Vigilis
EU AI Act

Understanding high-risk AI systems under Annex III

Sourced from Regulation (EU) 2024/1689, Article 6 and Annex III

In short

Under Article 6(2), an AI system is high-risk if it falls into one of eight areas in Annex III, biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration/border control, or justice and democratic processes. High-risk systems stay lawful but carry the full Articles 9–15 provider obligations plus the Article 26 deployer obligations, regardless of company size. A narrow Article 6(3) carve-out can exempt genuinely low-risk procedural tasks, but never where the system profiles people.

Article 6(2) of the EU AI Act classifies an AI system as high-risk if it falls within one of eight areas listed in Annex III. Unlike the prohibited practices in Article 5, which are banned outright, high-risk systems remain lawful but carry the Act’s strictest compliance burden: risk management, data governance, technical documentation, logging, transparency, human oversight, and accuracy/robustness/cybersecurity requirements (Articles 9–15). These obligations apply regardless of company size.

The eight Annex III categories

  1. Biometrics, remote biometric identification, biometric categorisation of sensitive attributes, and emotion recognition, where not otherwise prohibited under Article 5.
  2. Critical infrastructure, safety components in the management or operation of critical digital infrastructure, road traffic, or the supply of water, gas, heating, or electricity.
  3. Education and vocational training, systems determining access or admission, evaluating learning outcomes, assessing the appropriate level of education, or monitoring/detecting prohibited student behaviour during tests.
  4. Employment, worker management, and self-employment, recruitment or selection systems (targeted job ads, screening/filtering applications, evaluating candidates), and systems making decisions on promotion, termination, task allocation, or monitoring and evaluating performance and behaviour.
  5. Access to essential private and public services, creditworthiness evaluation and credit scoring, life and health insurance risk assessment and pricing, evaluating eligibility for public assistance benefits, and dispatching or prioritising emergency services.
  6. Law enforcement, assessing the risk of a person offending or reoffending, polygraph-type tools, evaluating the reliability of evidence, and profiling of individuals during detection, investigation, or prosecution.
  7. Migration, asylum, and border control, polygraph-type tools, assessing security or irregular-migration risk, examining asylum, visa, or residence applications, and detecting or recognising individuals in this context.
  8. Administration of justice and democratic processes, assisting judicial authorities in researching and interpreting facts and law, and systems intended to influence the outcome of an election or referendum, or the voting behaviour of natural persons.

The narrow-task carve-out, and its own exception

Article 6(3) allows a system that technically falls within Annex III to avoid the high-risk label if it does not pose a significant risk of harm, because it performs a narrow procedural task, improves the result of a previously completed human activity, detects decision-making patterns or deviations from them without replacing or influencing human assessment, or performs a purely preparatory task. A provider relying on this carve-out must document the assessment under Article 6(4). Critically, this exception itself does not apply if the AI system performs profiling of natural persons , profiling always results in high-risk classification.

What high-risk classification actually requires

Once a system is classified as high-risk, providers must implement a documented risk management system (Art. 9), ensure training/validation/testing data meets quality criteria (Art. 10), maintain technical documentation (Art. 11) and automatic logging capability (Art. 12), design the system for transparency and provide instructions for use (Art. 13), enable effective human oversight (Art. 14), and achieve appropriate levels of accuracy, robustness, and cybersecurity (Art. 15). Deployers face a parallel but distinct set of obligations under Article 26.

Because the eight categories are broad by design (covering HR, lending, insurance, education, and public benefits) many companies that have never thought of themselves as “AI companies” discover they are operating one or more high-risk systems the moment they map their AI use cases against Annex III.

Frequently asked questions

What are the high-risk categories under Annex III?
Eight areas: biometrics; critical infrastructure; education and vocational training; employment and worker management; access to essential private and public services (such as credit scoring, insurance pricing, and benefits eligibility); law enforcement; migration, asylum and border control; and administration of justice and democratic processes.
Do high-risk obligations depend on company size?
No. Once a system is classified as high-risk, the Articles 9–15 provider obligations and the parallel Article 26 deployer obligations apply regardless of company size.
Can a system in an Annex III area avoid being high-risk?
Sometimes. Article 6(3) exempts a system that performs a narrow procedural task, improves the result of a completed human activity, detects patterns without replacing human judgement, or performs a purely preparatory task, but this carve-out never applies if the system profiles natural persons, and the provider must document the assessment under Article 6(4).

Related guides

Want to know if your AI system falls into Annex III?

Our free assessment classifies your systems against Annex III (free and anonymous) no account needed.

Start the free check