Point of law
How a system's risk class is determined
A system is high-risk under Art. 6(1) AI Act where it is a safety component of a product under Annex I, or under paragraph 2 where it falls within one of the eight areas of Annex III, such as creditworthiness assessment under point 5(b). For the cases under Annex III, paragraph 3 excludes a system again under four narrow conditions, unless it performs profiling. Deployers of a system under point 5(b) or (c) additionally owe a fundamental rights impact assessment under Art. 27 AI Act, which builds on an existing data protection impact assessment under Art. 35 GDPR.
A system pre-screens creditworthiness
An organisation deploys a system that scores the creditworthiness of its customers automatically and derives a rating from that. The question of which duties follow is asked before it is settled whether the system is high-risk at all.
Without that classification, every further assessment has no standard to measure against.
Two routes into the high-risk class
Classification follows from Art. 6 AI Act along two separate routes.
Two paragraphs, two tests
| Paragraph 1 | Merkmal | Paragraph 2 |
|---|---|---|
| Safety component of a product under Annex IArt. 6(1) AI Act. Or the system is itself such a product. | Trigger | Use case listed in Annex IIIArt. 6(2) AI Act. Eight areas, among them employment, education and access to essential services. |
| A third-party conformity assessment is required | Further condition | None, other than the derogation in paragraph 3 |
A creditworthiness-assessment system falls under paragraph 2, because Annex III point 5(b) names it expressly.
The derogation is narrow and comes with a duty to document
Whether an Annex III system can be excluded is not a matter of discretion. Art. 6(3) AI Act sets out an exhaustive list for that purpose.
One of the four conditions has to be met, or the system stays high-risk
Liste zu erledigender Punkte
- The system is intended to perform only a narrow procedural task
- It improves the result of a human activity already completed
- It detects deviations from prior decision-making patterns without replacing human review
- It merely prepares an assessment under Annex III
A provider relying on the derogation documents that assessment under Art. 6(4) AI Act before placing the system on the market. It also registers the system under Art. 49(2) AI Act in the EU database.
The fundamental rights impact assessment builds on an existing data protection impact assessment
Whether classification alone settles every duty depends on the Annex III area. Art. 27(1) AI Act obliges every deployer of a system under point 5(b) or (c) to carry out an assessment of the impact on fundamental rights before first use, regardless of whether it is a public or private body.
A creditworthiness assessment evaluates personal aspects systematically and extensively based on automated processing including profiling, and forms the basis for a decision on access to a service. Under Art. 35(3)(a) GDPR it therefore regularly requires a data protection impact assessment anyway.
How we support you with the classification
A system’s classification can be recorded in four steps: the trigger under paragraph 1 or 2, the derogation under paragraph 3, the documentation under paragraph 4 and, where it applies, the fundamental rights impact assessment. That assessment precedes every other duty, because it settles which duties apply at all.
Get in touch!
Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!
Contact usAlternatively you can request a call back.