High-Risk AI System, Annex III Examples Explained
High-Risk AI System, Annex III Examples Explained

What is a “High-Risk” AI System? Annex III Examples Explained

EU AI Act Explained · 8 min read · Updated March 2026

The EU AI Act reserves its most demanding compliance requirements for high-risk AI systems. But what exactly makes an AI system “high-risk” — and how do you know if yours qualifies? This guide walks through the legal definition, the full Annex III list, and real-world examples for each category.

Key Takeaways
  • High-risk classification triggers 13 mandatory compliance obligations — including conformity assessment, technical documentation, and EU database registration.
  • Annex III lists eight specific use-case domains where AI is presumed high-risk: from biometrics and HR to credit scoring and law enforcement.
  • Many organisations discover their existing AI tools — HR screening software, credit APIs, proctoring platforms — are already in scope.
  • The compliance deadline for high-risk AI is 2 August 2026. Conformity assessments take 4–12 months.

The Legal Definition of “High-Risk” Under the EU AI Act

Article 6 of the EU AI Act (Regulation EU 2024/1689) establishes two routes to high-risk classification:

Route 1 — Annex I (Safety Components)
AI systems that are a safety component of a product already regulated under existing EU product safety legislation — medical devices, machinery, aviation equipment, vehicles, toys, and others listed in Annex I. (Article 6(1))
Route 2 — Annex III (Standalone Use Cases)
AI systems that fall within one of the eight specific use-case domains listed in Annex III, regardless of whether they are part of a regulated product. This covers most enterprise and public-sector AI deployments. (Article 6(2))

For most businesses, Route 2 — Annex III — is what matters. It captures the AI systems your legal, HR, finance, and operations teams are most likely already using or building.

One important nuance: Article 6(3) allows a provider to rebut the high-risk presumption if they can document that an Annex III use case “does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons.” This exception is narrow and requires documented justification — it cannot be claimed without a formal written assessment.

Deadline reminder: All high-risk AI systems under Annex III must be fully compliant by 2 August 2026. Conformity assessments for complex systems take 4–12 months. Start your compliance programme now →

The Eight Annex III High-Risk AI Categories

Here is each Annex III category with the legal scope, real-world examples of in-scope systems, and the specific compliance challenge it creates.

Category 1 Biometric Identification and Categorisation of Natural Persons

Scope: AI systems that use biometric data to remotely identify individuals — including real-time identification in publicly accessible spaces and post-hoc identification from databases, CCTV footage, or images. Also covers systems that categorise individuals based on biometric data to deduce sensitive attributes.

Real-world examples: Facial recognition systems at transport hubs, stadiums, or retail stores. Employee attendance monitoring via biometric scanners. AI that infers age, gender, or emotional state from camera feeds.

Important: Real-time biometric identification in public spaces is prohibited outright under Article 5, with narrow law-enforcement exceptions. Post-hoc identification is high-risk and subject to Annex III obligations. Systems that categorise individuals by race, political opinion, or sexual orientation from biometric data are also prohibited under Article 5.
Category 2 Critical Infrastructure Management and Operation

Scope: AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, and utilities supply — including water, gas, heating, and electricity.

Real-world examples: AI that controls power grid load balancing, flood prediction systems informing dam management, AI-driven railway signal optimisation, autonomous vehicle routing on public roads, and network traffic management AI in telecoms infrastructure.

Compliance note: Providers in this category often also fall under NIS2 Directive obligations simultaneously. Align your EU AI Act risk management system with your NIS2 incident reporting procedures.
Category 3 Education and Vocational Training

Scope: AI that determines access to educational and vocational training institutions; evaluates learning outcomes that have significant consequences; assesses the appropriate level of education for individuals; or monitors and detects prohibited behaviour of students during tests.

Real-world examples: University admissions scoring AI, automated essay grading systems that affect qualifications, AI-powered exam proctoring tools (eye-tracking, behaviour monitoring), adaptive learning platforms that direct students toward or away from specific career pathways.

EdTech alert: Remote proctoring tools that monitor student behaviour during exams are one of the most commonly overlooked Annex III systems. If your institution uses third-party proctoring software, verify the vendor’s conformity assessment status before the August 2026 deadline.
Category 4 Employment, Workers Management and Access to Self-Employment

Scope: AI used for recruitment or selection of natural persons — in particular advertising vacancies, screening or filtering applications, and evaluating candidates in interviews or assessments. Also covers promotion and termination decisions, task allocation, and monitoring and evaluating performance and behaviour of employees.

Real-world examples: ATS platforms that automatically rank or reject CVs. Video interview analysis tools that score candidate personality or “culture fit” from facial expressions. Workforce management platforms that algorithmically allocate shifts. Employee productivity monitoring software that uses AI to flag underperformance.

High exposure sector: This category has the broadest enterprise footprint of any Annex III domain. According to the OECD, over 80% of large organisations use some form of AI in their recruitment process. Most are unaware their ATS vendor’s tool is an Annex III high-risk system requiring conformity assessment.
Category 5 Access to and Enjoyment of Essential Private Services and Public Services and Benefits

Scope: AI used to evaluate the creditworthiness of natural persons or to establish their credit score; AI used for risk assessment and pricing of life and health insurance; AI that makes or materially influences decisions on individuals’ eligibility for public benefits and services; AI used for emergency services dispatching.

Real-world examples: Algorithmic credit scoring engines at banks and fintechs. AI underwriting tools at insurers that calculate premiums based on predicted risk. Benefits eligibility decision-support tools used by welfare agencies. AI triage systems in healthcare that prioritise patient treatment.

Financial sector note: Credit scoring AI must comply with both the EU AI Act and existing requirements under the Consumer Credit Directive and EBA Loan Origination Guidelines. Plan for dual compliance from the outset.
Category 6 Law Enforcement

Scope: AI used by law enforcement for individual risk assessment; lie detection and similar tools; evaluation of evidence reliability; prediction of criminal activity; profiling of natural persons; and analysis of audio-visual data related to criminal investigations.

Real-world examples: Predictive policing platforms that assess individual recidivism risk. AI tools that analyse CCTV footage for suspicious behaviour. Forensic AI that authenticates or analyses digital evidence. Gunshot detection and localisation AI deployed in public spaces.

Additional safeguards: Law enforcement AI deployments are subject to heightened oversight requirements and must be logged with national competent authorities. The European Parliament specifically added provisions requiring fundamental rights impact assessments for all law enforcement AI.
Category 7 Migration, Asylum and Border Control Management

Scope: AI used for lie detection and similar tools in the context of migration; risk assessment of individuals for irregular migration or security threats; examination of visa and asylum applications; and document authentication in border control contexts.

Real-world examples: Automated document verification systems at border crossings. AI tools that analyse interview responses in asylum procedures. Risk profiling systems that flag travellers for secondary screening. AI-assisted visa decision-support tools used by consular staff.

Category 8 Administration of Justice and Democratic Processes

Scope: AI intended to assist judicial authorities in researching and interpreting facts and law, and in applying the law to a concrete set of facts. Also covers AI used to influence electoral and referendum results and the voting behaviour of natural persons.

Real-world examples: Legal research AI that recommends case law relevant to a pending judgment. AI decision-support tools that suggest sentencing ranges. AI used in election administration for vote counting or fraud detection. Micro-targeted political advertising AI based on psychological profiling.

What High-Risk Classification Actually Means for Your Organisation

Being classified as high-risk under Annex III is not a ban — it is an invitation to prove your AI system is safe and trustworthy through a rigorous compliance process. The obligations apply to Providers (who build the AI) and Deployers (who use it in operations) differently, but both carry significant responsibilities.

ObligationArticleProviderDeployer
Risk Management SystemArt. 9
Technical Documentation (Annex IV)Art. 11
Human Oversight ControlsArt. 14✅ design✅ operate
Conformity AssessmentArt. 43
EU AI Database RegistrationArt. 49✅ some
Fundamental Rights Impact AssessmentArt. 27
6-Month Use Log RetentionArt. 26

Not sure which role applies to your organisation — or whether you might be both? Use our free 2-minute EU AI Act Risk Assessment Tool to get a personalised classification instantly.

How to Identify Your High-Risk AI Systems: A Practical Approach

The EU AI Act does not self-identify which of your systems are in scope. That determination is your responsibility. Here is a proven three-step approach used by compliance teams:

1
Build a Complete AI System Inventory
List every AI system your organisation develops, uses, or procures. Include off-the-shelf SaaS tools, APIs, custom-built models, and embedded AI in existing software. Most organisations discover 30–50% more AI systems than they initially estimate.
2
Cross-Reference Each System Against Annex III
For each system, ask: what is its primary function? Who does it affect, and in what context? Does it make or influence decisions about individuals? If yes — and the context falls within any of the eight Annex III domains — the system is presumptively high-risk.
3
Document the Classification Decision
For each system classified as high-risk — or deliberately classified as not high-risk under Article 6(3) — create a written classification memo with supporting rationale. This document is your first line of defence if a market surveillance authority questions your classification.
Ready to start your compliance programme?
Our 4-phase compliance checklist walks you through every high-risk AI obligation — with article references and “how to comply” tips for each item.
View the Compliance Checklist →

Frequently Asked Questions

Quick answers to the most common questions about Annex III high-risk AI classification.

Can an Annex III system be reclassified as non-high-risk? +
Yes — Article 6(3) allows a provider to rebut the high-risk presumption if they can document that their Annex III system “does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making.” This requires a formal written assessment and must be notified to the EU AI Office. It is a narrow exception that regulators will scrutinise closely.
Does the Annex III list ever change? +
Yes. Article 7 grants the European Commission the power to update Annex III via delegated acts — expanding or contracting the list as AI technology and its applications evolve. The Commission must consider the severity and probability of harm, the number of affected persons, the irreversibility of harm, and the dependency of affected persons on the AI system. AI systems not currently on the list could be added as the technology matures.
We use an AI system built by a vendor — are we responsible? +
Yes — as a Deployer you carry specific obligations including: using the system only as intended by the provider, implementing the human oversight measures the provider specifies, maintaining 6-month use logs, conducting Fundamental Rights Impact Assessments in regulated-sector contexts, and reporting serious incidents. You must also verify that your vendor has completed their conformity assessment — if they haven’t, deploying their system creates compliance risk for you.
What are the fines for non-compliant high-risk AI systems? +
Violations of the high-risk AI obligations attract fines of up to €15,000,000 or 3% of global annual turnover — whichever is higher. Beyond financial penalties, national market surveillance authorities can order market withdrawal of the non-compliant system and require public disclosure of the violation. For the complete breakdown of EU AI Act fines, see our EU AI Act Summary.
Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like