Why is classification the most consequential decision under the AI Act?
Because classification decides whether your compliance burden is one page or a hundred. For a minimal-risk system the whole obligation is a single reasoned note. For a high-risk system you get a risk management system, data governance, technical documentation, logging, human oversight, conformity assessment and CE marking, all at once.
Every AI Act project either goes wrong or goes right at this step. Companies that declare everything high risk burn six figures on paperwork nobody asked for. Companies that declare everything minimal find out they were wrong when a market surveillance authority asks. The correct answer usually sits somewhere in between, and it differs system by system inside the same company.
There is a second reason this matters more in 2026 than it did two years ago: most European companies now run AI they did not build. The ifo Institute measured 54.5 percent of German companies using AI in May 2026, with the Mittelstand at 47.2 percent, and only 18.7 percent of users developing their own systems. Four out of five are deployers rather than providers, and that changes which obligations land on them and which ones stay with the vendor.
This article gives you a seven-question tree with article numbers and dates, then runs eight typical business systems through it. At the end you get the part most summaries skip: what you have to document when your system turns out not to be high risk.
When do the high-risk obligations actually apply?
Standalone Annex III high-risk systems have to comply from 2 December 2027, and high-risk systems embedded in Annex I products from 2 August 2028. That is not the original schedule. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026, six days before the previous deadline, and postponed Chapter III, Sections 1 to 3 by 16 months.
2027-12-02
Annex III high-risk systems, Chapter III Sections 1 to 3 (Art. 8 to 27)
Regulation (EU) 2026/1744
2028-08-02
High-risk systems embedded in Annex I products
Regulation (EU) 2026/1744
2026-08-02
Art. 50 transparency duties, the date that did take effect
AI Act Article 113
The postponement is not a general amnesty. Four things carry on unchanged, and two of them are enforceable today.
| Date | What applies | Moved by the omnibus? |
|---|---|---|
| 2025-02-02 | Art. 5 prohibited practices, Art. 4 AI literacy | No (Art. 4 wording softened) |
| 2025-08-02 | GPAI obligations (Art. 53 to 55), Art. 99 penalties, national authority designation | No |
| 2026-08-02 | Art. 50 transparency, Commission enforcement powers over GPAI | No |
| 2026-12-02 | Art. 50(2) marking for systems already on the market, end of the CSAM/NCII transition | New date |
| 2027-12-02 | Annex III high risk: Art. 8 to 27, including the Art. 27 FRIA | Yes, 16-month delay |
| 2028-08-02 | High-risk systems embedded in Annex I products | Yes, 12-month delay |
There is an awkward side effect. The Commission’s Art. 6 classification guidelines also slipped, to 2 August 2027. So you have to classify now, while the official interpretive aid arrives four months before the compliance deadline. That legal uncertainty is real and it is worth saying out loud rather than papering over.
How do you settle classification in seven questions?
The order of the tree is not arbitrary. First rule out what is prohibited, then what is high risk through the product-safety route, only then look at Annex III, then at the narrowing exceptions. By question seven you know whether any obligation remains at all. Run one system through it at a time, not your whole AI portfolio.
Question 1: does the system implement a prohibited practice?
Art. 5 lists eight prohibitions and the omnibus added a ninth. These have applied since 2 February 2025, so there is no preparation window here, only compliance or infringement.
| Legal basis | Prohibited practice |
|---|---|
| Art. 5(1)(a) | Subliminal, manipulative or deceptive techniques that distort behaviour and impair informed decision-making |
| Art. 5(1)(b) | Exploiting vulnerability based on age, disability, or social or economic situation |
| Art. 5(1)(c) | Social scoring, where it leads to disproportionate treatment or treatment outside the context of collection |
| Art. 5(1)(d) | Predicting criminal offending solely on the basis of profiling |
| Art. 5(1)(e) | Building facial recognition databases through untargeted scraping of the internet or CCTV footage |
| Art. 5(1)(f) | Emotion recognition in the workplace and in education, outside medical or safety purposes |
| Art. 5(1)(g) | Biometric categorisation to infer race, political opinion, trade union membership, religion or sexual orientation |
| Art. 5(1)(h) | Real-time remote biometric identification in public spaces for law enforcement, with three narrow exceptions |
| Art. 5, added by the omnibus | Generating or manipulating non-consensual intimate images (NCII) and child sexual abuse material (CSAM). Transition period until 2 December 2026 |
If any row matches your system, the tree ends here. The remedy is not documentation, it is shutting the feature down or redesigning it. Two rows tend to activate unexpectedly in ordinary companies: 5(1)(f) in video-interview or webcam sentiment analysis, and 5(1)(c) in employee or customer scoring systems where the score causes a detriment far removed from the original purpose of collection.
Question 2: is it a safety component of a product under Annex I harmonisation law?
Art. 6(1) sets two cumulative conditions. The system is a safety component of a product, or is the product itself, covered by one of the Union harmonisation acts listed in Annex I, and that product requires third-party conformity assessment. Machinery, medical devices, lifts, toy safety and vehicle type approval all sit here.
If you stop at this question, your system is high risk but your deadline is 2 August 2028. The omnibus also introduced a significant carve-out: AI built into machinery products is taken out of the high-risk regime, with the detail left to a Commission delegated act. That delegated act was not available in August 2026, so in manufacturing this question cannot be answered definitively yet.
Question 3: does it fall into one of the Annex III areas?
There are eight areas. For most private-sector companies areas three, four and five are the ones that bite, since the rest sit in public administration or law enforcement contexts.
| # | Annex III area | Typical business example |
|---|---|---|
| 1 | Biometrics | Facial recognition access control, voice-based caller identification, emotion recognition |
| 2 | Critical infrastructure | Safety component of an electricity, gas or district heating network, road traffic management, critical digital infrastructure |
| 3 | Education and vocational training | Admission ranking, automated exam marking, behaviour monitoring during online exams |
| 4 | Employment and worker management | CV pre-screening, targeting of job adverts, performance monitoring, promotion or termination recommendations |
| 5 | Access to essential services | Creditworthiness assessment outside fraud detection, life and health insurance pricing, social benefit eligibility, emergency call triage |
| 6 | Law enforcement | Recidivism risk scoring, evidence reliability assessment, investigative profiling |
| 7 | Migration, asylum and border control | Entry risk assessment, asylum application support, biometric identification at borders |
| 8 | Justice and democratic processes | Judicial decision support, systems intended to influence election outcomes |
If none of the areas applies, jump to question six. If one does, nothing is settled yet, because the derogation comes next.
Question 4: does the Art. 6(3) derogation apply?
Two things have to be true at the same time. The system must not pose a significant risk to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision-making. And one of the following four conditions has to hold.
- The system performs a narrow procedural task, such as sorting documents into categories or removing duplicates.
- The system improves the result of a previously completed human activity, such as rewording a decision rationale a person already wrote.
- The system detects decision-making patterns or deviations from them, and does not replace or influence the previously completed human assessment without proper human review.
- The system performs a preparatory task for an assessment listed in Annex III, such as assembling data for the decision maker.
In practice far more companies want to use this derogation than can. The decisive question is not whether a human makes the final call, it is whether the system’s output materially influences that call. A score, a ranking or a green-amber-red recommendation influences it, even when a person clicks Approve.
If you stop here, your system is not high risk, but it is not free of obligations either. Go to question five first, because the derogation may be excluded from the start.
Question 5: does the system perform profiling?
If an Annex III system performs profiling of natural persons, it is always high risk. The closing sentence of Art. 6(3) states this without qualification: no balancing exercise, and none of the four conditions rescues it.
Profiling here means the GDPR Art. 4(4) concept: automated processing of personal data to evaluate or predict characteristics of a natural person. A CV filter that matches candidates against the pattern of previously successful employees is profiling. A scoring model that categorises customers by payment behaviour is profiling. An OCR pipeline that pulls the invoice number out of a PDF is not.
Question 6: are there Art. 50 transparency duties?
This question catches systems that are neither prohibited nor high risk, plus high-risk systems that Art. 50 covers in parallel. Four situations matter, and all of them have applied since 2 August 2026.
- Art. 50(1): where a system interacts directly with a natural person, that person has to be informed they are dealing with AI, unless it is obvious from the circumstances.
- Art. 50(2): synthetic audio, image, video or text has to be marked in a machine-readable format. Systems already on the market before 2 August 2026 have until 2 December 2026.
- Art. 50(3): people exposed to an emotion recognition or biometric categorisation system have to be informed of its operation.
- Art. 50(4): deepfake content and AI-generated text published to inform the public on matters of public interest have to be labelled.
For most European SMEs this step is the only obligation that is already live. It is cheap to implement, and skipping it falls under the second fine tier of Art. 99.
Question 7: is anything left?
If you reached this point with no for every answer, your system is minimal risk and the AI Act imposes no specific obligations on it. That does not mean you have nothing to do. Art. 4 requires you to support the development of AI literacy among your staff, which the omnibus softened from an obligation of result to one of effort. And the GDPR runs on an entirely separate track, which is still where most disputes actually happen.
One thing is required even here: write down why you reached this conclusion. Our article on the AI Act documentation package goes through what that record looks like in more detail.
Where do eight typical business systems land on the tree?
Classification becomes concrete once you watch it operate on real systems. The eight below are the ones we meet most often at European companies between 50 and 500 employees. For each, what matters is where the tree stops, and what would tip it into another category.
1. Customer service chatbot on a webshop
Order status, delivery times, sizing advice. Not prohibited, not a safety component, and not in Annex III, because none of the eight areas covers commercial customer service. It stops at question six: Art. 50(1) disclosure that the user is talking to AI, plus Art. 50(2) machine-readable marking if the bot generates text. Classification: transparency risk, obligations live since 2 August 2026.
What would tip it? If the bot decided on credit or instalment payments, Annex III 5(b) would make it high risk. If it inferred emotion from a voice recording, the Art. 50(3) information duty would come in as well.
2. CV pre-screening tool
It enters at question three: Annex III point 4, recruitment and CV filtering. The question-four derogation is arguable if the system only checks formal criteria, such as eligibility requirements. The moment it scores or ranks, question five closes the debate: profiling, therefore high risk. Classification: high risk, applicable from 2 December 2027.
One important warning. If the tool analyses a candidate’s facial expression or voice in a video interview to infer emotional state, Art. 5(1)(f) makes it a prohibited practice today. The Regulation prohibits emotion recognition in the workplace context, and treating recruitment as part of that context is a defensible reading. We found no authority position on this point in Hungary, Germany or Austria as of August 2026, which is exactly why caution is warranted here.
3. Credit decisioning assistant
Annex III 5(b), creditworthiness assessment of natural persons, excluding fraud detection. No derogation, because the score materially influences the decision and because the system performs profiling. Classification: high risk from 2 December 2027, and the deployer also has to carry out the Art. 27 fundamental rights impact assessment, since 5(b) reaches private companies too.
A useful boundary: Annex III 5(b) speaks about natural persons. A corporate scoring model that only rates legal entities is outside it. If it also scores the managing director as a personal guarantor, it comes back in. For financial-sector high-risk AI in Hungary the central bank acts as sectoral supervisor, which we cover on our banking sector page.
4. Factory-floor quality inspection vision system
A camera system that rejects defective parts on the line. Not prohibited. Question two decides it: if the vision system is a safety component of the machine under the Machinery Regulation, it would be high risk via the Annex I route, deadline 2 August 2028. If it only performs quality sorting and does not affect machine safety, it drops out. Annex III does not apply, because it makes no decisions about natural persons. Classification: usually minimal risk.
Two complications. The omnibus takes AI embedded in machinery products out of the high-risk regime, with the detail deferred to a delegated act that has not been published. And if the same cameras also monitor how workers perform, Annex III point 4 can tip the system into high risk.
5. Invoice processing system
Incoming PDF invoice, data extraction, posting into the accounting system. Not prohibited, not a safety component, and outside every Annex III area. It performs no profiling, because a supplier’s tax number is not used to predict a characteristic of a natural person. Art. 50 does not apply either: no interaction, no published synthetic content. Classification: minimal risk.
This is the cleanest of the eight, and good news for most European process automation projects. Document processing, data migration and system integration work overwhelmingly lands in the same place.
6. Employee performance rating system
Annex III point 4, performance monitoring and support for decisions affecting the employment relationship. The derogation gets interesting here. A report that adds up output data already recorded is defensibly a narrow procedural task. A system that ranks colleagues against each other or assigns them a risk score performs profiling and is high risk. Classification: depends on how the system works, and the line runs between reporting and evaluation.
On the deployer side Art. 26 adds a separate rule: before putting a system into service in the workplace, you have to inform workers’ representatives and the affected workers. In Germany and Austria this lands on top of an existing works council regime, so in practice it is the first thing that will be raised internally, well before any authority looks at your file.
7. Exam grading system in education
Annex III point 3, evaluation of learning outcomes and monitoring behaviour during exams. A script that marks a multiple-choice test against a key is defensibly a narrow procedural task under 6(3)(a). A language model that scores an essay is not, because it materially influences the outcome. Classification: minimal for the former, high risk for the latter.
Proctoring is a separate question. If the system infers emotional state, it hits the Art. 5(1)(f) prohibition for education settings. If it only watches screen sharing and browser focus, it stays in the Annex III point 3 high-risk category. It is also unsettled whether the final assessment of an internal corporate training course counts as education and vocational training. If the result feeds a promotion decision, Annex III point 4 catches it anyway.
8. Marketing copy generator
Product descriptions, newsletters and ad copy from a large language model. Not prohibited, not in Annex III, no profiling. At question six the only thing that happens is Art. 50(4), which requires labelling of AI-generated text published to inform the public on matters of public interest. Marketing copy about your own product is not that. Classification: minimal risk.
Two exceptions. If you publish AI-generated or manipulated image, video or audio content depicting a real person or event, that is a deepfake and Art. 50(4) requires labelling. And the Art. 50(2) machine-readable marking duty sits with the provider of the generative system, not with you, as long as you are only a deployer of the tool.
| System | Where the tree stops | Classification | From when |
|---|---|---|---|
| Customer service chatbot | Question 6, Art. 50(1) | Transparency risk | 2026-08-02 |
| CV pre-screening | Question 5, profiling | High risk (Annex III 4) | 2027-12-02 |
| Credit decisioning assistant | Question 5, profiling | High risk plus Art. 27 FRIA | 2027-12-02 |
| Factory vision system | Question 2, usually no | Minimal, Annex I if a machine safety component | 2028-08-02 if Annex I |
| Invoice processing | Question 7 | Minimal | No AI Act obligation |
| Performance rating | Question 4 or 5 | Reporting minimal, scoring high risk | 2027-12-02 if it scores |
| Exam grading | Question 4, depends on task type | Test marking minimal, essay scoring high risk | 2027-12-02 if it scores |
| Marketing copy generator | Question 6, usually no | Minimal, Art. 50(4) for deepfakes | 2026-08-02 if deepfake |
What do you document if the system is not high risk?
If the system falls into an Annex III area but you classify it as not high risk by relying on the derogation, you pick up two obligations. Art. 6(4) requires the classification assessment to be documented before the system is placed on the market or put into service, and Art. 49(2) requires the system to be registered in the EU database.
This is the part that falls out of most summaries, even though it is effectively the entry level of AI Act compliance. The logic is straightforward: whoever invokes an exception has to evidence the basis for it. The omnibus reduced the registration to a lighter administrative footprint, but it did not remove it, even though the original Commission proposal would have deleted Art. 49(2) entirely.
A usable Art. 6(4) assessment contains the following.
- Identification of the system and its intended purpose, written in your own words rather than copied from the vendor datasheet.
- Which Annex III point came into play, and precisely why the intended purpose falls within its scope.
- Which of the four Art. 6(3) conditions you rely on, and which concrete operational fact supports it.
- The reasoning for why the system does not materially influence the outcome of decision-making. This is where you describe what the human decision maker sees, and how often they depart from the system’s suggestion.
- The exclusion of profiling of natural persons. This is the point where most assessments fall apart.
- The date, the name of the responsible person, and a commitment to redo the assessment when the intended purpose changes.
The assessment has to be handed to the national competent authority on request. If the system is high risk to begin with, you move on to Annex IV technical documentation, Art. 43 conformity assessment, Art. 47 declaration of conformity and Art. 48 CE marking. We break that package down on our high-risk AI checklist, and the shape of a classification and compliance project is described on our EU AI Act compliance page.
Who enforces this, and where?
Enforcement is national. Each Member State designates its own Art. 70 market surveillance authority and single point of contact, and the designation deadline itself passed on 2 August 2025. That means the answer differs depending on where your system is placed on the market, not on where your development team sits.
In Hungary the authority is the Artificial Intelligence Authority (Mesterséges Intelligencia Hivatal), designated under Act LXXV of 2025 and Government Decree 344/2025 (X. 31.). It is a ministerial organisational unit rather than a standalone agency. The notifying authority is the National Accreditation Authority, and in the financial sector the National Bank of Hungary acts as sectoral supervisor. The data protection authority (NAIH) is not an AI market surveillance authority; it acts in parallel under its own GDPR mandate.
For Germany and Austria we could not find a public source in our August 2026 research that names the designated Art. 70 authority, so we are not going to guess one. What we can say is how German implementation has behaved on the neighbouring file: the NIS2 implementation act was published in the Bundesgesetzblatt on 5 December 2025 and entered into force the following day, it covers roughly 30,000 companies, and the BSI states that the statutory registration deadline has already passed. If NIS2 is also on your plate, our NIS2 applicability quiz is a faster starting point than reading the act.
Fines come from Art. 99 and the tiers were not touched by the omnibus. Prohibited practices attract up to 35 million EUR or 7 percent of worldwide annual turnover, whichever is higher. Provider, deployer and Art. 50 transparency breaches attract up to 15 million EUR or 3 percent. Supplying incorrect or misleading information attracts up to 7.5 million EUR or 1 percent. Art. 99(6) inverts the logic for SMEs and startups, where the cap is the lower of the two figures, and the omnibus added a similar lower cap for small mid-caps, defined as under 750 employees and up to 150 million EUR turnover. That new category matters in the DACH market, where a lot of Mittelstand companies sit above the SME thresholds but well below large-enterprise scale.
Two things are worth stating plainly. We found no public source confirming that Hungary has aligned Act LXXV of 2025 or Decree 344/2025 to the postponed deadlines after the omnibus entered into force on 27 July 2026, so the national rules currently rest on the old application logic. And there is no known AI Act fining practice in Hungary as of August 2026; the authority runs an information and complaints function. Anyone claiming today that they know how strictly a given national authority will read Art. 6 is speculating. The overlap between the GDPR and the AI Act is covered in our earlier article.
Summary and frequently asked questions
Did the 2 August 2026 high-risk deadline move?
Yes. The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and postponed Chapter III, Sections 1 to 3 (Art. 8 to 27) to 2 December 2027. High-risk systems embedded in Annex I products moved to 2 August 2028. What actually became applicable on 2 August 2026 was the Art. 50 transparency set.
What makes an AI system high risk?
Two routes. Under Art. 6(1) the system is a safety component of a product, or is the product itself, covered by the Union harmonisation law listed in Annex I, and that product needs third-party conformity assessment. Under Art. 6(2) the system falls into one of the eight areas listed in Annex III.
When can you rely on the Article 6(3) derogation?
When an Annex III system poses no significant risk to the health, safety or fundamental rights of natural persons, and one of four conditions holds: it performs a narrow procedural task, it improves the result of a previously completed human activity, it detects deviations from decision patterns without replacing human assessment, or it performs a preparatory task.
Why is a system that performs profiling always high risk?
Because the closing sentence of Art. 6(3) removes the derogation outright: an Annex III system that performs profiling of natural persons is always considered high risk. No balancing, no four conditions, no exception. CV scoring and credit scoring tools usually fall back into the high-risk category for exactly this reason.
Do you have to tell users they are talking to a chatbot?
Yes, under Art. 50(1), applicable since 2 August 2026. Where a system interacts directly with a natural person, the provider has to make sure the person knows they are dealing with AI, unless that is obvious from the circumstances. Breaching this falls under the second fine tier in Art. 99.
What do you document if the system is not high risk?
If the system falls into an Annex III area but you rely on the Art. 6(3) derogation, Art. 6(4) requires the classification assessment to be documented before the system is placed on the market, and Art. 49(2) still requires registration in the EU database. The omnibus lightened that registration, it did not delete it.
Who supervises the AI Act in Hungary, Germany and Austria?
In Hungary the Artificial Intelligence Authority (Mesterséges Intelligencia Hivatal) is the Art. 70(1) market surveillance authority and the Art. 70(2) single point of contact, under Act LXXV of 2025 and Government Decree 344/2025 (X. 31.). For Germany and Austria we found no public source in August 2026 naming the designated Art. 70 authority, so we will not guess.
How large can the fines be?
Art. 99 sets three tiers: 35 million EUR or 7 percent of worldwide annual turnover for prohibited practices, 15 million EUR or 3 percent for provider and deployer breaches including Art. 50, and 7.5 million EUR or 1 percent for supplying incorrect information. For SMEs the cap is the lower of the two figures, and the omnibus added a lower cap for small mid-caps.
This article is written for information purposes and does not replace legal advice on your specific case. Classification always depends on the intended purpose and the actual behaviour of the system, and national enforcement practice across the EU is still forming.
If you want the classification done on your own systems, our EU AI Act compliance service covers the AI inventory, the seven-question classification and the Art. 6(4) assessment as a fixed-price project. For the step-by-step execution, see EU AI Act compliance step by step.
Sources
- EUR-Lex: Regulation (EU) 2026/1744 (Digital Omnibus on AI)
- European Commission: Regulatory framework for AI
- Future of Privacy Forum (2026-07-28): the timeline after the omnibus
- Gibson Dunn (2026-05-27): the postponed high-risk deadlines
- Freshfields (2026-07-10): the final omnibus amendments
- Bird & Bird (2026): the final Transparency Code of Practice
- AI Act Art. 5: prohibited practices
- AI Act Art. 6: classification rules and the derogation
- AI Act Annex III: the eight high-risk areas
- AI Act Art. 25: when a deployer becomes a provider
- AI Act Art. 26: deployer obligations
- AI Act Art. 27: fundamental rights impact assessment (FRIA)
- AI Act Art. 50: transparency obligations
- AI Act Art. 99: penalties
- Act LXXV of 2025 on the Hungarian implementation of the AI Act
- Government Decree 344/2025 (X. 31.)
- Hungarian Artificial Intelligence Authority
- ifo Institute (2026-06-05): AI use among German companies
- openKRITIS: the German NIS2 implementation act (BSIG)
- BSI: entities regulated under NIS2 in Germany
