| Takeaway | Detail |
|---|---|
| Annex III is the entry threshold | A system is within Article 6 scope only if it falls within an Annex III use case. |
| Two product limbs control the default result | Unless an Annex III(3) exception applies, the system must satisfy both Article 6(2) limbs concerning regulated products and third-party conformity assessment. |
| Pilots require exact point matching | For every EU-launched or EU-used AI pilot, document the exact Annex III point before treating it as provisionally in Article 6 scope. |
| Scope review requires a two-part test | First identify the Annex III use case, then test both Article 6(2) product limbs; either failure prevents the default Article 6 classification. |
This guide delivers a two-part classification test for Article 6: Annex III use-case matching followed by the Article 6(2) product-limb analysis. It identifies the conditions that determine whether the default scope rule applies and when an Annex III(3) exception must be considered.

Run the two cumulative Article 6 filters
Begin the classification record with the system’s intended purpose and the specific Annex III use case it matches. State the exact Annex III point and explain the factual connection between that use case and the pilot’s actual function. An innovation objective, algorithmic approach, or project sponsor’s description of the system as “high risk” cannot replace that match. If the purpose is still evolving, document whether the system is already being used in the Annex III activity and preserve evidence of the current use.
Next, determine whether the AI is itself a regulated product or a safety component of a regulated product. For the first branch, identify the product and the Union harmonisation legislation governing it. For the second, identify the finished product in which the AI is incorporated and explain how the AI functions as a safety component, including its role under the product’s applicable technical and conformity requirements. Product-related marketing, deployment by an EU institution, or operation in an EU pilot does not itself satisfy this limb.
Then test the separate requirement for third-party conformity assessment. Check the applicable Union harmonisation legislation to establish whether conformity assessment must be performed by a notified body or another third party, rather than solely through internal manufacturer controls. Record the provision or product rule that triggers that requirement and retain evidence of the assessment method, applicable standards, and any notified-body involvement. The relevant question is what the product law requires, not whether the provider voluntarily commissioned an external review.
Apply the results as a decision matrix. An Annex III match plus both Article 6(2) limbs supports classification as high-risk through the standard route. An Annex III match with no qualifying regulated-product status does not support that route. An Annex III match and a regulated-product status without a third-party conformity-assessment requirement likewise do not support it. Preserve each finding separately so that a change in product purpose, integration, or applicable product law can be reassessed without collapsing the analysis.
Article 6 uses cumulative legal tests rather than a general risk score. Accordingly, keep the Annex III purpose analysis, regulated-product analysis, safety-component analysis, and third-party conformity-assessment analysis in distinct fields. Every conclusion should cite an Annex III point, the relevant product-law provision, and evidence supporting the conformity-assessment finding. This structure makes the classification reproducible and exposes precisely which element is satisfied, missing, or unresolved.

Verify the law against official sources
Use the official text of Regulation (EU) 2024/1689, Article 6 and Annex III as the controlling evidence for this gate. For every pilot, preserve a dated copy or official link to those provisions and record the exact Annex III point. Avoid replacing the legal text with a vendor label, a procurement description, or a Commission summary.
Check Article 6(2) against the pilot’s actual product and regulatory context. Its first limb concerns a safety component of a product, or the product itself, covered by specified Union harmonisation legislation. The second limb requires that, under that legislation, third-party conformity assessment be required. Record which product rule applies, identify the relevant AI function, and retain evidence showing that an independent conformity-assessment procedure applies. If neither condition is documented, the record is not ready for a standard Article 6 classification.
Map Annex III precisely rather than by broad project label. Check its points for recruitment or selection, education or vocational training, access to or evaluation of creditworthiness, employment or worker management, access to essential private and public services, law enforcement, migration or border control, administration of justice and democratic processes, and the other listed uses. The classification entry should quote the relevant language and explain how the pilot’s intended purpose matches it; a general reference to “HR,” “education,” or “public services” is insufficient.
Review Article 6(3) whenever Annex III might otherwise place the system within the high-risk category. Its treatment of certain systems that pose limited risk depends on the narrow conditions stated there, including the system’s role in a broader activity, its procedural character, and whether it materially influences the activity’s outcome. Confirm the narrower exception from the official wording and document why the pilot satisfies it. The special rule concerning profiling of natural persons must be checked separately and not treated as a general exemption.
Official Commission guidance can help locate provisions, terminology, and interpretive considerations, but the Regulation itself remains controlling. Compare any guidance statement with the enacted text, preserve the exact quoted wording, and flag uncertainty instead of silently harmonizing differences. For a governance record, the minimum defensible set is therefore an official Article 6 excerpt, the exact Annex III point, the product-rule reference, the third-party conformity-assessment reference, and any Article 6(3) analysis. This creates a source-based check that another reviewer can reproduce without relying on an institutional description of the pilot.

Compare the classification routes
Start with the standard route. Confirm that the pilot’s intended purpose matches an Annex III use case, identify the exact point, and verify that the system is a high-risk AI system under Article 6(2). That verification has two separate product-based checks: the system must be a safety component of a product, or the product itself must be a safety component, and the relevant product must be subject to third-party conformity assessment. Record the product, its role in that product, the applicable product rules, and the conformity-assessment procedure. The standard high-risk classification applies only when the Annex III match and both limbs are established.
Use a comparison record to keep the analysis from collapsing the two limbs into one question. The product-status column should identify what the AI system does and whether it is a safety component. The conformity-assessment column should identify the required third-party procedure and show that the product is covered by it. If either check fails, the system does not become high-risk through the standard route merely because its Annex III label sounds consequential or its underlying product is regulated.
Then assess the limited-risk alternative. Under Article 6(3), an Annex III(1) system is outside the standard high-risk classification only if it does not pose a risk of harm to health, safety, or fundamental rights; does not materially influence the outcome of decision-making in employment, worker management, access to essential private or public services, education, creditworthiness, law enforcement, or migration; and does not materially influence the provision or selection of essential public or private services. These checks require more than identifying the system’s nominal task.
Document the evidence for each Article 6(3) condition. Examine foreseeable use and misuse, the people affected, vulnerable individuals, the system’s actual functions, and the extent to which its output drives or shapes a human decision. Pay particular attention to proxy discrimination, exclusion from services or opportunities, unsafe recommendations, and decisions that cannot be meaningfully challenged or reversed. The reason for treating the system as limited-risk should be tied to the system’s design, deployment controls, operating environment, and decision role.
The Annex III(3) limited-risk route is the only alternative to the standard Annex III plus Article 6(2) route. Accordingly, when either Article 6(2) product limb is met, classify the pilot as high-risk through the standard route and do not substitute an Article 6(3) analysis. Use that analysis only when the pilot is eligible for the limited-risk treatment and the record supports every required condition.

Budget for classification evidence
Budget one classification record for each materially distinct system variant, rather than one generic record for the entire pilot program. Each record should identify the variant’s intended purpose, operating environment, affected persons, and foreseeable use. It should also map the variant to an exact Annex III point and preserve the factual evidence supporting that mapping. For a product covered by Article 6(2), the record should separately address whether the system is a regulated product requiring third-party conformity assessment and whether applicable Union product legislation requires such assessment. The file should contain or reference the applicable product-law requirements, proposed conformity-assessment evidence, and final classification decision, including the responsible decision-maker and approval date. Any change to purpose, users, deployment context, or product status should trigger a documented reclassification check.
Allow a two-reviewer quality check when the pilot can materially affect people or when competing readings of product legislation could change whether deployment may proceed. The first reviewer should confirm the Annex III mapping; the second should

Distinguish legal scope from evidence gaps
Treat an EU-launched or EU-used AI pilot as provisionally within Article 6 only after matching its intended purpose and actual function to a specific Annex III use case. In the classification record, identify the exact Annex III point and describe the factual connection between that use case and the pilot. Neither accuracy nor the word “high-risk,” by itself, determines Article 6 status. An accuracy score may describe model performance, but it does not establish that a system falls within Annex III.
Use the same separation when reviewing product evidence. Accuracy testing cannot, on its own, prove that the AI system is a regulated product, that it is covered by the relevant Union harmonisation legislation, or that third-party conformity assessment is legally required. For each Article 6(2) product condition, the file should contain a separate supporting record: evidence identifying the applicable product legislation, an explanation of how the AI system relates to that legislation’s requirements, and a documented basis for whether conformity assessment must be performed by a third party. Performance results should not be used as substitutes for those records.
Marketing language is also not a safe classification route. A system promoted as an assistive tool can remain covered if its intended purpose and functions make the Article 6(2) product conditions apply. Check what the system is designed to do, what role it performs in the wider product or service, and whether the supplier’s claims describe a regulated safety-related function. If the intended purpose and the pilot’s implementation point in different directions, resolve that discrepancy before relying on the label “assistive.”
Internal use does not automatically remove a model from assessment. A model used only inside an organisation can still require conformity assessment if the relevant conditions are met. The separate question is whether that assessment must be completed by a third party rather than through an available internal route. Keep those decisions distinct: first document the legal classification and applicable requirements; then document who may perform the required conformity assessment. If the file contains only an internal validation report, mark unresolved questions as evidence gaps rather than treating the report as proof of Article 6 scope or compliance.
Classify a wearable knee-control model
Start with the controller’s intended purpose. Assume the machine-learning controller influences the safety function of a prosthetic knee governed by an Annex I medical-device law and that the finished device requires conformity assessment by a notified body. Document whether the controller is a safety component placed on the market with the finished device or is itself intended as an active implant. That product-role determination is essential because the pilot record must connect the controller to the applicable medical-device product and its third-party assessment.
Next, test the pilot against Annex III. Record the exact Annex III point and explain how the controller’s actual function matches it. If the pilot also assesses a regulated rehabilitation or clinical outcome, classify that use as high-risk when the stated Annex III mapping covers the assessment function. The assessment purpose should not be treated as incidental if it is part of the deployed system’s intended purpose. By contrast, if the controller is only a safety component of the prosthetic knee, the relevant route remains Article 6(2), even without a separate rehabilitation-assessment use.
For the product analysis, test both Article 6(2) branches rather than assuming that medical relevance is enough. The first branch covers an AI system intended as a safety component of a product governed by listed Union harmonization legislation when third-party conformity assessment is required. The second covers an AI system that is itself a product, or is intended to be used as a product, under those laws and likewise requires third-party conformity assessment. The evidence should therefore identify the applicable medical-device law, the regulated product, the notified-body requirement, and whether the controller occupies the safety-component role, the regulated-product role, or both.
A machine-learning controller intended for a third-party-assessed active implant illustrates the standard high-risk route. In that configuration, the intended product status and the notified-body requirement support Article 6(2), provided the record also establishes the applicable Annex III use case and the exact point that covers it.
Apply a separate exclusion check to a general wellness knee coach. If it provides exercise guidance or wellness support, does not assess a regulated rehabilitation or clinical outcome, and has no independent Annex III use-case mapping, it does not enter the high-risk classification through this analysis. Merely influencing a prosthesis or using machine learning does not cure the absence of an Annex III use case. The classification file should state the reason for exclusion, preserve the product-safety analysis, and flag any later expansion into regulated assessment as a change requiring reclassification.
Apply five final decision rules
Rule 1: Require an exact Annex III match. Begin with the pilot’s intended purpose, actual function, and operating context, then identify the specific Annex III use case that covers it. Record the exact point and preserve the factual basis for that match. The canonical control is an exact Annex III match followed by a two-limb product test, with Article 6(3) reserved for its narrow statutory cases. If the pilot merely resembles a listed use case, ask what changes would make its purpose, users, inputs, outputs, and consequences fit that point.
Rule 2: If no specific Annex III point fits, record Article 6 as not applicable. Record the system as outside Article 6 rather than assigning a qualitative “high-risk” label. The record should identify the Annex III points considered and explain why the system’s actual function falls outside each one. Do not use general concerns about safety, fairness, privacy, autonomy, or potential harm to substitute for an enumerated use case. An inconclusive comparison is not an affirmative match: narrow the stated purpose or document the evidence still needed before completing the classification.
Rule 3: Test the regulated-product limb. Once an Annex III point applies, determine whether the AI system is itself a regulated product or a safety component of one. Identify the product legislation, if any, and show the connection between the pilot and that product. If the system is neither, record the Article 6(2) product limb as not met. In that situation, do not proceed as though an Annex III match alone establishes Article 6 scope.
Rule 4: Test the third-party conformity-assessment limb. If the system is a regulated product or qualifying safety component, identify the applicable product requirements and check whether they require assessment by a third party. Record the provision, procedure, or authority supporting that conclusion. If no third-party conformity assessment is required, record that Article 6(2) limb as not met. Do not treat supplier self-assurance, an internal test, a customer review, or voluntary external validation as the required third-party assessment unless the governing product rules say so.
Rule 5: Resolve the result through a controlled final record. For each limb, mark it “met,” “not met,” or “not yet evidenced,” and attach the supporting document. An Annex III match with both product limbs met remains within Article 6; failure of either limb places the system outside the standard Article 6(2) route. Before closing the file, check whether a narrow Article 6(3) statutory case actually applies. Otherwise, state the final result and the precise reason in one concise classification entry.
What to do next
| Step | Action | Why it matters |
|---|---|---|
| 1 | For every EU-launched or EU-used AI pilot, record whether its intended purpose matches an Annex III use case. | Annex III is the entry threshold for Article 6 scope. |
| 2 | Document the exact Annex III point supporting the pilot’s provisional classification. | Exact point matching creates a traceable scope decision. |
| 3 | Check whether the Annex III(3) exception applies. | An applicable exception prevents the default Article 6 classification. |
| 4 | Absent that exception, test both Article 6(2) limbs: whether the AI system concerns a regulated product and whether safety is assessed through a third-party conformity assessment. | Both product limbs must be satisfied before treating the pilot as high-risk under Article 6. |
| 5 | Record the evidence and outcome of each limb test, including any failure. | Either failure prevents the default Article 6 classification. |
| 6 | Complete the classification review within 2 days, then design high-risk controls only if the Annex III use case and both Article 6(2) limbs support classification. | The classify-or-stop gate avoids implementing high-risk controls for a system outside Article 6 scope. |
Frequently Asked Questions
What must happen before an AI system is treated as provisionally within Article 6 scope?
The system’s exact Annex III use case must be identified and the factual connection between that use case and the system’s actual function must be documented.
What are the two cumulative filters in the Article 6 classification test?
The first filter is matching the system to an Annex III use case, and the second is testing both Article 6(2) product limbs concerning regulated products and third-party conformity assessment.
What happens if the AI system fails either Article 6(2) product limb?
Either failure prevents the default Article 6 classification.
When should an Annex III(3) exception be considered?
It should be considered when applying the Article 6(2) product limbs, because the exception may alter the otherwise applicable default scope result.
Can calling an AI pilot “high risk” establish its Article 6 classification?
No, because a project sponsor’s description of the system as “high risk” cannot replace an exact match to an Annex III use case.
What must be recorded before reviewing an EU-launched or EU-used AI pilot under Article 6?
The classification record must begin with the system’s intended purpose and the specific Annex III use case it matches.
Quick answers
| What is the entry threshold for determining whether an AI system falls within Article 6 scope? | A system is within Article 6 scope only if it falls within an Annex III use case. |
| What must happen unless an Annex III(3) exception applies? | The system must satisfy both Article 6(2) limbs concerning regulated products and third-party conformity assessment. |
| What must be documented for every EU-launched or EU-used AI pilot? | The exact Annex III point must be documented before the pilot is treated as provisionally in Article 6 scope. |
| What are the two cumulative filters used to classify a system under Article 6? | First identify the Annex III use case, then test both Article 6(2) product limbs. |
| Can an innovation objective, algorithmic approach, or sponsor description establish high-risk scope? | No, an innovation objective, algorithmic approach, or project sponsor’s description of the system as “high risk” cannot replace the required Annex III use-case match. |
Also worth reading: Stage-Gate Kill Rates: Why Top Innovators Kill 50% at Gate 2: Stage-Gate Kill Rates: Why Top · Kill, Extend, or Scale: 2026 Cost-per-Learn Benchmarks for Pilots: Kill, Extend, or Scale: 2026 · Run 15 Corporate Pilots a Quarter: 3 Gates, 70% Fail: Run 15 Corporate Pilots a