The derogation: when Annex III does not mean high-risk
Being listed in Annex III creates a presumption, not a conclusion. Article 6(3) lets a provider rebut it, and getting this right is the difference between a full Chapter III programme and a documented assessment. It is also the provision most often claimed without the evidence to support it.
Read this before you rely on the page
Article 6 was amended by Regulation (EU) 2026/1744. The Commission’s own AI Act Service Desk carries a notice that its displayed Article 6 text has not yet been updated for those amendments. The structure described below reflects Regulation (EU) 2024/1689 as originally enacted. Read the consolidated text on EUR-Lex before relying on a derogation assessment, and re-check any assessment you documented before 27 July 2026.
The gate, then the four conditions
The derogation has two layers and people routinely skip the first. The threshold requirement is that the system does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision-making. Only then do you look for one of the four conditions.
| Condition | What it looks like in practice, and where it breaks | |
|---|---|---|
| (a) | Performs a narrow procedural task | Parsing a CV into structured fields. Breaks the moment the parser ranks, scores or filters, that is no longer procedural. |
| (b) | Improves the result of a previously completed human activity | Tidying the prose of a decision a human already made. Breaks if the model can change the substance of the decision. |
| (c) | Detects decision-making patterns or deviations, and is not meant to replace or influence the previously completed human assessment without proper human review | Flagging that a reviewer’s scores drift from peers. Breaks if the flag routes back into the live decision without review. |
| (d) | Performs a preparatory task to an assessment relevant to an Annex III use case | Transcribing an interview. Breaks if the transcript is scored, summarised evaluatively, or ranked. |
The absolute override
Notwithstanding all four conditions, a system referred to in Annex III is always high-risk where it performs profiling of natural persons. Profiling carries its GDPR Article 4(4) meaning — any automated processing of personal data to evaluate personal aspects, in particular to analyse or predict performance at work, economic situation, health, preferences, interests, reliability, behaviour, location or movements.
This is where most claimed derogations fail. A “narrow” task that evaluates a personal aspect of an identified individual is profiling, and profiling ends the analysis.
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
What you must produce if you claim it
- A documented assessment, before market placement. Article 6(4) is explicit on the timing. An assessment reconstructed after an authority asks is not compliance with 6(4).
- Registration. Providers claiming the derogation still register: the derogation removes the Chapter III obligations, not your visibility to authorities.
- A defence against Article 80. Article 80 gives a market surveillance authority a procedure to challenge a provider’s non-high-risk classification. If the authority disagrees, the system is treated as high-risk and you are, at that point, non-compliant with everything you skipped.
The honest risk calculus
Expert analysis, not legal advice. The derogation is legitimate and was drafted to be used. But the asymmetry is brutal: if you are right, you saved a compliance programme. If you are wrong, you have been placing a non-conforming high-risk system on the market, with no technical documentation, no conformity assessment and no registration, exposure under Article 99(4) of up to €15M or 3%.
The organisations we see handle this well do the same thing: they document the derogation assessment to the standard of the technical documentation they would otherwise have written. It costs a fraction of full compliance and it is the only version of the argument that survives contact with Article 80.
Document the assessment properly
A derogation assessment is a written artefact with a named author, a date, the four conditions addressed one by one, and an explicit profiling analysis. That is the same discipline an AI management system produces as a matter of routine.
Not sure where you sit?
The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.
Questions
Can an Annex III AI system avoid being high-risk?
Yes, through the Article 6(3) derogation. An AI system listed in Annex III is not high-risk where it does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision-making.
At least one of four conditions must be met: the system performs a narrow procedural task; it improves the result of a previously completed human activity; it detects decision-making patterns or deviations from prior patterns and is not meant to replace or influence the previously completed human assessment without proper human review; or it performs a preparatory task to an assessment relevant to an Annex III use case.
What is the profiling override in Article 6?
Article 6(3) contains an absolute carve-back: notwithstanding the four conditions, an AI system referred to in Annex III is always considered high-risk where it performs profiling of natural persons. Profiling has the GDPR Article 4(4) meaning. If your system profiles, the derogation is unavailable regardless of how narrow the task is.
Do you have to document a decision that a system is not high-risk?
Yes. Article 6(4) requires a provider who considers that an Annex III system is not high-risk to document that assessment before the system is placed on the market or put into service. The provider is also subject to a registration obligation. Article 80 sets out the procedure by which a market surveillance authority may challenge that classification.
Was Article 6 changed by the Digital Omnibus?
Article 6 was amended by the Digital Omnibus on AI, Regulation (EU) 2026/1744. The European Commission's AI Act Service Desk carries a notice that its displayed Article 6 text has not yet been updated to reflect those amendments. Anyone relying on the derogation should read the consolidated text on EUR-Lex rather than a secondary source, and should re-check any assessment documented before 27 July 2026.