Service decision and evidence guide

AI project scope: product-safety route, Annex III use case and actor changes

The acquired, dated AI Act distinguishes the Article 6 product-safety route from Annex III use cases and addresses exceptions and actor changes. Start with the actual function, intended purpose, product legislation and assessment route. A description such as “AI software” or a NIST mapping cannot determine high-risk status or the complete compliance scope.

Evidence retrieved 2026-10-06. Source versions and topic-specific limits are listed below.

Sourced criteria · EU

What changes the service scope?

Decision or taskWhat the source describesWhat to prepare
Is the product-safety route supported?Article 6(1) combines the Annex I product/safety-component context with third-party conformity assessment; the acquired version also contains qualifications in paragraphs 1a–1c. [1]Record the exact safety function, failure consequences, product legislation and reason for third-party assessment. Review the current authentic amendments before a final classification.
What Annex III use case and exception facts matter?Article 6(2) addresses Annex III; paragraphs 3–4 describe qualified exceptions, a profiling qualification and documentation/registration for the described non-high-risk assessment. [1]Identify the exact Annex III context, influence on decisions and human review/profiling facts; keep the conclusion unresolved without them.
Does a modification or brand change the actor?Article 25 addresses name/trademark, substantial modification and changed intended purpose, with cooperation and information/access provisions. [2]Map original provider, integrator, deployer and product manufacturer; compare modification and purpose changes against the cited conditions.
Which version and timing govern this project?Articles 111 and 113 address systems already placed on the market and application provisions. The acquired version contains amendments; a generic deadline cannot settle every project. [3] [4]Build a dated deployment/modification timeline and review the authentic amending acts and relevant provision before quoting a deadline or phase.

High-risk status, actor role and applicability dates remain incomplete and need specialist review. Novel legal interpretations are not approved here; NIST controls and record similarity do not prove AI Act compliance.

A scoped evidence and handoff plan

Use this checklist to gather your business or product details before speaking with a specialist. The items below explain what to record and suggest useful supporting documents. You can add your own answers in the editable project brief.

  1. Is the product-safety route supported?

    Record the exact safety function, failure consequences, product legislation and reason for third-party assessment. Review the current authentic amendments before a final classification.

    Useful evidence: Intended-purpose/safety-function description, applicable product regime and conformity-assessment rationale.

  2. What Annex III use case and exception facts matter?

    Identify the exact Annex III context, influence on decisions and human review/profiling facts; keep the conclusion unresolved without them.

    Useful evidence: Use-case/decision workflow, human-review design, profiling facts and reasoned assessment record.

  3. Does a modification or brand change the actor?

    Map original provider, integrator, deployer and product manufacturer; compare modification and purpose changes against the cited conditions.

    Useful evidence: Supply-chain/brand map, modification/purpose history and contractual evidence/access handoff.

  4. Which version and timing govern this project?

    Build a dated deployment/modification timeline and review the authentic amending acts and relevant provision before quoting a deadline or phase.

    Useful evidence: Source/version register, placement/use/modification dates and provision-specific applicability review.

Work packages and dependencies

Questions for providers

Sources and data dates

Read the official document in context. The audit details identify the precise locators and preserved versions used for this page.

EUR-Lex — Regulation (EU) 2024/1689 ↗

Consolidated text dated 2026-07-27 · retrieved 2026-10-06

Audit details: precise locators and snapshot identifiers

Source key D05 · snapshot c8e67034f8003acc0a11d1ae6ab83ddb97dd1564aa57e9858f06e1ce90608aa1

  • [1] #art_6 · record 50e7ff67fad33a8d25da7d570cabcd39de73dda463da460957d247ee710d3e87
  • [2] #art_25 · record c165859b7b1e5bc203fc3b6e41ea53869e2709357cba7224154569334c141991
  • [3] #art_111 · record 2993e182d0118ddede010a31c2b069ad76773120aa6b224fa21e9acaf9da188e
  • [4] #art_113 · record 6e55ba670215d537e0a3e42a38b820005b2b19546536e1df9b1b67f768e90488

Prepare an editable project brief

Confirm the facts, scope and contact preference before sharing your project. Preparing this page sends no provider outreach.

Choose work packages to discuss

Compare EU AI Act High‑Risk AI Compliance Services (Readiness & Implementation)

Medical Device Cybersecurity