What are the Annex III high-risk categories under the EU AI Act?
Updated 9 August 2026 for Regulation (EU) 2026/1744.
Annex III lists eight areas in which AI systems are high-risk under Article 6(2): biometrics, critical infrastructure, education, employment, essential services and benefits, law enforcement, migration, asylum and border control, and justice and democratic processes. The attached obligations apply from 2 December 2027.
Quick answer
- The mechanism: under Article 6(2), AI systems referred to in Annex III "shall be considered to be high-risk".
- Match at letter level: the specific point and letter plus the system's intended purpose decide, not the area heading.
- Two express carve-outs: biometric verification (point 1(a) of Annex III) and financial-fraud detection within credit scoring (point 5(b)).
- Applies from 2 December 2027 — Article 113, third paragraph, point (c), as amended by Regulation (EU) 2026/1744. Annex III itself is unamended; Article 7 lets the Commission change the list by delegated act.
How does Annex III make a system high-risk?
Article 6(2) is one sentence: "In addition to the high-risk AI systems referred to in paragraph 1, AI systems referred to in Annex III shall be considered to be high-risk." A system is caught when its intended purpose matches a specific letter of the Annex, so read the exact wording; points 1, 6 and 7 are additionally limited to uses "permitted under relevant Union or national law". How to run the check is the classification guide's job; the Article 6(3) exemption takes a matched system back out of high-risk.
What do the biometrics and infrastructure points cover (points 1 and 2)?
Point 1 — "Biometrics, in so far as their use is permitted under relevant Union or national law". Three letters: (a) remote biometric identification systems — retrospective identification in recorded CCTV footage, say; (b) biometric categorisation "according to sensitive or protected attributes or characteristics based on the inference of those attributes or characteristics"; (c) emotion recognition. The carve-out in point 1(a), verbatim: "This shall not include AI systems intended to be used for biometric verification the sole purpose of which is to confirm that a specific natural person is the person he or she claims to be" — one-to-one face-match for phone unlock or airport e-gates is out. Some variants of (b) and (c) are prohibited — workplace emotion recognition under Article 5(1), first subparagraph, point (f), save its medical-or-safety exception; point 1 catches the lawful remainder.
Point 2 — "Critical infrastructure". AI systems intended as "safety components in the management and operation of critical digital infrastructure, road traffic, or in the supply of water, gas, heating or electricity" — grid load-balancing, an AI controller in a water-treatment plant. Whether reporting-only analytics are caught turns on the Article 3, point (14) definition of "safety component": a component which "fulfils a safety function" or whose failure or malfunctioning "endangers the health and safety of persons or property" — tools that merely report typically do neither. Regulation (EU) 2026/1744 sharpened that test: Article 3, point (14) now adds that a component fulfils a safety function "where its intended purpose is to prevent or mitigate risks to health and safety of persons or property", and new Article 6(1a) puts outside "safety component" systems "solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control" — while Article 6(1b) makes systems "the failure or malfunctioning of which would endanger health and safety" qualify notwithstanding 6(1a).
What do the education and employment points cover (points 3 and 4)?
Point 3 — "Education and vocational training". Four letters, all scoped to educational and vocational training institutions "at all levels": (a) determining access, admission or assignment of people to institutions; (b) evaluating learning outcomes, including where those outcomes steer the learning process; (c) assessing the appropriate level of education an individual will receive or be able to access; (d) monitoring and detecting prohibited behaviour of students during tests — exam proctoring. An admissions scorer matches (a); an adaptive-learning engine that grades and re-routes learners, (b).
Point 4 — "Employment, workers' management and access to self-employment" — the third limb pulls in gig-work and freelance platforms, not just employers. (a) recruitment or selection, "in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates" — the CV screener matches; (b) decisions affecting terms of work-related relationships, promotion or termination, task allocation "based on individual behaviour or personal traits or characteristics", and monitoring and evaluating performance and behaviour in such relationships — a rider-dispatch algorithm sits squarely here.
Every time we shortened an official heading — in our own product and in these guides — a limb fell off: "and access to self-employment", "and benefits", "border control management". It kept happening until we made verbatim headings a hard rule. Read the letters in full before ruling a system out; the scope you drop is the scope that catches you.
What does the essential-services point cover (point 5)?
Point 5 — "Access to and enjoyment of essential private services and essential public services and benefits". Four letters:
- (a) systems used "by public authorities or on behalf of public authorities" to evaluate eligibility for essential public assistance benefits and services, including healthcare, and to grant, reduce, revoke or reclaim them — the authority limitation is part of the text;
- (b) evaluating creditworthiness or establishing credit scores of natural persons, with the second express carve-out, verbatim: "with the exception of AI systems used for the purpose of detecting financial fraud";
- (c) "risk assessment and pricing in relation to natural persons in the case of life and health insurance" — other insurance lines are not listed;
- (d) evaluating and classifying emergency calls, dispatching or prioritising emergency first response services, and emergency healthcare patient triage.
Under Article 27(1), deployers of high-risk AI systems referred to in points 5 (b) and (c) of Annex III — the fintech and insurtech core — must also run a fundamental-rights impact assessment before first use; the fintech guide maps both letters to concrete lending and pricing products.
What about the public-sector points (6, 7 and 8)?
Point 6 — "Law enforcement, in so far as their use is permitted under relevant Union or national law". Five letters, all scoped to use by or on behalf of law-enforcement authorities (or Union bodies supporting them): victim-risk assessment; polygraphs and similar tools; evaluating the reliability of evidence in criminal investigations or prosecutions; assessing offending or re-offending risk "not solely on the basis of the profiling of natural persons" — the solely-profiling variant is prohibited under Article 5 — or assessing personality traits and past criminal behaviour; and profiling of natural persons in the detection, investigation or prosecution of criminal offences.
Point 7 — "Migration, asylum and border control management", under the same lawful-use proviso and scoped to competent public authorities (or Union bodies): polygraphs and similar tools; assessing security, irregular-migration or health risks posed by a person who intends to enter or has entered a Member State; assisting the examination of asylum, visa and residence-permit applications and associated complaints, including assessing evidence reliability; and detecting, recognising or identifying natural persons in that context — "with the exception of the verification of travel documents".
Point 8 — "Administration of justice and democratic processes". Two letters: (a) systems intended to be used by a judicial authority or on their behalf, to assist it in researching and interpreting facts and the law and applying it to a concrete set of facts, or used in a similar way in alternative dispute resolution — a legal-research tool is caught when used by or on behalf of a court; (b) influencing the outcome of an election or referendum or people's voting behaviour, excluding tools whose output people are not directly exposed to, such as campaign-logistics software.
Can the list change?
Yes. Article 7(1) empowers the Commission to adopt delegated acts "to amend Annex III by adding or modifying use-cases of high-risk AI systems" — but only where the systems are "intended to be used in any of the areas listed in Annex III" and pose equivalent or greater risk than the use cases already listed. New areas need a legislative amendment; new letters need only a delegated act. Article 7(3) allows removing use cases that no longer pose significant risks, provided the deletion does not decrease the overall level of protection. Whether such an act has been adopted cannot be read off the Regulation — check the consolidated version on EUR-Lex before relying on this list as current.
What this means for you
If you're a provider: match each system against the letters per intended purpose, and record the exact citation ("point 4(a) of Annex III") — a match triggers the obligations that apply from 2 December 2027. Near a carve-out, keep the analysis: the exclusion's exact words are your defence. Complipath's guided risk classification returns the risk level with the provisions and reasoning attached, so that record exists per system.
If you're a deployer: classification follows the intended purpose, which Article 3, point (12) defines as "the use for which an AI system is intended by the provider" — so start from the provider's classification. Modify that purpose so a system not classified as high-risk becomes high-risk, and you are treated as its provider under Article 25(1), point (c) — see when a deployer becomes a provider. Under points 5 (b) and (c) of Annex III you also owe the Article 27(1) fundamental-rights impact assessment before first use. If a vendor claims a matched system is exempt, ask for the documented Article 6(3) assessment.
Does your use case appear in Annex III?
Classify your system now — 7 questions on the main line, plus follow-ups where they apply, no account, and the classification runs in your browser: answers stay there unless you choose to keep the result.
FAQ
Is every AI system used in these eight areas high-risk? No. The match happens at specific points and letters against the system's intended purpose, not the area heading. Two carve-outs — biometric verification and financial-fraud detection — are written into the Annex itself, and the Article 6(3) exemption can take a matched system out under strict, documented conditions.
Are Annex III systems banned? No. High-risk is a permitted tier: the system may be placed on the market and used, subject to the Chapter III requirements and conformity assessment. Bans live in Article 5, which is a separate tier — some practices adjacent to Annex III points, like workplace emotion recognition, fall there instead.
When do Annex III obligations start to apply? 2 December 2027 (Article 113, third paragraph, point (c), as amended by Regulation (EU) 2026/1744). Article 111(2), also as amended, anchors the legacy cut-off to that date: pre-existing systems are pulled in only if their designs change significantly from it — except systems intended for use by public authorities, which must comply by 2 August 2030 regardless.
Can the Commission add new categories to Annex III? It can add or modify use cases by delegated act under Article 7(1), but only within the eight existing areas and only where the risk is equivalent to or greater than the listed use cases. It can also remove use cases under Article 7(3). Entirely new areas would require amending the Regulation itself.
Sources: Regulation (EU) 2024/1689 (EUR-Lex), Articles 3, 6, 7, 27, 111 and 113, and Annex III, as amended by Regulation (EU) 2026/1744 (EUR-Lex) — in force 27 July 2026 — which rewrote Article 3, point (14), inserted Article 6(1a), (1b) and (1c), replaced Article 111(2) and replaced Article 113, third paragraph, points (a) and (c). Annex III itself was not amended. Annex III quotes follow the Official Journal text. Whether an Article 7 delegated act has since amended Annex III cannot be determined from the Regulation alone — check the EUR-Lex consolidated version before relying on the list as current.