TrustReady.eu
Not High-Risk Is Not the End of an EU AI Act Assessment
← All articles
EU AI ActDigital Omnibus on AIRegulation (EU) 2026/1744European Artificial Intelligence Office

Not High-Risk Is Not the End of an EU AI Act Assessment

A non-high-risk status does not end EU AI Act obligations. Learn how to maintain compliance for transparency, prohibited practices, and evolving regulatory roles.

Junzhe Dai·2026-08-18

Key Takeaways

  • A 'non-high-risk' classification does not by itself end an EU AI Act assessment; other obligations may still apply depending on the system, use case and regulatory role.
  • Transparency obligations under Art. 50 EU AI Act may apply to interactive and generative AI systems even where they are not classified as high-risk.
  • For Annex III systems that a provider treats as not high-risk under Art. 6(3) EU AI Act, Article 6(4) documentation and Article 49(2) EU-database registration remain relevant under the Digital Omnibus on AI (Regulation (EU) 2026/1744).
  • Under Article 25 EU AI Act, a downstream actor may become the provider of a high-risk AI system in specified circumstances, including where it changes the intended purpose of a previously non-high-risk system so that it becomes high-risk.

Introduction

For many technical founders, the EU AI Act assessment often feels like a binary gate: either a system is high-risk, triggering an extensive compliance roadmap, or it is not, signaling a green light to launch. However, a 'non-high-risk' conclusion is merely an intermediate step in the broader regulatory framework. The EU AI Act contains obligations that may apply independently of a high-risk classification. With the enactment of the Digital Omnibus on AI (Regulation (EU) 2026/1744), the landscape has evolved, but the basic point remains. Relying on a 'non-high-risk' status to bypass the AI Act is an incorrect interpretation of the law, because transparency, literacy and prohibited-practice requirements may still apply depending on the system, use case and regulatory role..

1. Why “Not High-Risk” Is Only an Intermediate Conclusion

A high-risk classification is a classification outcome, not a comprehensive description of your legal duties under the EU AI Act assessment. The AI Act demands a granular understanding of your system’s lifecycle.

1.1 Identify the relevant regulatory object

Under Art. 3(1) EU AI Act, identifying the precise legal definition of an AI system establishes the regulatory boundary of your assessment. Misidentifying the 'object' of your assessment, such as confusing a general-purpose AI (GPAI) model API with your own downstream application, can lead to an incorrect analysis.

1.2. Define the intended purpose

The 'intended purpose' under Art. 3(12) EU AI Act is central to your classification. It is defined by reference to the use intended by the provider, including the information supplied with the system. If you market a system for general tasks but a downstream user deploys it for a prohibited practice under Art. 5 EU AI Act or a high-risk application under Annex III, that use does not automatically invalidate your original classification. It may instead create separate obligations for the deployer and, where a third party changes the intended purpose so that the system becomes high-risk, may trigger Art. 25(1)(c) EU AI Act.

1.3 Apply the full classification route

Determining that a system is not high-risk requires an analysis of the criteria in Art. 6 and, where relevant, Annex I and Annex III EU AI Act. If a system does not meet the requirements under Art.6(1) EU AI Act and does not fall within any use case in Annex III under Art. 6(2), it is outside the high-risk categories in Art. 6. Art. 6(3) EU AI Act, by contrast, provides a specific exception for certain systems that do fall within Annex III but do not pose a significant risk of harm under the conditions set out in that provision. Only providers relying on this route are subject to the specific documentation requirement in Art. 6(4) EU AI Act and the related registration obligation in Art. 49(2).

2. What Must Still Be Assessed

Even for systems outside the high-risk category, other AI Act provisions may still apply depending on the system, use case and regulatory role.

2.1. Prohibited practices

Under Art. 5 EU AI Act, certain AI practices are prohibited. These include systems that manipulate human behavior or exploit vulnerabilities. The Digital Omnibus on AI) added further prohibited practices concerning certain non-consensual intimate material and child sexual abuse material , applicable from 2 December 2026. Where the conditions of Art. 5 EU AI Act are met, these prohibitions apply independently of the system's high-risk classification.

2.2. Transparency obligations

Article 50 requires providers to disclose when natural persons are interacting with certain AI systems and separately requires machine-readable marking for outputs of AI systems generating synthetic contents. Under the Digital Omnibus on AI, Article 50 generally applies from 2 August 2026, subject to the transitional period in Article 111(4) for certain generative AI systems placed on the market before that date. While the regulation sets binding requirements, the European Commission’s Guidance explains how machine-readable marking and the applicable disclosure duties can be implemented.

2.3. AI literacy

Article 4 requires providers and deployers to take measures to support the development of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf. The Digital Omnibus on AI modified this text to require that providers and deployers 'support the development of AI literacy' among staff instead of 'ensuring' specific literacy levels, and it remains an actionable organisational obligation without requiring a provider or deployer to guarantee or prove a particular level of understanding.

2.4. GPAI-related obligations and dependencies

If your downstream AI system integrates a third-party General Purpose AI model, the model provider's obligations under Chapter V EU AI Act may create important documentation and information dependencies for you. These dependencies can affect your overall compliance posture even if your downstream AI system is not high-risk; integration alone does not make you a GPAI model provider subject to the obligations under Art. 53 or 55 EU AI Act.

3. Why Roles and Deployment Context Still Matter

The AI Act assigns responsibilities based on your position in the value chain, which can shift unexpectedly depending on deployment context.

3.1. Identify the organisation’s role for the specific service

You must distinguish if you are a provider, deployer, importer or distributor under Art. 3 EU AI Act. Your legal duties differ significantly depending on whether you place the AI system on the market under your own name or merely deploy a third-party tool.

3.2. Separate the model from the downstream system

A GPAI model and the downstream AI system built on it are distinct regulatory objects. The model may be subject to Chapter V EU AI Act, including the systemic-risk regime under Art. 51, while the downstream AI system must be assessed separately under Art. 6. Assessing the entire software stack as a single unit without separating these distinct software objects often leads to compliance gaps.

3.3. Distinguish intended use from actual deployment

Regulatory scrutiny focuses on both your stated intended purpose under Art, 3(12) EU AI Act and the actual use cases you facilitate. If your system is deployed outside the provider's stated intended purpose, that does not automatically alter the provider's original classification. It may create separate obligations for the deployer and, where a third party changes the intended purpose so that the system becomes high-risk, may trigger the provider transition in Art. 25(1)(c) EU AI Act.

3.4. Consider role and classification changes

Art. 25 EU AI Act clarifies that a downstream distributor, importer, deployer or other third party becomes the primary 'provider' of a high-risk AI system only in specified circumstances: where it places its name or trademark on an AI system already classified as high-risk; where it makes a substantial modification to a high-risk AI system and the system remains high-risk; or where it changes the intended purpose of an AI system that was not previously high-risk so that it becomes high-risk under Art. 6. If this happens, the new provider assumes the provider obligations referred to in Art. 16 EU AI Act. Art. 26 EU AI Act separately governs deployer’s obligations.

4. How to Complete and Maintain the Assessment

Governance under the EU AI Act is a continuous state, not a one-time check.

4.1. Document the conclusion precisely

Documentation requirements depend on the classification route. The Digital Omnibus on AI maintained the Art. 6(4) EU AI Act documentation and Art. 49(2) registration framework for providers of Annex III systems that rely on Art. 6(3) to conclude that the system is not high-risk. Art. 6(4) EU AI Act requires that assessment to be documented before the system is placed on the market or put into service, and Art. 49(2) requires registration of that category of system in the EU database. This does not mean that every AI system outside the high-risk categories must be registered, although maintaining a clear internal record of the classification logic remains prudent.

4.2. Map the remaining obligations

Create an internal compliance matrix that maps the potentially applicable duties under Art. 4, 5, and 50 EU AI Act, together with any role-specific or GPAI-related obligations. Ensure every product team and developer knows which requirements apply to their specific software workstreams.

4.3. Define supported and excluded uses

Proactively document and state which uses your system supports and which uses are excluded or prohibited. This documentation supports the clear definition of your system's intended purpose and provides evidence of the supported deployment context where downstream use falls outside that scope.

4.4. Set reassessment triggers

Review your classification whenever the software undergoes material updates, new features change its intended purpose or deployment context, or a change may amount to a substantial modification under Art. 3(23) EU AI Act occurs. Establish regular monitoring schedules in anticipation of evolving guidelines from the European Artificial Intelligence Office.

Conclusion

The EU AI Act establishes a comprehensive, tiered governance framework. Concluding that your software is a non-high-risk AI system does not grant a total compliance exemption;it shifts the assessment to other applicable rules. By carefully defining your regulatory object, distinguishing systems outside Art. 6(1) and (2) EU AI Act from those relying on the Art. 6(3) exception, documenting an Art. 6(4) assessment where that exception is relied on, assessing Art. 50 where applicable, and staying vigilant regarding Art. 25 role transitions, your organization can successfully navigate the EU regulatory environment with the precision required by enterprise customers and European authorities.

About the author

Junzhe Dai

Junzhe Dai is a PhD candidate at the Faculty of Law, Humboldt University of Berlin. His research focuses on data market regulation, data protection law, and AI governance, with particular interest in the GDPR, the AI Act, the Data Act, and comparative analyses of EU and Chinese digital regulatory frameworks.

Need help with compliance?

Book a free 30-minute call to review your GDPR and EU AI Act readiness.

Book a call →