EU AI ACT · OPERATING ENVIRONMENTKnow what applies · prove why · preserve change? LEARN THIS PAGE
EU AI ACT · ARTICLE 6 · HIGH-RISK AI
HIGH-RISK AI STARTS WITH THE CLASSIFICATION BASIS.
The hardest part of high-risk AI governance is not memorizing a list of requirements. It is proving why the system is or is not on a high-risk route, which actor obligations follow, what evidence supports each requirement, and whether that evidence still holds after the system changes.
Article 6 defines the high-risk classification routes. The Regulation also requires documented support when a provider concludes that an Annex III system is not high-risk under Article 6(3). The Commission published draft high-risk classification guidance in May 2026 to support practical application.
Start with the actual system, role, use case and evidence boundary. The same regulation can produce different obligations for different actors and systems.
01
DOES ARTICLE 6 PUT THE SYSTEM ON A HIGH-RISK ROUTE?
Check whether the AI is a safety component or regulated product under Annex I, or whether its intended use falls into an Annex III category. Do not assume “important” means high-risk or that “not dangerous” automatically means excluded.
02
IS AN ARTICLE 6(3) EXCLUSION ACTUALLY SUPPORTABLE?
Some Annex III systems may not be high-risk if they do not pose a significant risk of harm and meet one of the listed conditions. The provider must document that assessment before market placement or putting into service.
03
WHAT HIGH-RISK REQUIREMENTS APPLY TO THIS ACTOR?
Map the relevant duties to the actual role and system, including risk management, data governance, technical documentation, records, transparency, human oversight, accuracy, robustness and cybersecurity.
04
WHAT EVIDENCE PROVES THE CURRENT POSITION?
Preserve the intended purpose, classification basis, versions, tests, risk controls, instructions, oversight design, performance evidence and any revalidation triggers. A label without the underlying record is fragile.
THE TA-14 OPERATING ROUTE
Turn the question into a governed record.
The goal is not merely to reach an answer. It is to preserve what facts, evidence, scope and limitations supported that answer at that time.
01
Classify the route before building a compliance package
Establish the product context, Annex I or Annex III pathway, intended purpose, actor role and any claimed Article 6(3) exclusion before treating high-risk obligations as fixed.
02
Bind each requirement to the evidence that supports it
Map risk-management records, testing, technical documentation, logs, instructions, human-oversight controls, accuracy, robustness and cybersecurity evidence to the specific proposition they support.
03
Preserve unresolved and conditional states
If classification depends on missing facts, pending guidance, product integration or an unproven exclusion, keep the determination conditional rather than silently converting uncertainty into a compliance claim.
04
Revalidate after material change
Changes to intended purpose, model, data, product integration, authority, deployment context or legal-source state can change classification or make prior evidence insufficient.
READY TO OPERATE · START PAID ACCESS NOW
Move from reading about the EU AI Act to maintaining the record.
Choose the smallest operating tier that fits the portfolio today. Upgrade when system count, team size or governance scope actually requires it.
1–3 AI systems
Evidence Passport
$19/MO
Keep a living system-level evidence record with obligations, gaps, versions and revalidation state.
Use the free classifier to establish the system, intended purpose, possible actor role, EU exposure and unresolved facts. When continuing evidence infrastructure is needed, paid access begins at $19 per month. Independent human readiness review remains a separate service.
What makes an AI system high-risk under the EU AI Act?
Article 6 establishes two principal routes: certain AI systems tied to regulated products under Annex I, and systems listed in Annex III. The exact classification depends on intended purpose and the conditions in Article 6.
Are all Annex III systems automatically high-risk?
Not always. Article 6(3) provides a limited route for some Annex III systems not to be treated as high-risk where they do not pose a significant risk of harm and one of the listed conditions applies. Profiling systems in Annex III remain high-risk.
If we say our Annex III system is not high-risk, do we need documentation?
Yes. Article 6(4) requires a provider relying on the Article 6(3) route to document the assessment before placing the system on the market or putting it into service.
What are the main requirements for high-risk AI systems?
The Regulation’s high-risk section includes requirements covering risk management, data and data governance, technical documentation, record-keeping, transparency and instructions, human oversight, and accuracy, robustness and cybersecurity.
Are the Commission high-risk classification guidelines final?
As of August 2026, the Commission has published draft guidelines on high-risk classification. They are useful interpretive material, but the Regulation itself remains the controlling legal text.
Does using TA-14 prove that our high-risk AI system complies?
No. TA-14 can preserve the classification basis, evidence, gaps, reviews and revalidation history. It does not itself provide legal advice, conformity assessment, certification or regulatory approval.
EU AI ACT WORLD · TA-14 AUTHORITY GOVERNANCE INSTITUTION
Understand the requirement. Preserve the evidence. Revalidate when reality changes.