Is your lead scoring high-risk under the EU AI Act? For most marketing and sales teams, the honest answer is no — routine lead scoring appears nowhere in Annex III’s eight high-risk domains. But the question deserves better than a shrug. The Digital Omnibus has just reset the Annex III compliance clock to December 2, 2027, the European Commission’s draft classification guidelines are already circulating, and one carve-out — profiling — has no exceptions at all.
The timing makes this walkthrough unusually easy to get wrong. A wave of coverage written earlier in 2026 assumed that Annex III high-risk obligations would become enforceable on August 2, 2026. That date moved — one week before this article’s publication — and much of what currently ranks for this topic still carries the old deadline. Meanwhile, obligations that genuinely did arrive on August 2 (Article 50 transparency) and duties that have applied for years (GDPR profiling rules) get conflated with the high-risk regime that is still sixteen months out.
This guide walks the actual classification logic for the systems SMBs and mid-market teams really run — lead scoring, churn prediction, credit-adjacent gating, and hiring screens. Which land in Annex III, which escape through the Article 6(3) filter, why profiling overrides that filter, what already applies today, and what the sixteen-month preparation window is actually for.
- 01Routine lead scoring is generally not high-risk.Annex III lists eight high-risk domains — marketing and sales scoring appears in none of them. That is a reading of the Annex text; the Commission’s draft guidelines give no marketing-specific example either way.
- 02The high-risk deadline moved to December 2, 2027.The Digital Omnibus (Regulation (EU) 2026/1744, in force July 27, 2026) deferred Annex III obligations by sixteen months. No Annex III high-risk duty is enforceable at the time of writing.
- 03Article 50 transparency did arrive on August 2, 2026.Chatbot, deepfake, and synthetic-content disclosure duties kept their original date — only the watermarking sub-requirement carries a four-month grace window for systems already on the market.
- 04The profiling override has no exceptions.Article 6(3)’s four escape conditions never apply to an Annex III system that profiles natural persons. Profiling plus an Annex III domain equals high-risk, however narrow the task looks.
- 05Credit gating and hiring screens are the real exposure.Financing pre-qualification lands in Annex III point 5(b); candidate screening is named in point 4(a). Document the classification for every scoring system now — the lead time is the value.
01 — The TimelineThe deadline you read about moved.
Start with the correction, because everything else depends on it. Under the AI Act as adopted in 2024, the obligations for stand-alone high-risk systems listed in Annex III were scheduled to apply from August 2, 2026. The Digital Omnibus on AI changed that: political agreement on May 6–7, 2026, a European Parliament vote on June 16 (423 for, 57 against, 174 abstentions), the Council’s final green light on June 29, publication in the Official Journal as Regulation (EU) 2026/1744 on July 24, and entry into force on July 27, 2026 — one week before this article’s publication date.
The substance of the deferral, per the client alerts from Gibson Dunn and Hunton Andrews Kurth: Annex III high-risk obligations now apply from December 2, 2027 — a sixteen-month deferral — and Annex I high-risk systems embedded in regulated products moved from August 2027 to August 2, 2028.
Aug 2026 → Dec 2027
The Digital Omnibus moved Annex III high-risk obligations from August 2, 2026 to December 2, 2027. Annex I product-embedded systems moved twelve months, to August 2, 2028.
Votes in favour
The European Parliament approved the Digital Omnibus on June 16, 2026 — 423 for, 57 against, 174 abstentions — with the Council’s final approval following on June 29.
Transparency duties
Chatbot, deepfake, and synthetic-content disclosure obligations took effect on August 2, 2026 as originally scheduled. Only the watermarking sub-requirement carries a four-month grace window for systems already on the market.
Two other layers of the Act were untouched by the deferral and are worth keeping straight. The Article 5 prohibited practices — the outright bans — have applied since February 2025, with a further tranche of additions (covering non-consensual intimate imagery and related material) operating on a transitional window that runs to December 2, 2026. And the general governance provisions that took effect on August 2, 2026 arrived on schedule. The deferral is specific: it is the Annex III high-risk regime — the documentation, risk management, and oversight duties — that now binds from December 2027, not the Act as a whole.
02 — Annex IIIEight domains — and lead scoring is in none of them.
Annex III enumerates eight domains in which stand-alone AI systems are classified high-risk: biometrics; critical infrastructure; education and vocational training; employment and worker management; access to essential private and public services; law enforcement; migration, asylum, and border control; and the administration of justice and democratic processes.
Read the list twice and note what is absent: marketing and sales lead scoring, churn prediction, and engagement scoring appear nowhere in it. They are not employment, not credit, not insurance, not public benefits, not biometrics, not law enforcement. On our reading of the Annex text, routine commercial scoring is generally not an Annex III system at all — though this is a reasoned inference from the text rather than a citable Commission statement, because the Commission’s draft guidelines stop short of a marketing-specific example. Our risk-tier compliance checklist covers the full four-tier triage; this walkthrough stays on the classification question.
Four Annex III points sit close enough to CRM territory that scoring teams should know them by number. These are the boundaries a scoring system can drift across:
Recruitment & selection
AI used to recruit or select people — targeted job ads, analysing and filtering applications, evaluating candidates — is named high-risk in the Annex text itself. Candidate screening has no interpretive gap to hide in.
Work-relationship decisions
Systems that decide promotion or termination, allocate tasks based on individual behaviour or personal traits, or monitor and evaluate performance and behaviour within a work relationship.
Creditworthiness scoring
Evaluating the creditworthiness of natural persons or establishing their credit score is high-risk — with one named exception: systems used for the purpose of detecting financial fraud. This is where credit-adjacent CRM gating lands.
Life & health insurance pricing
Risk assessment and pricing in relation to natural persons in life and health insurance is high-risk. Relevant the moment scoring output feeds insurance quoting rather than marketing offers.
Two further points complete the essential-services picture: point 5(a) covers AI used by or on behalf of public authorities to evaluate eligibility for essential public benefits — including healthcare — and to grant, reduce, revoke, or reclaim them; point 5(d) covers triage of emergency calls and dispatch of first responders. Neither is CRM territory in the ordinary case, but 5(a) matters if your scoring stack ever serves a public-sector client’s eligibility workflow.
03 — Article 6(3)The filter with four escape routes.
Landing inside an Annex III domain is not the end of the analysis. Article 6(3) provides a filter: paraphrasing the operative text, a system that falls within an Annex III use case is nevertheless not high-risk where it does not pose a significant risk of harm to health, safety, or fundamental rights and it meets one of four conditions. In plain English, the four escape routes are:
- Narrow procedural task. The system performs a narrow, procedural step rather than the substantive assessment itself.
- Improving completed human work. The system improves the result of an activity a human has already completed.
- Pattern detection without influence. The system detects decision-making patterns or deviations from them without replacing or influencing the prior human assessment — subject to proper human review.
- Preparatory task. The system performs a task that is merely preparatory to an Annex III-relevant assessment.
The proviso attached to all four: the system must not materially influence the outcome of decision-making in a way that could adversely affect individuals. A “preparatory” score that a human rubber-stamps in practice is not preparatory in substance.
04 — The Profiling OverrideThe carve-out with no exceptions.
Here is the mechanism most coverage skips, and the one that makes this walkthrough non-trivial. The final subparagraph of Article 6(3) removes all four escape routes for one class of system: an Annex III-domain system that performs profiling of natural persons is always high-risk. The Commission’s draft classification guidelines — published on May 19, 2026 with a targeted stakeholder consultation — restate the point explicitly: as summarized in DLA Piper’s analysis, the filter mechanism does not apply to Annex III systems that profile natural persons, and no Article 6(3) exception can rescue them.
What counts as profiling comes from the GDPR. Article 4(4) defines it, in essence, as any automated processing of personal data used to evaluate personal aspects of a natural person — in particular to analyse or predict things like performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, or location. Measure a standard lead-scoring model against that definition: it ingests personal data to predict a person’s economic situation (budget, buying power), interests (intent signals), reliability, and behaviour (engagement propensity). On its face, ordinary lead scoring meets the GDPR definition of profiling. That chain — our own reading of how the two regimes interact, not a Commission or law-firm statement — is exactly why the classification question has teeth.
Note the gap the draft guidelines leave open. Their worked examples concentrate on employment — HR tools that filter, score, or rank candidates — and on credit scoring. Marketing-adjacent scoring is left in an interpretive space the Commission has not yet filled. That gap is why the next section exists: nobody has published the mapping for the systems CRM teams actually run, so we built it.
05 — The WalkthroughWhere four common systems land.
This table is ours, not the Commission’s. It maps the four scoring systems SMBs most commonly run against the three-step logic above — Annex III domain, GDPR profiling status, Article 6(3) filter availability — and states the practical outcome plus the one design choice that flips each row. The cells are built from the Annex III text, Article 6, and the GDPR Article 4(4) profiling definition; the outcome column follows mechanically from the three tests before it.
| System | Annex III domain? | GDPR profiling? | Art. 6(3) filter? | Practical outcome | What flips the row |
|---|---|---|---|---|---|
| Lead scoring — fit + engagement scoring in marketing and sales | No — absent from all eight domains | Plausibly yes — predicts economic situation, interests, behaviour | Not needed — the system sits outside Annex III entirely | Not Annex III high-risk in the ordinary case; GDPR profiling duties still apply | Letting the score gate credit, employment, insurance, or benefits decisions |
| Churn prediction — retention and win-back scoring | No — absent from all eight domains | Plausibly yes — predicts behaviour and preferences | Not needed — outside Annex III entirely | Not Annex III high-risk in the ordinary case; GDPR profiling duties still apply | Feeding the score into insurance pricing or credit terms instead of retention offers |
| Credit-adjacent gating — financing pre-qualification or BNPL eligibility in a sales funnel | Yes — point 5(b), creditworthiness evaluation | Yes — evaluates economic situation and reliability | No — the profiling override removes all four escape routes | High-risk once Annex III duties apply on December 2, 2027 | Restricting the system to financial-fraud detection — the one carve-out named in 5(b) |
| Hiring screens — candidate filtering, scoring, and ranking | Yes — point 4(a), recruitment and selection | Typically yes — evaluates work performance and reliability | No — profiling override; filtering applications is a named Annex use case anyway | High-risk once Annex III duties apply on December 2, 2027 | Nothing realistic — candidate filtering and evaluation are in the Annex text itself |
The pattern worth internalizing: the first two rows and the last two rows fail in opposite directions. Lead scoring and churn prediction are safe on the AI Act axis but carry unexamined GDPR profiling exposure that most teams have never documented. Credit gating and hiring screens feel like natural CRM extensions — a checkout that pre-qualifies financing, a pipeline that doubles as a recruiting funnel — but each one crosses into a named Annex III point, and the profiling override guarantees there is no filter escape.
06 — Live TodayWhat already applies, deferral or not.
The December 2027 clock covers the Annex III high-risk regime only. Two sets of obligations bind scoring systems today, and conflating them with the deferred regime is the second-most-common error in current coverage.
Article 50 transparency, live since August 2, 2026. If your CRM stack puts a chatbot in front of customers, generates synthetic content, or runs emotion-recognition features, the disclosure duties apply now — people must be told they are interacting with AI, and synthetic content must be identifiable as such. The watermarking sub-requirement carries a four-month grace window for systems already on the market; the rest arrived on schedule.
GDPR, already live. If lead scoring meets the Article 4(4) profiling definition — and on its face it typically does — then the GDPR’s profiling obligations apply regardless of what the AI Act says. Article 22 gives individuals the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects — subject to three narrow exceptions (contract necessity, member-state law, explicit consent), each of which requires safeguards including a route to human review. A scoring system that silently disqualifies people from an offer with no human in the loop is a GDPR question in 2026, not a 2027 one. For teams outside the EU wondering whether any of this reaches them, our guide to what US businesses must do now covers the extraterritorial mechanics.
Keep the two regimes separate in your documentation. “Not Annex III high-risk” and “not GDPR profiling” are different verdicts reached by different tests — most lead-scoring systems will honestly earn the first and fail the second, and collapsing them into one “we’re fine” is how classification memos go wrong.
07 — PenaltiesWhat non-compliance will cost.
The fine architecture is set by Article 99, in three tiers — each ceiling the higher of a fixed sum or a share of global annual turnover. None of the analyses we reviewed reported the Digital Omnibus changing these ceilings, but given that the Omnibus just moved the application dates themselves, verify the current consolidated text before building budget models on any figure here.
Article 99 administrative fine ceilings · by breach tier
Source: Regulation (EU) 2024/1689, Article 99 — ceilings, whichever amount is higherNotice where scoring systems sit in that structure. A misclassified high-risk system that misses its December 2027 obligations falls in tier 2 — as do Article 50 transparency breaches that are enforceable already. The tier-3 line deserves more attention than it gets: supplying incorrect, incomplete, or misleading information to authorities carries its own ceiling, which is precisely why a sloppy classification memo is worse than an honest open question. Who actually levies these fines — the AI Office versus national market-surveillance authorities — and how the complaint machinery works is its own topic; our companion piece on who enforces the AI Act and what its penalty powers look like covers the enforcement architecture in depth.
08 — PreparationSixteen months of lead time — use them.
If a system in your stack does classify high-risk, the duty set that binds from December 2027 is substantial. For providers — the party that builds the system — the compliance guides tracking the Act converge on four pillars: technical documentation to the Annex IV standard (system description, architecture, data governance, risk management), a documented risk-management system under Article 9, CE marking, and registration in the EU database. For deployers — the party that uses it — effective human-oversight procedures, log-retention obligations, notifying affected individuals where required, and, for public-sector deployers, fundamental-rights impact assessments. If you build scoring in-house, you may hold both roles at once.
Salesforce publishes a dedicated EU AI Act resource hub framing readiness as a shared responsibility between vendor (as provider of AI features) and customer (as deployer) — a framing that is vendor-stated marketing, not independent verification, but whose provider/deployer split is the right mental model. Whatever platform runs your scoring, the deployer-side homework — what data goes in, what decisions come out, who reviews them — stays yours.
Document the classification call
Write the one-page memo now: why the system sits outside the eight Annex III domains, what personal data feeds it, and the GDPR profiling analysis with its lawful basis. A dated memo beats a scramble under final Commission guidance.
Ring-fence what the score touches
Keep churn scores driving retention offers, not eligibility decisions. The design boundary is the classification boundary — write it into the system spec so a future feature request can’t silently cross it.
Start the build-out now
Annex III point 5(b) plus the profiling override makes this the clearest high-risk candidate in a CRM stack. Annex IV documentation, risk management, and oversight design take longer than sixteen months in most organizations.
Treat as named high-risk
Point 4(a) names application filtering and candidate evaluation explicitly. If your CRM doubles as a recruiting funnel, separate the two workflows — and their data — before the duties bind.
Where does this go next? Expect the Commission to finalize the classification guidelines with the marketing gap still only partially addressed — the draft’s worked examples stayed on employment and credit, and nothing signals a marketing example is coming. That leaves scoring teams carrying the interpretive load themselves through 2027, which is an argument for writing the classification memo against the primary text now and revisiting it when the final guidelines land. Expect, too, that the boundary cases multiply: as scoring models absorb more data and gate more decisions, systems built as marketing tools will drift toward the credit and employment lines. The teams that documented their classification logic will adapt with an edit; the teams that never wrote it down will re-litigate from scratch.
The mechanics of building scoring systems that keep these boundaries clean is its own discipline — scoped data inputs, explainable weights, human checkpoints where scores touch decisions. Our guides to building an AI lead-scoring agent and the lead-scoring workflow cover the build side; our bias-audit compliance guide for small business covers the adjacent US obligations. And if you want the classification memo, the scoring build, and the documentation produced as one engagement, that is exactly what our CRM & automation practice does.
09 — ConclusionClassification is the cheap part.
Routine lead scoring is generally not high-risk — and that answer is only useful if you write it down.
The walkthrough lands in a defensible place: marketing and sales lead scoring sits outside Annex III’s eight domains, so in the ordinary case it is not an EU AI Act high-risk system — and no Annex III duty is enforceable at the time of writing anyway, because the Digital Omnibus moved that clock to December 2, 2027. Panic is the wrong response to this topic, and so is the compliance-vendor pitch that treats every scoring model as a regulatory emergency.
But the comfortable answer has two sharp edges. Lead scoring plausibly meets the GDPR’s profiling definition, which carries live obligations that predate the AI Act entirely. And the profiling override means the Article 6(3) filter can never rescue a scoring system that drifts into credit, employment, insurance, or benefits territory — the four escape routes vanish precisely when you need them. The systems most likely to cross those lines — financing pre-qualification and hiring screens — are the ones CRM stacks absorb most naturally.
So use the sixteen months for what they are: lead time. Classify every scoring system against the three-step logic — Annex III domain, profiling status, filter availability — date the memo, and re-run it when the Commission finalizes its guidelines and whenever a feature request moves what the score touches. The classification is a one-page document today. In December 2027, for the systems that need it, it becomes the foundation of a documentation, oversight, and risk-management build — and the teams that started from a written verdict will be the ones for whom that deadline is boring.