Reglog

← Guides & analysis

EU AI Act Article 6(3): when an Annex III system is not high-risk, and the public registration it triggers

· 20 min read

Most of the work of deciding whether the EU AI Act's heavy obligations apply to you happens at one table: Annex III. Eight areas, a list of use cases, and a simple-looking question — is your system on it?

For a lot of companies the honest answer is "sort of". The tool sits in one of the Annex III areas, but what it actually does there is narrow. It sorts CVs into folders. It flags an outlier for a human to look at. It drafts a first pass that someone else rewrites.

Article 6(3) is the provision written for exactly that situation. It is a genuine exit from the high-risk regime. It is also the least quiet exit in the Act: taking it creates a documentation duty and a public entry in an EU database under your own company name. The Digital Omnibus changed what goes in that entry in July 2026.

This is an information service to help you plan, not legal advice. To see which obligations attach to your own AI use, start with the obligation check.

First, confirm you are actually in Annex III

Article 6(3) only helps you if Annex III is the reason you are high-risk. There are two doors into the high-risk tier, and this one only opens on the second.

  • Article 6(1) is the product route — an AI system that is a safety component of, or is itself, a product covered by the Union harmonisation legislation in Annex I and subject to third-party conformity assessment. There is no Article 6(3) derogation from that route. See the safety-component question.
  • Article 6(2) is the Annex III route: "In addition to the high-risk AI systems referred to in paragraph 1, AI systems referred to in Annex III shall be considered to be high-risk." This is the route Article 6(3) derogates from.

If you are not sure which door you are at, the high-risk test walks through both. Before either door, check that the software is an AI system at all — see is your software actually an "AI system"?.

The test: four conditions, an open question, and a profiling override

Article 6(3), first subparagraph:

"By derogation from paragraph 2, an AI system referred to in Annex III shall not be considered to be high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making."

Second subparagraph:

"The first subparagraph shall apply where any of the following conditions is fulfilled:"

So at least one of four listed conditions must be met. If none is, the derogation is not available, and a general sense that your use is low-stakes does not stand in for one. What is not settled is whether the "significant risk" wording in the first subparagraph is a separate test on top of the conditions. We come to that below the table.

The four conditions

Article 6(3) condition The text What it turns on
(a) "the AI system is intended to perform a narrow procedural task" The task, not the domain. "Narrow" and "procedural" are both doing work.
(b) "the AI system is intended to improve the result of a previously completed human activity" A human did the thing first. The system refines the output.
(c) "the AI system is intended to detect decision-making patterns or deviations from prior decision-making patterns and is not meant to replace or influence the previously completed human assessment, without proper human review" Detecting patterns, with the prior human assessment left standing.
(d) "the AI system is intended to perform a preparatory task to an assessment relevant for the purposes of the use cases listed in Annex III" Preparation for the assessment, not the assessment.

Note what all four have in common: they are framed around intended purpose, not around observed outcomes or your internal risk appetite. If your own product page says the tool ranks candidates, condition (d) is a hard argument to run.

Is "no significant risk" a second test? Not settled

The text supports two readings of how the two subparagraphs fit together.

  • Two steps. This reading takes each subparagraph at its word. The first has its own condition (the system "does not pose a significant risk of harm"), and the second says the first "shall apply where" one of the four conditions is met. On this reading you need both, and meeting a condition is not enough on its own.
  • The conditions are the test. Meeting a condition is how a system shows that it does not pose a significant risk, and there is nothing further to assess.

The Commission's draft Article 6 guidelines, published for consultation on 19 May 2026, take the second reading. Paragraph 88 of the draft says the conditions "are exhaustive, but alternative", and adds: "There is no separate or independent assessment to determine whether the AI system poses a significant or any risk of harm besides those conditions." For the reasoning, the draft points to Recital 53 of the Act. That recital says a system that does not materially influence the outcome of decision-making "could include situations in which one or more of the following conditions are fulfilled". The same paragraph of the draft also limits the conditions in two ways. They "must be interpreted narrowly", and they must be read "in the light of the first sub-paragraph of Article 6(3) AI Act that the system should not materially influence the outcome of the decision".

That is the Commission's reading, and it is not final. The guidelines are still a draft, and the draft itself says (paragraph 6) that "The Guidelines are not binding" and that an authoritative interpretation may ultimately only be given by the Court of Justice of the European Union. They still carry weight in practice. Under Article 80(1), a market surveillance authority that doubts your classification evaluates the system "based on the conditions set out in Article 6(3) and the Commission guidelines".

Two things follow for your assessment, whichever reading prevails:

  • Show both. Name the condition you rely on, and explain why the system does not materially influence the outcome of decisions. An assessment that does both holds up under either reading.
  • Check the system around it. Paragraph 90 of the draft says that a system meeting a condition (its example is a narrow procedural task) "cannot benefit from that mechanism and will still be classified as high-risk if it forms part of a complex system where its combined intended purpose or joint outputs materially influence an individual decision within a high-risk use case". The same applies, in the draft's words, where the system is part of complex interconnected systems, such as agentic AI systems. On the draft's approach, split architectures are assessed as a whole (paragraph 75), so a module that would be exempt on its own is not automatically exempt inside your product.

The override that ends the conversation

"Notwithstanding the first subparagraph, an AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons."

That is an absolute override, and it sits outside the four conditions. If the system profiles natural persons, the derogation is unavailable no matter how narrow the task is. Run this question first — it is the fastest way to finish the analysis.

For the two sectors where this bites hardest, see HR and recruitment software and credit scoring and creditworthiness AI.

Taking the exit is a filing, not a silence

This is the part that surprises people. Article 6(4):

"A provider who considers that an AI system referred to in Annex III is not high-risk shall document its assessment before that system is placed on the market or put into service. Such provider shall be subject to the registration obligation set out in Article 49(2). Upon request of national competent authorities, the provider shall provide the documentation of the assessment."

Three duties, in order:

  1. Document the assessment — before placing on the market or putting into service, not afterwards when someone asks.
  2. Register under Article 49(2).
  3. Hand the documentation over on request from a national competent authority.

And Article 49(2):

"Before placing on the market or putting into service an AI system for which the provider has concluded that it is not high-risk according to Article 6(3), that provider or, where applicable, the authorised representative shall register themselves and that system in the EU database referred to in Article 71."

Article 71(4) then makes it public: with the exception of the secure non-public section under Article 49(4) (systems in Annex III points 1, 6 and 7, in the areas of law enforcement, migration, asylum and border control management) and real-world-testing registrations, "the information contained in the EU database registered in accordance with Article 49 shall be accessible and publicly available in a user-friendly manner. The information should be easily navigable and machine-readable."

So the practical shape of the derogation is: you decide you are out, and you say so on a public, machine-readable register — naming the condition you relied on. The exception is a system in one of those Annex III points 1, 6 or 7 areas: Article 49(4) puts its registration, including one under Article 49(2), in that secure non-public section and limits it to Annex VIII Section B points 1 to 5 and 8 (Article 49(4)(b) still also lists point 9, which the Omnibus deleted), so the condition relied on is not part of that entry.

What the Digital Omnibus changed: the filing got shorter

Regulation (EU) 2026/1744, the Digital Omnibus on AI, amended Annex VIII. Article 1, point (42) of that Regulation reads: "in Annex VIII, section B, points 7 and 9 are deleted".

Annex VIII Section B is the list of what a provider files under Article 49(2). Here is the before and after.

Point Original (Regulation (EU) 2024/1689) Now
1 Name, address and contact details of the provider Unchanged
2 Details of the person filing on the provider's behalf, where applicable Unchanged
3 Details of the authorised representative, where applicable Unchanged
4 Trade name and any additional unambiguous reference allowing identification and traceability Unchanged
5 A description of the intended purpose of the AI system Unchanged
6 "The condition or conditions under Article 6(3) based on which the AI system is considered to be not-high-risk" Unchanged
7 "A short summary of the grounds on which the AI system is considered to be not-high-risk in application of the procedure under Article 6(3)" Deleted
8 Status of the AI system (on the market or in service; no longer placed on the market/in service; recalled) Unchanged
9 "Any Member States in which the AI system has been placed on the market, put into service or made available in the Union" Deleted

Nine fields became seven. The two that went are the narrative one and the geographic one.

That matters more than the field count suggests. The deleted point 7 was the only part of the public entry that asked you to explain yourself — to write out, for anyone to read, why your system qualifies under Article 6(3). What survives is point 6: the bare condition or conditions you relied on. The reasoning stays private, in the Article 6(4) documentation, available to national competent authorities on request.

The legislator said why

Recital (22) of Regulation (EU) 2026/1744:

"To streamline compliance and reduce associated costs, the registration of AI systems referred to in Article 6(3) of Regulation (EU) 2024/1689 in the EU database pursuant to Article 49(2) of that Regulation should be simplified by streamlining the content required under Annex VIII to that Regulation. While it remains crucial for effective market surveillance and public accountability that such AI systems are registered in the EU database, the registration requirements should be simplified and made more proportionate."

The same recital is explicit that the underlying duty survives the simplification: a provider applying Article 6(3) "remains obligated to document its assessment before that AI system" is placed on the market.

Read plainly: the filing got lighter, the register stayed, and the documentation duty did not move. If you were hoping the Omnibus quietly removed the public entry for not-high-risk systems, it did nearly the opposite — it reaffirmed the entry while trimming it.

The dates, and one thing to watch

Article 113 as amended by the Digital Omnibus:

Provision Where it sits Applies from
Article 4 AI literacy, Article 5 prohibitions Chapters I and II 2 February 2025 (two new Article 5 prohibitions from 2 December 2026)
Notifying authorities and notified bodies (Articles 28–39) Chapter III, Section 4 2 August 2025
Articles 6 and 7 — classification Chapter III, Section 1 2 December 2027 (Annex III) / 2 August 2028 (Annex I)
High-risk requirements (Articles 8–15) Chapter III, Section 2 Same as above
Provider and deployer obligations (Articles 16–27) Chapter III, Section 3 Same as above
Article 50 transparency Chapter IV 2 August 2026 (generative AI systems placed on the market before that date have until 2 December 2026 for Article 50(2), under Article 111(4))

Two details in that table are worth pausing on.

First, Article 113(c) carves one provision out of the deferral by name: Chapter III Sections 1, 2 and 3 apply from those 2027 and 2028 dates "with the exception of Article 6(5)". Article 6(5) is the Commission's own duty, and we come back to it below.

Second, the deferral is drafted by reference to Sections 1, 2 and 3 of Chapter III. Recital (40) of Regulation (EU) 2026/1744 uses the same formulation: "it is appropriate that the date of application of Sections 1, 2 and 3 of Chapter III is set to 2 December 2027…". Article 49 does not sit in any of those Sections — it sits in Section 5 (Standards, conformity assessment, certificates, registration; Articles 40–49), which Article 113 does not name, and which therefore falls under the Regulation's general rule: "It shall apply from 2 August 2026."

We flag that as a reading of the text, not as a compliance instruction. A registration duty drafted to attach to a classification decision under a provision that does not yet apply is an odd thing to act on, and, as of 29 September 2026, we have found no Commission guidance on the sequencing: the section of the Commission's draft Article 6 guidelines on entry into application says that Article 6(2) "and the corresponding obligations for high-risk AI systems classified under that provision" move to 2 December 2027, and Article 6(1) to 2 August 2028, but it does not mention Article 49. Treating registration as deferred to 2 December 2027, alongside Article 6, is an inference from that sequencing, not what Article 113 says on its face. If you would rather have that discrepancy resolved than assumed, we will tell you when it is.

For the wider picture of what moved and what did not, see the deadline that was delayed to 2027 and the full timeline.

The guidelines you were promised are late

Article 6(5) is the provision that was supposed to make all of this easy:

"The Commission shall, after consulting the European Artificial Intelligence Board (the 'Board'), and no later than 2 February 2026, provide guidelines specifying the practical implementation of this Article in line with Article 96 together with a comprehensive list of practical examples of use cases of AI systems that are high-risk and not high-risk."

That is a date in the binding text, and the Digital Omnibus deliberately did not move it — Article 113(c) excepts Article 6(5) from the deferral of Section 1.

As of 30 September 2026, the guidelines are still a draft. The Commission published the draft on 19 May 2026 for a targeted stakeholder consultation, which was extended by four weeks and ran until 23 July 2026. The Commission's policy page for the guidelines, last updated 6 July 2026, says feedback will be incorporated "in the final version of the guidelines before adoption by the Commission". Its consultation page says "The final guidelines will be adopted by the end of 2026". No more specific date has been given. The 2 February 2026 date in Article 6(5) is already more than seven months past.

The practical consequence is specific: the comprehensive list of practical examples of high-risk and not-high-risk use cases — the artefact designed to tell you whether your narrow procedural task really is one — exists only as a draft, published for consultation on 19 May 2026, and has not been adopted. Anyone relying on Article 6(3) today can read the draft, but cannot rely on a final Commission position.

The draft is still the most useful thing to read before you write your assessment. Its Annex III part has a section on the Article 6(3) "filter" and goes through all eight Annex III areas with examples of systems that fall inside or outside each use case, or that may be exempted under Article 6(3). The Commission says the examples "strive to cover all areas and use cases" but are not exhaustive and may be updated over time.

As at 29 September 2026, the Commission's AI Act Service Desk page for Article 6 still displays the pre-Omnibus text, under a notice: "This provision has been amended by the Digital Omnibus on AI. The text displayed on this page has not yet been updated to reflect those amendments." The Service Desk now shows that same notice on every article page we checked, including Article 49, which the Omnibus did not amend — so the notice on its own does not tell you whether a provision changed.

What happens if you get it wrong

Be careful with the fine question here, because the Act is less tidy than the headlines.

Article 99(4) sets the EUR 15 million / 3% tier and lists the provisions it covers: Article 16 (provider obligations), Article 22 (authorised representatives), Article 23 (importers), Article 24 (distributors), Article 25(2) and (4), Article 26 (deployers), notified-body requirements, and Article 50. Article 49 is not named in that list. It is reached only indirectly: through Article 16(i), which requires providers of high-risk systems to "comply with the registration obligations referred to in Article 49(1)", through Article 22(3)(e), which points authorised representatives to the same Article 49(1), and through Article 26(8), which covers deployers that are public authorities or Union bodies. None of those routes reaches the Article 49(2) registration of a system its provider has concluded is not high-risk.

That does not make Article 49(2) unenforceable. Article 99(1) requires Member States to lay down rules on penalties and other enforcement measures "applicable to any infringement of this Regulation by operators", which must be "effective, proportionate and dissuasive". National law fills the gap, and it will vary between Member States. The exception is an AI system the AI Office supervises under Article 75(1) — broadly, one built on a general-purpose AI model by the same provider, or one that is or is integrated into a very large online platform or search engine: there, Article 75c(4) makes "infringement of any applicable provision of this Regulation, including those not listed in Article 99(4)" subject to Article 99(4) fines. See the full fine structure for the tiers, and who actually enforces the Act for the authorities involved.

The more realistic exposure is not the registration field at all. It is the Article 6(3) call itself, and the Act has a dedicated procedure for it. Under Article 80, a market surveillance authority that has sufficient reason to consider that a system its provider classified as non-high-risk under Article 6(3) is in fact high-risk evaluates it against the Article 6(3) conditions and the Commission guidelines. If it finds the system is high-risk, it requires the provider to bring the system into compliance with the Regulation's requirements and obligations, and to take appropriate corrective action, within a period it may prescribe (Article 80(2)). The provider is subject to fines under Article 99 if it does not bring the system into compliance within that period (Article 80(4)), or if the authority establishes that the system was misclassified as non-high-risk in order to circumvent the Chapter III, Section 2 requirements (Article 80(7)). And Article 80(8) lets authorities carry out checks taking into account, in particular, the information stored in the EU database, which is where your Article 49(2) entry sits.

What to do now

  1. Separate the two doors. Confirm whether Annex III is why you are in scope. If it is Article 6(1), Article 6(3) is not available to you.
  2. Run the profiling question first. If the system profiles natural persons, the derogation is unavailable and nothing else in Article 6(3) helps.
  3. Name the condition, in writing. Point 6 of Annex VIII Section B asks which of the four conditions you relied on. If you cannot pick one cleanly today, that is the answer.
  4. Write the assessment now, not at filing time. Article 6(4) requires it before placing on the market. The Omnibus removed the public summary; it did not remove the document, and that document is what a national authority will ask for. Make it show both which condition applies and why the system does not materially influence the outcome of decisions, so it holds up under either reading of Article 6(3).
  5. Check your intended-purpose paper trail. Instructions for use, technical documentation and promotional material all describe the intended purpose. Marketing copy that overclaims can undo a careful assessment.
  6. Plan for a public entry. Your company name, the system, its intended purpose and the condition you relied on are destined for a machine-readable public register, unless the system falls under the Article 49(4) non-public section described above. Competitors, journalists and researchers will be able to read it in bulk.
  7. Read the draft guidelines, and watch for the final version. The Article 6(5) list of practical examples is the artefact that will move a lot of these calls. It exists in draft and is worth reading now. The final, adopted version is overdue; the Commission's consultation page says it will be adopted by the end of 2026.

One related watch item if you build high-risk AI: EN 18286:2026, the first AI Act harmonised standard, is published but still has no reference in the Official Journal, so it confers no presumption of conformity under Article 40 today. As at 28 September 2026, no reference to it had been published in either the L or the C series of the Official Journal. What EN 18286 does and does not give you.


Primary source: Regulation (EU) 2024/1689, read in the consolidated version as at 27 July 2026, as amended by Regulation (EU) 2026/1744.

Reglog is an information service that tracks changes to the EU AI Act and tells you which ones touch your obligations. It is not legal advice, and it does not create a lawyer–client relationship. For a decision with consequences, take qualified advice on your specific facts.

Frequently asked questions

What are the four Article 6(3) conditions, and do I need to meet all of them?

At least one, not all. Article 6(3) of the EU AI Act says an Annex III system is not high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making, and that this applies where any of four conditions is met: a narrow procedural task, improving the result of a previously completed human activity, detecting decision-making patterns or deviations from prior patterns where the system is not meant to replace or influence the previously completed human assessment without proper human review, or performing a preparatory task to an assessment relevant to an Annex III use case. If no condition is met, the derogation is not available. How the conditions relate to the 'significant risk' wording is not settled. The Commission's draft Article 6 guidelines, published for consultation on 19 May 2026 and not yet adopted, treat meeting one condition as sufficient, with no separate or independent risk assessment, but say the conditions must be interpreted narrowly and in the light of the 'not materially influencing' wording. A system that performs profiling of natural persons is always high-risk regardless.

Do I have to register an AI system that I decide is not high-risk?

Article 6(4) says a provider who considers that an Annex III system is not high-risk must document the assessment before the system is placed on the market or put into service, is subject to the registration obligation in Article 49(2), and must provide the documentation to national competent authorities on request. Article 49(2) requires that provider to register itself and the system in the EU database under Article 71, which Article 71(4) makes publicly available and machine-readable, except where Article 49(4) requires registration in a secure non-public section (Annex III points 1, 6 and 7, in the areas of law enforcement, migration, asylum and border control management). When that duty starts to apply is less clear than it looks; see the timing question below.

What information goes into the EU database for a not-high-risk Annex III system?

Annex VIII, Section B. As amended by Regulation (EU) 2026/1744, it lists seven items: the provider's details, the details of anyone filing on its behalf, the authorised representative's details, the system's trade name and reference, a description of the intended purpose, the condition or conditions under Article 6(3) relied on, and the system's market status. The Omnibus deleted the former point 7 (a short summary of the grounds) and point 9 (the list of Member States).

When does the Article 6(3) derogation start to matter?

Article 113, as amended by the Digital Omnibus, applies Chapter III Sections 1, 2 and 3 (Articles 6 to 27; Section 1 contains Articles 6 and 7) from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. Article 6(5), the Commission's duty to issue guidelines, is expressly carved out of that deferral. Note that the deferral in Article 113 is drafted by reference to Sections 1, 2 and 3 only; Section 5, which contains the registration provision in Article 49, is not named in it.

See which obligations apply to your company → or join the waitlist

This is an information service, not legal advice.