does not yet work through: under Article 2(2), as also replaced by Regulation (EU) 2026/1744, "for AI systems classified as high-risk AI systems in accordance with Article 6(1) related to products covered by the Union harmonisation legislation listed in Section B of Annex I, only Article 6(1), Article 60a and Articles 102 to 112 shall apply" — so an AI safety component of machinery is still high-risk under Article 6(1) but carries a reduced obligation set. The Article 6(5) Commission guidelines were due by 2 February 2026 and are not in our source corpus as of 12 August 2026 — verify their publication status and content before relying on an Article 6(3) exemption.

← All guides
Complipath

Complipath is EU AI Act compliance software for AI-heavy software companies without a compliance team — an AI system register, deterministic risk classification, the obligations that follow, and the evidence behind every decision.

Complipath is built by Yobel Tzegai in Gothenburg, Sweden.

Complipath provides legal information, not legal advice. Every guide cites its source on EUR-Lex — Regulation (EU) 2024/1689, and Regulation (EU) 2026/1744 where that has amended it; where the law is still settling, the guide says so.

We measure page views with Vercel Web Analytics. It uses no third-party cookies. Visitors are identified by a hash derived from the incoming request, which is discarded after 24 hours, and no identifier is stored that could follow a visitor to another site. What is collected: the time of the visit, the URL, the referring page, filtered query parameters, city-level location, operating system, browser and device type.