← Course outline
Aavistus Training · ai-act · AIA.03

High-risk classification

What you'll learn

When an AI system is high-risk: the two routes (safety component of an Annex I product vs an Annex III use case); the Article 6(3) filter for systems not posing significant risk and its documentation duty; Commission power to amend Annex III.

Regulation — cited to the current EU text

Overview

The AI Act draws a sharp distinction between high-risk and non-high-risk AI systems. Article 6 establishes two independent routes to high-risk classification, and Article 6(3) narrows the second route with a filter that providers must actively apply and document before market placement 32024R1689 Article 6@2024-06-13.

Route 1 — Safety component of an Annex I product

An AI system is high-risk under Route 1 when two cumulative conditions are both satisfied. First, the system must be intended to be used as a safety component of a product, or must itself be a product, covered by the Union harmonisation legislation listed in Annex I 32024R1689 Article 6@2024-06-13. Second, that product must be required to undergo a third-party conformity assessment before it is placed on the market or put into service under the applicable Annex I legislation 32024R1689 Article 6@2024-06-13. Both conditions must be met; satisfying only one is not sufficient.

Annex I groups the covered legislation into two sections. Section A lists New Legislative Framework instruments, including the Machinery Directive, the Toy Safety Directive, the medical devices regulation (EU) 2017/745, the in vitro diagnostic medical devices regulation (EU) 2017/746, and the personal protective equipment regulation (EU) 2016/425, among others 32024R1689 Annex I@2024-06-13. Section B covers further harmonisation legislation including civil aviation security, motor vehicle type-approval, marine equipment, and rail interoperability 32024R1689 Annex I@2024-06-13. Whether the third-party assessment requirement under condition (b) is triggered is determined by those sector-specific instruments, not by the AI Act itself.

Route 2 — Listed Annex III use case

Independently of Route 1, an AI system is considered high-risk if it falls within one of the areas and use cases enumerated in Annex III 32024R1689 Article 6@2024-06-13. Annex III covers eight areas: biometrics (remote biometric identification, categorisation according to sensitive or protected attributes or characteristics based on the inference of those attributes or characteristics, and emotion recognition); safety components in the management and operation of critical digital infrastructure, road traffic, and utilities; education and vocational training (access and admission decisions, learning outcome evaluation, level-of-education assessment, and exam-monitoring systems); employment and workers' management (recruitment and selection, decisions affecting terms of work, task allocation, and performance monitoring); access to essential private and public services (eligibility for public benefits, creditworthiness assessment, life and health insurance pricing, and emergency call triage); law enforcement (risk-of-victimisation assessment, polygraph-type tools, evidence reliability evaluation, re-offending risk assessment, and profiling); migration, asylum and border control; and administration of justice and democratic processes, including systems intended to influence elections or voting behaviour 32024R1689 Annex III@2024-06-13.

The Article 6(3) filter — when an Annex III system escapes high-risk status

Article 6(3) creates a derogation from Route 2. An Annex III system is not considered high-risk where it does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision making 32024R1689 Article 6@2024-06-13. The derogation is available when any one of four conditions is fulfilled: the system is intended to perform a narrow procedural task; it is intended to improve the result of a previously completed human activity; it is intended to detect decision-making patterns or deviations from prior decision-making patterns without being designed to replace or influence a previously completed human assessment without proper human review; or it is intended to perform a preparatory task to an assessment relevant to an Annex III use case 32024R1689 Article 6@2024-06-13.

The derogation contains a hard override: an Annex III system that performs profiling of natural persons is always considered high-risk, regardless of which filter conditions might otherwise apply 32024R1689 Article 6@2024-06-13.

Documentation duty

A provider that concludes an Annex III system is not high-risk must document that assessment before the system is placed on the market or put into service. That provider remains subject to the registration obligation in Article 49(2), and must supply the documentation to national competent authorities on request 32024R1689 Article 6@2024-06-13. The filter therefore does not eliminate regulatory accountability; it trades conformity assessment obligations for a documented pre-market self-assessment with ongoing availability to supervisors.

Commission powers to amend the classification

The Annex III list and the Article 6(3) filter conditions are both subject to delegated amendment. Article 7 empowers the Commission to add or modify Annex III entries where proposed systems are intended for Annex III areas and pose a risk of harm to health and safety or an adverse impact on fundamental rights equivalent to or greater than that posed by systems already listed 32024R1689 Article 7@2024-06-13. When assessing equivalence, the Commission weighs criteria including the system's degree of autonomy, the reversibility of its outputs, the vulnerability of affected persons, the potential extent and intensity of harm, and whether existing Union law provides effective redress 32024R1689 Article 7@2024-06-13. Annex III entries can also be removed by delegated act where a listed system no longer poses significant risk and removal would not decrease the overall level of protection 32024R1689 Article 7@2024-06-13.

Separately, the Commission may add new conditions to, or modify, the Article 6(3) filter conditions where there is concrete and reliable evidence that certain Annex III systems do not pose significant risk, and must delete filter conditions where evidence shows deletion is necessary to maintain the protection the Regulation provides 32024R1689 Article 6@2024-06-13. Any such amendment must not decrease the overall level of protection, must remain consistent with delegated acts adopted under Article 7, and must take account of market and technological developments 32024R1689 Article 6@2024-06-13.

Your operations manual

This block connects to your organisation's own AI governance policy. In the full product it shows, cited to your policy, how YOUR organisation implements the regulation above — private to your organisation. (Demo placeholder.)

Real-world context — illustrative only

No recent cases are cached for this topic.

Check your understanding

1. Under Route 1, when is an AI system classified as high-risk?

2. A provider concludes their Annex III system meets one of the Article 6(3) filter conditions. The system also performs profiling of natural persons. What is the outcome?

3. Which piece of legislation appears in Section A (New Legislative Framework) of Annex I?

4. A provider applies the Article 6(3) filter and concludes their Annex III system is not high-risk. Which obligations remain?

5. Which criterion must the Commission weigh when deciding whether to add a new entry to Annex III under Article 7?