IN BRIEF

A structured guide to classification, provider controls, deployer duties and phased high-risk application dates.

01 / ASSESS

Classification first

Check Article 6 and the relevant Annex. Capture the system’s intended purpose and the reasoning behind the assessment. Seek qualified review for borderline applications.

Read the legal text ↗
02 / ASSESS

Provider control areas

For applicable high-risk systems, the Act sets requirements across risk management, data and data governance, documentation, record-keeping, transparency to deployers, human oversight, accuracy, robustness and cybersecurity.

  • Design and test controls against the intended use
  • Maintain technical documentation and logs where required
  • Plan the conformity route and post-market processes
03 / ASSESS

Check the applicable date

Following the 2026 AI Omnibus amendments, Annex III high-risk rules are scheduled for 2 December 2027 and Annex I product-linked high-risk rules for 2 August 2028. Other provisions may already apply.

Check the official timeline ↗
04 / ASSESS

Two main classification routes

Article 6(1) covers certain AI used as a safety component of a product, or itself a product, under the Union legislation listed in Annex I where third-party conformity assessment is required. Article 6(2) points to the use cases in Annex III, such as specified employment, education and essential-service contexts. The detailed wording, purpose and any Article 6(3) exception matter. The route affects both analysis and later conformity work.

Examine the classification criteria ↗
05 / ASSESS

Build an evidence chain, not a badge

A high-risk provider must connect requirements to a risk-management process, relevant data governance, technical documentation, logging design, deployer information, human oversight and performance measures. Document the testing and reasoning that support the intended purpose. The Act also addresses quality management, conformity assessment, EU declaration and registration in specified cases. The exact route is not identical for every high-risk system.

Review provider duties ↗
06 / ASSESS

What does the deployer control?

The deployer operates within the provider’s instructions and controls real use conditions: staff training, oversight assignments, input quality where relevant, monitoring and escalation. The provider’s conformity work does not replace deployer obligations. A shared handoff should identify which party supplies logs, handles updates, receives incidents and decides whether a new use remains within the assessed intended purpose.

Read the deployer guide ↗
07 / ASSESS

Example: a hiring workflow

An AI system intended to filter job applications may engage the employment use cases in Annex III. An organisation should identify the specific function, whether a human reviews the output, who provides the system and who deploys it. A generic claim that the tool is “assistive” is not enough to conclude it falls outside high-risk classification; Article 6 must be tested on the full facts.

Compare risk pathways ↗
Verify the source

This guide is an orientation, not a legal determination. Check the current legal text and official implementation guidance for your system.

Read the AI Act ↗European Commission overview ↗