AI project scope: product-safety route, Annex III use case and actor changes
The acquired, dated AI Act distinguishes the Article 6 product-safety route from Annex III use cases and addresses exceptions and actor changes. Start with the actual function, intended purpose, product legislation and assessment route. A description such as “AI software” or a NIST mapping cannot determine high-risk status or the complete compliance scope.
Evidence retrieved 2026-10-06. Source versions and topic-specific limits are listed below.
Sourced criteria · EU
What changes the service scope?
Decision or task
What the source describes
What to prepare
Is the product-safety route supported?
Article 6(1) combines the Annex I product/safety-component context with third-party conformity assessment; the acquired version also contains qualifications in paragraphs 1a–1c. [1]
Record the exact safety function, failure consequences, product legislation and reason for third-party assessment. Review the current authentic amendments before a final classification.
What Annex III use case and exception facts matter?
Article 6(2) addresses Annex III; paragraphs 3–4 describe qualified exceptions, a profiling qualification and documentation/registration for the described non-high-risk assessment. [1]
Identify the exact Annex III context, influence on decisions and human review/profiling facts; keep the conclusion unresolved without them.
Does a modification or brand change the actor?
Article 25 addresses name/trademark, substantial modification and changed intended purpose, with cooperation and information/access provisions. [2]
Map original provider, integrator, deployer and product manufacturer; compare modification and purpose changes against the cited conditions.
Which version and timing govern this project?
Articles 111 and 113 address systems already placed on the market and application provisions. The acquired version contains amendments; a generic deadline cannot settle every project. [3][4]
Build a dated deployment/modification timeline and review the authentic amending acts and relevant provision before quoting a deadline or phase.
High-risk status, actor role and applicability dates remain incomplete and need specialist review. Novel legal interpretations are not approved here; NIST controls and record similarity do not prove AI Act compliance.
A scoped evidence and handoff plan
Use this checklist to gather your business or product details before speaking with a specialist. The items below explain what to record and suggest useful supporting documents. You can add your own answers in the editable project brief.
Is the product-safety route supported?
Record the exact safety function, failure consequences, product legislation and reason for third-party assessment. Review the current authentic amendments before a final classification.
Useful evidence: Intended-purpose/safety-function description, applicable product regime and conformity-assessment rationale.
What Annex III use case and exception facts matter?
Identify the exact Annex III context, influence on decisions and human review/profiling facts; keep the conclusion unresolved without them.
Map original provider, integrator, deployer and product manufacturer; compare modification and purpose changes against the cited conditions.
Useful evidence: Supply-chain/brand map, modification/purpose history and contractual evidence/access handoff.
Which version and timing govern this project?
Build a dated deployment/modification timeline and review the authentic amending acts and relevant provision before quoting a deadline or phase.
Useful evidence: Source/version register, placement/use/modification dates and provision-specific applicability review.
Work packages and dependencies
Conditional: Use-case, actor and dated evidence-gap assessment — For this work package, agree the supported criteria, evidence access, covered entities/products and unresolved facts in the table above. Additional services require their own justified scope.
Optional: Device-specific security evidence when the product context justifies it — For this work package, agree the supported criteria, evidence access, covered entities/products and unresolved facts in the table above. Additional services require their own justified scope.
Questions for providers
Which exact actor, product or processing facts support the quoted scope, and what is still unresolved?
How will the listed records reach the responsible people, and who owns each change or authority request?
Which tasks and entities are excluded from the agreement, and which additional services need a separate assessment?
Sources and data dates
Read the official document in context. The audit details identify the precise locators and preserved versions used for this page.