EU AI ACT · ARTICLES 6, 26 & 27

Do you know which of your
AI systems are high-risk?

Annex III high-risk obligations apply from 2 December 2027; Annex I from 2 August 2028. That sounds distant until you consider that classification, governance redesign, and human-oversight structures take longer to build than they do to describe.

Classification comes first.
Everything else follows from it.

High-risk status is not obvious from looking at a system. It turns on whether the system falls within Annex III, or is a safety component of a product covered by Union harmonisation legislation requiring third-party conformity assessment. Neither is a judgement most organisations have made.

The dates moved, and they are still closer than they look. Following the amendments consolidated in July 2026, Annex III high-risk obligations apply from 2 December 2027 and Annex I from 2 August 2028. Organisations reading that as breathing room are measuring the wrong thing — the work is governance redesign, not a documentation exercise.

The deployer obligations are operational, not technical. Article 26 requires human oversight assigned to people with the necessary competence, training and authority, use in accordance with the provider’s instructions, and control over input data relevance. That is accountability architecture, and it does not get built in a quarter.

And for public bodies there is a second layer. Article 27 requires a fundamental rights impact assessment before deploying certain high-risk systems, with the result notified to the market surveillance authority. It complements an Article 35 GDPR DPIA rather than replacing it.

What the Assessment establishes

A structured classification and obligation map. Not a legal determination — the analysis your counsel confirms.

Stage 01

System-by-system classification

Every AI system assessed against Article 6(1) and Article 6(2), with the Annex III categories and Annex I harmonisation legislation applied explicitly. Where a classification is arguable, we say so rather than resolving it silently.

  • Which of your systems fall within Annex III?
  • Which are safety components requiring third-party conformity assessment?

Stage 02

Which timeline applies to which system

Annex III systems fall under 2 December 2027. Annex I product-embedded systems fall under 2 August 2028. Knowing which of your systems sits on which date determines what you start now and what can be sequenced behind it.

  • Which of your systems carry the earlier date?
  • What has to be in place before that date, not on it?

Stage 03

Article 26 deployer obligations mapped

Human oversight assigned to people with the necessary competence, training and authority. Use in accordance with the provider’s instructions. Input data relevance where you control it. Each obligation mapped to a named owner in your organisation.

  • Who currently holds oversight authority for each system?
  • Is that authority real, or nominal?

Stage 04

Article 27 exposure identified

Public bodies and private entities providing public services face a fundamental rights impact assessment obligation before deploying certain high-risk systems, with the result notified to the market surveillance authority. Where an Article 35 GDPR DPIA exists, the FRIA complements it.

  • Does your organisation fall within the Article 27 categories?
  • Do you have existing DPIAs the FRIA would build on?

Stage 05

Governance gaps named

Where oversight sits with someone lacking the authority to stop a system. Where accountability diffuses between IT, procurement, and the service owner. Where nobody would know a system had drifted. These are the gaps that make obligations unmeetable in practice.

  • Could anyone in your organisation actually halt a deployed AI system?
  • Would they know when to?

Stage 06

Sequenced remediation roadmap

Ordered by which systems are already in scope, then by exposure, then by what your organisation can realistically execute. Every item with an owner, a timeline, and the obligation it addresses.

  • What has to happen before the next deployment decision?
  • What can wait, and on what evidence?

Scope and engagement

Priced on scope. You know the full number before anything starts.

The scope

Priced on scope

Scoped to the number of AI systems in your estate and the complexity of the classification questions they raise. Assessed on a scoping call, quoted as a fixed fee before any work begins.

No hourly billing. No scope creep. You approve the number first.

The entry point

Start with the Scan

Most engagements begin with the Article 4 Literacy Scan at a fixed €2,800. It produces the AI system inventory this Assessment classifies — so the work is sequential, not duplicated.

The full €2,800 credits against a follow-on engagement of €10,000 or more contracted within 90 days.

The terms

How it runs

Remote delivery. A defined turnaround agreed at scoping, with a matching turnaround expected on your side for information requests. Misses move the delivery date day for day.

Clear on both sides. That is what makes a fixed date deliverable.

What follows

Where it leads

Where the Assessment identifies Article 27 exposure, a fundamental rights impact assessment — complementing an Article 35 DPIA where one exists — is the natural next engagement. Where it identifies governance gaps, remediation is scoped separately.

You are not committed to any of it. The Assessment tells you what you need, including if the answer is less than you expected.

What you receive

A working record your leadership can act on and your counsel can review. Not a compliance certificate.

Classification register

Every AI system, its assessed status against Articles 6(1) and 6(2), the Annex reference applied, and the reasoning — including where the classification is arguable.

Timeline map

Which systems fall under 2 December 2027 and which under 2 August 2028, and what has to be in place ahead of each date rather than on it.

Obligation matrix

Article 26 deployer obligations mapped system by system, each assigned to a named owner rather than to a function.

Article 27 determination support

Where FRIA obligations appear likely to attach, what an assessment would need to cover, and how existing DPIAs would feed it.

Governance gap analysis

Where oversight, authority, and accountability break down in practice — and what has to change for the obligations to be meetable.

Board-ready summary

A short, plain-language read of where the organisation stands, what applies now, and what is coming.

Who this is for

  • Public bodies and private entities providing public services — the categories Article 27 names directly
  • Health authorities, municipalities, universities, and housing bodies deploying AI in service delivery
  • Organisations that have deployed AI systems without establishing whether any are high-risk
  • Deployers who assume everything waits until 2027 and have not checked whether Annex III already applies to them
  • Boards that need to know their exposure before the next deployment decision, not after it
  • Law firms advising on the AI Act whose clients need the classification analysis their opinion will rest on

Why Connext

LL.M. in Innovation, Law, and Technology, University of Toronto Faculty of Law (2026) — AI, privacy, cybersecurity, and technology regulation.

Article 26 obligations are governance obligations. Human oversight, decision authority, and accountability structure are what 22+ years of building governance infrastructure in public-sector and health environments actually produces.

Cross-jurisdictional practice across the EU AI Act and GDPR, Canadian privacy legislation, CCPA/CPRA, and Asia Pacific regimes.

Implementation and governance only. Legal interpretation stays with your counsel — the boundary is written into every engagement.

Scope of engagement — please read

Connext does not provide legal advice. Nothing in our deliverables constitutes a legal opinion or a determination of regulatory status.

Classification and applicability are legal determinations. Whether an AI system falls within a given obligation, and whether any measure is sufficient to satisfy it, remain the responsibility of the client and its legal counsel. Our analysis is prepared to support that determination — it does not replace it.

Deliverables should be reviewed by qualified counsel in the relevant jurisdiction before you rely on them. Connext accepts no liability for any consequence arising from a decision not to obtain that review, or from reliance on our deliverables without it.

START THE CONVERSATION

Find out what you’re actually holding.

A 45-minute scoping call. We’ll walk your AI estate, identify which systems raise classification questions, and tell you whether the Assessment is the right instrument — or whether you should start with the Article 4 Scan instead.

BOOK A 45-MINUTE CALL

Or email hello@connextbusinesssolutions.com — a short question doesn’t need a meeting. Remote-first across Canada, the United States, Europe, and Asia Pacific.