EU AI Act guide · updated 2 August 2026

Is your AI system high-risk? Annex III, explained

“High-risk” is the EU AI Act’s load-bearing concept: it decides whether you owe a disclosure notice or a full conformity stack. Two routes lead there — being a safety component of an Annex I regulated product (enforced from 2027), or falling into one of the eight Annex III use-case categories, whose obligations became enforceable on 2 August 2026. This guide covers the Annex III route, which is where nearly all software companies live.

Classification is about intended use context, not model sophistication. A linear regression that scores creditworthiness is high-risk; a frontier LLM writing marketing copy is not.

The eight Annex III categories

1 · Biometrics

Remote biometric identification, biometric categorisation by sensitive attributes, emotion recognition (where not outright prohibited by Art. 5).

2 · Critical infrastructure

Safety components in the management of critical digital infrastructure, road traffic, and water/gas/heating/electricity supply.

3 · Education & vocational training

Admission, allocation, learning-outcome evaluation, level assessment, and exam-cheating surveillance.

4 · Employment & worker management

CV screening, recruitment ads targeting, candidate evaluation, promotion/termination decisions, task allocation, monitoring and performance evaluation.

5 · Essential services

Public-benefit eligibility, creditworthiness scoring, life & health insurance risk pricing, emergency-call classification and dispatch.

6 · Law enforcement

Individual risk assessment, evidence-reliability evaluation, recidivism prediction, profiling in investigations.

7 · Migration, asylum & border control

Visa/asylum application examination, risk assessments of persons, identity-document verification.

8 · Justice & democratic processes

Assisting judicial authorities in researching and applying the law; systems intended to influence election outcomes or voting behaviour.

The escape hatch: Article 6(3)

An Annex III match is not the end of the analysis. Article 6(3) takes a system out of high-risk when it does not pose a significant risk to health, safety or fundamental rights because it only:

  • performs a narrow procedural task,
  • improves the result of a previously completed human activity,
  • detects decision-making patterns or deviations without replacing or influencing the human assessment, or
  • performs a preparatory task for an assessment.

Two hard edges: a system that profiles natural persons is always high-risk regardless of the derogation, and a provider relying on 6(3) must document the assessment before placing the system on the market and register it. The derogation is a documented legal position, not a vibe — treat borderline calls as counsel-review items.

Get an article-referenced classification for your system

The free AnnexWise assessment classifies a system in about 10 minutes — risk tier, open obligations and a gap report, with article references throughout. It runs in your browser; answers never leave your device.

Run the free assessment →

Both answers need paperwork

If the system is high-risk, the provider owes the Chapter III stack — start with the Annex IV technical documentation — and the deployer owes Article 26 duties. If it is nothigh-risk, you still want the dated, article-referenced record showing why: the classification memo is what turns “we think we’re fine” into an answer a regulator, customer or investor accepts.

Frequently asked questions

Our AI only assists a human who makes the final decision — is it still high-risk?

Possibly. The Article 6(3) derogation can take a system out of high-risk when it performs a narrow procedural task, improves the result of prior human work, only detects decision patterns without replacing human assessment, or performs a purely preparatory task. But the derogation is narrow, must be documented before market placement, and never applies when the system profiles natural persons.

Is a chatbot high-risk?

A customer-facing chatbot is normally not high-risk — but it does trigger Article 50: users must be told they are interacting with AI. High-risk status comes from the use context in Annex III (hiring, credit, essential services and so on), not from the underlying technology.

We use GPT/Claude via API inside our product. Does that make us high-risk?

Using a general-purpose model doesn't itself set your tier — what matters is what your product does with it. If your GPT-powered tool screens job applications, the tool is an Annex III employment system and you are likely its provider. The model vendor's own GPAI duties (Art. 53) run in parallel and don't cover you.

What happens the moment a system is classified high-risk?

The provider owes the full Chapter III stack — risk management, data governance, Annex IV technical documentation, logging, human oversight, conformity assessment, CE marking and registration — before EU market placement. Deployers owe the Article 26 duties. Since 2 August 2026 both are enforceable.

Where does your AI system actually stand?

The free AnnexWise assessment classifies a system in about 10 minutes — risk tier, open obligations and a gap report, with article references throughout. It runs in your browser; answers never leave your device.

Run the free assessment →

Keep reading

AnnexWise is compliance software, not a law firm; this guide is general information about Regulation (EU) 2024/1689, not legal advice for your situation. Verdict logic is documented on the methodology page.