Understanding AI Risk Classification: A Practical Guide to Article 6

By Jurista.ai Editorial

Why Classification Matters More Than Anything Else

Every obligation under the EU AI Act flows from how your AI system is classified. If your system is high-risk, you face the full weight of the compliance regime — quality management systems, conformity assessments, technical documentation, post-market monitoring, and registration in the EU database. If it is limited-risk or minimal-risk, your obligations are minimal or nonexistent.

Misclassification is the single greatest compliance risk. Classifying a high-risk system as low-risk does not eliminate your obligations — it merely ensures that when regulators discover the error, you face maximum penalties for both the underlying violation and the failure to comply with high-risk requirements.

The Two Pathways to High-Risk Classification

Article 6 of the AI Act establishes two independent pathways through which an AI system can be classified as high-risk. If either pathway applies, the system is high-risk.

Pathway 1: AI as a Safety Component (Article 6(1))

An AI system is high-risk if it is intended to be used as a safety component of a product — or is itself a product — covered by specific EU harmonization legislation. This includes:

  • Machinery Regulation (EU) 2023/1230
  • Medical Devices Regulation (MDR) 2017/745
  • In Vitro Diagnostic Medical Devices Regulation (IVDR) 2017/746
  • Automotive type-approval frameworks
  • Aviation safety regulations
  • Marine equipment
  • Toys safety
  • Lifts
  • Pressure equipment
  • Personal protective equipment

Under this pathway, the AI system must also undergo a third-party conformity assessment under the relevant product legislation. If it does, the AI Act requirements apply through that assessment.

Pathway 2: Listed in Annex III (Article 6(2) and Annex III)

This is the pathway that catches most enterprise AI systems. Annex III lists specific use cases that are automatically classified as high-risk, regardless of whether they involve physical products:

  1. Biometrics — remote biometric identification, biometric categorization, emotion recognition
  2. Critical infrastructure — systems used as safety components in management of road traffic, water supply, gas, heating, and electricity
  3. Education and vocational training — admissions, learning outcome evaluation, proctoring
  4. Employment and worker management — recruitment, evaluation, promotion, termination decisions, task allocation
  5. Access to essential services — creditworthiness, credit scores, insurance pricing, benefits eligibility
  6. Law enforcement — polygraphs, evidence reliability assessment, profiling
  7. Migration, asylum, and border control — eligibility assessment, security checks, border monitoring
  8. Administration of justice and democratic processes — assisting judicial authorities, influencing elections

Each Annex III category includes specific sub-use cases. The classification is about intended purpose, not about the underlying technology. A large language model used for customer support is not high-risk under Annex III. The same model used to evaluate job applicants is.

The Practical Classification Checklist

Use this decision tree for every AI system in your organization:

Step 1: Does the system fall under a prohibited practice (Article 5)?

  • Social scoring? Manipulative or deceptive AI? Exploitation of vulnerabilities? Real-time biometric identification in public spaces (with narrow exceptions)? If yes, the system is banned. No further classification needed — stop using it.

Step 2: Is the system a safety component of EU-regulated products?

  • Does it fall under the Machinery Regulation, MDR, IVDR, automotive, aviation, or other harmonization legislation? Does it require third-party conformity assessment? If yes → high-risk via Article 6(1).

Step 3: Is the system used for any Annex III use case?

  • Review each of the eight Annex III categories against your system’s actual and intended purpose. Consider not just what the system was designed for, but how it is actually used by deployers. If yes → high-risk via Article 6(2).

Step 4: Could the system cause harm to health, safety, or fundamental rights?

  • If it doesn’t fit neatly into Annex III but poses significant risk, consider whether it might meet the Commission’s future expansion criteria under Article 7. The Commission can add new high-risk use cases via delegated acts.

Step 5: Does the system only have transparency obligations?

  • If it’s an emotion recognition system used in a non-high-risk context, a chatbot, a deepfake generator, or AI-generated content — it likely falls under Article 50 transparency rules. Not high-risk, but disclosure obligations apply.

Step 6: Is the system minimal-risk?

  • If none of the above applies → minimal-risk. No AI Act obligations. Examples include spam filters, inventory optimization, and recommendation engines that don’t touch Annex III areas.

Common Classification Pitfalls

”We only use it internally”

Internal use does not exempt you. An AI system used by HR to screen internal candidates for promotion is high-risk under Annex III(4), regardless of whether it is deployed externally.

”It’s just a chatbot”

If your chatbot is used in education (evaluating learning outcomes) or employment (screening candidates), it may be high-risk despite its conversational interface. The technology is irrelevant — the intended purpose determines classification.

”The vendor handles compliance”

Deployers of high-risk AI have their own obligations under Articles 26–29. Vendor compliance does not transfer. If you deploy a high-risk system, you must ensure human oversight, monitor operations, and maintain usage logs independently.

”It’s a general-purpose model, not application-specific”

GPAI models have their own regulatory regime (Articles 51–55), separate from the high-risk classification. However, a GPAI model incorporated into a high-risk system inherits the high-risk obligations. The provider of the GPAI model has transparency obligations toward the downstream provider, who then bears the full high-risk compliance burden.

Documentation Requirements for Classification

Whatever your classification result, document the reasoning. Regulators will ask not just “what is the classification?” but “how did you determine it?” Maintain:

  • A classification rationale for each AI system
  • Mapping to the relevant Article 6 pathway or Annex III category
  • Consideration of intended purpose versus actual deployment
  • Review dates and reviewer names
  • Escalation records for borderline cases

Key Takeaways

  • Classification is about intended purpose, not technology
  • Annex III is the most common pathway to high-risk status
  • Deployers and providers each have independent obligations
  • Document your classification reasoning from the start
  • When in doubt, classify conservatively and seek regulatory guidance

Jurista.ai automates AI risk classification with an interactive Article 6 decision tree and Annex III mapping. Try the classification tool.