EU AI Act Compliance
AI Act Article 6 High-Risk Classification: What Microsoft Copilot Means for Your Business
Microsoft Copilot is live in thousands of European SMEs right now. Whether it triggers AI Act Article 6 high-risk classification depends on a two-part test your IT and compliance teams need to run today.
The Classification Question That Changes Everything
AI Act Article 6 high-risk classification is not about how sophisticated your AI tool is. It is about what the tool does and who it affects. Microsoft Copilot is a capable AI assistant, but whether it counts as a high-risk system under the EU AI Act depends entirely on how your organisation deploys it, not on the Microsoft brand name or the underlying model.
Get this classification wrong and you face two very different problems. Classify Copilot as high-risk when it is not, and you waste time and money on unnecessary controls. Miss a genuine high-risk deployment and you are exposed to fines of up to €15 million or 3% of global annual turnover under Article 99. The two-prong test in Article 6 is how you find the right answer.
The Two-Prong Test Explained
Article 6 of the EU AI Act defines a high-risk AI system using two cumulative conditions. Both must be true simultaneously.
Prong 1: Is the system intended to be used as a safety component, or is it listed in Annex III?
Annex III lists eight specific use-case areas:
- Biometric identification and categorisation
- Critical infrastructure management
- Education and vocational training
- Employment, workers management, and access to self-employment
- Access to essential private and public services and benefits
- Law enforcement
- Migration, asylum, and border control management
- Administration of justice and democratic processes
Category 4 is the one most SMEs need to watch. It explicitly covers AI used for recruitment, CV screening, promotion decisions, task allocation, and performance monitoring.
Prong 2: Does the system pose a significant risk to health, safety, or fundamental rights?
The system must not merely touch one of those topic areas. It must also carry genuine risk of real-world harm to individuals. A Copilot deployment that drafts a generic project update email does not meet this threshold. A Copilot deployment configured to rank job applicants or flag employees for performance review does.
Both prongs must be satisfied. If your use case does not appear in Annex III, the system is not high-risk under Article 6, regardless of how impactful it seems internally.
A Practical Decision Tree for Copilot Deployments
Walk through these four questions for each Copilot integration or plugin your organisation runs.
Step 1. What task is Copilot performing? Write down the concrete output. "Summarise emails" is different from "score candidate suitability."
Step 2. Does that task map to one of the eight Annex III categories? Be honest. "HR analytics" is not automatically Annex III Category 4. Only deployments that make or substantially influence decisions about employment qualify.
Step 3. Does the output directly influence a decision about a real person's rights or opportunities? If a human manager simply ignores the Copilot output, the risk profile drops sharply. If the output feeds directly into a shortlist or a termination workflow, it does not.
Step 4. Is there a meaningful human review before the decision is acted on? Article 26 requires deployers of high-risk systems to ensure human oversight is real, not cosmetic. A tick-box approval of an AI-generated shortlist without any independent review does not count.
If all four answers confirm a high-risk deployment, your obligations under Articles 26 and 27 activate.
Common Misconceptions That Get Companies Into Trouble
"Microsoft handles compliance, so we don't have to."
Microsoft is the provider. You are the deployer. Article 26 places a distinct set of obligations on deployers that no vendor can discharge on your behalf. You are responsible for defining the use case, implementing human oversight, and keeping records of your deployment decisions.
"Copilot is just a productivity tool, it can't be high-risk."
The AI Act does not classify tools. It classifies use cases. The same Copilot licence used to draft meeting summaries (not high-risk) could be configured via a plugin to analyse employee productivity patterns and flag underperformers (potentially high-risk under Annex III Category 4). The tool is identical. The deployment is not.
"We are too small to be regulated."
The AI Act applies to any organisation that deploys AI systems affecting people in the EU, regardless of headcount. The regulation does not have an SME exemption for deployers, though it does offer some procedural flexibilities for providers who are SMEs.
"We need a full AI impact assessment for everything."
A Fundamental Rights Impact Assessment (FRIA) is only required where a public authority deploys a high-risk system, or in specific sector contexts. Private sector SMEs are not automatically required to produce one, but the internal documentation obligations under Article 26 still apply to all high-risk deployers.
Worked Examples by Use Case
Example 1: Marketing team using Copilot to draft campaign copy
Output: Text for email campaigns. No Annex III category applies. No rights or employment decisions involved. Result: Not high-risk. Standard AI literacy obligations under Article 4 apply, but nothing more.
Example 2: Finance team using Copilot to summarise contract clauses
Output: Summaries that a human lawyer reviews before any action. Annex III does not cover internal legal review tools used by private companies in a support capacity. Result: Not high-risk. Ensure staff understand the tool's limitations and that final decisions remain with qualified humans.
Example 3: HR team using a Copilot plugin that scores CVs and ranks applicants
Output: Ranked shortlists that recruiters use to decide who gets an interview. This squarely matches Annex III Category 4 (employment decisions) and affects fundamental rights (equal access to work). Result: High-risk. Article 26 obligations apply. You must implement human oversight, maintain logs, and ensure the system is only used within the intended purpose defined by Microsoft.
Example 4: Operations manager using Copilot to generate shift schedules
Output: Draft rosters that the manager adjusts before publishing. No automated disciplinary or dismissal decision involved. Human review is genuine. Result: Borderline. If the roster is always published unmodified and influences pay or conditions, revisit. If the manager regularly edits it, the risk classification is unlikely to reach high-risk threshold.
Example 5: Copilot integrated with a performance management platform, flagging employees below a KPI threshold for manager attention
Output: Automated alerts used to initiate performance improvement plans. This combination affects employment and is driven by automated analysis. Result: High-risk under Annex III Category 4. Article 26 obligations activate immediately.
What Your IT Team Needs to Do Right Now
The August 2026 deadline for most Article 26 deployer obligations is closer than it looks. Three actions matter most.
First, build an AI inventory. List every Copilot integration, plugin, and connected workflow. For each one, run the two-prong test above. Document your reasoning. This record is what a regulator or a works council will ask for first.
Second, check your Microsoft agreement. Microsoft publishes documentation describing the intended purpose of each Copilot product. Article 27 requires providers to give deployers the information they need to comply. If that documentation does not exist or is unclear, escalate to your Microsoft account manager in writing.
Third, brief your HR and department heads. The classification decision is not purely technical. It requires input from the people who know how outputs are actually used day-to-day. A monthly AI governance review meeting, even a short one, builds the habit your compliance team will thank you for later.
The EU AI Act does not punish organisations for using AI. It penalises organisations that use it without knowing what they are doing. Running the Article 6 two-prong test is how you demonstrate that your organisation does know what it is doing.
Not sure whether your Copilot deployment crosses the high-risk threshold? Run the free 2-minute compliance check at comply.khairos.ai and get a clear starting point for your AI Act obligations.
# Need help getting compliant?
The free 2-minute compliance check shows you exactly where your gaps are. No email gate to see your score.
Start the free check →