EU AI Act Art. 6 + Annex III Risk Classification for SAP
As of 2026-10-06
What is EU AI Act Art. 6 + Annex III Risk Classification for SAP?
The classification call is made by the system architect at design time, not the legal department at audit time — and two concrete SAP use cases already land in Annex III's credit and employment categories.
What it is
Article 6 and Annex III of the EU AI Act are the classification engine that decides whether an AI system embedded in an SAP landscape must comply with the Act's full high-risk regime — technical documentation, conformity assessment, human oversight design, post-market monitoring, and CE-style declaration of conformity — or can proceed under the much lighter transparency-only or no-obligation tiers. For an SAP analytics architect, this is not a legal afterthought bolted on before go-live: the classification determines the shape of the build itself, because high-risk systems need traceability, logging, and human-override hooks designed in from day one, not retrofitted after a pilot succeeds.
Why it matters: SAP landscapes are exactly where Annex III triggers hide in plain sight. A Joule extension that ranks candidates for internal mobility touches the employment category. A Datasphere-fed credit-scoring model touches the access-to-essential-services category. A supplier-risk model that throttles payment terms touches the same category from the other side. None of these look like "AI systems" to the business stakeholder who requested them — they look like a smarter version of a report that already existed. That gap between subjective perception and legal classification is where most exposure sits.
Why it matters
- Discovering high-risk classification post-deployment risks a €15-35M fine (Art. 99) plus mandatory withdrawal from service
- A demand-sensing model adjusting payment terms by supplier risk score falls in the Annex III credit category — a common, easy-to-miss case
- The 200-800 person-day documentation burden must be budgeted before build, since the architect's design decisions determine the classification
Key points
- EU AI Act Art. 6 two-step classification: (1) product safety annex check (rarely applies to pure SAP analytics); (2) Annex III list check — 8 categories, two highly relevant for SAP: Category 4 (employment) and Category 5 (credit).
- SAP high-risk triggers: Joule for HR performance/promotion → Category 4. Supplier risk scoring feeding payment terms → Category 5. AI for energy grid / transport logistics → Category 2.
- High-risk obligations: Art. 9 risk management + Art. 10 data governance + Art. 11 technical documentation (47-field EU template) + Art. 13 transparency + Art. 14 HITL + Art. 15 accuracy/robustness + Art. 43 conformity assessment + CE marking.
- Estimated compliance effort: 200–800 person-days per high-risk system (EU Commission impact assessment).
- Fine risk for non-compliance: up to €15–35M or 3–7% of global annual turnover under Art. 99.
- GPAI obligations (Joule LLMs): Art. 50 transparency applies to all GPAI; Art. 55 systemic risk applies if training compute > 10^25 FLOPs. SAP covers model-layer GPAI compliance; customers own application-layer Annex III classification.
- Effective date for Annex III obligations: 2027-12-02 (Digital Omnibus, in force since 2026-07-27) (companion study “Regulatory Impact 2026”, Part II.1).
Terms used on this page
- Art. 6 EU AI Act
- Article defining the two-step classification logic for high-risk AI systems: (1) product safety annex check; (2) Annex III list check.
- Annex III
- The eight-category list of high-risk AI system domains in the EU AI Act. Categories 4 (employment) and 5 (credit) have the highest relevance for SAP deployments.
- CE Marking (AI Act)
- Mandatory conformity marking affixed to high-risk AI systems and their EU Declaration of Conformity after a conformity assessment under Art. 43.
- Art. 11 Technical Documentation
- Required documentation file for high-risk AI systems: 47-field EU Commission template covering architecture, training data, performance metrics, limitations, and HITL design.
- GPAI (General-Purpose AI)
- AI models capable of performing a wide range of tasks. Subject to Art. 50 transparency obligations. Systemic-risk GPAI (> 10^25 FLOPs) additionally subject to Art. 55.
- Systemic Risk (AI Act)
- Classification for GPAI models trained with > 10^25 FLOPs of compute. Triggers additional obligations under Art. 55 including adversarial testing and incident reporting to the EU AI Office.
- Art. 99
- Penalties article of the EU AI Act: up to €35M or 7% of global annual turnover for infringements related to prohibited AI practices; up to €15M or 3% for non-compliance with high-risk obligations.
Sources
- EU AI Act — Regulation (EU) 2024/1689 (full text)
- EU Commission — AI Act technical documentation template (Art. 11)
- SAP — EU AI Act compliance statement for Joule and BTP AI
- CJEU Case C-311/18 — Schrems-II ruling (EUR-Lex)
- Artificial Intelligence Act (EU) — Article 6, classification rules for high-risk AI systems
- Artificial Intelligence Act (EU) — Annex III, list of high-risk AI system use-case categories
- SAP News Center — AI agents work at scale: AI Governance Assistant, EU AI Act + NIST classification (22 Sep 2026)
- Databricks — Unity Catalog data governance and lineage documentation
- Microsoft Learn — Purview data lineage concept
- Microsoft — Responsible AI Standard
- Snowflake Docs — Cortex Analyst semantic model
- Orrick — EU AI Act Update: Digital Omnibus Finalizes 8 Compliance Changes, 29 July 2026 (Annex III date 2 Dec 2027, Annex I 2 Aug 2028, Art. 50(2) and Art. 5 dates, safety-component test)
- Osborne Clarke — European Commission publishes draft AI Act guidelines on high-risk classification, 18 June 2026 (Art. 6(3) filter, profiling exclusion, agentic systems)
- Gibson Dunn — EU AI Act Omnibus Agreement: postponed high-risk deadlines and other key changes
- Freshfields — EU AI Act Unpacked #32: draft Commission guidelines on high-risk AI (implications of the Art. 6 reading)
Full card available to members. What the full card adds: the full decision framework · the SAP vs Snowflake / Databricks / Fabric comparison · the common pitfalls and their fix · the cheat sheet · the architecture schemas · the code blocks · the facts worth quoting.