ART-AIMS-EU-003 v1.1 · EU AI Act Bridge Series · ISO/IEC 42001:2023 · IEC 82079-1:2012 · ITIL 4
EU AI Act Bridge Series · Gap C · ART-AIMS-EU-003 v1.1

The EU AI Act Classification Your Firm Has Never Done

Annex III of the EU AI Act classifies certain AI systems as High-Risk and triggers a cascade of obligations. Most law firm AI tools are Not High-Risk — but the Act does not accept silence as a classification. You need a documented assessment, per system, with a written rationale.

Direct Answer

Annex III of Regulation (EU) 2024/1689 lists eight categories of high-risk AI use cases. Article 6 determines whether a system falls within them. If it does, Arts. 9–15 (risk management, data governance, technical documentation, transparency, human oversight, accuracy and robustness) and Art. 26 (deployer obligations) apply, with a compliance deadline of 2 December 2027 (standalone AI systems) or 2 August 2028 (AI systems embedded in regulated products). If it does not, the classification record — with documented rationale — is itself the compliance evidence. REG-AIMS-CLASS-001 produces that record for every AI system in scope.

Document ref ART-AIMS-EU-003 v1.1
Published 25 July 2026
Next review 25 October 2026
Regulation EU AI Act Annex III · Art. 6
Series EU AI Act Bridge Series — Gap C

Priya asks the question Pemberton Capital will eventually ask

Scenario — Halstead & Cole LLP · October 2026

The governance questionnaire evolves

Three months after responding to Pemberton Capital's Section 7 AI literacy questions, Priya Anand receives an updated supplier questionnaire. Section 7 now has a subsection 7(c): "Has your firm assessed whether any AI systems used in matter delivery constitute High-Risk AI systems under EU AI Act Annex III? If so, which systems were classified as High-Risk and what obligations are you complying with? If not, what is the basis for your assessment that no High-Risk systems are in use?"

Priya opens REG-AIMS-CLASS-001. She clicks through to the Halstead & Cole register view. Four systems assessed. Zero High-Risk. Each assessment includes the Annex III area screened, the use-case specificity test result, the Art. 6(3) exclusion assessment, and a plain-English rationale signed off by the COLP in July. She copies the four rationale paragraphs into Pemberton Capital's questionnaire, notes the document reference, and attaches the register export. Section 7(c): answered.

A second firm across town — same four AI tools — has no register. Their response: "We do not believe our AI tools are high-risk." Unsubstantiated belief is not a compliance record. It is an invitation for a follow-up question.

⚑ Warning — The Default is Not Assessed, Not Not High-Risk

A firm that has not performed an Annex III assessment is not in a "Not High-Risk" position. It is in an "unassessed" position. The EU AI Act does not classify silence — it requires documented assessment. If a firm's AI systems are subsequently found to fall within Annex III, the absence of any prior assessment will be an aggravating factor, not a neutral one.

What Annex III and Article 6 actually require

Regulation (EU) 2024/1689 — Article 6(1) · Classification as High-Risk AI System

"Irrespective of whether an AI system is placed on the market or put into service independently from the products referred to in this paragraph, that AI system shall be considered to be high-risk where both of the following conditions are fulfilled: (a) the AI system is intended to be used as a safety component of a product, or the AI system is itself such a product, covered by the Union harmonisation legislation listed in Annex I; (b) the product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment with a view to the placing on the market or putting into service of that product pursuant to the Union harmonisation legislation listed in Annex I."

Regulation (EU) 2024/1689 — Article 6(2) · Annex III Classification

"In addition to the high-risk AI systems referred to in paragraph 1, AI systems referred to in Annex III shall be considered to be high-risk."

For law firms, Article 6(1) is almost never triggered — it covers AI embedded in regulated products requiring CE marking, not software tools used in legal practice. The relevant provision is Article 6(2): does the AI system fall within Annex III?

Annex III lists eight areas. For the AI tools in common use at UK law firms — drafting assistants, matter management tools, email copilots — the honest assessment is that they are almost universally Not High-Risk. But almost universally is not the same as without exception, and the Act does not accept the former as a substitute for the latter. Every system requires its own documented assessment.

Regulation (EU) 2024/1689 — Article 6(3) · Narrow Exclusions

"Notwithstanding paragraph 2, an AI system referred to in Annex III shall not be considered to be high-risk if it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making."

ℹ Note — Article 6(3) is Narrow, Not a General Escape Hatch

Article 6(3) provides specific exclusion grounds — the AI system performs a narrow preparatory task, or its output is subject to human override, or it detects patterns without making decisions affecting individuals. These are interpreted strictly. A firm that asserts Art. 6(3) as the basis for Not High-Risk shall document the specific exclusion ground and the factual basis for it. "We have human review" is not, by itself, an Art. 6(3) exclusion — it is an Art. 50(4) editorial responsibility position. The two are distinct.

ITIL 4 — Risk Management · Service Configuration Management

Under ITIL 4, the Annex III classification assessment maps to two practices. As a Risk Management input, it determines whether a specific AI system creates a regulatory risk that must be managed to a compliance deadline of 2 December 2027 (standalone) or 2 August 2028 (embedded in products). As a Service Configuration Management record, it documents a property of each Configuration Item (AI system): its EU AI Act classification. The cls_assessment table in REG-AIMS-CLASS-001 is the CMDB entry for classification status, updated annually or on material change — exactly the lifecycle cadence that ITIL 4 Configuration Management requires.

How to classify any AI system in three documented steps

The classification process is a three-step structured test. Each step produces a documented answer. The three answers together constitute the classification record.

1 Step 1
Annex III Area Screening

Screen all eight Annex III areas against the AI system's primary use case. Identify the most plausible area. Document which area was selected and why, or document that no area was identified as applicable and why. This step produces one of: (a) a specific area identified for testing in Step 2; or (b) a documented finding that no area applies, which closes the assessment as Not High-Risk.

2 Step 2
Use-Case Specificity Test

Annex III lists specific use cases within each area. The firm's actual use case must match one of those listed use cases — a general sector match is not sufficient. A law firm using AI to draft legal documents is in the legal sector but is not using AI to assist courts in adjudication. Document the specific listed use case tested and the conclusion. This step closes most law firm AI systems as Not High-Risk.

3 Step 3 (if needed)
Art. 6(3) Exclusion Assessment

Only reached if Steps 1 and 2 both point toward High-Risk. Assess whether the system qualifies for one of the Art. 6(3) narrow exclusions. Document the specific exclusion ground and factual basis. If no exclusion applies, the system is High-Risk and the obligation cascade is triggered. If an exclusion applies, record it and close as Not High-Risk under Art. 6(3).

Outcome: Not High-Risk
What the record must contain

Area screened (and why selected or why none applies). Use-case specificity test result. Art. 6(3) exclusion assessment (if applicable). Plain-English rationale. COLP approval date. Next review date (annual minimum). Retains for 7 years.

Outcome: High-Risk
What happens next

Arts. 9–15 obligations generated per system. Art. 26 deployer obligations documented. Art. 27 FRIA assessment triggered (Bridge 04). Obligation rows opened in cls_hr_obligation. Target: all obligations implemented by 2 December 2027 (standalone) or 2 August 2028 (embedded in products).

Four systems. Zero High-Risk. Full documentation.

The Halstead & Cole LLP scenario assessment produces Not High-Risk classifications for all four AI systems in use. The table below summarises the three-step test result for each system. All four assessments are recorded in REG-AIMS-CLASS-001 with rationale and COLP approval.

System Annex III Area Screened Step 1: Area Applies? Step 2: Use Case Listed? Classification
AIMS-SYS-001
GPT-4o
Area 8 — Administration of Justice No Not reached Not High-Risk
AIMS-SYS-002
M365 Copilot Word
Area 4 — Employment Management No Not reached Not High-Risk
AIMS-SYS-003
M365 Copilot Outlook
None — All Eight Screened No Not reached Not High-Risk
AIMS-SYS-004
LEAP AI
Area 5 — Access to Essential Services No Not reached Not High-Risk
⚐ Caution — The LEAP AI Note

The LEAP AI assessment includes a conditional caveat: if LEAP AI is configured to make autonomous recommendations on matter acceptance, fee arrangements, or client eligibility decisions without human review, the Area 5 assessment shall be revisited. This is the correct approach. Not High-Risk classifications are conditional on the use case as described — they shall be reviewed if the use case changes. REG-AIMS-CLASS-001 triggers an annual review and an on-change review for exactly this reason.

The critical insight from the Halstead & Cole assessment is that Area 8 (Administration of Justice) is the most commonly misidentified risk for law firm AI tools. The area covers AI assisting courts, tribunals, and similar adjudicatory bodies in determining legal outcomes. It does not cover AI assisting solicitors in drafting submissions, researching case law, or advising clients. The distinction is between adjudication and advocacy — two entirely different functions, and Annex III covers only the former.

REG-AIMS-CLASS-001 — what it is and how it gates the rest of the series

REG-AIMS-CLASS-001 is the gateway document in the EU AI Act Bridge Series. Its classification outcome determines whether Bridges 04, 05, and 06 are triggered:

ℹ Gateway Logic — Classification to Obligation

Zero High-Risk systems → Bridges 04 (FRIA), 05 (Incident Notification), and 06 (GPAI Verification) are not triggered by classification. They may still be required for other reasons — Bridge 06 applies if the firm uses GPAI models regardless of classification. Bridge 05 applies as a risk management measure regardless of classification. But the primary trigger — Annex III high-risk classification — is absent.

One or more High-Risk systems → Bridge 04 is triggered immediately. Arts. 9–15 obligation rows are opened in cls_hr_obligation. 2 December 2027 (standalone) or 2 August 2028 (embedded in products) becomes an active deadline for those systems. Bridge 05 (incident notification) is prioritised as an operational necessity.

The module includes three deliverables: the Supabase schema (five tables, four views, two stored procedures, immutable audit triggers, and RLS), the HTML dashboard with an interactive three-step decision tree, and this article. The decision tree in the dashboard walks through Steps 1–3 and produces a classified outcome — but every outcome it generates shall be reviewed by the COLP before entry into the database. The tool is guidance; the COLP's approval is the compliance record.

ℹ Note — Regulatory Sandboxes: Available from 2 August 2027

The EU AI Act Simplification Regulation (Omnibus VII, adopted 29 June 2026) postpones the deadline for national AI regulatory sandboxes to 2 August 2027. Regulatory sandboxes allow firms to test AI systems under competent authority supervision — directly relevant where a classification outcome is borderline or classified as "Requires Legal Advice" in REG-AIMS-CLASS-001. Firms holding a borderline assessment should note that a supervised sandbox pathway will become available from August 2027, providing a risk-managed route to deploy and test systems with uncertain Annex III status before committing to a full high-risk compliance programme.

Area 8 — why it matters and why most law firms are outside it

Area 8 deserves specific treatment because it is the area that generates the most uncertainty for law firms. The area covers AI systems intended to be used by a judicial or quasi-judicial body to assist in researching and interpreting facts and the law and in applying the law to a concrete set of facts. The key phrase is "judicial or quasi-judicial body." A law firm is neither.

A solicitor using GPT-4o to research case law, draft a skeleton argument, or summarise a witness statement is engaged in legal advocacy — preparing material for submission to a court. The court itself may use AI in its processes, and that use would fall within Area 8. The solicitor's preparation of that material does not.

This distinction matters because it is where the most common misconclassification risk lies. A firm that classifies its legal drafting AI as High-Risk under Area 8, on the basis that it "relates to" the administration of justice, has misread the Annex. The obligations that would then flow from that misclassification — Arts. 9–15, Art. 26, Art. 27 FRIA — are substantial and disproportionate. The correct classification is Not High-Risk, with a documented rationale that explains exactly why Area 8 does not apply to solicitor-side legal drafting tools.

⚐ Caution — Immigration Law Firm Exception

Firms practising immigration law should assess Area 7 (Migration, Asylum, Border Control) carefully. Area 7 covers AI used to assist competent public authorities in assessing risk or determining status in immigration and asylum contexts. If an AI tool is used to assist in the preparation of asylum applications, this may warrant closer analysis than the standard law firm assessment. Borderline cases shall be recorded as "Requires Legal Advice" in REG-AIMS-CLASS-001 and referred for external review.

Quality gate record

The following gates were checked before publication. All 10 gates pass. This record satisfies ISO 9001:2015 Clause 7.5.3 (control of documented information) for the EU AI Act Bridge Series.

Governance Academy — EU AI Act Bridge Series

Run your Annex III assessments this month

REG-AIMS-CLASS-001 is available to Governance Academy members: Supabase schema, interactive classification dashboard, and COLP-ready assessment records pre-populated for four AI systems. One module per month. All infrastructure owned permanently. £97/month.

Join the Governance Academy

This article is published for educational purposes only and does not constitute legal advice or advice on compliance with Regulation (EU) 2024/1689 (the EU AI Act), ISO/IEC 42001:2023, or any other standard or regulation. The Annex III analysis contained herein is a structured educational guide and does not constitute a legal opinion on classification. Classification assessments for specific AI systems shall be performed by or with a qualified legal adviser. Halstead & Cole LLP, Priya Anand, Pemberton Capital LLP, and all associated names are fictional constructs. Any resemblance to real persons or firms is coincidental. · Document ref: ART-AIMS-EU-003 v1.1 · Published 25 July 2026 · Next review: 25 October 2026 · Retention: 7 years · UNUS London Ltd. · unuslondon.com/legal/eu-ai-act-bridge-03-annex-iii-classification-register