# Annex III Classification Changes and Updates — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/annex-iii-classification-changes
> Sources are cited per item. Verify against the official texts before relying on them.

The content specifically addresses amendments to Annex III, which represents a distinct regulatory mechanism for updating high-risk AI system classifications. This topic would capture the procedural and substantive aspects of how Annex III is modified over time.

## Overview

## Legal Framework

Annex III of the AI Act enumerates standalone high-risk AI systems—those classified as high-risk independent of their role as safety components in regulated products. The primary mechanism for updating Annex III is Article 7 of the AI Act, which empowers the European Commission to adopt delegated acts modifying, adding to, or removing use-cases from Annex III. This power is bounded by substantive criteria: the Commission must assess whether the AI system in question poses a significant risk of harm to health, safety, or fundamental rights, and whether such risk is not already adequately mitigated by existing Union law or the system's own design features.

Articles 103 and 104 of the AI Act illustrate the broader architecture of classification updates by amending sectoral regulations—specifically Regulation (EU) No 167/2013 (agricultural machinery) and Regulation (EU) No 168/2013 (two- and three-wheel vehicles). Each amendment inserts a new subparagraph requiring that, when delegated acts are adopted under those sectoral frameworks concerning AI systems functioning as safety components, the requirements set out in Chapter III, Section 2 of the AI Act must be taken into account. This creates a bridge between product safety legislation and the AI Act's high-risk regime.

## Key Developments

No enforcement decisions or case law yet exist interpreting Annex III amendment procedures, as the AI Act's application dates have not fully arrived. However, the procedural design establishes several practical thresholds. The Commission's delegated act power under Article 7 is subject to the conditions of Article 8, meaning amendments must be based on documented evidence of emerging risks. The delegated acts are also subject to the standard scrutiny mechanisms under Regulation (EU) 2018/1725, allowing the European Parliament and Council to object. The interplay between Annex III updates and sectoral regulation amendments (as seen in Articles 103 and 104) signals that classification changes will likely proceed in parallel across both tracks—standalone high-risk categories and product safety component categories.

## Practical Guidance

- **Monitor delegated act consultations**: Article 7 amendments to Annex III will be preceded by Commission consultations; organizations deploying AI systems near current Annex III boundaries should track these to anticipate reclassification of their systems from non-high-risk to high-risk.

- **Map dual-track exposure**: If your AI system functions as a safety component in machinery or vehicles regulated under Regulations 167/2013 or 168/2013, prepare for concurrent obligations under both the sectoral framework and AI Act Chapter III, Section 2, as mandated by Articles 103 and 104.

- **Maintain risk documentation aligned with Article 7 criteria**: Since Annex III amendments hinge on demonstrated significant risk to health, safety, or fundamental rights, maintain internal risk assessments using these same criteria to anticipate whether your system may be swept into Annex III through future delegated acts.

- **Build classification flexibility into compliance programs**: Because Annex III is explicitly designed to evolve, avoid static compliance architectures; ensure your AI governance framework can accommodate reclassification without full system redesign.

## Legislation (full text of key provisions)

### Amendment to Regulation (EU) No 167/2013

*Source: AI Act, aiact-art-103-en, 2024-06-12 — https://overview.legal/posts/93609*

In Article 17(5) of Regulation (EU) No 167/2013, the following subparagraph is added:‘When adopting delegated acts pursuant to the first subparagraph concerning artificial intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.

### Amendment to Regulation (EU) No 168/2013

*Source: AI Act, aiact-art-104-en, 2024-06-12 — https://overview.legal/posts/93611*

In Article 22(5) of Regulation (EU) No 168/2013, the following subparagraph is added:‘When adopting delegated acts pursuant to the first subparagraph concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.

### Amendment to Directive (EU) 2016/797

*Source: AI Act, aiact-art-106-en, 2024-06-12 — https://overview.legal/posts/93615*

In Article 5 of Directive (EU) 2016/797, the following paragraph is added:‘12. When adopting delegated acts pursuant to paragraph 1 and implementing acts pursuant to paragraph 11 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.

### Amendment to Regulation (EU) 2018/858

*Source: AI Act, aiact-art-107-en, 2024-06-12 — https://overview.legal/posts/93617*

In Article 5 of Regulation (EU) 2018/858 the following paragraph is added:‘4. When adopting delegated acts pursuant to paragraph 3 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.

### Recital 173 — Commission delegated powers to adapt AI rules

*Source: AI Act, aiact-rec-173-en, 2024-06-12 — https://overview.legal/posts/94028*

In order to ensure that the regulatory framework can be adapted where necessary, the power to adopt acts in accordance with Article 290 TFEU should be delegated to the Commission to amend the conditions under which an AI system is not to be considered to be high-risk, the list of high-risk AI systems, the provisions regarding technical documentation, the content of the EU declaration of conformity the provisions regarding the conformity assessment procedures, the provisions establishing the high-risk AI systems to which the conformity assessment procedure based on assessment of the quality management system and assessment of the technical documentation should apply, the threshold, benchmarks and indicators, including by supplementing those benchmarks and indicators, in the rules for the classification of general-purpose AI models with systemic risk, the criteria for the designation of general-purpose AI models with systemic risk, the technical documentation for providers of general-purpose AI models and the transparency information for providers of general-purpose AI models. It is of particular importance that the Commission carry out appropriate consultations during its preparatory work, including at expert level, and that those consultations be conducted in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making (55). In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States’ experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated acts.

### Recital 52 — classification of standalone high-risk AI systems

*Source: AI Act, aiact-rec-52-en, 2024-06-12 — https://overview.legal/posts/93786*

As regards stand-alone AI systems, namely high-risk AI systems other than those that are safety components of products, or that are themselves products, it is appropriate to classify them as high-risk if, in light of their intended purpose, they pose a high risk of harm to the health and safety or the fundamental rights of persons, taking into account both the severity of the possible harm and its probability of occurrence and they are used in a number of specifically pre-defined areas specified in this Regulation. The identification of those systems is based on the same methodology and criteria envisaged also for any future amendments of the list of high-risk AI systems that the Commission should be empowered to adopt, via delegated acts, to take into account the rapid pace of technological development, as well as the potential changes in the use of AI systems.

### Recital 101 — General-purpose AI model provider transparency obligations

*Source: AI Act, aiact-rec-101-en, 2024-06-12 — https://overview.legal/posts/93884*

Providers of general-purpose AI models have a particular role and responsibility along the AI value chain, as the models they provide may form the basis for a range of downstream systems, often provided by downstream providers that necessitate a good understanding of the models and their capabilities, both to enable the integration of such models into their products, and to fulfil their obligations under this or other regulations. Therefore, proportionate transparency measures should be laid down, including the drawing up and keeping up to date of documentation, and the provision of information on the general-purpose AI model for its usage by the downstream providers. Technical documentation should be prepared and kept up to date by the general-purpose AI model provider for the purpose of making it available, upon request, to the AI Office and the national competent authorities. The minimal set of elements to be included in such documentation should be set out in specific annexes to this Regulation. The Commission should be empowered to amend those annexes by means of delegated acts in light of evolving technological developments.

## Related topics

- **Delegated Acts** — https://overview.legal/topics/delegated-acts-adoption-procedures
  This content specifically addresses the procedural framework for adopting delegated acts under the AI Act, including how they apply to safety components and sec
- **Committee Procedure under AI Act** — https://overview.legal/topics/committee-procedure-ai-act
  The content specifically addresses 'Committee procedure' as a distinct procedural mechanism under the AI Act. This topic is not adequately covered by existing t
- **Delegation of Powers** — https://overview.legal/topics/delegation-of-powers-procedures
  The content specifically addresses 'Exercise of the delegation' which is a distinct procedural topic covering how delegated powers are exercised, implemented, a
- **Provider Obligations for AI Systems** — https://overview.legal/topics/provider-obligations-ai
  The content specifically addresses obligations imposed on providers of high-risk AI systems, which is a distinct and important category of requirements that des
- **High-Risk AI Classification** — https://overview.legal/topics/high-risk-ai-classification
  The content specifically addresses classification rules for high-risk AI systems under the AI Act, which is a distinct regulatory concept requiring its own dedi
- **Conformity Assessment for AI Systems** — https://overview.legal/topics/conformity-assessment-ai
  Provider obligations typically include conformity assessment procedures and documentation requirements, which is a specific compliance mechanism under the AI Ac

---
Generated by overview.legal · https://overview.legal/topics/annex-iii-classification-changes · 2026-08-22
