The Article 6(3) Filter: When an Annex III System Is Not High Risk
Article 6(3) creates a critical gateway for Annex III systems. If an organisation can demonstrate through proper assessment that an Annex III-listed system would not pose a significant risk to fundamental rights or safety, it may fall outside the high risk regime. This is not a blanket exemption, but rather a risk-based filter that requires structured evidence.
The key phrase is “significant risk to fundamental rights and safety.” This is not merely any risk. A biometric access control system in an office building might present minimal fundamental rights risk compared to a facial recognition system used in criminal investigations. The assessment must examine whether the specific deployment, context and technical safeguards mean the system does not create a significant risk threshold.
The assessment process requires two components. First, the organisation must conduct a risk assessment under Article 9, examining how the system might fail or be misused, what the consequences would be, and what safeguards are in place. Second, the organisation must conduct an impact assessment in accordance with Articles 27 for public bodies or similar structured review for others, examining consequences for fundamental rights. A recruitment AI system used in a single department has different consequences than one used across an entire public sector hiring pipeline.
The context of deployment matters enormously. A high risk category applies but Article 6(3) assessment depends on specifics. A local government housing allocation system serving a defined geographic area might demonstrate low fundamental rights risk through sufficient human review, audit trails and appeal mechanisms. The same system nationwide without local oversight and review would present high risk.
Technical safeguards reduce risk significantly. A biometric system with multiple verification layers, human review at key points and reliable data protection measures may fall below the significant risk threshold. A system with weak data governance, no audit logging and no human oversight does not. The assessment must identify specific safeguards already in place and quantify their effect on risk reduction.

Proportionality plays a role. A small training provider using a course recommendation engine where students have full visibility and can always opt out of recommendations faces different risk from a large institution using an opaque system where students cannot challenge decisions. The availability of meaningful human oversight and challenge mechanisms directly affects whether risks become significant.
Documentation is essential. The assessment must be written down, with clear reasoning. An organisation cannot merely assert that an Annex III system poses no significant risk. The assessment should specify which parts of Annex III are triggered, what impact on fundamental rights was examined, what safeguards reduce risk, and why the residual risk remains insignificant. This documentation becomes evidence if regulators investigate or disputes arise.
The assessment is not permanent. As the system evolves, as deployment expands, or as data characteristics change, the Article 6(3) justification must be revisited. If a recruitment system initially used for a single job category is later expanded to cover all hiring, the risk profile changes and reassessment is required.
Consider a practical example. An employer operates an AI system that recommends employees for upskilling programmes. The system is in Annex III because it affects employment and worker management. The employer conducts Article 6(3) assessment. They document that the system is advisory only, employees are informed of recommendations, recommended candidates are interviewed by humans who make final decisions, the system’s recommendations are logged and auditable, and employees can appeal decisions. They demonstrate that the system has been validated for accuracy and bias on their workforce data, that adequate monitoring is in place, and that independent review found no significant risk to workers’ rights. This assessment may support a conclusion that despite being listed in Annex III, the system does not pose significant risk and can operate under a lighter regulatory regime.
The burden of proof lies with the organisation. Regulators will ask for this assessment. National authorities enforcing the EU AI Act from 2 August 2026 will review whether organisations have conducted genuine assessments or merely stated conclusions without evidence.
Article 6(3) is a genuine pathway to lower compliance burden for systems that truly pose no significant risk. However, it is not a loophole to avoid high risk designation. Organisations attempting to circumvent Annex III classification through inadequate Article 6(3) assessments will face enforcement action. Regulators will scrutinise whether risk assessments are thorough, whether impact assessments genuinely examine fundamental rights consequences and whether safeguards identified are actually implemented and effective. The assessment must be defensible in a regulatory investigation or dispute.
