← All articles

EU AI Act Article 6(3): The High-Risk Exemption That Could Get You Fined

· Updated
Article 6(3) is likely to be one of the most litigated provisions in the Act AI-GENERATED IMAGE
Article 6(3) is likely to be one of the most litigated provisions in the Act

If your AI system falls within one of the Annex III high-risk use cases, there is a way out. Article 6(3) of the EU AI Act says an Annex III system “shall not be considered to be high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons.”

On first reading, this looks like a generous escape hatch. Read it again. The exemption is narrow, the assessment sits with the provider, and the consequences of getting it wrong are measured in millions of euros and months of retrospective compliance work. The phrase “significant risk” is undefined. Article 6(3) is likely to be one of the most litigated provisions in the Act.

What Article 6(3) actually says

The provision disapplies high-risk classification for Annex III systems that meet one or more of four conditions:

(a) A narrow procedural task. The system performs a limited, well-defined procedural step, such as converting unstructured data into a structured format or detecting duplicates in a dataset.

(b) Improving a previously completed human activity. The system’s role is to enhance or refine output that a human has already produced. The human did the work; the AI polishes it.

(c) Detecting decision-making patterns or deviations. The system identifies patterns or deviations in prior decision-making but is not meant to replace or influence the previously completed human assessment without proper human review.

(d) A preparatory task. The system performs a preparatory step to an assessment relevant to an Annex III use case, such as gathering information, formatting inputs, or pre-sorting. It does not make the assessment itself.

If any one of these fits, the Annex III system escapes high-risk classification.

The profiling carve-out

Here is the part most summaries of Article 6(3) bury. The final subparagraph states that an AI system referred to in Annex III shall always be considered high-risk where it performs profiling of natural persons.

There is no exemption. There is no careful reading of the four conditions. If your system profiles people and it operates in an Annex III area, it is high-risk. Full stop.

This carve-out cuts through a lot of the exemption arguments businesses are tempted to make. Employment screening tools, creditworthiness models, insurance risk scoring, and most people-analytics systems involve profiling almost by definition. The exemption is not available to them.

The documentation trap

A common misreading of Article 6(3) is that claiming the exemption means you have no obligations. This is wrong.

Under Article 6(4), a provider who considers that its Annex III system is not high-risk must document its assessment before the system is placed on the market or put into service. The documentation must be provided to national competent authorities upon request.

Under Article 49(2), providers that apply the Article 6(3) exemption are still required to register the system in the EU database before placing it on the market. The registration identifies the system, the provider, and the grounds for the exemption.

In other words, you cannot quietly decide you are exempt. You must produce a written assessment, file it, and expose it to regulator review. If the assessment is thin, wishful, or unsigned, the exemption will not survive contact with a market surveillance authority.

Why “significant risk” is the real problem

The phrase “significant risk of harm to the health, safety or fundamental rights of natural persons” is undefined in the Act. It is the hinge on which the entire exemption turns, and there is no bright-line test.

Article 6(5) asks the European Commission to fix this. It empowers the Commission to publish guidelines on how Article 6 works in practice, including a list of examples that are high-risk and examples that are not. The Act set a deadline of 2 February 2026, and the Commission missed it. It has since published draft guidelines, released on 19 May 2026 in three documents. One of them carries the list of high-risk and not-high-risk examples, and you can read it now in the Commission’s online Guidelines Explorer or as downloadable PDFs.

But this is still only a draft. Public consultation runs until 23 July 2026, and even once adopted the guidelines will be illustrative rather than binding. So for now there is no authoritative test for what counts as “significant risk”.

So providers end up self-certifying that their own system does not pose a significant risk. That is not a neutral judgement. The alternative is a six-figure compliance programme, and everyone knows it.

This is where most Article 6(3) claims will fail in practice. Not because the four conditions were wrong, but because the underlying “significant risk” judgement was optimistic.

The cost of being wrong

Misclassifying a high-risk system as exempt does not just mean you skipped some paperwork. It means every Chapter III Section 2 obligation was breached from the moment the system was placed on the market:

Every one of these is a separate breach. Penalties under Article 99 for non-compliance with the high-risk obligations run to €15 million or 3% of global turnover, whichever is higher.

Market surveillance authorities can also reclassify the system retrospectively under Article 79 and require withdrawal, recall, or corrective action. If the system has been in the market for a year when this happens, the remediation bill is not small.

The Commission can change the goalposts

Article 6(4) second subparagraph lets the Commission adopt delegated acts that amend the conditions of the exemption, adding new ones or removing existing ones. It can do this wherever there is concrete evidence that Annex III systems are being wrongly treated as not high-risk.

The practical effect is simple. An exemption that is defensible today may not be defensible in two years. Build your compliance posture on the assumption that Article 6(3) applies forever, and you are building on sand.

How to think about Article 6(3)

The exemption is real, and it exists for a reason. The Act is not trying to sweep narrow procedural tools and preparatory pipelines into the same category as hiring algorithms and credit scoring models. If your system is genuinely a narrow procedural tool, claim the exemption.

But treat it as a last resort, not a first filter:

1. Default to high-risk. If the system touches an Annex III use case, assume high-risk compliance is required. Only deviate from that default with explicit analysis.

2. Rule out the profiling carve-out first. Before assessing the four conditions, confirm the system does not profile natural persons. If it does, the analysis stops there.

3. Apply the four conditions narrowly. “Improves a previously completed human activity” does not mean “is used somewhere in a process where humans also work.” The human must have completed the activity; the AI must refine the output.

4. Document the significant-risk assessment. The four conditions sit on top of the “not a significant risk” judgement. Your documentation should cover two things. First, why the system fits one of the four conditions. Second, why it does not pose a significant risk to health, safety, or fundamental rights, given how it is actually deployed.

5. Register, even if exempt. Article 49(2) requires database registration. This is often overlooked and is an easy breach to identify on audit.

6. Get legal sign-off. For any Annex III system where the business consequence of high-risk classification is significant, the Article 6(3) decision warrants a written legal opinion. A thorough, signed assessment survives regulator challenge. A product manager’s judgement call does not.

Where this leaves you

Article 6(3) is not a loophole. It is a narrow, documented, reviewable, and contingent exemption. It trades some compliance work today for the risk of catastrophic non-compliance tomorrow. Organisations that lean on it casually, because compliance is expensive and the conditions are vague, are the ones most likely to end up as the case law that tightens it.

The safe posture is to treat the exemption as available only when you can prove, in writing, that it applies. Everything else is high-risk until a lawyer says otherwise.

Frequently asked questions

What is the Article 6(3) high-risk exemption?

Article 6(3) says an Annex III system is not high-risk where it does not pose a significant risk of harm to people's health, safety or fundamental rights, provided it meets at least one of four conditions: it performs a narrow procedural task; it improves the result of a previously completed human activity; it detects patterns or deviations in prior decision-making without replacing or influencing the human assessment; or it performs a preparatory task for an assessment. The phrase 'significant risk' is left undefined, which is where most exemption claims come unstuck.

Does profiling rule out the Article 6(3) exemption?

Yes. The final subparagraph of Article 6(3) states that an Annex III system is always high-risk where it performs profiling of natural persons, with no exemption available. Employment screening, creditworthiness scoring, insurance risk models and most people-analytics systems involve profiling almost by definition, so the exemption is closed to them. Rule out profiling before you even assess the four conditions.

If I claim the exemption, do I still have obligations?

Yes. Under Article 6(4) a provider that decides its Annex III system is not high-risk must document that assessment before placing the system on the market, and provide it to national authorities on request. Under Article 49(2) the provider must still register the system in the EU database. You cannot quietly decide you are exempt. You must produce a written, reviewable assessment and file it.

What happens if I classify a high-risk system as exempt and I am wrong?

Every Chapter III obligation you skipped counts as breached from the moment the system was placed on the market. That means risk management, data governance, technical documentation, conformity assessment, post-market monitoring, and incident reporting. Penalties under Article 99 for non-compliance with the high-risk requirements reach 15 million euros or 3% of global turnover, and a market surveillance authority can reclassify the system under Article 79 and order its withdrawal.

Written by
John Pitchers
John Pitchers
Founder, ComplyDrive

John holds editorial responsibility for all ComplyDrive content.

About the author →
The Toolkit

The 47-item checklist, an editable tracker, nine sample documents and nine fill-in templates.

Get the Toolkit

Free worked document

Get a complete Article 26 AI System Register, free.

One of the nine worked documents from the toolkit. A finished Article 26 AI System Register for a high-risk AI deployment, completed end-to-end so you can see exactly what a completed register looks like instead of starting from a blank page. Enter your email and we'll send you the download link. Unsubscribe at any time.