Two routes into high-risk

Lesson 1 of 5 in High-Risk Classification: Art 6, Annexes I & III, and the Filter.

Most of the EU AI Act’s weight — the seven requirement articles, conformity assessment, CE marking, registration, post-market monitoring — lands on exactly one tier: high-risk. Prohibited systems are simply banned; limited-risk systems get disclosure duties; minimal-risk systems get nothing. So the single most consequential question you will ever answer about a system under this law is: is it high-risk?

Article 6 answers with a structure that trips up even experienced lawyers, because there is not one test but two independent routes, and a system can enter through either:

Route 1 — the product-safety route (Art 6(1) + Annex I). The AI is a product, or a safety component of a product, that already falls under EU product-safety law listed in Annex I — machinery, medical devices, toys, lifts — and that law requires third-party conformity assessment.

Route 2 — the use-case route (Art 6(2) + Annex III). The AI is intended for one of the sensitive uses enumerated in Annex III — hiring, credit, education, policing — regardless of what product it sits in.

Article 6: the two-track classification logic

  1. An AI system (Art 3(1))
  2. Product or safety component under Annex I legislation?

    Art 6(1)(a): the AI is itself a product — or a safety component of a product — covered by the Union harmonisation legislation listed in Annex I (machinery, toys, lifts, medical devices, vehicles…).

  3. Third-party conformity assessment required for that product?

    Art 6(1)(b): the product must undergo third-party conformity assessment under that Annex I law. Both conditions of Art 6(1) must be met — a safety component in a product that only needs self-assessment does not enter through Route 1.

  4. High-risk via Route 1 (Art 6(1))

    Requirements apply from 2 Aug 2028 (post-Omnibus). Conformity assessment is embedded in the sectoral product procedure (Art 43(3)).

  5. Intended for an Annex III use case?

    Art 6(2): eight areas — biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and borders, justice and democratic processes. Check the sub-point wording and its carve-outs, not just the headline.

  6. Art 6(3) filter: no significant risk?

    The derogation: no significant risk of harm to health, safety or fundamental rights — evidenced by one of four narrow conditions. But profiling of natural persons always stays high-risk.

  7. High-risk via Route 2 (Art 6(2))

    Requirements apply from 2 Dec 2027 (post-Omnibus). Conformity assessment is usually internal control (Annex VI); Annex III point 1 biometrics may need a notified body.

  8. Not high-risk — but document and register

    Art 6(4): document the assessment before market placement; register per Art 49(2); hand the assessment to authorities on request. Misjudge it and Art 80 reclassification awaits.

  9. Not high-risk via Art 6 — check other tiers

    The system may still carry Art 50 transparency duties or fall under the GPAI chapter. Not-high-risk never means unregulated by default.

Why the route matters beyond the label: it determines when the obligations bite and who checks your homework. Route 2 systems mostly self-assess under internal control (Annex VI); Route 1 systems ride along with their product’s notified-body procedure. And the Digital Omnibus split the calendar: Annex III systems from 2 December 2027, Annex I systems from 2 August 2028 — dates you will be asked about in every compliance-planning meeting until then.

Key terms: high-risk AI, Annex III, safety component, conformity assessment, Digital Omnibus

Interactive checkpoint quiz (1 questions) — open this page in a browser to take it.