EU AI ACT · ARTICLES 6, 26 & 27
Do you know which of your
AI systems are high-risk?
Annex III high-risk obligations apply from 2 December 2027; Annex I from 2 August 2028. That sounds distant until you consider that classification, governance redesign, and human-oversight structures take longer to build than they do to describe.
Classification comes first.
Everything else follows from it.
High-risk status is not obvious from looking at a system. It turns on whether the system falls within Annex III, or is a safety component of a product covered by Union harmonisation legislation requiring third-party conformity assessment. Neither is a judgement most organisations have made.
The dates moved, and they are still closer than they look. Following the amendments consolidated in July 2026, Annex III high-risk obligations apply from 2 December 2027 and Annex I from 2 August 2028. Organisations reading that as breathing room are measuring the wrong thing — the work is governance redesign, not a documentation exercise.
The deployer obligations are operational, not technical. Article 26 requires human oversight assigned to people with the necessary competence, training and authority, use in accordance with the provider’s instructions, and control over input data relevance. That is accountability architecture, and it does not get built in a quarter.
And for public bodies there is a second layer. Article 27 requires a fundamental rights impact assessment before deploying certain high-risk systems, with the result notified to the market surveillance authority. It complements an Article 35 GDPR DPIA rather than replacing it.
What the Assessment establishes
A structured classification and obligation map. Not a legal determination — the analysis your counsel confirms.
Stage 01
System-by-system classification
Every AI system assessed against Article 6(1) and Article 6(2), with the Annex III categories and Annex I harmonisation legislation applied explicitly. Where a classification is arguable, we say so rather than resolving it silently.
- Which of your systems fall within Annex III?
- Which are safety components requiring third-party conformity assessment?
Stage 02
Which timeline applies to which system
Annex III systems fall under 2 December 2027. Annex I product-embedded systems fall under 2 August 2028. Knowing which of your systems sits on which date determines what you start now and what can be sequenced behind it.
- Which of your systems carry the earlier date?
- What has to be in place before that date, not on it?
Stage 03
Article 26 deployer obligations mapped
Human oversight assigned to people with the necessary competence, training and authority. Use in accordance with the provider’s instructions. Input data relevance where you control it. Each obligation mapped to a named owner in your organisation.
- Who currently holds oversight authority for each system?
- Is that authority real, or nominal?
Stage 04
Article 27 exposure identified
Public bodies and private entities providing public services face a fundamental rights impact assessment obligation before deploying certain high-risk systems, with the result notified to the market surveillance authority. Where an Article 35 GDPR DPIA exists, the FRIA complements it.
- Does your organisation fall within the Article 27 categories?
- Do you have existing DPIAs the FRIA would build on?
Stage 05
Governance gaps named
Where oversight sits with someone lacking the authority to stop a system. Where accountability diffuses between IT, procurement, and the service owner. Where nobody would know a system had drifted. These are the gaps that make obligations unmeetable in practice.
- Could anyone in your organisation actually halt a deployed AI system?
- Would they know when to?
Stage 06
Sequenced remediation roadmap
Ordered by which systems are already in scope, then by exposure, then by what your organisation can realistically execute. Every item with an owner, a timeline, and the obligation it addresses.
- What has to happen before the next deployment decision?
- What can wait, and on what evidence?
Scope and engagement
Priced on scope. You know the full number before anything starts.
The scope
Priced on scope
Scoped to the number of AI systems in your estate and the complexity of the classification questions they raise. Assessed on a scoping call, quoted as a fixed fee before any work begins.
No hourly billing. No scope creep. You approve the number first.
The entry point
Start with the Scan
Most engagements begin with the Article 4 Literacy Scan at a fixed €2,800. It produces the AI system inventory this Assessment classifies — so the work is sequential, not duplicated.
The full €2,800 credits against a follow-on engagement of €10,000 or more contracted within 90 days.
The terms
How it runs
Remote delivery. A defined turnaround agreed at scoping, with a matching turnaround expected on your side for information requests. Misses move the delivery date day for day.
Clear on both sides. That is what makes a fixed date deliverable.
What follows
Where it leads
Where the Assessment identifies Article 27 exposure, a fundamental rights impact assessment — complementing an Article 35 DPIA where one exists — is the natural next engagement. Where it identifies governance gaps, remediation is scoped separately.
You are not committed to any of it. The Assessment tells you what you need, including if the answer is less than you expected.
What you receive
A working record your leadership can act on and your counsel can review. Not a compliance certificate.
Classification register
Every AI system, its assessed status against Articles 6(1) and 6(2), the Annex reference applied, and the reasoning — including where the classification is arguable.
Timeline map
Which systems fall under 2 December 2027 and which under 2 August 2028, and what has to be in place ahead of each date rather than on it.
Obligation matrix
Article 26 deployer obligations mapped system by system, each assigned to a named owner rather than to a function.
Article 27 determination support
Where FRIA obligations appear likely to attach, what an assessment would need to cover, and how existing DPIAs would feed it.
Governance gap analysis
Where oversight, authority, and accountability break down in practice — and what has to change for the obligations to be meetable.
Board-ready summary
A short, plain-language read of where the organisation stands, what applies now, and what is coming.
Who this is for
- Public bodies and private entities providing public services — the categories Article 27 names directly
- Health authorities, municipalities, universities, and housing bodies deploying AI in service delivery
- Organisations that have deployed AI systems without establishing whether any are high-risk
- Deployers who assume everything waits until 2027 and have not checked whether Annex III already applies to them
- Boards that need to know their exposure before the next deployment decision, not after it
- Law firms advising on the AI Act whose clients need the classification analysis their opinion will rest on
Why Connext
LL.M. in Innovation, Law, and Technology, University of Toronto Faculty of Law (2026) — AI, privacy, cybersecurity, and technology regulation.
Article 26 obligations are governance obligations. Human oversight, decision authority, and accountability structure are what 22+ years of building governance infrastructure in public-sector and health environments actually produces.
Cross-jurisdictional practice across the EU AI Act and GDPR, Canadian privacy legislation, CCPA/CPRA, and Asia Pacific regimes.
Implementation and governance only. Legal interpretation stays with your counsel — the boundary is written into every engagement.
Scope of engagement — please read
Connext does not provide legal advice. Nothing in our deliverables constitutes a legal opinion or a determination of regulatory status.
Classification and applicability are legal determinations. Whether an AI system falls within a given obligation, and whether any measure is sufficient to satisfy it, remain the responsibility of the client and its legal counsel. Our analysis is prepared to support that determination — it does not replace it.
Deliverables should be reviewed by qualified counsel in the relevant jurisdiction before you rely on them. Connext accepts no liability for any consequence arising from a decision not to obtain that review, or from reliance on our deliverables without it.
START THE CONVERSATION
Find out what you’re actually holding.
A 45-minute scoping call. We’ll walk your AI estate, identify which systems raise classification questions, and tell you whether the Assessment is the right instrument — or whether you should start with the Article 4 Scan instead.
BOOK A 45-MINUTE CALLOr email hello@connextbusinesssolutions.com — a short question doesn’t need a meeting. Remote-first across Canada, the United States, Europe, and Asia Pacific.