Source: OJ L, 2024/1689, 12.7.2024Consolidated text

Current language: EN

Article 6 Classification rules for high-risk AI systems


Summary What does Article 6 of the AI act regulation say?

This is a foundational classification article that defines what makes an AI system "high-risk" — a designation that triggers the full set of obligations laid out in Chapter III of the regulation.

It establishes two separate routes to high-risk classification: first, where an AI system functions as a safety component of, or is itself, a product covered by Union harmonisation legislation listed in Annex I and that product requires third-party conformity assessment; and second, where an AI system falls within the use cases listed in Annex III.

Importantly, the article also carves out a derogation from that second route, allowing Annex III systems to escape the high-risk classification where they pose no significant risk of harm — though profiling of natural persons is explicitly excluded from this escape route.

The Commission retains the power to adjust the conditions for that derogation through delegated acts, in both directions.

Important points:

  • Providers must document their assessment that an Annex III AI system is not high-risk before placing it on the market or putting it into service, and register accordingly under Article 49(2).
  • An AI system listed in Annex III can avoid high-risk classification if it meets one of the specified low-impact conditions, but this exemption never applies where the system performs profiling of natural persons.
  • The Commission is required to publish practical implementation guidelines, including examples of high-risk and non-high-risk use cases, no later than 2 February 2026.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Irrespective of whether an AI system is placed on the market or put into service independently of the products referred to in points (a) and (b), that AI system shall be considered to be high-risk where both of the following conditions are fulfilled:

      1. the AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I;

      2. the product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service of that product pursuant to the Union harmonisation legislation listed in Annex I.

  1. ▼M1
      1. For the purposes of this Regulation, including paragraph 1 of this Article, AI systems that are solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control shall not qualify as safety components.

      1. Notwithstanding paragraph 1a, AI systems the failure or malfunctioning of which would endanger health and safety shall qualify as safety components.

      1. A product that is required to undergo a third-party conformity assessment solely due to risks other than risks to health and safety, in particular risks relating to the distribution of radio spectrum or electromagnetic interference that do not affect health and safety, shall not be considered as fulfilling the condition in paragraph 1, point (b).

    1. In addition to the high-risk AI systems referred to in paragraph 1, AI systems referred to in Annex III shall be considered to be high-risk.

    1. By derogation from paragraph 2, an AI system referred to in Annex III shall not be considered to be high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making.

    2. The first subparagraph shall apply where any of the following conditions is fulfilled:

      1. the AI system is intended to perform a narrow procedural task;

      2. the AI system is intended to improve the result of a previously completed human activity;

      3. the AI system is intended to detect decision-making patterns or deviations from prior decision-making patterns and is not meant to replace or influence the previously completed human assessment, without proper human review; or

      4. the AI system is intended to perform a preparatory task to an assessment relevant for the purposes of the use cases listed in Annex III.

    3. Notwithstanding the first subparagraph, an AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons.

    1. A provider who considers that an AI system referred to in Annex III is not high-risk shall document its assessment before that system is placed on the market or put into service. Such provider shall be subject to the registration obligation set out in Article 49(2). Upon request of national competent authorities, the provider shall provide the documentation of the assessment.

    1. The Commission shall, after consulting the European Artificial Intelligence Board (the ‘Board’), and no later than 2 February 2026, provide guidelines specifying the practical implementation of this Article in line with Article 96 together with a comprehensive list of practical examples of use cases of AI systems that are high-risk and not high-risk.

    1. The Commission is empowered to adopt delegated acts in accordance with Article 97 in order to amend paragraph 3, second subparagraph, of this Article by adding new conditions to those laid down therein, or by modifying them, where there is concrete and reliable evidence of the existence of AI systems that fall under the scope of Annex III, but do not pose a significant risk of harm to the health, safety or fundamental rights of natural persons.

    1. The Commission shall adopt delegated acts in accordance with Article 97 in order to amend paragraph 3, second subparagraph, of this Article by deleting any of the conditions laid down therein, where there is concrete and reliable evidence that this is necessary to maintain the level of protection of health, safety and fundamental rights provided for by this Regulation.

    1. Any amendment to the conditions laid down in paragraph 3, second subparagraph, adopted in accordance with paragraphs 6 and 7 of this Article shall not decrease the overall level of protection of health, safety and fundamental rights provided for by this Regulation and shall ensure consistency with the delegated acts adopted pursuant to Article 7(1), and take account of market and technological developments.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod