Everyone quotes Annex III. Almost nobody reads Article 6(3), which sits directly underneath it and can move a system out of the high-risk category entirely.
This is the most consequential paragraph in the AI Act for small companies, and it is routinely missed — by founders, by consultants, and by most of the free classification tools currently online. The result is teams budgeting for conformity assessments, notified bodies and CE marking they may never owe.
What it says
A system that falls within an Annex III area is not high-risk if it does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision-making. That applies where any one of these four conditions is met:
| # | Condition | In practice |
|---|---|---|
| a | The system performs a narrow procedural task | Sorting documents by type, checking a form is complete, routing a ticket to the right queue |
| b | It improves the result of a previously completed human activity | Tidying the language of an assessment a person already wrote and decided |
| c | It detects decision-making patterns or deviations from prior patterns, without replacing or influencing the human assessment without proper review | Flagging that this month's decisions look unlike last month's, for a human to investigate |
| d | It performs a preparatory task to an assessment relevant to the listed use cases | Gathering and structuring information that a person will then evaluate |
And then the condition that overrides all four. The exemption does not apply — the system is always high-risk — if it performs profiling of natural persons. This is not weighed against the other factors. It is absolute. Profile individuals and you are high-risk, no matter how narrow the task.
The profiling condition is where almost every case is decided
Because it is absolute, this is the question to answer first. Profiling under GDPR Article 4(4), which the AI Act draws on, means automated processing of personal data to evaluate personal aspects of a natural person — in particular to analyse or predict performance at work, economic situation, health, preferences, interests, reliability, behaviour, location or movements.
The trap: teams read "profiling" as "building a dossier". It is much broader. Evaluating or predicting anything about a person from their data is profiling, even once, even transiently, even if you never store the result.
| System | Profiling? | Why |
|---|---|---|
| Checks whether a CV includes a required certificate | No | Verifies a fact about a document, evaluates nothing about the person |
| Ranks CVs by predicted job performance | Yes | Predicts performance at work — the textbook example |
| Transcribes an interview | No | Converts speech to text; no evaluation |
| Scores an interview for "communication skills" | Yes | Evaluates a personal aspect |
| Flags that a batch of loan decisions deviates from the norm | No | Analyses the decisions, not the applicants |
| Assigns each applicant a risk score | Yes | Evaluates economic reliability per person |
The pattern: is the person the subject of the evaluation, or is something else? Documents, decisions, transcripts and processes can be analysed freely. The moment the output is a judgement about a human being, you are profiling.
The other trap: "materially influencing the outcome"
Even without profiling, the exemption requires that the system not materially influence decision-making. Two ways teams talk themselves past this and shouldn't:
"A human makes the final call." Formally true, frequently meaningless. If your system presents a ranked shortlist and the human picks from the top three ninety-five percent of the time, the system is materially influencing the outcome. Regulators look at what actually happens, not at where the button is. If you have the data on override rates, look at it before you rely on this argument.
"It's only a suggestion." A suggestion that is followed by default is a decision with extra steps. The test in limb (c) is explicit — the system must not influence the human assessment without proper review. Proper review means the reviewer has the information, the time and the authority to disagree, and sometimes does.
The exemption is not free
This is the part that gets skipped, and it converts a good position into a bad one.
A provider who concludes their system is exempt under 6(3) must document that assessment before placing the system on the market, and must still register the system in the EU database. The competent authority can ask for the documentation. So the exemption removes the heavy Chapter III obligations — risk management, technical file, conformity assessment, CE marking — but it is not silence. It is a lighter, documented position.
"We assumed we were exempt" is not an assessment. An assessment is a dated document that names the system, states which of the four limbs you rely on, explains why, and records explicitly that the system does not profile natural persons. One page is enough. Written after a regulator asks, it is worth very little; written before you ship, it is the whole defence.
A worked example
An eleven-person company sells software to hospitals that reads incoming referral letters and routes them to the right department.
Annex III? Yes — healthcare access can engage essential services, and this touches patient pathways.
Which limb? (a), a narrow procedural task. It classifies a document by subject matter and sends it onward.
Profiling? No. It reads the letter's clinical content and matches it to a department. It forms no view about the patient — not urgency, not risk, not likelihood of attendance.
Materially influencing? No. A clinician reviews every referral on arrival regardless of routing, and misrouted letters are reassigned daily.
Conclusion: likely exempt. Document it, register it, move on.
Now change one thing. The company adds a feature that flags referrals as "likely urgent" based on patient history. That is a prediction about a person's health — profiling. The exemption closes instantly and the system is high-risk, with the full Chapter III set due by 2 December 2027.
One feature. Same product, same customers, same team. That is how quickly this moves, and it is why the assessment has to be revisited whenever the product changes.
How to run the check
- Confirm you're actually in an Annex III area. If not, 6(3) is irrelevant — you were never high-risk.
- Ask the profiling question first. It is absolute, so a yes ends the analysis and saves you the rest.
- Identify which limb you rely on. One is enough, but name it. "It's pretty narrow" is not a limb.
- Pressure-test material influence. Look at real override rates if you have them.
- Write it down, date it, register the system.
- Re-run it when the product changes. Put it on the roadmap review, not in a folder.
Why this matters more than it sounds. The difference between exempt and high-risk, for a small team, is roughly twelve to eighteen months of work and a notified body's fee against a one-page document and a database entry. It is the single largest swing available in the whole classification exercise — and it turns on a paragraph most people never read.
Run the 6(3) check on your system
The exemption check is built into the full assessment — including the profiling question that decides most cases.
Start the free scanNo card, no account. Full gap report from €59. See a real report first.
Self-assessment, not legal advice. This page and the Reglynn report are a structured self-assessment based on the EU AI Act (Regulation 2024/1689, as amended by the June 2026 Omnibus). They indicate where you likely stand and what to verify with a qualified advisor. Reglynn is not a notified body and issues no certification.
How this was made. Reglynn reports are generated by an AI system and reviewed before delivery. Reglynn is a Limited Risk AI system under Article 50; we disclose AI involvement wherever it occurs, including in our chat assistant. Our own self-assessment.