EU AI Act Annex III infographic by AnnexOps showing a radar scanning eight high-risk AI categories, including employment, education, law and justice, biometric identification, critical infrastructure, health and essential services, financial services, and public services

EU AI Act Annex III Explained: Which AI Systems Are Covered

Annex III of the EU AI Act lists eight categories of AI systems treated as high-risk on their own: biometric identification, critical infrastructure, education, employment, essential services, law enforcement, migration, and administration of justice.

If your AI system falls into one of these categories, it faces the Act’s full set of obligations, including risk management, technical documentation, human oversight, and conformity assessment, with the compliance deadline now set for December 2, 2027.

This article breaks down exactly which systems fall under Annex III, with real examples, so you can quickly check whether your AI system is in scope. For the full timeline and what changed with the 2027 deadline, see our complete guide to the Annex III deadline.

Checking if your AI system falls under Annex III?

AnnexOps runs an automated risk classification against the Act’s Annex III categories, so you don’t have to interpret the regulation yourself.

What Makes a System “High-Risk” Under Annex III?

Annex III systems are considered high-risk because of what they’re used for, not because of the underlying technology itself. A simple scoring algorithm and a large language model can both fall under Annex III if they’re deployed in one of the listed use cases, since the risk comes from the impact the decision has on a person’s life, rights, or opportunities. This use-case-first approach is a deliberate design choice in the Act, meant to keep the regulation relevant even as the underlying AI technology itself keeps changing year over year.

This is different from Annex I, which covers AI embedded inside products already regulated by other EU product safety laws, like medical devices or machinery. Annex III systems stand alone, they don’t need to be part of a separately regulated product to fall under the Act.

The list itself is not arbitrary. Each of the eight categories was chosen because AI systems in that area can materially affect a person’s access to opportunities, rights, safety, or fair treatment, areas where the EU has historically applied stricter regulatory scrutiny even before AI entered the picture. Understanding the reasoning behind the list makes it easier to correctly judge edge cases that don’t map neatly onto one of the eight headings.

Which Eight Categories Does Annex III Cover?

The table below gives a quick-reference view of all eight categories, with a real-world example for each. Use it to scan quickly, then read the detailed section below for the category that applies to you.

Category Example System Who’s Typically Affected
1 Biometric identification and categorization Facial recognition for identity verification Individuals being identified or categorized
2 Critical infrastructure Predictive maintenance for power grids General public relying on utilities
3 Education and vocational training Admissions algorithms, exam proctoring AI Students and applicants
4 Employment and worker management Resume screening, performance monitoring tools Job applicants and employees
5 Access to essential services Credit scoring, insurance underwriting AI Loan and insurance applicants
6 Law enforcement Reoffending risk assessment tools Individuals under investigation
7 Migration, asylum, and border control Automated visa or asylum application review Migrants and visa applicants
8 Administration of justice and democratic processes AI-assisted legal research for judges Litigants and the judicial system

1. Biometric identification and categorization

This category covers certain AI systems used for remote biometric identification, emotion recognition, and biometric categorization based on sensitive characteristics.

For example, facial recognition used to verify someone’s identity may fall within this area. The category can also cover systems that attempt to infer sensitive characteristics from biometric data.

Biometric identification can appear in many everyday business settings, including banking, travel, and workplace access. So, even if a system is presented as an identity or security solution rather than a surveillance tool, its actual use still needs to be assessed under the EU AI Act.

2. Critical infrastructure

AI systems used as safety components in the management of critical infrastructure can fall under Annex III. This includes areas such as water, gas, heating, and electricity supply.

The reason for the higher level of scrutiny is clear: an AI failure or manipulation in these environments could potentially affect public safety or disrupt essential services.

Examples can include AI-powered predictive maintenance systems or monitoring tools that influence how infrastructure is operated or maintained. Where an AI error could contribute to a serious outage or safety incident, the risks become particularly important.

3. Education and vocational training

Annex III also covers certain AI systems used in education and vocational training.

This can include AI used to determine access to educational institutions, evaluate learning outcomes, assess a person’s appropriate education level, or monitor students during examinations.

For example, an admissions algorithm that helps determine which students are accepted could fall within this category. AI-based exam proctoring systems may also be covered when they are used to detect prohibited behavior during tests.

Not every educational AI tool is automatically high-risk. The key question is how the system is being used and whether its output can materially influence a person’s educational opportunities or outcomes.

4. Employment, worker management, and access to self-employment

Employment is one of the areas where businesses are likely to encounter Annex III requirements.

The category covers certain AI systems used for recruitment, candidate selection, job advertising, promotion, termination, task allocation, and worker management.

A resume-screening tool that ranks job applicants is a straightforward example. Other systems, such as AI tools used to monitor employee performance or influence scheduling, compensation, or disciplinary decisions, may also require careful assessment.

This is particularly relevant because many businesses already use AI-powered recruitment and workplace tools without initially thinking of them as regulated high-risk AI systems.

5. Access to essential private and public services

This category covers certain AI systems used when people are seeking access to important private or public services.

Examples include credit scoring and creditworthiness assessments, as well as certain AI systems used for risk assessment in life and health insurance.

A fintech company using an AI model to assess whether someone qualifies for credit is a clear example. Similarly, an insurance system that uses AI to assess risk for pricing purposes may fall within the relevant Annex III provisions.

The category also covers certain AI systems used by public authorities when determining eligibility for services such as social benefits or other essential support.

6. Law enforcement

AI used in law enforcement receives particular attention under the EU AI Act because decisions in this area can directly affect a person’s liberty, privacy, and fundamental rights.

The category includes certain systems used to assess the risk of offending or reoffending, evaluate evidence, or support criminal investigations.

Predictive policing systems and AI tools that assist with the analysis of evidence are examples of technologies that require careful consideration under the Act.

For organisations developing or deploying AI in this area, understanding exactly what the system does and how its output is used is critical to determining the applicable obligations.

7. Migration, asylum, and border control management

AI systems used in migration, asylum, and border control can also fall under Annex III.

This includes certain systems used to assess security or health risks, examine visa or asylum applications, or assist with detecting, recognizing, or identifying people in migration-related contexts.

For example, an automated document verification system used at a border or an AI tool that assists officials in reviewing asylum applications may fall within this category.

Because decisions in these situations can have serious consequences for the people involved, AI systems used in migration and border processes receive additional regulatory attention.

8. Administration of justice and democratic processes

The final Annex III category covers certain AI systems used in the administration of justice and democratic processes.

This includes AI systems designed to assist judicial authorities with researching or interpreting facts and applying the law to specific circumstances.

The category also addresses certain AI systems that can influence the outcome of elections or referendums or affect how people vote.

For example, an AI system that supports judicial research may need to be assessed differently from a basic legal search tool, depending on how it is used and the role its output plays in judicial decision-making.

How Do I Check if My AI System Is In Scope?

The easiest way to start is to look at what your AI system actually does and what decisions it influences rather than focusing only on the technology behind it.

The same machine learning model could be considered low-risk in one situation and potentially high-risk in another. The difference may come entirely from the use case.

For example, a recommendation algorithm used to suggest products on an online store is not automatically a high-risk AI system. If a similar type of technology is used to rank candidates during a hiring process, however, the situation changes because employment is one of the areas covered by Annex III.

This is why having a clear AI system inventory is so important. Businesses sometimes discover during a compliance review that a tool adopted by an individual department was never properly assessed. A recruitment team might start using an AI-powered candidate sourcing platform, while another department adopts a third-party scoring tool, without either system being included in the organisation’s original AI inventory.

These kinds of situations can create what is often referred to as shadow AI,  AI being used within an organisation without proper oversight or documentation.

It is also important to remember that classification is not necessarily a one-time exercise. If the purpose of an AI system changes, its regulatory status may need to be reviewed again.

For instance, a tool originally introduced as a simple scheduling assistant could later be expanded to help evaluate employee performance. That change in use could create a very different compliance assessment.

What Happens Once a System Is Classified as Annex III?

Being classified as high-risk under Annex III is only the beginning. The organisation then needs to determine which EU AI Act requirements apply and put the necessary controls in place.

For standalone Annex III systems, the applicable compliance deadline is currently December 2, 2027. Depending on the organisation’s role and the specific system involved, requirements can include risk management, technical documentation, data governance, human oversight, monitoring, and conformity assessment.

The distinction between a provider and a deployer is also important.

Providers generally have broader responsibilities around developing, documenting, assessing, and placing high-risk AI systems on the market. Deployers, meanwhile, have their own obligations around how those systems are used, monitored, and overseen within their organisation.

So, once an AI system is identified as Annex III, the next step isn’t simply to label it “high-risk.” Businesses need to understand their role, identify the applicable obligations, document the system properly, and establish processes to keep it compliant as the system and its use evolve.

Ready to classify your AI systems properly?

AnnexOps helps AI teams run risk classification, generate the required documentation, and build an audit-ready evidence trail well before the Annex III deadline.

Author: Nitin Grover

Nitin Grover is an AI compliance strategist and writer focused on EU AI Act compliance, AI governance, Annex IV documentation, AI risk management, and AI compliance operations for AI startups, SaaS companies, and enterprise AI teams across Europe.

Post a Comment

Your email address will not be published. Required fields are marked *

Analyse your AI exposure