EU AI Act Article 6: High-Risk Classification — Navigating the Annex III Framework
Article 6 is the hinge of the EU AI Act. Every deployer and provider must answer one question before anything else: is this system high-risk under Article 6, or not? The answer determines whether you face the full Title III conformity assessment, risk management, data governance, transparency, human oversight, and accuracy obligations — or the lighter Title IV transparency duties. Article 6(1) says a system is high-risk if it is (a) a safety component of a product covered by EU harmonisation legislation listed in Annex I, or (b) the AI system is itself such a product, and in either case the system must undergo a third-party conformity assessment under that legislation. Article 6(2) covers the Annex III list: eight areas — biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and administration of justice — each with specific use-case gateways. The Commission can add to Annex III via delegated acts; the first review is due by August 2028. For a verification-first operator, the classification moment is where measurement evidence becomes procurement collateral. If you classify a system as non-high-risk, you must document that decision and be ready to defend it to a notified body and market surveillance authority. If you classify it as high-risk, you need a quality management system (Article 17), technical documentation (Article 11), and a conformity assessment procedure. A verified measurement credential — showing quantified care, governance, refusal, and sandbox-escape scores across a measurement board — is the strongest single piece of evidence a deployer can produce whether the classification decision goes one way or the other. The Council of AI positions Article 6 classification as the first measurable checkpoint in the AI Act compliance lifecycle, not a legal opinion to be bought once and filed.
References
- Regulation (EU) 2024/1689 (EU AI Act), Articles 6-7, Annexes I and III
- Commission Guidelines on the classification of high-risk AI systems (expected Q4 2026)
- Council of AI Containment Incident Index (CONTAINMENT_INCIDENT_INDEX.json)
- CSOAI Verified Measurement Credential standard (signed GSPC card)
Measurement, not certification. Verify a card at /gspc-verify.