Article 6, Annexes I and III
High-risk systems
Applies from 2 December 2027
Additions apply from 2 August 2028
This is the heavy part of the AI Act, and it is the part that moved. Annex III systems now fall due on 2 December 2027 and Annex I on 2 August 2028. Less widely noticed is that the definition of what counts narrowed at the same time, which takes some companies out of the regime altogether.
What it requires
- A risk management system running across the lifecycle, with the residual risks judged acceptable and recorded.
- Data governance for training, validation and testing sets, including relevance, representativeness and examination for bias.
- Technical documentation to Annex IV, drawn up before the system goes to market and kept current.
- Automatic logging of events across the system's lifetime.
- Instructions for use that let a deployer understand and control the system, plus human oversight designed in.
- Accuracy, robustness and cybersecurity appropriate to the purpose, then conformity assessment and registration.
- Deployers carry a shorter list of their own: use it as instructed, assign competent human oversight, monitor, and keep logs.
Who it applies to
- Annex III lists the stand-alone cases: biometrics, critical infrastructure, education, employment, essential public and private services including credit and insurance, law enforcement, migration, and the administration of justice.
- Annex I covers AI acting as a safety component of a product already regulated by EU harmonisation law, such as machinery, medical devices, lifts or toys.
- Article 6(3) means presence in an Annex III area is not the end of it. A system performing a narrow procedural task, improving a completed human activity, or doing preparatory work may fall outside, provided it does not profile people.
What changed in July 2026
- The Digital Omnibus deferred the Annex III obligations to 2 December 2027 and the Annex I obligations to 2 August 2028.
- A new Article 6(1a) provides that AI used solely for non-safety-related aspects of user assistance, performance optimisation, service efficiency, automation, convenience or quality control does not qualify as a safety component. Article 6(1b) preserves the regime where failure would endanger health and safety.
- Article 3(14) narrowed the definition of a safety component to one whose purpose is preventing or mitigating risks to the health and safety of persons or property.
- Article 111 leaves systems already placed on the market or put into service before the regime applies outside it, unless they undergo significant changes in design after that date. Systems intended for public authorities are excepted and must comply by 2 August 2030.
What most guidance still gets wrong
- Reading the deferral as a reprieve. The documentation this regime wants is retrospective: it describes decisions made during development, and organisations that start in 2027 find the evidence was never recorded in the first place.
- Assuming industrial AI is high-risk because it sits on a factory floor. Quality control and process optimisation are now expressly excluded unless a failure would endanger someone.
- Assuming the whole Act was delayed. It was not. Article 4, Article 5 and Article 50 are all in force now, and only the high-risk regime moved.
Which of these apply to you?
Ten questions, about three minutes, no account and nothing stored on our side. It tells you which of these obligations reach your organisation and which dates you are already past.
Start the free assessmentWritten against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. Not legal advice. Every change to this drafting is dated and published on the change history page.