Annex III vs Annex I infographic by AnnexOps showing two diverging glowing paths, representing the different rules and deadlines under the EU AI Act for standalone high-risk AI systems versus AI embedded in regulated products

Annex III vs Annex I: What’s the Difference Under the EU AI Act?

Annex III vs Annex I is one of the most common points of confusion under the EU AI Act. Annex III covers standalone high-risk AI systems, like hiring tools or credit scoring, with a compliance deadline of December 2, 2027. Annex I covers AI embedded inside products already regulated by other EU safety laws, like medical devices, with a deadline of August 2, 2028. Both are treated as “high-risk” under the EU AI Act, but they follow different rules, different deadlines, and different assessment routes.

This is one of the most common points of confusion for businesses working through EU AI Act compliance, since both annexes lead to the same “high-risk” label but get there through completely different logic. This article breaks down exactly how they differ, so you can correctly classify your own AI systems. For the broader timeline and deadline context, see our complete guide to the Annex III deadline. For a full breakdown of what falls under Annex III specifically, see EU AI Act Annex III Explained.

Not sure which annex applies to your AI system?

AnnexOps runs automated classification against both Annex III and Annex I criteria, so you don’t have to work through the regulation manually.

What Is Annex I Under the EU AI Act?

Annex I is a list of existing EU product safety laws, not a list of AI use cases. It covers sectors like medical devices, machinery, toys, lifts, radio equipment, and civil aviation, areas where the EU already had strict product safety regulation in place before the AI Act existed.

An AI system falls under Annex I when it is a safety component of a product covered by one of these existing laws, or when the AI system itself is the product, and that product already requires third-party conformity assessment under the relevant sectoral law. In simple terms, if an AI feature is built into a product that already had to pass EU safety certification before the AI Act even applied, that AI feature likely falls under Annex I.

A good example is AI-powered diagnostic software embedded in a medical device. The device was already regulated under the EU Medical Device Regulation, and the AI feature inside it now also falls under Annex I of the AI Act. Another example is an AI-based safety system inside industrial machinery, already regulated under the Machinery Regulation.

The full list of sectoral laws referenced by Annex I spans thirteen areas, including machinery, toy safety, recreational craft, lifts, equipment for explosive atmospheres, radio equipment, pressure equipment, cableway installations, personal protective equipment, appliances burning gaseous fuels, medical devices, in vitro diagnostic medical devices, and civil aviation security. Businesses operating in any of these thirteen sectors should specifically check whether their AI features trigger Annex I obligations, since these industries often assume AI Act compliance only applies to obviously “AI-native” businesses like SaaS platforms, when in fact a manufacturer adding a smart safety feature to existing machinery can be just as squarely in scope.

What Is Annex III Under the EU AI Act?

Annex III works differently. It does not attach to an existing product law, it defines eight use case categories directly, covering AI systems used in biometric identification, critical infrastructure, education, employment, access to essential services, law enforcement, migration, and administration of justice.

An AI system falls under Annex III purely because of what it’s used for, regardless of whether it’s tied to a separately regulated physical product. A resume-screening tool, a credit-scoring model, or a facial recognition system for identity verification are all Annex III systems, none of them require an underlying product to already be regulated elsewhere. This is what makes Annex III a much bigger compliance surface area for most digital-first businesses, since SaaS platforms, fintech products, HR tech, and edtech companies rarely produce a physical product that would already fall under an Annex I sectoral law in the first place.

Annex III vs Annex I: Side-by-Side Comparison

The table below summarizes the core differences at a glance.

Aspect Annex III Annex I
What it covers Standalone high-risk AI use cases AI embedded in already-regulated products
Basis for classification Use case (what the AI does) Existing EU product safety law
Compliance deadline December 2, 2027 August 2, 2028
Example systems Hiring tools, credit scoring, biometric ID AI in medical devices, machinery, toys
Conformity assessment route Internal control or notified body, depending on category Follows the sectoral product law’s existing process
Registration in EU database Required for most Annex III systems Generally not required, follows sectoral rules
Number of categories 8 use case categories 13 sectoral product laws referenced

Why the Deadlines Are Different

The two annexes moved on different timelines under the Digital Omnibus package for a practical reason, not an arbitrary one. Annex III systems are entirely new territory for most businesses; there was no pre-existing regulatory framework requiring documentation or risk assessment for a hiring algorithm or a credit scoring model. Building this compliance infrastructure from scratch takes real time, which is part of why regulators gave these systems until December 2, 2027.

Annex I systems, on the other hand, already sit inside products that go through established conformity assessment processes under sectoral law. A medical device manufacturer already has quality management systems, technical documentation practices, and notified body relationships in place, they’re extending existing processes to cover the AI component, not building compliance infrastructure from zero. This is reflected in the slightly later but arguably less disruptive August 2, 2028 deadline, since these businesses already have a functioning compliance apparatus to build on.

How Conformity Assessment Differs Between the Two

For Annex III systems, most high-risk AI can go through an internal conformity assessment process, meaning the provider self-assesses against the requirements and issues a declaration of conformity. Only remote biometric identification systems specifically require third-party notified body involvement in most cases.

For Annex I systems, the AI component generally has to go through whatever conformity assessment procedure the underlying sectoral law already requires. If the sectoral law mandates notified body involvement for the physical product, that same requirement typically extends to the embedded AI system as well. This means an Annex I classification can sometimes trigger a stricter third-party review than an equivalent Annex III system would, simply because it’s inheriting the assessment rigor of a mature, established regulatory regime like medical devices.

Can a System Fall Under Both Annexes?

Generally, no, a specific AI system is classified under one annex or the other, not both simultaneously. But a company can absolutely have systems in both categories at the same time. A healthcare company might have an AI diagnostic feature inside a certified medical device (Annex I) and, separately, an AI hiring tool used by its HR department (Annex III). These would be tracked, documented, and assessed on entirely separate timelines and processes, even within the same organization.

This is why building a proper AI inventory matters so much before attempting classification. Treating “our AI systems” as one single compliance project, rather than mapping each system individually against the correct annex, is a common and costly mistake. It also means a single compliance calendar with one deadline is usually the wrong tool for a business operating across both categories, since the December 2027 and August 2028 dates need to be tracked and resourced separately, each with its own documentation timeline and internal ownership.

Practical Steps to Classify Your Systems Correctly

Step 1: identify what the AI system does

Start by asking what decision or output the system produces, and who it affects. This determines whether Annex III’s use-case categories apply at all.

Step 2: check if it’s embedded in an already-regulated product

If the AI system is a component inside a product that already needs to comply with an EU product safety law, like medical devices, machinery, or toys, check the Annex I list of thirteen sectoral regulations to confirm the match.

Step 3: apply the correct deadline and assessment route

Once classified, apply the correct deadline (December 2027 for Annex III, August 2028 for Annex I) and follow the matching conformity assessment path, since these differ meaningfully between the two.

Getting this classification step right early avoids a scenario where a business builds documentation against the wrong framework, then has to redo the work closer to the actual deadline under time pressure.

How AnnexOps Helps With Both Annex Classifications

Manually working through thirteen sectoral product laws and eight use case categories to figure out where each AI system belongs is exactly the kind of task that becomes error-prone once a company has more than a handful of AI systems in active use. AnnexOps runs this classification automatically, checking each system against both Annex III’s use case categories and Annex I’s sectoral product law references, and flags which deadline and conformity assessment route applies before any documentation work begins.

This matters because getting the classification wrong at the start doesn’t just cost time, it can mean building an entire technical file against the wrong assessment process, something that’s far more expensive to unwind six months before a deadline than to get right on the first pass. By keeping classification, documentation, and evidence tracking in one place, AnnexOps helps businesses avoid exactly the kind of misclassification mistake this article has been walking through.

Ready to classify your AI systems the right way?

AnnexOps runs automated risk classification against both Annex III and Annex I, generates the required documentation, and keeps your evidence trail audit-ready.

Author: Nitin Grover

Nitin Grover is an AI compliance strategist and writer focused on EU AI Act compliance, AI governance, Annex IV documentation, AI risk management, and AI compliance operations for AI startups, SaaS companies, and enterprise AI teams across Europe.

Post a Comment

Your email address will not be published. Required fields are marked *

Analyse your AI exposure