EU AI Act · Qualification protocol

Qualify an AI system and the role of each entity

A defensible qualification connects an identified system, a precise use, a legal entity, a date and a regulatory basis. If one is missing, the conclusion is not auditable.

On this page
Required conclusion

Produce a qualification another reviewer can reproduce

The published method shows the order of the tests. The client record retains the facts, evidence, provision applied and reasoning leading to the conclusion. Another reviewer must be able to understand what was decided, for which version and within which limits.

Object
One bounded system, version and use
Conclusion
In scope, out of scope or point for determination
Authority
Provision, source and consultation date
Review
Named trigger, owner and due date
Technical object

Bound the system before qualifying the regime

A product name, the presence of a model or the word “AI” in a contract does not define the boundary. We isolate the chain that receives inputs, infers how to produce an output and influences a physical or virtual environment, then test the material and territorial scope under Article 2.

Architecture
Components, rules, models, data and interfaces
Autonomy
Independence of action from human intervention
Inference
Mechanism that determines how the output is produced
Effect
Influential prediction, content, recommendation or decision
Intended purpose

State a use that can be tested against the Annexes

Intended purpose comes from the provider; actual use comes from operation. We record them separately before reaching a risk conclusion. The sector alone is not enough: Annex III identifies specific use cases and conditions.

System
identify the function and version under review.
Action
state what the output recommends, triggers or executes.
Population
name the people or groups affected.
Context
specify the process, territory and operating conditions.
Human
establish who interprets, confirms, contests or stops the output.
Decision order

Pass six gates without jumping to the conclusion

Each gate produces an answer, a regulatory basis and a record. A “no” does not always end the analysis: a system that is not high-risk may still fall under a prohibited practice, a transparency duty or another body of law.

  1. Scope

    Article 2: operator, territory, placing on the market, putting into service and exclusions.

  2. Definition

    Article 3(1): the seven elements of an AI system.

  3. Prohibitions

    Article 5: purpose, capabilities, actual use and exceptions.

  4. Annex I

    Article 6(1): safety component or product and third-party assessment.

  5. Annex III

    Article 6(2)–(4): listed use, filter, profiling and documented rationale.

  6. Additional regimes

    Article 50, general-purpose AI models, GDPR and sector law.

Article 6(3)

Document the high-risk exception; never assume it

For an Annex III use case, the exception first requires no significant risk to health, safety or fundamental rights, including no material influence on decision-making. One of the following four conditions must then be demonstrated.

TestDecisive questionExpected record
Narrow procedural taskIs the output confined to one precise operation?Function, inputs, outputs and limits
Completed human resultDoes the system improve a result already produced by a person?Sequence and pre-AI version
Pattern detectionDoes it detect deviations without replacing or influencing the completed human assessment?Review rules and decision log
Preparatory taskDoes it only prepare an assessment covered by Annex III?Stopping point and human authority
ProfilingDoes the system profile natural persons?If yes: it remains high-risk
Value chain

Assign the role from the act actually performed

A role is not assigned to a corporate group as a whole. It is qualified for one legal person, one system and one market or operating act. The same organisation may therefore hold different roles for different objects.

RoleTriggering fact to establishUseful evidence
ProviderDevelops or has a system developed and markets it or puts it into service under its name or trademarkDevelopment contract, brand and service date
DeployerUses the system under its authority in a professional activityProcedure, permissions and use decision
ImporterEstablished in the Union, places on the market a system bearing the name or trademark of a non-EU operatorContract chain and import record
DistributorMakes a system available in the supply chain without being its provider or importerAvailability flow and responsibilities
Product manufacturerMarkets or puts into service an AI system with its product under its name or trademarkProduct file, integration and applicable assessment
Article 25

Identify the facts that may transfer the provider role

Purchasing or configuring a tool does not automatically transfer provider duties. For high-risk systems, Article 25 identifies precise role changes that must be established from evidence.

Observed factEffect to examineControl
Name or trademark placed on a high-risk systemThe actor becomes provider of that systemDisplayed brand, contracts and system reference
Substantial modification of a high-risk systemA new provider if the system remains high-riskUnplanned change and effect on requirements or purpose
Purpose changed so a non-high-risk system becomes high-riskThe third party becomes provider of the requalified systemPurpose before and after, plus Article 6 test
Safety system integrated into an Annex I productThe product manufacturer may become the providerName or trademark, integration and service date
Reference date

Apply the timeline to the qualification reached

Qualification identifies the regime; the date determines which provisions already apply, transitional measures and the next deadline. Regulation (EU) 2026/1744 notably separated the two high-risk routes.

DateEffect on the record
2 August 2026General application of the Regulation and Article 50 transparency duties
2 December 2026Application of the prohibitions added to Article 5 by Regulation (EU) 2026/1744
2 December 2027Chapter III, Sections 1–3 apply to Annex III high-risk systems
2 August 2028The same sections apply to Annex I high-risk systems
After a changeReassess scope, purpose, role, risk and the transitional regime
Qualification record

Retain the conclusion, reasoning and limits

The deliverable separates established facts, regulatory analysis and points for determination. It becomes the baseline for the requirements–controls–evidence matrix and remains tied to the version actually in operation.

  1. Technical reference identifier, architecture, components and versions.
  2. Use intended purpose, actual use, population and decision influenced.
  3. Entities role reached, triggering act and corresponding records.
  4. Regimes tests performed, provisions applied and reasoned exclusions.
  5. Conclusion result, uncertainty, approver and date.
  6. Review change trigger, owner and next review.

Primary sources

Sources this page relies on

Last documentary review: 5 September 2026.

Before you write to us

Frequently asked questions

Does a purchased solution always retain the role defined by its provider?

Purchase alone does not answer the question. An organisation is generally a deployer when it uses the system under its authority. For a high-risk system, rebranding, substantial modification or certain changes of intended purpose may assign it the provider role under Article 25.

Is every use mentioned in Annex III automatically high-risk?

The exact use case and Article 6 conditions must be checked. The Article 6(3) filter may apply in some cases; a system that profiles natural persons nevertheless remains high-risk.

When should the qualification be reopened?

After a change of intended purpose, component, version, population, value chain or operating condition that may alter scope, role or the applicable regime.

Can a third party review the conclusion?

Yes. The record retains the system and version, facts, sources, every test performed, conclusion, uncertainties and review trigger. A second reviewer must be able to reconstruct the reasoning.

EU AI Act qualification

Would your qualification withstand a second review?

Present the system, use, entity and date concerned. We identify the tests to perform and the points that require legal determination.

Present the system