EU AI Act

Which AI Systems Are High-Risk Under Annex III of the EU AI Act?

If your AI system falls under Annex III, you face the strictest compliance requirements in the entire EU AI Act, and many companies don't realise they're in scope until it's too late. Here is a plain-English breakdown of all eight categories, with practical examples for fintech, healthcare, employment, and other sectors.

← Back to EU AI Act Complete Guide

Annex III of the EU AI Act lists eight categories of AI systems that the regulation classifies as high-risk. Providers of these systems face the Act's most demanding requirements: conformity assessments, detailed technical documentation, human oversight mechanisms, automatic logging, bias testing, and registration in the EU AI database before deployment. Understanding whether your AI system is in scope for Annex III is the most important classification decision most companies need to make.

How the high-risk test works

An AI system is high-risk under Annex III if it falls within one of the eight listed categories AND poses a significant risk of harm to the health, safety, or fundamental rights of persons. The second condition means that even if a system technically falls in a category, it might not be high-risk if it is not used in a context where it could cause significant individual harm. Article 6(3) allows providers to self-assess whether this exception applies, but the bar is high: the burden of proof is on the provider to demonstrate the system does not pose the relevant risk.

The eight Annex III categories are:

Category 1

Biometric systems

AI systems used for biometric identification, verification, categorization, or emotion recognition of natural persons. This includes real-time and post-hoc remote biometric identification, biometric categorization systems inferring sensitive attributes (race, gender, sexual orientation, political views, health), and emotion-recognition systems in professional or educational settings.

Examples: Face recognition for access control, emotion-detection in job interviews, voice-based identity verification in financial services.

Category 2

Critical infrastructure

AI systems used as safety components in the management and operation of critical digital infrastructure, road traffic, and water, gas, heating, and electricity supply. The key test is whether the AI is in the decision chain for infrastructure that affects large populations.

Examples: AI-based grid load balancing, autonomous traffic management systems, AI for water treatment plant operations.

Category 3

Education and vocational training

AI systems that determine access to or assignment to educational institutions, evaluate learning outcomes that have a bearing on prospects, monitor student behavior, and assess performance in ways that affect students' futures.

Examples: AI admissions scoring tools, adaptive testing platforms where AI scores determine progression, AI monitoring tools in exam settings.

Category 4

Employment and worker management

AI systems used for recruitment and selection decisions (CV screening, interview analysis), decisions affecting working conditions, performance evaluation and monitoring, and dismissal decisions. This is a broad category that covers a large portion of HR technology.

Examples: Automated CV screening tools, AI systems that rank candidates, productivity monitoring software that influences termination decisions.

Category 5

Essential private and public services

This is the most commercially significant category for fintech companies. It covers: creditworthiness assessment of natural persons (5b), insurance risk assessment and pricing (5c), and AI systems used to dispatch or prioritize emergency services (5a). Access to essential public services such as housing and social benefits is also in scope.

Examples for fintech: Any ML model contributing to personal loan approvals, credit card limit decisions, BNPL eligibility, insurance premium setting, or mortgage underwriting. Fraud detection systems that result in account suspension also potentially fall here.

Category 6

Law enforcement

AI systems used by law enforcement for individual risk assessment (predicting reoffending), evidence evaluation, criminal profiling, and crime prediction. These also require third-party conformity assessment (not self-certification) for most uses.

Examples: Recidivism prediction tools, predictive policing software, AI lie-detection systems.

Category 7

Migration and border control

AI systems used to assess immigration or asylum claims, predict risk of illegal entry, assist in examination of applications for international protection, and detect document fraud. Border control agencies deploying AI for traveler risk assessment are in scope.

Examples: AI risk scoring for visa applications, document authenticity checking at borders, asylum claim assessment tools.

Category 8

Administration of justice and democratic processes

AI systems assisting judicial authorities in researching and interpreting facts and law, in applying the law to a specific set of facts, and influencing elections or democratic deliberation. The category reflects concerns about AI influence on legal and democratic outcomes.

Examples: Legal research AI that assists judges in rendering decisions, AI tools used in electoral campaign targeting or voter profiling.

What high-risk classification means in practice

If your system falls in any of these categories and you cannot rely on the Article 6(3) exception, you need to:

The Digital Omnibus proposal would defer high-risk Annex III obligations from 2 August 2026 to 2 December 2027. This is a legislative proposal under review as of mid-2026, not settled law. The 2 August 2026 deadline for GPAI, transparency (Article 50), and enforcement is not affected. Talk to us about your timeline.

Related reading

Frequently asked questions

What is Annex III of the EU AI Act?

Annex III lists eight categories of AI systems that the Act classifies as high-risk because of the potential harm to individuals. Providers of these systems must meet strict requirements including conformity assessments, technical documentation, human oversight measures, and registration in the EU AI database.

Is credit scoring high-risk under the EU AI Act?

Yes. Creditworthiness assessment of natural persons is explicitly listed in Annex III, category 5(b). Banks, fintech lenders, and BNPL providers using AI for credit decisions are squarely in scope.

When do high-risk Annex III obligations apply?

The Digital Omnibus proposal proposes deferring Annex III obligations to 2 December 2027. This is a proposal, not settled law. The 2 August 2026 obligations for GPAI, transparency, and enforcement are not affected. Companies should plan for the earlier date or track the proposal closely.

Can I self-certify a high-risk AI system?

For most Annex III categories, yes: self-assessment by the provider is permitted. Third-party conformity assessment by a notified body is required for biometric identification systems used by law enforcement and a few other specific categories.

Not sure if your system is high-risk?

Better Societies runs a structured 6-week compliance engagement that starts with a classification exercise and ends with a signed compliance declaration.