Annex III high-risk categories explained
The eight Annex III categories of high-risk AI under the EU AI Act, with worked examples in biometrics, employment, credit, education, and infrastructure.
Annex III is the heart of the EU AI Act’s high-risk regime. It lists eight categories of intended use that — absent the Article 6(3) carve-out — make an AI system high-risk and trigger the full Chapter III obligations. This guide walks through all eight, with concrete examples of what falls in and what doesn’t.
How to read Annex III
A few framing rules first:
- Intended use matters more than architecture. The same underlying model can fall in or out of Annex III depending on what your system is built to do.
- The list is not theoretical. Each item names specific use cases. If your system fits the description, it’s high-risk unless the Article 6(3) carve-out applies.
- The Commission can update Annex III. Article 7 gives the Commission power to add use cases. Expect occasional revisions.
1. Biometrics
This category covers AI systems used for:
- Remote biometric identification of natural persons (face recognition cameras in semi-public space, for example)
- Biometric categorisation based on sensitive attributes (inferring ethnicity, political opinion, sexual orientation, etc.)
- Emotion recognition
Note that some uses are prohibited outright under Article 5 (real-time biometric ID in public spaces by law enforcement, workplace emotion recognition). Annex III covers the use cases that are merely high-risk, not banned.
Examples that fall in: a fraud-detection system that fingerprints customers using biometric vectors; an HR tool that uses voice analysis to detect “candidate confidence” (likely both Annex III and an Art. 5 violation).
2. Critical infrastructure
AI systems intended for use as safety components in the management or operation of:
- Road traffic
- Water, gas, heating, electricity
- Critical digital infrastructure
Examples that fall in: AI-driven traffic-signal control; ML-based predictive maintenance for a water utility’s pumps; an anomaly detector deployed by a TSO on the electricity grid.
Examples that don’t: a SaaS that lets utilities log their maintenance work; AI that drafts internal reports for the utility (preparatory under Article 6(3)(d)).
3. Education and vocational training
AI systems intended for use to:
- Determine access or admission to educational institutions
- Evaluate learning outcomes or steer the learning process
- Assess the appropriate level of education an individual will receive
- Monitor and detect prohibited behaviour during exams
Examples that fall in: an AI that scores university entrance essays; remote proctoring software that flags cheating; an “AI tutor” that decides which difficulty level a student should be placed in next.
Examples that don’t: a flashcard app that uses spaced repetition; a study-summary generator with a human teacher always in the loop.
4. Employment, workers management, access to self-employment
AI systems intended for use to:
- Recruit or select natural persons — placing targeted job ads, analysing or filtering applications, evaluating candidates
- Make decisions affecting work relationships — promotions, terminations, task allocation based on individual traits, monitoring and evaluation
This is the category that catches the most SaaS startups. Every modern ATS, candidate-ranking tool, performance-management AI, and intelligent task-routing system needs to be examined.
Examples that fall in: candidate-ranking algorithms; CV screening AI; AI that scores video interviews; algorithmic shift assignment for gig workers based on individual behavioural traits.
Examples that don’t: a job-board search engine that surfaces relevant openings; a meeting transcription tool used for HR notes (preparatory under 6(3)(d)).
5. Access to and enjoyment of essential private and public services
This category includes:
- Public benefits — eligibility AI used by social-services authorities
- Creditworthiness assessment and credit scoring (with carve-out for AI detecting financial fraud)
- Risk assessment and pricing for life and health insurance
- Emergency response dispatch and triage
Examples that fall in: automated underwriting for SME loans; an AI that scores life-insurance applicants; a triage AI for emergency call centres.
Examples that don’t: a fraud-detection model that flags suspicious transactions (explicit carve-out); a customer-service chatbot for a bank’s general support (limited risk, not Annex III).
6. Law enforcement
AI systems intended for use:
- To assess the risk of a natural person committing an offence
- As polygraphs or to detect emotional state in criminal proceedings
- To evaluate the reliability of evidence
- To predict criminal behaviour
- To profile natural persons in the course of investigations
These are exclusively used by law-enforcement bodies, so most private-sector SaaS doesn’t touch them. Mentioned here for completeness.
7. Migration, asylum, and border control management
AI systems used to:
- Assess risks posed by a natural person seeking to enter Member State territory
- Polygraphs or emotion detection in migration contexts
- Verify the authenticity of travel documents
- Assist competent authorities in examining asylum, visa, residence-permit applications
Public-sector category. Relevant for SaaS that sells into migration agencies or border-management authorities.
8. Administration of justice and democratic processes
- AI systems intended to assist a judicial authority in researching and interpreting facts and law, and in applying the law to a concrete set of facts
- AI systems intended to influence the outcome of elections or referenda, or voting behaviour
The first half catches “AI for judges” tools — typically large-language-model assistants used in courts. The second half catches political microtargeting and AI-generated political content.
Examples that fall in: an LLM tool used by a judge’s clerks to draft opinions; an AI that targets voters with personalised messaging during an election.
Examples that don’t: a SaaS for law firms that helps with internal document review for non-court work; a media-monitoring AI that summarises political news.
What if your system fits multiple categories
If your AI sits across two or more Annex III categories, all the relevant obligations apply. The classification doesn’t “pick the most severe” — it stacks. In practice that means your technical documentation needs to address all the relevant categories, and your risk-management system covers the union of foreseeable harms.
What to do if you land in Annex III
The full provider obligations in Articles 9–17 apply, plus EU database registration (Article 49) and post-market monitoring (Article 72). Backwards-plan your conformity assessment from 2 December 2027 (postponed from 2 August 2026 to 2 December 2027 under the Digital Omnibus, agreed May 2026 and pending formal adoption) — the date the high-risk regime is expected to become enforceable for systems not embedded in regulated products.
If your system is genuinely preparatory and doesn’t profile natural persons, consider Article 6(3)(d). We walk through that carve-out in detail in Article 6(3)(d) explained.