Annex III Risk Classification Explained
The EU AI Act uses a risk-based approach. Article 6(2) defines high-risk AI systems as those falling within the eight categories listed in Annex III. If your AI system matches any of these categories, it is subject to the full set of obligations in Chapter III, Section 2 (Articles 8-15).
This guide walks through each category with plain-language explanations so you can determine whether your AI systems qualify as high-risk.
How Classification Works
There are two paths to being classified as high-risk under the EU AI Act:
- Article 6(1) — Safety component path: The AI system is a safety component of a product covered by existing EU harmonisation legislation (e.g., medical devices, machinery, toys, vehicles) and requires a third-party conformity assessment under that legislation.
- Article 6(2) — Annex III path: The AI system falls within one of the eight use-case categories listed in Annex III. This is the path most organisations need to evaluate.
Important exception: An Annex III AI system is not high-risk if it poses no significant risk of harm to health, safety, or fundamental rights. This includes cases where the system does not materially influence the outcome of decision-making. However, this exception does not apply if the system performs profiling of natural persons.
Category 1: Biometrics
AI systems used for biometric identification, categorisation, or emotion recognition — where permitted under EU or national law.
- Remote biometric identification — Systems that identify natural persons at a distance by comparing biometric data against reference databases. This excludes simple biometric verification (confirming someone is who they claim to be).
- Biometric categorisation — Systems that infer sensitive or protected attributes from biometric data. Examples include race, political opinions, trade union membership, religious beliefs, sex life, and sexual orientation.
- Emotion recognition — Systems intended to recognise emotions of natural persons.
Category 2: Critical Infrastructure
AI systems intended to be used as safety components in the management and operation of:
- Critical digital infrastructure
- Road traffic management
- Supply of water, gas, heating, or electricity
Example: An AI system that manages traffic signal timing at intersections, or one that predicts and manages electrical grid load distribution.
Category 3: Education & Vocational Training
- Determining access or admission to educational or vocational institutions
- Evaluating learning outcomes, including steering the learning process
- Assessing the appropriate level of education a person will receive or be able to access
- Monitoring and detecting prohibited behaviour of students during tests
Example: An AI system used by a university to screen and rank applicants, or an automated essay grading system used for final examinations.
Category 4: Employment & Workers Management
- Recruitment and selection — Placing targeted job advertisements, filtering applications, and evaluating candidates in interviews or tests
- Work-related decisions — Affecting promotion, termination, task allocation based on individual behaviour or personal traits, or monitoring and evaluating performance and behaviour
Example: An AI screening tool that ranks CVs and shortlists candidates, or a performance monitoring system that flags employees for review based on behavioural patterns.
Category 5: Essential Services
AI systems used in access to and enjoyment of essential private and public services and benefits:
- Public benefit eligibility — Evaluating eligibility for public assistance, healthcare services, or granting/reducing/revoking such benefits
- Credit scoring — Evaluating creditworthiness or establishing credit scores (excluding fraud detection)
- Insurance risk assessment — Risk assessment and pricing for life and health insurance
- Emergency services — Evaluating or classifying emergency calls, dispatching first responders, or triaging patients in emergency healthcare
Category 6: Law Enforcement
Where permitted under EU or national law:
- Assessing risk of a person becoming a victim of criminal offences
- Systems functioning as polygraphs or similar deception detection tools
- Evaluating reliability of evidence in criminal investigations
- Assessing risk of a person offending or re-offending (not solely based on profiling)
- Profiling of persons during detection, investigation, or prosecution of criminal offences
Category 7: Migration & Border Control
Where permitted under EU or national law:
- Polygraphs or similar tools used in migration contexts
- Assessing risks (security, irregular migration, health) posed by persons at borders
- Assisting in examination of applications for asylum, visas, or residence permits
- Detecting, recognising, or identifying persons in migration and border control contexts (excluding travel document verification)
Category 8: Justice & Democratic Processes
- Assisting judicial authorities in researching and interpreting facts and law, applying the law to concrete facts, or in alternative dispute resolution
- Influencing elections or referendums — AI systems intended to influence voting behaviour (excluding campaign logistics tools that don't directly expose users to AI outputs)
What Happens If Your System Is High-Risk?
If your AI system falls into any of the above categories, you must comply with:
- Risk management system (Article 9)
- Data and data governance requirements (Article 10)
- Technical documentation per Annex IV (Article 11)
- Automatic logging and record-keeping (Article 12)
- Transparency and instructions for use (Article 13)
- Human oversight measures (Article 14)
- Accuracy, robustness, and cybersecurity standards (Article 15)
- Conformity assessment before market placement (Article 43)
- EU Declaration of Conformity and CE marking (Articles 47-48)
- Registration in the EU database (Article 49)
Frequently asked questions
What is Annex III of the EU AI Act?
Annex III lists the use cases in which an AI system is classified as high-risk under Article 6(2). It covers eight areas. These include biometrics; critical infrastructure; education and vocational training; and employment, workers’ management and access to self-employment. They also include access to essential private and public services and benefits. The final areas are law enforcement; migration, asylum and border control management; and the administration of justice and democratic processes.
Is every AI system in an Annex III area automatically high-risk?
No. Article 6(3) creates an exception for systems in Annex III areas. A system is not high-risk if it does not pose a significant risk of harm to health, safety or fundamental rights. For example, this covers systems that only perform a narrow procedural task or a preparatory task. The exception never applies when the system profiles natural persons. A provider relying on the exception must document its assessment before placing the system on the market.
When do the high-risk obligations for Annex III systems apply?
Following the Digital Omnibus, obligations for high-risk systems under Annex III apply from 2 December 2027. Systems embedded in products regulated under Annex I follow from 2 August 2028. The prohibited-practice and AI-literacy provisions already apply.
What obligations follow once a system is classified as high-risk?
The provider must implement the requirements of Chapter III, Section 2. These cover risk management, data governance, Annex IV technical documentation, logging, transparency, human oversight, and accuracy, robustness and cybersecurity. The provider must then pass a conformity assessment and draw up the EU declaration of conformity. Finally, the provider affixes CE marking and registers the system in the EU database.
Can the Annex III list change?
Yes. The Commission may amend Annex III by delegated act under Article 7, adding or modifying use cases that pose an equivalent or greater risk. Classification is therefore not a one-off exercise — re-check your systems against the current list periodically.
Related resources
- Annex IV technical documentation template (free DOCX download)
- Free AI Act risk self-assessment — get a shareable readiness report
Not sure where your system falls? LandingRed's risk classification engine walks you through a guided questionnaire mapped to every Annex III category. It then determines your risk level automatically, with a full evidence trail.
LandingRed automates all of this
Stop managing compliance in spreadsheets. Classify, document, assess, and monitor your AI systems from one platform.