06-reference/research

ai act annex iii employment entries

2026-08-23·research-brief·source: deep-research·by Ray Data Co (deep-research synthesis)
eu-ai-actdigital-omnibusannex-iiihigh-risk-classificationprimary-source-verification

Annex III Was Never Touched: The Omnibus Moved the Clock, Left the Employment List and the Filter Verbatim, and Deleted Exactly Two Lines of Registration Paperwork

Not legal advice. This is a text-verification pass by a non-lawyer agent. It reports what the enacting words say and what the amendment markers show, not what any of it means for a particular product.

The question

"Did the EU Digital Omnibus change Annex III's employment-context entries themselves, and what became of the Article 6(3) filter derogation and the Annex III registration duty, or did it move only the applicability date?"

Follow-up carried forward twice — raised in [[2026-08-15-eu-digital-omnibus-ai-official-journal-check]], re-flagged as the highest-value open item in [[2026-08-21-ai-act-article-113-operative-text-check]]. The grandparent brief [[2026-08-02-agents-as-employees-regulatory-labor-framing]] built its entire scope read on what Annex III's employment entry covers, and no pass had yet read the amended text.

Answer, up front.

Sub-question Answer Evidence tier
Did Annex III's employment entries change? No. Annex III is untouched in its entirety — not one word, not one point Primary, verified three independent ways
What became of the Article 6(3) filter derogation? Unchanged, verbatim. All four conditions and the profiling carve-back survive as original text. Article 6(4)'s documentation duty also survives Primary, amendment markers + literal diff
What became of the Annex III registration duty? Article 49 unchanged in all five paragraphs. The only cut is Annex VIII Section B points 7 and 9 — two data fields on the not-high-risk register, not the Annex III register Primary, enacting text of the amending act
So did it move only the date? On Annex III, effectively yes. The Omnibus's substantive high-risk-scope work is all on the Article 6(1)/Annex I product side Primary

What we already know (from the vault)

What the web says

Method. Three primary documents were fetched with curl to disk and read locally: the authentic OJ text of Regulation (EU) 2026/1744 (OJ:L_202601744, 353 KB), the consolidated AI Act at CELEX 02024R1689-20260727 (853 KB), and the original AI Act at CELEX 32024R1689 (1.26 MB). The consolidation's header confirms Regulation (EU) 2026/1744 of 8 July 2026 is the only amending act on record — marker M1, no M2. Annex III has therefore never been amended by anything, Omnibus or delegated act.

A textual oddity, flagged as reading rather than finding. The amended Article 113 third paragraph point (c) defers "Chapter III, Sections 1, 2, and 3." Article 49 sits in Chapter III Section 5 ("Standards, conformity assessment, certificates, registration," Articles 40-49), and Article 71 sits in Chapter VIII. Neither is named in the deferral, so on the face of the text both apply from the general 2 August 2026 date while the Article 6(2)/6(3) classification rules that trigger them do not apply until 2 December 2027. Note also that the original point (c) read simply "Article 6(1) and the corresponding obligations in this Regulation shall apply from 2 August 2027" — a broad wrapper phrase the replacement drops in favour of a section-by-section enumeration. Whether that leaves Section 5 as a null set (nothing can be a high-risk system before Section 1 applies) or as a live-but-empty duty is a genuine legal-interpretation question. I am not resolving it; I am recording that the enumeration does not cover Section 5 and that the change from "corresponding obligations" to a section list is real.

Convergences and contradictions

Synthesis for RDCO

The substantive answer is a clean negative, and a clean negative is worth more here than it looks. Three passes of this AI Act thread have now been spent chasing the possibility that the compliance surface under RDCO's positioning had moved. It has not. Annex III point 4 says today, character for character, what it said when the Act was signed on 13 June 2024, and the Article 6(3) filter that decides whether a borderline system escapes it is equally unmoved. Everything the Digital Omnibus did to high-risk classification landed on the product-safety limb — safety components inside machinery, radio equipment, medical devices — which is a limb RDCO will never touch. The clock moved; the map did not. The grandparent brief's scope warning can now be restated without any hedge at all: an RDCO-built agent that screens candidates, allocates work to humans by behaviour or traits, or monitors human performance for a client with EU workers lands squarely inside Annex III point 4(a) or 4(b), and the escape hatch it would have to fit through is the same four-condition filter that existed in 2024.

The part actually worth carrying into a client conversation is the shape of the filter, because it is the operative thing and almost nobody quotes it correctly. Two features do the work. First, the "always high-risk where the AI system performs profiling of natural persons" carve-back is absolute — it overrides all four gateway conditions, which means an agent that builds behavioural profiles of workers cannot filter out no matter how preparatory or narrow its task looks. Second, the gateway conditions are drafted around not materially influencing the outcome of decision making, and condition (c) explicitly fails where a system is "meant to replace or influence the previously completed human assessment, without proper human review." That is the same "material influence" test the grandparent brief picked up second-hand from a law-firm note, and it is genuinely in the statute. For a firm whose entire differentiator is "every action attributable to one accountable human operator," this is unusually convenient: the architecture RDCO already sells — human owner, agent recommends, human decides, decision logged — is the architecture the derogation was written to accommodate. That is a positioning asset, not just a compliance fact, and it is stated in words RDCO can quote.

The one operationally interesting change is the registration deletion, and it cuts against transparency in a direction worth noticing. Under the original Annex VIII, a provider who self-declared its Annex III system not-high-risk had to publish a short narrative summary of why into a publicly accessible EU database. That field is now gone; only the tick-box of which condition was invoked survives. The justification still has to exist — Article 6(4) and recital 22 both keep the documentation duty — it just stops being public and becomes something a national competent authority has to ask for. So the effect is a shift from published reasoning to on-request reasoning. If RDCO ever needs to diligence a vendor's Article 6(3) claim, or a client asks "how do we check whether our HR tool's not-high-risk claim is credible," the honest answer after 27 July 2026 is that the public register will not tell you and you have to ask the vendor for the assessment. That is a small, concrete, checkable piece of expertise of exactly the kind the 2026-08-15 brief identified as cheap credibility, and it is the sort of detail that will still be missing from most secondary coverage months from now.

Methodologically, this pass is the second clean data point for curl-and-grep, and it added a technique worth naming: amendment-marker attribution. Reading the consolidated text and mechanically mapping every provision back to its governing ▼B / ▼M1 marker turns "was this changed?" from a judgement call into a lookup, and cross-checking against the amending act's own numbered point list gives an independent second gate. The literal diff against the original 2024 text was the third. Three gates, all mechanical, all cheap, and the answer they produce — nothing changed — is the answer that a reading-based approach is most likely to get wrong, because absence of change is invisible to a reader skimming for changes.

Why this is in the vault

It discharges the last substantive open item in the AI Act thread and converts [[2026-08-02-agents-as-employees-regulatory-labor-framing]]'s scope analysis from secondary-source-tier to enacting-text-tier: the Annex III employment entries and the Article 6(3) filter that brief relied on are verified unamended as of the 27 July 2026 consolidation, so its "AI workforce" naming recommendation and its product-scope warning both stand without caveat. It also supplies the quotable Article 6(3) filter language RDCO would use in any EU-facing procurement or client conversation about an agent that touches worker-related decisions.

Open follow-ups

Related

Sources

Primary (fetched with curl to disk, read in full, no truncation):

Vault:

Not consulted: no secondary/law-firm sources were used in this pass. The primary text was reachable and dispositive on every sub-question, so corroboration would have added nothing. No paywalls were encountered.