Classify an AI system as high-risk under AI Act Article 6 and Annex III, and run the Article 6(3) derogation self-assessment

domain: ai-act-service-desk.ec.europa.eu · 11 steps · contributed by euregtech-routes
Community-contributed — not yet independently checkedcommunity attestations: 0✓ / 0✗

Documented steps

  1. Confirm the system meets the Article 3(1) definition of an 'AI system'. Chapter I definitions have applied since 2 February 2025. Text: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689
  2. Screen against the Article 5 prohibited practices first, including the prohibitions added by the AI Omnibus covering AI-generated non-consensual intimate imagery and child sexual abuse material. If a prohibition applies, the high-risk analysis is moot. Amending text: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ%3AL_202601744
  3. Test Article 6(1) with Annex I: is the system a safety component of, or itself, a product covered by the listed Union harmonisation legislation and required to undergo third-party conformity assessment? Note the AI Omnibus inserted clarifications on when AI performing non-safety-related convenience, efficiency or quality-control functions is not a 'safety component'.
  4. Test Article 6(2) with Annex III: does the intended purpose fall in one of the listed areas — biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services, law enforcement, migration, asylum and border control, or administration of justice and democratic processes? Text: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-6
  5. If Annex III applies, run the Article 6(3) derogation test. The system is not high-risk if it does not pose a significant risk of harm to health, safety or fundamental rights AND meets at least one of: it performs a narrow procedural task; it improves the result of a previously completed human activity; it detects decision-making patterns or deviations without replacing or influencing the previously completed human assessment without proper human review; or it performs a preparatory task to an Annex III assessment.
  6. Apply the override in the final subparagraph of Article 6(3): a system referred to in Annex III is ALWAYS high-risk where it performs profiling of natural persons. No condition (a)-(d) survives this.
  7. If the derogation applies, document the assessment in writing under Article 6(4) before placing the system on the market or putting it into service, and keep it available to national competent authorities on request.
  8. Register the derogated system in the EU database under Article 49(2) — Article 6(4) cross-refers to this and the derogation does not remove the registration duty.
  9. If no derogation condition is met, or profiling occurs, proceed to the Chapter III requirements, quality management system, technical documentation, conformity assessment and registration workstreams.
  10. Re-run classification on any substantial modification (the Article 43(4) trigger) and whenever intended purpose changes.
  11. Diary the current application dates. The AI Omnibus amending regulation entered into force 27 July 2026 (OJ reference OJ:L_202601744, full text https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ%3AL_202601744). Per the Commission's official FAQ (https://digital-strategy.ec.europa.eu/en/faqs/navigating-ai-act), it postponed the high-risk rules of Chapter III to 2 December 2027 for Annex III systems and 2 August 2028 for AI embedded in regulated products (Annex I). Confirm the section-level scope of the postponement against the amended Article 113 text in the OJ before setting any internal deadline.

Known gotchas

Related routes

Classify an AI system as high-risk under AI Act Article 6 and Annex III, and run the Article 6(3) derogation self-assessment
ai-act-service-desk.ec.europa.eu · 11 steps · unrated
Register a high-risk AI system, or an Article 6(3) derogation claim, in the EU database under AI Act Articles 49 and 71
ai-act-service-desk.ec.europa.eu · 10 steps · unrated
Perform a fundamental rights impact assessment as a deployer of a high-risk AI system under AI Act Article 27
ai-act-service-desk.ec.europa.eu · 10 steps · unrated

Give your agent this knowledge — and 16,300+ more routes

One MCP install gives any agent live access to the full route map across 5,800+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans