Dec 2027EU AI Act compliance
    Browse all 14 resources
    Guide9 min read

    Annex III (Annex 3) of the EU AI Act: the 8 high-risk areas, Article 6 and the risk categories

    Annex III (Annex 3) of the EU AI Act is the list of AI uses that Regulation (EU) 2024/1689 treats as high-risk. It has eight areas and twenty-five entries. An AI system intended for one of the listed purposes is high-risk, unless the derogation in Article 6(3) applies. The duties for these systems apply from 2 December 2027.

    Looking for the answer to the risk-category quiz? Go to the quiz section.

    This page follows the consolidated text of 27 July 2026. Regulation (EU) 2026/1744 changed the dates, not the list.

    The 8 areas of Annex III (Annex 3), point by point

    The annex says that high-risk systems under Article 6(2) are the systems listed in one of its areas. The intended purpose decides, not the technology.

    1. Biometrics. Only where Union or national law permits the use. a) Remote biometric identification. Verification that only confirms a claimed identity is out. b) Biometric categorisation by sensitive or protected attributes. c) Emotion recognition.
    2. Critical infrastructure. Safety components in the management of critical digital infrastructure, road traffic, or the supply of water, gas, heating or electricity.
    3. Education and vocational training. a) Access, admission or assignment to institutions. b) Evaluation of learning outcomes. c) Assessment of the level of education a person should receive. d) Detection of prohibited behaviour during tests. Point 3 has its own guide: AI Act and schools, Annex III point 3.
    4. Employment, workers' management and access to self-employment. a) Recruitment and selection: targeted job ads, filtering applications, evaluating candidates. b) Decisions on working conditions, promotion or termination, task allocation based on behaviour or personal traits, performance monitoring.
    5. Essential private services and essential public services and benefits. a) Eligibility for public assistance benefits, healthcare included, and granting, reducing, revoking or reclaiming them. b) Creditworthiness and credit scoring of natural persons. Systems used to detect financial fraud are excluded. c) Risk assessment and pricing for life and health insurance. d) Classification of emergency calls, dispatch of first responders, emergency patient triage.
    6. Law enforcement. Only where the law permits the use. a) Risk of a person becoming a victim of crime. b) Polygraphs and similar tools. c) Reliability of evidence. d) Risk of offending or re-offending, not only on the basis of profiling, and assessment of personality traits or past criminal behaviour. e) Profiling during detection, investigation and prosecution.
    7. Migration, asylum and border control management. Only where the law permits the use. a) Polygraphs and similar tools. b) Assessment of a security, irregular migration or health risk. c) Examination of asylum, visa or residence permit applications. d) Detecting, recognising or identifying persons. Checking travel documents is out.
    8. Administration of justice and democratic processes. a) Helping a judicial authority research and interpret facts and law. Alternative dispute resolution is covered too. b) Systems intended to influence the outcome of an election or referendum, or voting behaviour. Purely organisational campaign tools are excluded.

    Do not mix up high-risk and prohibited. Article 5(1)(g) bans biometric categorisation systems that classify individual people to infer sensitive traits. The traits are race, political opinions, trade union membership, religious or philosophical beliefs, sex life and sexual orientation. That is a prohibited practice. It is not an example of high-risk. Letter (f) bans inferring emotions in the workplace and in education institutions, except for medical or safety reasons.

    To classify a system step by step, use the Annex III classification guide.

    Article 6(1) and 6(2): the two roads to high-risk, Annex I and Annex III (Annex 3)

    Paragraph 1. Both conditions must hold. Point (a): the system is a safety component of a product, or is itself a product, covered by the legislation listed in Annex I. Point (b): that product needs a third-party conformity assessment. Paragraphs 1a and 1b, added in 2026, clarify what counts as a safety component. Paragraph 1c narrows the condition in point (b).

    Paragraph 2. Systems referred to in Annex III are also considered high-risk.

    Article 6(3): the four conditions, profiling and Annex III (Annex 3)

    A listed system is not high-risk if it poses no significant risk of harm to health, safety or fundamental rights. One of four conditions is enough. The system is intended to:

    • a) perform a narrow procedural task;
    • b) improve the result of a human activity already completed;
    • c) detect decision-making patterns or deviations from earlier patterns. It must not replace or influence the earlier human assessment without proper human review;
    • d) perform a preparatory task for an assessment relevant to the Annex III use cases.

    No condition beats this limit: an Annex III system is always high-risk when it profiles natural persons.

    The Commission's classification guidelines are still a draft.

    Article 6(4) and Article 49(2): document and register your Annex III (Annex 3) decision

    A provider who uses the derogation must document the assessment before placing the system on the market or putting it into service. The duty sits with the provider, not the deployer. Then, under Article 49(2), the provider registers itself and the system in the EU database.

    Which of these risk categories is not in the AI Act? The law, the Commission and Annex III (Annex 3)

    What the law says. No article of the Regulation lists four risk categories. Article 1(2) says what the Regulation lays down. Among the items: prohibitions of certain AI practices, requirements for high-risk AI systems, and transparency rules for certain AI systems. In practice: prohibited practices (Article 5), high-risk (Article 6, Annexes I and III), transparency duties (Article 50). General-purpose AI models with systemic risk (Article 51) are a separate track. They concern models, not systems.

    What the Commission says. The European Commission's page, updated 3 August 2026, says the AI Act "defines 4 levels of risk for AI systems". Its labels are "Unacceptable risk", "High risk", "Transparency risk" and "Minimal or no risk".

    How to answer the quiz. We do not know the options in your quiz. This part is our reading.

    • "Medium risk" and "moderate risk": not risk categories in the Regulation. No article and no annex uses them. They are not among the Commission's four levels. If one of them is an option, it is the one that is not provided for. Recital 51 mentions "medium-risk" products, but it is about medical devices.
    • "Limited risk": not a risk category in the Regulation. No article and no annex uses it. Recital 53 speaks of "limited risks" only to describe narrow tasks. Many courses use the name for the level the Commission calls "Transparency risk".
    • "Zero risk", "no risk", "low risk": not risk categories in the Regulation. A quiz may use them for the Commission's "Minimal or no risk" level.
    • "Systemic risk": it is in the Regulation, but it classifies general-purpose AI models, not systems.

    The dates for Annex III (Annex 3) and Annex I, and where Italy stands

    The dates are in Article 113 of the Regulation.

    • 2 February 2025: prohibited practices (Article 5). Two prohibitions added in 2026 start on 2 December 2026.
    • 2 August 2025: general-purpose AI models.
    • 2 August 2026: transparency duties (Article 50).
    • 2 December 2027: Annex III (Annex 3) high-risk.
    • 2 August 2028: Annex I high-risk.

    In Italy. Law no. 132 of 23 September 2025 has been in force since 10 October 2025. Its Article 20 names AgID as notifying authority and ACN as market surveillance authority. Legislative Decree no. 160 of 9 September 2026 is in the Gazzetta Ufficiale no. 214 of 15 September 2026, with entry into force on 30 September 2026. It defines high-risk by pointing to Article 6 and Annex III of the Regulation, so the list stays the European one. Government press release no. 185 of 5 August 2026 reports the final approval of a decree on national authorities and training. On 29 September 2026 we did not find it in the Gazzetta Ufficiale.

    What to do now with Annex III (Annex 3)

    List the AI systems you use or build. Write the intended purpose of each in one sentence. Compare it with the twenty-five entries. Note whether you are the provider or the deployer.

    The EU AI Act page sums up the duties. The free self-assessment takes five minutes and estimates your exposure and obligations.

    Frequently asked questions on Annex 3 and Annex III of the AI Act

    What is Annex 3 (Annex III) of the EU AI Act?

    It is the list of high-risk AI systems under Article 6(2) of Regulation (EU) 2024/1689. It has eight areas and twenty-five entries: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice and democratic processes.

    What are the specific Annex III (Annex 3) criteria for high-risk?

    The system must have an intended purpose listed in the annex. It leaves high-risk only if it meets at least one of the four conditions in Article 6(3)(a) to (d). It must also pose no significant risk. If it profiles natural persons, it always stays high-risk.

    From when do the duties for Annex III (Annex 3) systems apply?

    From 2 December 2027, under Article 113 in the consolidated text of 27 July 2026. For high-risk systems under Article 6(1) and Annex I the date is 2 August 2028. The Article 5 prohibitions apply from 2 February 2025. Two prohibitions added in 2026 start on 2 December 2026.

    Which risk category is not in the AI Act, next to the Annex III (Annex 3) high-risk one?

    "Medium risk" and "moderate risk" are not risk categories. No article of the Regulation uses them. They are also not among the four levels the Commission describes: unacceptable, high, transparency, minimal or no risk. The Regulation itself does not list four categories. This is our reading: check the options in your quiz.

    Does a provider who uses the Article 6 derogation for an Annex 3 (Annex III) system have to do anything?

    Yes. The provider documents the assessment before placing the system on the market or putting it into service, under Article 6(4). The provider must also register itself and the system in the EU database, under Article 49(2). The duty sits with the provider, not the deployer.

    Related resources

    This page gives information, not legal advice. The text cited is Regulation (EU) 2024/1689 in the consolidated version of 27 July 2026 (CELEX 02024R1689-20260727). The information on Italy is current as of 29 September 2026.

    Not sure whether your system falls under Annex III? Take the free EU AI Act self-assessment. It takes five minutes and estimates your exposure and obligations. Start the self-assessment.

    Reviewed and published under the editorial responsibility of AB Corporate Advisory S.R.L.

    LandingRed automates all of this

    Stop managing compliance in spreadsheets. Classify, document, assess, and monitor your AI systems from one platform.