Skip to content
EU AI Regulation DecodedKnowledge Platform

Is my AI system high-risk under the EU AI Act?

A guided walk through the Article 6 classification logic — the Annex I product route, the Annex III use-case route, the listed-function test, the profiling rule and the Article 6(3) exception — ending in an indicative classification plus the documentation an auditor will expect. Answer each question to jump to your result.

🔒 Private & in-browser. Nothing you select is uploaded or stored. This is a practitioner decision aid, not legal advice and not a binding classification — Article 6 turns on your system's specific intended purpose. Use it to structure the assessment, then verify against the primary text and, for anything borderline, take qualified advice. Classifying a system is primarily the provider's responsibility (Article 16); a deployer can use this to check the status of a system it uses.

This page shows the full decision tree in sequence. With JavaScript enabled it becomes a step-by-step flow that reveals one question at a time.

Question 1 of 4 — product-safety route

Is your AI system a safety component of — or itself — a product covered by the EU product-safety laws in Annex I?

Annex I lists existing EU product legislation such as machinery, medical devices and IVDs, toys, lifts, radio equipment, personal protective equipment, and vehicles, aviation, rail and marine equipment. Article 6(1) routes AI that is a safety component of such a product, or is such a product, into high-risk where that product must undergo third-party conformity assessment.

Two Omnibus clarifications narrow this route (Art. 6(1a)–(1c), inserted by Regulation (EU) 2026/1744): AI used solely for non-safety aspects such as user assistance, performance optimisation, service efficiency, automation, convenience or quality control is not a safety component — unless its failure or malfunction would endanger health and safety (Art. 6(1b)). And a product that needs third-party assessment only for non-safety risks (for example radio-spectrum or electromagnetic-interference risks that do not affect health and safety) does not satisfy the third-party-assessment limb (Art. 6(1c)).

Question 2 of 4 — Annex III use case

Does your system's intended purpose fall within one of the eight Annex III areas — and perform a listed function within it?

Open the area that best matches your intended purpose (not merely your sector) and check whether your system performs one of the listed functions.

1. Biometrics

Remote biometric identification, biometric categorisation according to sensitive/protected attributes, and emotion recognition — in the cases not already prohibited under Article 5.

Typical in-scope uses

  • Remote identification of individuals from camera feeds
  • Biometric categorisation systems
  • Emotion-recognition systems outside the prohibited workplace/education contexts

Function test

Some biometric uses are outright prohibited under Article 5; Annex III covers the high-risk (permitted-but-regulated) remainder. Annex III does not catch every AI system in this sector — only those performing a listed function.

2. Critical infrastructure

AI used as a safety component in the management and operation of critical digital infrastructure, road traffic, or the supply of water, gas, heating and electricity.

Typical in-scope uses

  • Safety components managing electricity grid load
  • AI controlling water-supply safety systems
  • Road-traffic management safety components

Function test

Only safety components are in scope — general operational AI without a safety-critical function may fall outside. Annex III does not catch every AI system in this sector — only those performing a listed function.

3. Education & vocational training

AI determining access or admission, evaluating learning outcomes, assessing the appropriate level of education, or monitoring and detecting prohibited behaviour during tests.

Typical in-scope uses

  • Automated admissions scoring
  • AI grading of exams
  • Exam proctoring / cheating-detection systems

Function test

Covers both access decisions and assessment; proctoring that detects behaviour during tests is explicitly included. Annex III does not catch every AI system in this sector — only those performing a listed function.

4. Employment & worker management

AI for recruitment or selection (targeting, screening, evaluating candidates), and for decisions on terms, promotion, termination, task allocation, or monitoring and evaluating performance and behaviour.

Typical in-scope uses

  • CV-screening and candidate-ranking tools
  • Automated interview scoring
  • Task-allocation and performance-monitoring systems (incl. gig/platform work)

Function test

A 'human in the loop' does not by itself remove high-risk status if the AI materially influences the decision; scope extends to platform and gig workers. Annex III does not catch every AI system in this sector — only those performing a listed function.

5. Access to essential services

AI evaluating eligibility for public assistance benefits, creditworthiness / credit scoring, risk assessment and pricing in life and health insurance, and dispatching or prioritising emergency services.

Typical in-scope uses

  • Credit-scoring / creditworthiness models
  • Public-benefit eligibility assessment
  • Health/life insurance risk-pricing; emergency-call triage

Function test

Credit scoring for fraud detection and certain financial-stability uses may be treated differently — check the specific carve-outs. Annex III does not catch every AI system in this sector — only those performing a listed function.

6. Law enforcement

AI used by or for law-enforcement authorities for individual risk assessment, as polygraphs, to evaluate evidence reliability, or to profile individuals in the course of detection, investigation or prosecution.

Typical in-scope uses

  • Individual crime-risk assessment tools
  • Evidence-reliability evaluation
  • Investigative profiling systems

Function test

Some predictive-policing and untargeted uses are prohibited under Article 5 rather than high-risk under Annex III. Annex III does not catch every AI system in this sector — only those performing a listed function.

7. Migration, asylum & border control

AI as polygraphs, for risk assessment (security, irregular migration, health), to examine applications for asylum/visa/residence, or to detect and identify persons in the migration context.

Typical in-scope uses

  • Visa/asylum application risk assessment
  • Border risk-scoring systems
  • Identity-verification in migration procedures

Function test

A politically sensitive domain with active guidance — verify current scope carefully. Annex III does not catch every AI system in this sector — only those performing a listed function.

8. Justice & democratic processes

AI intended to assist a judicial authority in researching and interpreting facts and the law and applying it, or to influence the outcome of an election or referendum or voting behaviour.

Typical in-scope uses

  • Tools assisting judges in legal research and fact interpretation
  • Systems intended to influence voting behaviour or election outcomes

Function test

Tools for purely administrative or ancillary court activities are generally out of scope. Annex III does not catch every AI system in this sector — only those performing a listed function.

Question 3 of 4 — profiling

Does the system carry out profiling of natural persons?

Profiling means any automated processing of personal data to evaluate or predict aspects of a person — for example their work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.

Why this comes first

Under the final subparagraph of Article 6(3), a system in an Annex III area that performs profiling of natural persons is always high-risk — the Article 6(3) exception below cannot rescue it.

If you are unsure whether your processing amounts to profiling, treat it as in scope and take advice — the classification consequence is significant.

Question 4 of 4 — the Article 6(3) exception

Could the Article 6(3) exception apply?

An Annex III system is not high-risk if it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision-making. That exception is available only where at least one of these conditions is met:

  • (a) the system is intended to perform a narrow procedural task;
  • (b) it is intended to improve the result of a previously completed human activity;
  • (c) it is intended to detect decision-making patterns or deviations from prior patterns and is not meant to replace or influence the previously completed human assessment without proper human review;
  • (d) it is intended to perform a preparatory task to an assessment relevant to an Annex III use case.

Likely high-risk via the Annex I product route — verify against the specific instrument

Article 6(1) makes an AI system high-risk where it is, or is a safety component of, a product covered by the Annex I legislation and that product must undergo a third-party conformity assessment under that same legislation. Whether both limbs are met is specific to the instrument (the Medical Devices Regulation, the Machinery Regulation, and so on), so this route cannot be settled by a generic walk-through. Apply the Art. 6(1a)–(1c) carve-outs first: a function used solely for non-safety assistance, optimisation, convenience or quality control is not a safety component unless its failure would endanger health and safety, and third-party assessment required only for non-safety risks (e.g. radio spectrum / EMI) does not count.

What to document

The link between your AI system and the applicable Annex I instrument, and whether that instrument requires third-party (notified-body) conformity assessment for your product class.

Expected evidence

The product's existing conformity documentation and how the AI Act's high-risk requirements are integrated with the sectoral assessment.

Audit red flags

  • Treating the AI system as out of scope because "it is only a component" without checking the third-party-assessment limb.
  • Running the AI Act assessment and the sectoral product assessment as if they were unrelated.
  • Classifying (or de-classifying) a function as a safety component without a written Art. 6(1a)/(1b) analysis of whether its failure would endanger health and safety.

Timing: high-risk obligations for the Annex I regulated-product route apply from 2 August 2028.

Take qualified advice for the instrument that applies to your product. Background: How Article 6 classifies high-risk systems →

Not high-risk under the Annex III route

If the intended purpose does not fall within any of the eight Annex III areas and the system is not caught by the Annex I product route, it is not a high-risk system under Article 6. That is not the end of the analysis:

Still check

  • Prohibited practices (Article 5) — a handful of uses are banned outright regardless of sector.
  • Transparency (Article 50) — chatbots, synthetic-content generation, deepfakes and emotion recognition carry disclosure duties even when not high-risk.
  • GPAI model duties — if you provide a general-purpose AI model, separate documentation and copyright duties apply.

Audit red flags

  • Recording "not high-risk" without documenting why the intended purpose falls outside Annex III.
  • Overlooking an Article 50 transparency duty that still applies.

Likely outside this Annex III area — confirm the function test

Annex III catches AI performing a listed function within an area, not every system operating in the sector. If your system does not perform one of the listed functions, it is likely not high-risk on that basis — but confirm you have read the area's scope against your actual intended purpose, and check the other seven areas before concluding.

What to document

The specific function your system performs and why it does not match the listed high-risk functions for that area.

Audit red flags

  • Reading the sector name only and skipping the enumerated functions.
  • Assuming a "human in the loop" removes high-risk status — it does not, where the AI materially influences the decision.

How Article 6 classifies high-risk systems →

High-risk — profiling always classifies as high-risk

Because the system operates in an Annex III area and performs profiling of natural persons, the final subparagraph of Article 6(3) makes it high-risk regardless of the narrow-task exception. The exception is unavailable.

What this means

The full high-risk obligation set applies: a risk-management system (Art. 9), data governance (Art. 10), technical documentation (Annex IV / Art. 11), logging (Art. 12), transparency and instructions for use (Art. 13), human oversight (Art. 14), accuracy, robustness and cybersecurity (Art. 15), a conformity assessment (Art. 43) and a declaration of conformity, plus deployer duties (Art. 26).

Expected evidence

  • The Annex IV technical documentation, kept current — the primary artefact assessed at conformity assessment.
  • Records of the risk-management and data-governance measures.
  • Registration in the EU database before placing on the market or putting into service (Article 49). Registration obligation →

Audit red flags

  • No technical file, or one that does not match the deployed system.
  • A conformity declaration without the underlying evidence to support it.

Timing: stand-alone (Annex III) high-risk obligations apply from 2 December 2027.

Build the evidence pack → audit-readiness checklist

Indicatively high-risk under Annex III

The system falls within an Annex III area, performs a listed function, does not profile natural persons, and does not qualify for the Article 6(3) exception (or it materially influences the decision). On that basis it is indicatively a high-risk AI system under Article 6(2).

What this means

The full high-risk obligation set applies: a risk-management system (Art. 9), data governance (Art. 10), technical documentation (Annex IV / Art. 11), logging (Art. 12), transparency and instructions for use (Art. 13), human oversight (Art. 14), accuracy, robustness and cybersecurity (Art. 15), a conformity assessment (Art. 43) and a declaration of conformity, plus deployer duties (Art. 26).

Expected evidence

  • The Annex IV technical documentation, kept current — the primary artefact assessed at conformity assessment.
  • Records of the risk-management and data-governance measures.
  • Registration in the EU database before placing on the market or putting into service (Article 49). Registration obligation →

Audit red flags

  • No technical file, or one that does not match the deployed system.
  • A conformity declaration without the underlying evidence to support it.

Timing: stand-alone (Annex III) high-risk obligations apply from 2 December 2027.

Build the evidence pack → audit-readiness checklist

The Article 6(3) exception may apply — but you must document it

If at least one Article 6(3) condition is met and the system genuinely does not pose a significant risk or materially influence decisions, it may fall outside high-risk. This is a self-assessment you are claiming, not an automatic result — and the Act treats an undocumented claim as a compliance gap.

What you must document — before market

  • A written assessment of why the system meets an Article 6(3) condition and does not pose a significant risk, prepared before the system is placed on the market or put into service (Article 6(4)).
  • Registration in the EU database of systems the provider considers not to be high-risk under Article 6(3) (Article 49(2)).

Audit red flags — the ones that catch teams out

  • Relying on the exception with no written pre-market assessment on file.
  • Not registering the system under Article 49(2).
  • Claiming "narrow procedural task" while the system in fact materially influences the Annex III decision.
  • Overlooking that profiling would remove the exception entirely.

Borderline calls belong with a qualified adviser. If the system sits close to the line, treat it as high-risk until advice confirms otherwise. Background: How Article 6 classifies high-risk systems →

Stay audit-ready as the Act changes

EU AI Regulation Decoded tracks each obligation and the evidence auditors expect — one practitioner email a week.

Subscribe — free, weekly

Not legal advice. This is a practitioner reference generated from a cited knowledge base built on the primary legal text and official Commission guidance. Verify against the cited primary sources before relying on it for a compliance decision. See editorial standards & methodology.