Template · Article 6 and Annex III · Annex III high-risk obligations apply from 2 December 2027
EU AI Act Risk Assessment Template (Article 6 & Annex III)
An EU AI Act risk classification assessment is the documented determination of whether an AI system is prohibited, high-risk or neither under Article 6 and Annex III of Regulation (EU) 2024/1689 (as amended by Regulation (EU) 2026/1744). It is the single most consequential compliance decision under the Act, because it determines whether the high-risk obligations — technical documentation, risk management, human oversight, conformity assessment — apply at all. Annex III high-risk obligations apply from 2 December 2027; AI in Annex I Section A regulated products follows from 2 August 2028; a provider relying on the Article 6(3) derogation must document the assessment (Article 6(4)) and register under Article 49(2).
Last reviewed: 26 August 2026 · Annex III high-risk obligations apply from 2 December 2027 · Included in the kit as 14_Risk_Classification_Assessment.docx
What this document is
Document 14 of the RegShelf kit is a step-by-step classification assessment, completed once per AI system before it is placed on the market or put into service: describe the system and its intended purpose, confirm it passes the prohibited practices check, screen it against the eight Annex III areas, and — only if an area matches — run the Article 6(3) derogation test. The intended purpose you record in Section 1 anchors the whole assessment: you classify the system as it will actually be marketed or used, not as it might be used in theory. The completed record is your Article 6(4) documentation, which a market surveillance authority may request.
Who needs it
Providers, before placing any system on the market — and deployers, because your duties from 2 December 2027 depend on whether the tools you use are high-risk (the template's worked example is a deployer classifying a vendor CV-screening tool). The Annex III areas that most often catch SMEs are employment (recruiting and worker management), education, creditworthiness and essential services, and biometrics. If your system is instead a safety component of a regulated product, it follows the separate Annex I track under Article 6(1) — noting two Digital Omnibus changes: the safety-component definition (Article 3(14)) is narrowed to functions whose intended purpose is to prevent or mitigate health-and-safety risks (user-assistance and convenience functions are excluded), and machinery under Regulation (EU) 2023/1230 moved to Annex I Section B, out of the Section A conformity path.
What the law requires — precisely
The mechanics SMEs most often get wrong:
- The Article 6(3) derogation is available across Annex III — including area 1, biometrics — where the system does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing decision outcomes, and one of four conditions is met: narrow procedural task, improving a completed human activity, detecting patterns or deviations without replacing human assessment, or a purely preparatory task.
- Profiling is an absolute gate. A system in an Annex III area that performs profiling of natural persons (in the GDPR sense) is always high-risk — no derogation.
- "Not high-risk" is not "nothing to file". The Digital Omnibus retained Article 49(2): a provider concluding under Article 6(3) that its Annex III-area system is not high-risk must still register the system and a summary of the assessment in the EU database before market placement.
- "Minimal/limited risk" is explanatory vocabulary, not a statutory category — and Article 50 transparency duties apply to systems that interact with people or generate content regardless of risk class.
What's inside the RegShelf template
Seven sections with eight fill-in tables:
- System description — ten fields including intended purpose, outputs, affected persons and degree of automation, with a worked CV-screening example;
- Prohibited practices gate — confirmation that the doc 10 screen returned "not prohibited" before classification starts;
- Annex III screening table — all eight areas as plain "does the system…" questions, from biometrics to justice and democratic processes;
- The Article 6(3) test — the profiling gate first, then the four conditions in plain terms, then a reasoned-conclusion box (half a page is typical) that becomes your Article 6(4) documentation;
- Registration section — Article 49(1) for high-risk outcomes, Article 49(2) for self-assessed non-high-risk outcomes;
- Classification decision record with sign-off and the deadline that follows, and six re-assessment triggers (purpose change, substantial modification, profiling starts, Annex III amendments, incidents, annual review).
How to use it
Run one assessment per system from your inventory, in order — the prohibited check comes first because a banned system needs no classification. Write the Section 4 reasoning as if an authority will read it, because it may (Article 6(4)). A high-risk outcome activates the preparation documents of the kit: Annex IV technical documentation, risk management, data governance, human oversight and test logs — start well before 2 December 2027, not at it. Re-run the assessment on any of the Section 7 triggers.
Related reading
- Annex IV Technical Documentation template
- Prohibited-Practices Screening template
- Timeline & deadlines
- Article 50 transparency
Frequently asked
How do I know if my AI system is high-risk under the EU AI Act?+
Two routes: it is a safety component of (or is itself) a product regulated under Annex I, or its intended purpose falls into one of the eight Annex III areas — biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice and democratic processes. An Annex III match can still escape high-risk status via the Article 6(3) derogation if the system poses no significant risk and meets one of four narrow conditions — but never if it performs profiling.
When do the high-risk AI obligations apply?+
For Annex III systems, from 2 December 2027 (moved by the Digital Omnibus, Regulation (EU) 2026/1744). For AI in Annex I Section A regulated products such as medical devices, from 2 August 2028. Machinery sits in Annex I Section B since the Omnibus and follows the machinery framework rather than the Section A conformity path.
Can a biometric AI system use the Article 6(3) derogation?+
In principle yes — there is no general exclusion of Annex III point 1 (biometrics) from the derogation, provided one of the Article 6(3)(a)–(d) conditions is met. But a system that performs profiling of natural persons is always high-risk, and remote biometric identification itself will rarely satisfy the conditions. Document the assessment and register under Article 49(2).
Do we have to register a system we concluded is not high-risk?+
Yes, if the conclusion rests on the Article 6(3) derogation for an Annex III-area system: Article 49(2) — retained by the Digital Omnibus — requires the provider to register the system and a summary of the assessment in the EU database before placing it on the market.
Primary sources
- Regulation (EU) 2024/1689 (consolidated)
- Regulation (EU) 2026/1744 (Digital Omnibus on AI)
- AI Act Explorer — Article 6 (classification rules)
This template ships in the EU AI Act Kit
24 fill-in documents in Word and Excel — launch price €149, twelve months of updates included.
See the full kit