Skip to content

Routing and classification

Routing selects the legal questions that must be answered for the named system. It is conservative, system-specific and recalculated from the current approved facts.

The cross-framework route first determines whether an EU territorial and role screen is required from the linked System Record and Intake. Unknown territorial facts remain screening required. The EU AI Act module then performs the more detailed legal routes below. See Routing and applicability.

Do not describe the result as a choice between “minimal,” “limited,” “high-risk” and “GPAI.” Different routes can apply together.

Scope and role
├─ Article 5 prohibited screen
├─ Article 6 / Annex I / Annex III classification
│ ├─ Articles 8–15 high-risk requirements
│ ├─ operator and conformity duties
│ ├─ FRIA where triggered
│ └─ monitoring and incidents
├─ Article 50 behaviour-based transparency
└─ Chapter V GPAI role and systemic-risk duties

The intake captures facts such as:

  • EU nexus and exclusion basis.
  • AI-system-definition determination.
  • Provider, deployer, importer, distributor, manufacturer and representative roles.
  • Intended purpose and actual use.
  • Article 5 screening for each prohibited practice.
  • Annex I product and third-party conformity-assessment status.
  • Each of the eight Annex III areas.
  • Article 6(3) exception factors and profiling.
  • Public-body and public-service status.
  • Article 50 behaviour triggers.
  • GPAI role, market-placement date and systemic-risk status.
  • Current system lifecycle and deployment state.

Free text can explain these fields but cannot override the authoritative route.

The central routing facts also provide decision impact, action capability, organisation roles, biometric, emotion-recognition, synthetic-content, deepfake and jurisdiction signals. These support screening but do not replace the module’s atomic legal determinations.

StateMeaning
not_assessedThe route has not yet been determined
applicableFacts trigger the route
not_applicable_with_evidenceA governed non-applicability decision is complete
incompleteRequired facts or decisions are missing
implementedRouted obligations have been addressed, subject to assurance
prohibited_stopA prohibited-practice hard stop applies
future_obligationApplicable provision is not yet in force for the current-law conclusion
proposed_change_onlyTracked proposal or political agreement is not binding law

The parent Article 5 question expands into eight atomic checks:

  1. Subliminal, manipulative or deceptive techniques.
  2. Exploitation of age, disability or social/economic vulnerability.
  3. Social scoring.
  4. Criminal-offence risk assessment based solely on profiling or personality traits.
  5. Untargeted scraping to create or expand facial-recognition databases.
  6. Emotion inference in workplace or education, subject to the narrow exception.
  7. Sensitive biometric categorisation.
  8. Real-time remote biometric identification in public spaces for law enforcement.

A confirmed prohibited practice stops confirmation. A potential prohibited practice also blocks confirmation until resolved. Strong scores elsewhere cannot offset this gate.

Two conditions must be analysed together:

  1. The AI system is a safety component of a product, or is itself a product, covered by legislation listed in Annex I.
  2. The product is required to undergo third-party conformity assessment under that legislation.

Record the product, applicable legal act, safety function, conformity route and responsible product manufacturer. Do not route solely because the system is safety-related.

Each point is atomic:

PointArea
1Biometrics
2Critical infrastructure
3Education and vocational training
4Employment, worker management and access to self-employment
5Essential private services and essential public services and benefits
6Law enforcement
7Migration, asylum and border control
8Administration of justice and democratic processes

Assess the precise use case, not just the industry. A bank chatbot is not automatically Annex III; a system evaluating creditworthiness may be.

Article 6(3) exception and profiling override

Section titled “Article 6(3) exception and profiling override”

For an Annex III use case, document whether the system poses a significant risk of harm to health, safety or fundamental rights. The statutory exception is narrow and requires a reasoned, documented analysis.

Consider whether the system:

  • Performs a narrow procedural task.
  • Improves the result of a previously completed human activity.
  • Detects patterns or deviations without replacing or influencing a prior human assessment.
  • Performs a preparatory task.

The exception does not apply where the system performs profiling of natural persons. Gamut records profiling separately and does not allow a generic “human in the loop” statement to establish the exception.

Where a provider concludes an Annex III system is not high-risk, preserve the Article 6(4) documentation and applicable registration evidence.

When high-risk classification is active, Gamut can activate:

  • Articles 8–15 system requirements.
  • Provider quality-management and record-retention duties.
  • Conformity assessment, declaration, CE marking and registration.
  • Deployer duties.
  • Article 21 authority cooperation.
  • Articles 22–25 representative, importer, distributor and value-chain duties.
  • Article 27 FRIA where its separate trigger applies.
  • Articles 72–73 monitoring and serious incidents.
  • Article 86 explanation rights where triggered.

The role matrix determines which of these belong to the organisation.

High-risk classification does not automatically mean every deployer must conduct a FRIA. Record the Article 27 trigger, including whether the deployer is:

  • A body governed by public law.
  • A private entity providing public services.
  • A deployer of specified Annex III systems for which the Act requires a FRIA.

Record linkage to any data-protection impact assessment without treating the DPIA as an automatic substitute.

Article 50 is behaviour-triggered and may apply whether or not the system is high-risk. Gamut checks:

  • Direct interaction with a natural person.
  • Machine-readable marking of synthetic content.
  • Emotion-recognition notice.
  • Biometric-categorisation notice.
  • Deepfake disclosure.
  • Public-interest text disclosure.
  • Timing at first interaction or exposure.
  • Clarity, distinguishability and accessibility.
  • Any relied-on statutory exception.

Each triggered duty receives its own conclusion.

Distinguish:

  • Direct GPAI model provider.
  • GPAI model provider with systemic risk.
  • Third-country provider requiring an authorised representative.
  • Downstream provider integrating a GPAI model.
  • Deployer or API consumer requiring supplier evidence.

For systemic risk, assess both the compute presumption and Commission designation. Do not treat a single compute threshold as the only route.

The Commission states that GPAI provider duties have applied since 2 August 2025. Its GPAI guidelines and voluntary GPAI Code of Practice can support interpretation and demonstration but do not replace the Regulation.

Examples that require resolution:

  • “Out of scope” with an EU market or output nexus.
  • No provider or deployer role despite professional operation.
  • Annex III use selected but classification left N/A.
  • Article 6 exception claimed while profiling is present.
  • GPAI systemic-risk duties selected while the organisation records no GPAI provider role.
  • FRIA marked N/A while trigger facts indicate applicability.
  • Article 50 notice marked N/A while a behaviour trigger is confirmed.

Gamut blocks confirmation rather than guessing through material uncertainty.

Confirmation is tied to the material routing facts. Changes to purpose, geography, role, model, Annex III use, Article 5 facts, transparency behaviour, GPAI status or other material fields invalidate the prior confirmation.

  • Route belongs to the displayed system.
  • All roles are factually supported.
  • Eight Article 5 and eight Annex III checks reviewed individually.
  • Annex I two-part test completed.
  • Article 6 exception and profiling analysed separately.
  • FRIA trigger determined independently.
  • Every Article 50 behaviour trigger recorded.
  • GPAI system and model roles distinguished.
  • Current, future and proposed legal states separated.
  • Contradictions and unknowns resolved before confirmation.