πŸ‡ͺπŸ‡Ί European Union

EU AI Act Annex III: the high-risk AI use cases

The eight areas listed in Annex III of the EU AI Act, with examples, the exceptions in Article 6(3), and when the rules apply.

Reviewed 11 Oct 2026·3 min read

Annex III is the list of AI use cases that the EU AI Act treats as high-risk. If your AI system falls into one of these areas, strict obligations apply. This guide lists the eight areas with plain-English examples.

What Annex III is

Article 6(2) of the AI Act says that AI systems used in the areas listed in Annex III are high-risk. These are stand-alone systems, meaning AI that is not built into a physical product already covered by EU product-safety law. (AI built into those products is covered by Annex I instead.)

When it applies

After the 2026 AI Omnibus, the high-risk obligations for Annex III systems apply from 2 December 2027, not 2 August 2026 as first planned. AI built into regulated products under Annex I applies from 2 August 2028.

The eight areas

  1. Biometrics. Remote biometric identification, biometric categorisation by sensitive characteristics, and emotion recognition, where permitted.
  2. Critical infrastructure. AI used as a safety component in managing critical digital infrastructure, road traffic, and the supply of water, gas, heating and electricity.
  3. Education and vocational training. Deciding who is admitted, evaluating learning outcomes, assessing the level of education a person should receive, and monitoring cheating in tests.
  4. Employment and worker management. Recruitment and selection (for example filtering applications or evaluating candidates), decisions on promotion or termination, task allocation based on behaviour or personal traits, and monitoring or evaluating performance.
  5. Essential private and public services. Deciding eligibility for public benefits, credit scoring, risk assessment and pricing in life and health insurance, and dispatching or prioritising emergency services.
  6. Law enforcement. Certain uses such as assessing the risk of a person becoming a victim or an offender, and evaluating evidence.
  7. Migration, asylum and border control. Certain uses such as risk assessment of people crossing borders and assisting with the examination of applications.
  8. Administration of justice and democratic processes. AI used to help judicial authorities research and apply the law, and AI intended to influence the outcome of an election or referendum.

These are summaries. The exact wording in Annex III decides what is covered, so read the official text for your use case.

Not everything in these areas is high-risk

Article 6(3) says an Annex III system is not high-risk if it does not pose a significant risk of harm to health, safety or fundamental rights. Examples include systems that only do a narrow procedural task, improve the result of a human activity already completed, detect patterns without replacing human judgement, or do a preparatory task.

There is an important limit: a system that performs profiling of people is always treated as high-risk.

If you rely on this exception, you must document your assessment and still register the system in the EU database. The 2026 Omnibus kept this registration duty but simplified the information required.

How to check your own system

  1. Write down exactly what your system does and who it affects.
  2. Compare that to the eight areas above.
  3. If it matches, check whether the Article 6(3) exception honestly applies, and document why.
  4. If it is high-risk, plan for the conformity assessment and your technical documentation.

For a step-by-step version, see Is my AI system high-risk? The official text is on EUR-Lex.

This article is general information, not legal advice. Rules change often, so check official sources before you rely on it.
Our network

More from our team

Other products built by the team behind ActAI Compliance.