Article 6: High-Risk AI System Classification
How to classify AI systems as high-risk under EU AI Act Article 6 and Annex III — the 8 categories, the Annex I product-safety path, and the decision tree.
Article 6 An AI system is high-risk if it falls under Annex I product-safety rules or is used in one of the eight Annex III use-case areas , unless a narrow Article 6(3) exemption applies. August 2, 2026.
Article 6 of the EU AI Act defines when your AI system becomes high-risk. High-risk systems face strict compliance requirements, including risk management, data governance, and technical documentation.
Misclassifying your system can trigger Article 99 penalties of up to €15 million or 3% of global turnover. , whichever is higher.
Two Routes to High-Risk
Route 1: Annex I Product Safety
Your AI is high-risk if it is a safety component of, or is itself, a product covered by EU product-safety legislation (machinery, medical devices, toys, lifts, radio equipment) that requires third-party conformity assessment.
Annex I obligations apply from August 2, 2027.
Route 2: Annex III Use Cases
Your AI is high-risk if used in one of eight areas: biometrics, critical infrastructure, education, employment, essential services (including credit scoring), law enforcement, migration/asylum/border control, or administration of justice/democratic processes.
Annex III obligations apply from August 2, 2026. Article 6(3) exemptions may apply for purely procedural tasks, result-improvement activities, pattern detection without human replacement, or preparatory tasks.
Eight Annex III Categories
Classification at a Glance
How Scanara Automates Classification
Use-Case Detection in Code
Scanara scans your codebase for keywords, API calls, and data patterns that signal Annex III use cases—biometric processing, credit scoring logic, law enforcement integrations.
Article 6(3) Exemption Flagging
Our rules identify borderline cases and flag potential Article 6(3) exemptions, helping you document why your system may not be high-risk despite Annex III overlap.
Classification Dossier Generation
Scanara generates structured classification reports with evidence trails, ready for auditors and regulators. Export Article 6 assessments directly from scan results.
Frequently Asked Questions
Related Compliance Topics
Article 9: Risk Management
Once classified as high-risk, your system must implement a continuous risk-management system throughout its lifecycle.
Article 10: Data Governance
High-risk AI systems require training, validation, and testing datasets that meet quality, relevance, representativeness, and bias standards.
Article 16: Provider Obligations
Providers of high-risk systems must establish quality management, maintain technical documentation, keep logs, and register in the EU database.
EU AI Act Compliance Checklist
Step-by-step guide to achieving full EU AI Act compliance, from classification through deployment and monitoring.
How Scanara Helps
Scanara automates EU AI Act compliance from code to dossier. Connect your GitHub repos and get compliance reports in minutes.