Which Systems Fall Into Annex III High Risk Categories

Which Systems Fall Into Annex III High Risk Categories

The EU AI Act defines high risk AI systems through Annex III categories, and understanding whether your system falls into this list is the foundation for compliance planning. Annex III sets out ten categories of AI systems that are presumed to pose a high risk to fundamental rights and safety.

The first two categories focus on safety-critical applications. Biometric systems that are not based on prohibited practices fall into the high risk classification. This includes facial recognition systems used for identification purposes in law enforcement, critical infrastructure monitoring through video analytics, and other biometric identification systems. The second category covers AI systems in employment and worker management contexts. These include systems that assess, monitor or evaluate employees or job candidates for recruitment, promotion, performance monitoring or termination decisions. A résumé screening tool that flags candidates or a system that monitors worker productivity and recommends disciplinary action both belong here.

Education and training systems form another high risk cluster. Any AI system that determines access to or the assignment of individuals to educational institutions or training programmes is classified as high risk. This includes admissions systems at universities, course recommendation engines and systems that evaluate learner progress to assign students to different educational pathways.

Critical infrastructure management systems represent a fourth category. AI systems used to operate or manage critical infrastructure in energy, water, transport or healthcare fall into high risk. A system that controls electricity distribution decisions, manages water treatment plant operations or routes emergency vehicles would qualify.

Law enforcement and criminal justice systems carry high risk designation. AI systems used by law enforcement to detect, investigate or prosecute criminal offences include facial recognition for identifying suspects, predictive policing systems, and tools that analyse evidence. Judicial systems that support decisions in legal proceedings are also captured.

Migration, asylum and border control systems are designated high risk. This includes systems that assess asylum applications, detect irregular border crossings, or make decisions affecting visa or residence status determination.

Lesson concept diagram

The final Annex III categories cover essential public services and civic participation. AI systems that determine eligibility for public benefits and government services, such as housing allocations, welfare payments or social assistance, are high risk. Also, AI systems used to support civic participation, including voting systems and systems that support public consultation or political campaigns, fall within the scope.

The key question is whether your organisation operates any system matching these categories. A financial services company deploying an AI model to assess creditworthiness must determine if that system fits the category covering AI systems used to determine credit or insurance eligibility. A healthcare organisation using an AI tool to triage patients against emergency department resources must consider whether this is a safety-critical system under the critical infrastructure or healthcare provisions.

Article 6(3) introduces a crucial qualifier: an AI system in Annex III can be excluded from high risk classification if, after a risk assessment and impact assessment, the organisation determines that the system would not pose a significant risk to fundamental rights. This filter is not a blanket exemption. An employer must still demonstrate through impact assessment why their biometric system for workplace access control poses no significant risk. A university must show why their course recommendation engine does not create substantial rights or safety risks.

The temporal dimension matters. Regulation (EU) 2026/1744, adopted in July 2026, deferred full compliance for Annex III high risk systems to 2 December 2027. Before that date, some obligations already apply through Articles 6, 8 and 26, but the full documentation, quality management and conformity assessment regime takes effect from 2 December 2027. For organisations with systems already in operation or under development, this means compliance planning must begin now.

Classification is not a one-time exercise. As your system evolves, the technical design changes, the data characteristics shift or the usage context expands, you must revisit whether your system remains high risk. A tool that starts as an internal employee training recommendation system might later be exposed to customers, changing its risk profile.

The compliance burden for high risk systems is substantial. From 2 December 2027, organisations must have completed technical documentation, risk assessments, impact assessments, quality management systems, conformity assessment and CE marking. This timeline is firm. Organisations should begin classification and compliance planning immediately. Waiting until late 2027 to start assessment and documentation will result in non-compliance.

Understanding the Annex III categories is the first step, but it is not the end. Each category has nuances. A biometric system used only internally for employee badges might present different risks than one used for public identification. An employment system used in hiring presents different considerations than one used for performance management. Understanding these distinctions helps assess whether your specific system, in your specific context, truly falls within the high risk classification. The assessment is not abstract but grounded in your organisational reality.