EU AI Act Art. 6 + Annex III Risk Classification for SAP
As of 2026-07-24T14:00:00Z
What is EU AI Act Art. 6 + Annex III Risk Classification for SAP?
The classification call is made by the system architect at design time, not the legal department at audit time — and two concrete SAP use cases already land in Annex III's credit and employment categories.
What it is
Article 6 and Annex III of the EU AI Act are the classification engine that decides whether an AI system embedded in an SAP landscape must comply with the Act's full high-risk regime — technical documentation, conformity assessment, human oversight design, post-market monitoring, and CE-style declaration of conformity — or can proceed under the much lighter transparency-only or no-obligation tiers. For an SAP analytics architect, this is not a legal afterthought bolted on before go-live: the classification determines the shape of the build itself, because high-risk systems need traceability, logging, and human-override hooks designed in from day one, not retrofitted after a pilot succeeds.
Why it matters: SAP landscapes are exactly where Annex III triggers hide in plain sight. A Joule extension that ranks candidates for internal mobility touches the employment category. A Datasphere-fed credit-scoring model touches the access-to-essential-services category. A supplier-risk model that throttles payment terms touches the same category from the other side. None of these look like "AI systems" to the business stakeholder who requested them — they look like a smarter version of a report that already existed. That gap between subjective perception and legal classification is where most exposure sits.
Why it matters
- Discovering high-risk classification post-deployment risks a €15-35M fine (Art. 99) plus mandatory withdrawal from service
- A demand-sensing model adjusting payment terms by supplier risk score falls in the Annex III credit category — a common, easy-to-miss case
- The 200-800 person-day documentation burden must be budgeted before build, since the architect's design decisions determine the classification
Key points
- EU AI Act Art. 6 two-step classification: (1) product safety annex check (rarely applies to pure SAP analytics); (2) Annex III list check — 8 categories, two highly relevant for SAP: Category 4 (employment) and Category 5 (credit).
- SAP high-risk triggers: Joule for HR performance/promotion → Category 4. Supplier risk scoring feeding payment terms → Category 5. AI for energy grid / transport logistics → Category 2.
- High-risk obligations: Art. 9 risk management + Art. 10 data governance + Art. 11 technical documentation (47-field EU template) + Art. 13 transparency + Art. 14 HITL + Art. 15 accuracy/robustness + Art. 43 conformity assessment + CE marking.
- Estimated compliance effort: 200–800 person-days per high-risk system (EU Commission impact assessment).
- Fine risk for non-compliance: up to €15–35M or 3–7% of global annual turnover under Art. 99.
- GPAI obligations (Joule LLMs): Art. 50 transparency applies to all GPAI; Art. 55 systemic risk applies if training compute > 10^25 FLOPs. SAP covers model-layer GPAI compliance; customers own application-layer Annex III classification.
- Effective date for Annex III obligations: 2026-08-02 (companion study “Regulatory Impact 2026”, Part II.1).
- EU AI Act Art. 6 + Annex III Risk Classification for SAP is mastered only when it changes a named buyer decision.
- Start with the semantic contract and control model before demonstrating the tool.
- Use current SAP, analyst, study, KG, and news signals as evidence, not decoration.
Terms used on this page
- Art. 6 EU AI Act
- Article defining the two-step classification logic for high-risk AI systems: (1) product safety annex check; (2) Annex III list check.
- Annex III
- The eight-category list of high-risk AI system domains in the EU AI Act. Categories 4 (employment) and 5 (credit) have the highest relevance for SAP deployments.
- CE Marking (AI Act)
- Mandatory conformity marking affixed to high-risk AI systems and their EU Declaration of Conformity after a conformity assessment under Art. 43.
- Art. 11 Technical Documentation
- Required documentation file for high-risk AI systems: 47-field EU Commission template covering architecture, training data, performance metrics, limitations, and HITL design.
- GPAI (General-Purpose AI)
- AI models capable of performing a wide range of tasks. Subject to Art. 50 transparency obligations. Systemic-risk GPAI (> 10^25 FLOPs) additionally subject to Art. 55.
- Systemic Risk (AI Act)
- Classification for GPAI models trained with > 10^25 FLOPs of compute. Triggers additional obligations under Art. 55 including adversarial testing and incident reporting to the EU AI Office.
- Art. 99
- Penalties article of the EU AI Act: up to €35M or 7% of global annual turnover for infringements related to prohibited AI practices; up to €15M or 3% for non-compliance with high-risk obligations.
- Decision owner
- The accountable person who accepts the trade-off and funds the next action.
Sources
- EU AI Act — Regulation (EU) 2024/1689 (full text)
- EU Commission — AI Act technical documentation template (Art. 11)
- SAP — EU AI Act compliance statement for Joule and BTP AI
- Applied AI study 2025 — Art. 9-49 documentation effort estimate (Munich)
- SAP News Center — Accelerate the Autonomous Enterprise with SAP Business Data Cloud
- SAP News Center — SAP Unveils the Autonomous Enterprise
- SAP News Center — The Future of the Enterprise Is Autonomous
- SAP Datasphere — Help Portal
- SAP Datasphere — official product page
- SAP Analytics Cloud — Help Portal
- SAP Analytics Cloud — official product page
- SAP BW/4HANA — Help Portal
- SAP S/4HANA — Help Portal
- SAP News Center
- SAP Community
- SAP — industries overview
- EFRAG — CSRD/ESRS standards
- Gartner — research & analyst site
- BARC — BI & Analytics research
- TDWI — data & analytics research
- DSAG — German-speaking SAP user group
- ASUG — Americas' SAP User Group
- Databricks — official site
- CJEU Case C-311/18 — Schrems-II ruling (EUR-Lex)
Full card available to members. What the full card adds: the full decision framework · the SAP vs Snowflake / Databricks / Fabric comparison · the common pitfalls and their fix · the cheat sheet · the architecture schemas · the code blocks · the facts worth quoting.