Annex III of the EU AI Act lists eight categories of AI systems that the regulation classifies as high-risk. Providers of these systems face the Act's most demanding requirements: conformity assessments, detailed technical documentation, human oversight mechanisms, automatic logging, bias testing, and registration in the EU AI database before deployment. Understanding whether your AI system is in scope for Annex III is the most important classification decision most companies need to make.
How the high-risk test works
An AI system is high-risk under Annex III if it falls within one of the eight listed categories AND poses a significant risk of harm to the health, safety, or fundamental rights of persons. The second condition means that even if a system technically falls in a category, it might not be high-risk if it is not used in a context where it could cause significant individual harm. Article 6(3) allows providers to self-assess whether this exception applies, but the bar is high: the burden of proof is on the provider to demonstrate the system does not pose the relevant risk.
The eight Annex III categories are:
Biometric systems
AI systems used for biometric identification, verification, categorization, or emotion recognition of natural persons. This includes real-time and post-hoc remote biometric identification, biometric categorization systems inferring sensitive attributes (race, gender, sexual orientation, political views, health), and emotion-recognition systems in professional or educational settings.
Examples: Face recognition for access control, emotion-detection in job interviews, voice-based identity verification in financial services.
Critical infrastructure
AI systems used as safety components in the management and operation of critical digital infrastructure, road traffic, and water, gas, heating, and electricity supply. The key test is whether the AI is in the decision chain for infrastructure that affects large populations.
Examples: AI-based grid load balancing, autonomous traffic management systems, AI for water treatment plant operations.
Education and vocational training
AI systems that determine access to or assignment to educational institutions, evaluate learning outcomes that have a bearing on prospects, monitor student behavior, and assess performance in ways that affect students' futures.
Examples: AI admissions scoring tools, adaptive testing platforms where AI scores determine progression, AI monitoring tools in exam settings.
Employment and worker management
AI systems used for recruitment and selection decisions (CV screening, interview analysis), decisions affecting working conditions, performance evaluation and monitoring, and dismissal decisions. This is a broad category that covers a large portion of HR technology.
Examples: Automated CV screening tools, AI systems that rank candidates, productivity monitoring software that influences termination decisions.
Essential private and public services
This is the most commercially significant category for fintech companies. It covers: creditworthiness assessment of natural persons (5b), insurance risk assessment and pricing (5c), and AI systems used to dispatch or prioritize emergency services (5a). Access to essential public services such as housing and social benefits is also in scope.
Examples for fintech: Any ML model contributing to personal loan approvals, credit card limit decisions, BNPL eligibility, insurance premium setting, or mortgage underwriting. Fraud detection systems that result in account suspension also potentially fall here.
Law enforcement
AI systems used by law enforcement for individual risk assessment (predicting reoffending), evidence evaluation, criminal profiling, and crime prediction. These also require third-party conformity assessment (not self-certification) for most uses.
Examples: Recidivism prediction tools, predictive policing software, AI lie-detection systems.
Migration and border control
AI systems used to assess immigration or asylum claims, predict risk of illegal entry, assist in examination of applications for international protection, and detect document fraud. Border control agencies deploying AI for traveler risk assessment are in scope.
Examples: AI risk scoring for visa applications, document authenticity checking at borders, asylum claim assessment tools.
Administration of justice and democratic processes
AI systems assisting judicial authorities in researching and interpreting facts and law, in applying the law to a specific set of facts, and influencing elections or democratic deliberation. The category reflects concerns about AI influence on legal and democratic outcomes.
Examples: Legal research AI that assists judges in rendering decisions, AI tools used in electoral campaign targeting or voter profiling.
What high-risk classification means in practice
If your system falls in any of these categories and you cannot rely on the Article 6(3) exception, you need to:
- Complete a conformity assessment (self-assessment for most categories; third-party audit required for biometrics used in law enforcement)
- Maintain detailed technical documentation per Annex IV
- Implement human oversight so a natural person can understand and override AI outputs
- Ensure automatic logging of the system's operation for post-hoc review
- Test for accuracy and bias across demographic groups
- Register the system in the EU AI database before deployment
- Establish post-market monitoring and incident reporting
The Digital Omnibus proposal would defer high-risk Annex III obligations from 2 August 2026 to 2 December 2027. This is a legislative proposal under review as of mid-2026, not settled law. The 2 August 2026 deadline for GPAI, transparency (Article 50), and enforcement is not affected. Talk to us about your timeline.