SignorCrypto note · AI
EU AI Act High-Risk AI: How to Classify a System
A practical test for Annex III use cases and regulated products, plus the amended 2027–2028 dates.

As of 8 October 2026, classify an EU AI Act high-risk system by its intended purpose and the route in Article 6—not simply by model type or industry. The Act has two routes: AI used in specific Annex III sensitive use cases, and AI that is a safety component or product under Annex I legislation requiring a third-party conformity assessment. A narrow Annex III filter may apply, but profiling of natural persons is always high-risk. Under the AI Omnibus, the relevant dates are 2 December 2027 for Annex III and 2 August 2028 for Annex I products.
This is an educational overview, not legal advice. Classification depends on the system’s intended purpose, product context and deployment facts.
Start with the system and its intended purpose
Article 6 applies to AI systems within the Act’s scope. First identify the system being assessed, then pin down its intended purpose: the use, context and conditions described by the provider. A model’s general capabilities, marketing label or presence in a regulated sector does not, on its own, make every use high-risk.
The practical question is what the system is designed to do in a particular setting. The same underlying model can support different tasks, and those tasks can fall under different parts of the Act.
Route one: a use case listed in Annex III
Article 6(2) treats the Annex III use cases as high-risk. The eight listed areas are:
- biometrics, where the use is permitted by applicable law;
- safety components in the management or operation of critical infrastructure;
- education and vocational training;
- employment, workers’ management and access to self-employment;
- access to essential public or private services and benefits;
- law enforcement;
- migration, asylum and border control; and
- administration of justice and democratic processes.
These are specific listed uses, not a blanket classification of every AI tool used in one of those sectors. For example, the relevant question is whether a system is intended for a listed function—such as evaluating job candidates or determining access to education—not merely whether a school or employer uses AI.
When the Annex III filter can apply
An Annex III system may fall outside the high-risk category only if it does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing a decision’s outcome, and it meets one of the conditions in Article 6(3). The listed conditions cover systems that:
- perform a narrow procedural task;
- improve the result of a previously completed human activity;
- detect decision-making patterns or deviations without replacing or influencing the completed human assessment, subject to proper human review; or
- perform a preparatory task for an assessment in an Annex III use case.
There is an explicit limit: an Annex III system that profiles natural persons is always high-risk. A provider claiming that an Annex III system is not high-risk must document the assessment before placing it on the market or putting it into service and meet the related registration obligation in Article 49(2).
Route two: AI in a regulated product under Annex I
The Annex I route has two conditions. The AI system must either be a product covered by the Union harmonisation legislation listed in Annex I or be intended as a safety component of such a product; and that product must require a third-party conformity assessment under the relevant product legislation. Both conditions matter.
The amended Article 6 also clarifies the safety-component test. AI used solely for non-safety functions—such as convenience, service efficiency, performance optimisation or quality control—does not qualify as a safety component. But if failure or malfunction of the AI would endanger health or safety, it does qualify. A product’s use of AI, by itself, is not enough to resolve the classification.
The revised high-risk deadlines
Regulation (EU) 2026/1744, the AI Omnibus, entered into force on 27 July 2026. The current EU implementation timeline sets different application dates for the two high-risk routes:
| Route | Relevant AI Act scope | Application date |
|---|---|---|
| Annex III | Listed sensitive use cases | 2 December 2027 |
| Annex I | High-risk AI in regulated products | 2 August 2028 |
These dates apply to the relevant high-risk rules; they are not a blanket postponement of the AI Act. Other provisions have separate schedules. Our guide to the AI Act’s 2026 transparency rules explains the distinct Article 50 obligations and why the deadlines should not be conflated.
A practical classification record for teams
For each system, keep a short record that answers five questions:
- What is the system, and does it qualify as an AI system under the Act?
- What intended purpose and deployment context are documented by the provider?
- Does that purpose match a specific Annex III use case?
- If it does, does the Article 6(3) filter genuinely apply—and is the evidence documented before market placement?
- If the system is part of a product, which Annex I product legislation applies, is third-party conformity assessment required, and could AI failure endanger health or safety?
Record the basis for the conclusion, the responsible provider or deployer, and the date of review. Revisit it if the intended purpose, product function or deployment changes. For a separate view of testing and evidence practices, see our NIST ARIA guide to AI evaluations.
The Commission’s classification materials identify their examples and guidelines as draft material pending formal adoption. They can help teams interpret the rules, but they are not a substitute for the amended Act or a binding legal classification. Check the current text and guidance again before relying on an assessment.
Frequently asked questions
Is every generative AI model high-risk under the EU AI Act?
No. The high-risk classification turns on the system’s intended purpose and whether it falls within Article 6’s product or listed-use routes. A model’s general-purpose capability alone does not make every application high-risk.
Can a provider decide that an Annex III system is not high-risk?
Only where the statutory filter applies: the system must not pose significant risk and must meet one of the listed task conditions. Profiling of natural persons remains high-risk, and a provider relying on the filter must document and register the assessment as required.
Did the AI Omnibus delay every AI Act obligation?
No. It changed parts of the implementation timetable, including the Annex III and Annex I high-risk dates. Other provisions, including transparency duties, have separate application dates.
Sources
- Regulation (EU) 2026/1744 — Digital Omnibus on AI, EUR-Lex
- AI Act Service Desk — Article 6: Classification rules for high-risk AI systems
- AI Act Service Desk — Annex III
- European Commission — AI Omnibus enters into force
- AI Act Service Desk — Implementation timeline
- European Commission — Draft guidelines on high-risk AI classification
If your team is putting AI into daily workflows, explore Botchi for governed employee assistants and specialist agents that run repeatable work inside company-controlled boundaries.