Article 80 of Regulation (EU) 2024/1689 — Procedure for systems misclassified as non-high-risk. Official text, practical interpretation, key obligations and compliance implications.
Article 80 polices the Act's biggest self-assessment: a provider's claim under Article 6(3) that its Annex III system is not high-risk. Market surveillance authorities can audit that claim — and reclassify the system with full consequences.
Official Text Summary
Market surveillance authorities may evaluate any AI system that its provider has classified as non-high-risk in application of Article 6(3), including following a reasoned request from another authority. Where the evaluation finds the system is in fact high-risk, the authority requires the provider to bring it into compliance with the full Chapter III regime within a period it may prescribe — requirements, conformity assessment, CE marking and registration included — and to take corrective action towards systems already on the market. Where the misclassification was carried out to circumvent the application of the rules, the provider is exposed to fines under Article 99, and the authority informs the Commission and the other Member States of the outcome.
Key Obligations
- The authority may evaluate any system classified by its provider as non-high-risk under Article 6(3), including on a reasoned request from another authority
- If the system is in fact high-risk, the provider must bring it into full Chapter III compliance within a set period, including conformity assessment and registration
- Misclassification aimed at circumventing the rules exposes the provider to fines under Article 99, and the authority informs the Commission and the other Member States
Compliance Timeline
Applies from 2 August 2026; the 2026 Digital Omnibus deferred the substantive high-risk obligations (Annex III to 2 December 2027, Annex I to 2 August 2028) but did not move this provision.
Official AI Act Compliance Deadline Calendar
Updated · Sources: Regulation (EU) 2024/1689 and the 2026 Digital Omnibus on AI.
| Obligation | Applies to | Original date | New date | Status | Countdown | Legal basis |
|---|---|---|---|---|---|---|
| Prohibited Practices (Art. 5) | All providers and deployers | active | — | AI Act Art. 5 | ||
| GPAI Rules (Chapter 5) | GPAI model providers | active | — | AI Act Art. 51-56 | ||
| Commission Enforcement Powers over GPAI | GPAI model providers | active | — | AI Act Art. 88-94, 101 | ||
| Transparency Obligations (Art. 50) | Providers and deployers of chatbots, generative, emotion recognition systems | active | — | AI Act Art. 50 | ||
| New Art. 5 Prohibition (CSAM / non-consensual intimate imagery) | Providers and deployers of generative AI systems | active | — | AI Omnibus 2026 Art. 5 | ||
| AI-Generated Content Marking (pre-existing systems) | Providers of generative AI systems on the market before 2 Aug 2026 | active | — | AI Act Art. 50(2) — transitional | ||
| Regulatory Sandboxes | National competent authorities | deferred | — | AI Omnibus 2026 Art. 57 | ||
| High-risk AI — Annex III (standalone) | Providers of standalone Annex III systems | deferred | — | AI Omnibus 2026 Art. 6(2) | ||
| High-risk AI — Annex I (embedded) | AI embedded in Annex I regulated products | deferred | — | AI Omnibus 2026 Art. 6(1) |
⬇ Download JSON · CC BY 4.0
AI Act meets DORA and NIS2
Is your organisation subject to both the AI Act and DORA? The two regulations intersect on the operational resilience of financial AI systems. Our sister site regulation-dora.eu covers DORA in depth — including what the AI Act adds on top of an existing DORA programme.
The AI Act for financial institutions ↗ Explore regulation-dora.eu ↗Frequently Asked Questions
The Article 6(3) exception is the Act's most tempting shortcut: a provider self-declares its Annex III system non-high-risk and escapes the whole Chapter III regime. Article 80 is the audit mechanism that makes that self-declaration a documented, defensible position rather than a free pass — and the documented assessment required by Article 6(4) is exactly what the authority will ask to see.
Only as far as it is credible. If reclassification happens, obligations cascade — a deployer using what turns out to be a high-risk system inherits the Article 26 duties. Due diligence on the provider's Article 6(3) reasoning is cheap insurance.
Stay ahead of AI Act changes
Get compliance alerts when deadlines or obligations change.
No spam. One-click unsubscribe.
Take compliance further with the AI Act Academy
Templates, training modules, and live Q&A — everything needed to implement AI Act compliance.