Analytics Legends The knowledge platform for SAP Analytics
Concept card

EU AI Act Art. 6 + Annex III Risk Classification for SAP

EU AI Act Art. 6 + Annex III Risk Classification for SAP — Analytics Legends section illustration for the SAP Analytics knowledge base (concepts, studies, Academy)

As of 2026-07-24T14:00:00Z

What is EU AI Act Art. 6 + Annex III Risk Classification for SAP?

The classification call is made by the system architect at design time, not the legal department at audit time — and two concrete SAP use cases already land in Annex III's credit and employment categories.

What it is

Article 6 and Annex III of the EU AI Act are the classification engine that decides whether an AI system embedded in an SAP landscape must comply with the Act's full high-risk regime — technical documentation, conformity assessment, human oversight design, post-market monitoring, and CE-style declaration of conformity — or can proceed under the much lighter transparency-only or no-obligation tiers. For an SAP analytics architect, this is not a legal afterthought bolted on before go-live: the classification determines the shape of the build itself, because high-risk systems need traceability, logging, and human-override hooks designed in from day one, not retrofitted after a pilot succeeds.

Why it matters: SAP landscapes are exactly where Annex III triggers hide in plain sight. A Joule extension that ranks candidates for internal mobility touches the employment category. A Datasphere-fed credit-scoring model touches the access-to-essential-services category. A supplier-risk model that throttles payment terms touches the same category from the other side. None of these look like "AI systems" to the business stakeholder who requested them — they look like a smarter version of a report that already existed. That gap between subjective perception and legal classification is where most exposure sits.

Why it matters

  • Discovering high-risk classification post-deployment risks a €15-35M fine (Art. 99) plus mandatory withdrawal from service
  • A demand-sensing model adjusting payment terms by supplier risk score falls in the Annex III credit category — a common, easy-to-miss case
  • The 200-800 person-day documentation burden must be budgeted before build, since the architect's design decisions determine the classification

Key points

  • EU AI Act Art. 6 two-step classification: (1) product safety annex check (rarely applies to pure SAP analytics); (2) Annex III list check — 8 categories, two highly relevant for SAP: Category 4 (employment) and Category 5 (credit).
  • SAP high-risk triggers: Joule for HR performance/promotion → Category 4. Supplier risk scoring feeding payment terms → Category 5. AI for energy grid / transport logistics → Category 2.
  • High-risk obligations: Art. 9 risk management + Art. 10 data governance + Art. 11 technical documentation (47-field EU template) + Art. 13 transparency + Art. 14 HITL + Art. 15 accuracy/robustness + Art. 43 conformity assessment + CE marking.
  • Estimated compliance effort: 200–800 person-days per high-risk system (EU Commission impact assessment).
  • Fine risk for non-compliance: up to €15–35M or 3–7% of global annual turnover under Art. 99.
  • GPAI obligations (Joule LLMs): Art. 50 transparency applies to all GPAI; Art. 55 systemic risk applies if training compute > 10^25 FLOPs. SAP covers model-layer GPAI compliance; customers own application-layer Annex III classification.
  • Effective date for Annex III obligations: 2026-08-02 (companion study “Regulatory Impact 2026”, Part II.1).
  • EU AI Act Art. 6 + Annex III Risk Classification for SAP is mastered only when it changes a named buyer decision.
  • Start with the semantic contract and control model before demonstrating the tool.
  • Use current SAP, analyst, study, KG, and news signals as evidence, not decoration.

Terms used on this page

Art. 6 EU AI Act
Article defining the two-step classification logic for high-risk AI systems: (1) product safety annex check; (2) Annex III list check.
Annex III
The eight-category list of high-risk AI system domains in the EU AI Act. Categories 4 (employment) and 5 (credit) have the highest relevance for SAP deployments.
CE Marking (AI Act)
Mandatory conformity marking affixed to high-risk AI systems and their EU Declaration of Conformity after a conformity assessment under Art. 43.
Art. 11 Technical Documentation
Required documentation file for high-risk AI systems: 47-field EU Commission template covering architecture, training data, performance metrics, limitations, and HITL design.
GPAI (General-Purpose AI)
AI models capable of performing a wide range of tasks. Subject to Art. 50 transparency obligations. Systemic-risk GPAI (> 10^25 FLOPs) additionally subject to Art. 55.
Systemic Risk (AI Act)
Classification for GPAI models trained with > 10^25 FLOPs of compute. Triggers additional obligations under Art. 55 including adversarial testing and incident reporting to the EU AI Office.
Art. 99
Penalties article of the EU AI Act: up to €35M or 7% of global annual turnover for infringements related to prohibited AI practices; up to €15M or 3% for non-compliance with high-risk obligations.
Decision owner
The accountable person who accepts the trade-off and funds the next action.

Sources

  1. EU AI Act — Regulation (EU) 2024/1689 (full text)
  2. EU Commission — AI Act technical documentation template (Art. 11)
  3. SAP — EU AI Act compliance statement for Joule and BTP AI
  4. Applied AI study 2025 — Art. 9-49 documentation effort estimate (Munich)
  5. SAP News Center — Accelerate the Autonomous Enterprise with SAP Business Data Cloud
  6. SAP News Center — SAP Unveils the Autonomous Enterprise
  7. SAP News Center — The Future of the Enterprise Is Autonomous
  8. SAP Datasphere — Help Portal
  9. SAP Datasphere — official product page
  10. SAP Analytics Cloud — Help Portal
  11. SAP Analytics Cloud — official product page
  12. SAP BW/4HANA — Help Portal
  13. SAP S/4HANA — Help Portal
  14. SAP News Center
  15. SAP Community
  16. SAP — industries overview
  17. EFRAG — CSRD/ESRS standards
  18. Gartner — research & analyst site
  19. BARC — BI & Analytics research
  20. TDWI — data & analytics research
  21. DSAG — German-speaking SAP user group
  22. ASUG — Americas' SAP User Group
  23. Databricks — official site
  24. CJEU Case C-311/18 — Schrems-II ruling (EUR-Lex)

Full card available to members. What the full card adds: the full decision framework · the SAP vs Snowflake / Databricks / Fabric comparison · the common pitfalls and their fix · the cheat sheet · the architecture schemas · the code blocks · the facts worth quoting.

Open in the app →