The EU Commission's high-risk AI system guidelines, released on May 19, 2026, make one thing clear: relying on Article 6(3) derogations to avoid high-risk classification requires thorough documentation. The narrow interpretation of these exemptions means most AI systems involved in employment, biometric identification, or critical infrastructure will face full provider obligations.
What Changed
The Commission published draft guidelines for general principles, Annex III standalone systems, and Annex I product-embedded systems. The Annex III guidance clarifies which AI systems qualify as high-risk and how providers can apply the Article 6(3) derogation. The consultation period runs until June 23, 2026.
The guidelines confirm that Article 6(3) acts as a filter, not a broad exemption. The four conditions listed are exhaustive. There's no general exemption for systems perceived as low-risk. You must fit within one of the four specified grounds, document your assessment, and register the system in the EU database.
Key Findings
Human-in-the-loop provides no exemption. Human involvement doesn't affect a system's high-risk classification. Adding a human review step won't exempt a system. While human involvement may demonstrate that your system performs a narrow procedural task under Article 6(3)(a), it can't be used to avoid high-risk classification.
Narrow interpretation of Article 6(3) conditions. These conditions include systems that: (a) perform narrow procedural tasks, (b) improve previously completed human work, (c) detect decision patterns without replacing human assessment, or (d) perform preparatory tasks. The Commission treats these as limited carve-outs.
Profiling blocks the exemption. Even if your system fits one of the four conditions, it remains high-risk if it profiles individuals by assessing their decisions and personal characteristics. An AI system evaluating recruiter decisions based on personal traits stays high-risk despite potentially qualifying under Article 6(3)(c).
Registration is mandatory for Article 6(3) claims. If you assess that Article 6(3) applies, you must register the system in the EU database. This isn't optional. The AI Omnibus will simplify registration requirements, but the obligation remains. Providers must document which high-risk category the system would fall under, which Article 6(3) condition applies and why, and confirm that the system doesn't perform profiling.
Employment use cases draw fine lines. Job description generators illustrate the guidance's precision. An AI system generating descriptions from a human-defined list of tasks and qualifications may qualify as a narrow procedural task under Article 6(3)(a). The same system generating necessary qualifications from a high-level description does not. CV parsers and interview schedulers qualify for Article 6(3). Automated job matching, candidate scoring, and targeted ad placement based on user characteristics remain high-risk without exemption.
What This Means for Your Team
If you're a provider, these guidelines require immediate action. The obligations for high-risk systems apply from December 2, 2027, assuming the AI Omnibus is published before July 10. That timeline seems comfortable until you realize that provider obligations require risk management embedded throughout the development lifecycle. You can't retrofit Technical Documentation (Annex IV) after development is complete.
CEN and CENELEC are developing harmonized standards that will provide presumed conformity when published in the Official Journal. Three standards are already available for public enquiry: prEN 18288 on AI Risk Management, prEN 18282 on Cybersecurity, and FprEN 18286 on Quality Management Systems. These standards will define how to comply, not whether to comply.
For deployers, the risk lies in accidental provider status. You become a provider subject to full obligations if you: use general-purpose tools for a high-risk purpose under Article 25(1)(c), create an agent for high-risk tasks like CV sifting, add your branding to another provider's high-risk system, or substantially modify a high-risk AI system. This happens more easily than most teams expect, particularly with off-the-shelf generative AI tools applied to employment decisions.
Action Items by Priority
Inventory your AI systems against Annex III purposes. Start with employment, biometric identification, and critical infrastructure categories. For each system, document the intended purpose and whether it falls under a high-risk category. Don't assume human review exempts the system.
Assess Article 6(3) applicability with documentation. If you believe a system qualifies under Article 6(3), create a written assessment covering: which high-risk category applies, which of the four conditions you're relying on, why that condition fits your system's function, and confirmation the system doesn't profile individuals. This documentation becomes your evidence if challenged.
Review general-purpose AI tool usage. Identify where your organization uses ChatGPT, Claude, or similar tools for recruitment, performance management, or task allocation. These applications may trigger provider status under Article 25(1)(c). Implement policy controls and technical guardrails to prevent high-risk applications of general-purpose tools.
Track harmonized standards development. Monitor the three draft standards now available and watch for additional standards addressing data governance, transparency, and human oversight. When standards are published in the Official Journal, evaluate whether adopting them provides clearer compliance paths than custom approaches.
Prepare for registration. Even Article 6(3) systems require EU database registration. Build the internal processes to capture registration data: system descriptions, intended purposes, derogation justifications, and profiling assessments. The AI Omnibus will simplify requirements, but registration obligations remain.
Embed lifecycle compliance processes. If you're developing high-risk systems, integrate risk management, technical documentation, and conformity assessment into your development process now. Waiting until 2027 to compile retrospective documentation will be significantly more difficult than building compliance into your existing workflows.


