← Blog

EU AI Act Annex III: 8 High-Risk Use Cases, Explained

Parminder Singh
Parminder Singh··6 min read
Summarize with AI

EU AI Act Annex III lists eight high-risk AI use-case categories, including biometrics, education, employment, credit scoring, law enforcement, and justice. See the covered systems, Article 6(3) exception, and the provider and deployer obligations that follow.

Compliance & Regulationeu-ai-actannex-iiihigh-risk-aicomplianceclassificationregulation
EU AI Act Annex III: What the High-Risk Use Case List Actually Covers

Under Article 6(2) and Annex III of Regulation (EU) 2024/1689, eight defined AI-use-case categories can trigger high-risk classification. They cover biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice or democratic processes. Classification attaches to the system's intended purpose, subject to Article 6(3)'s limited exception. That finding brings provider duties under Articles 9 through 15 into scope and gives deployers responsibilities under Article 26. For standalone Annex III systems, Regulation (EU) 2026/1744 moved the application date to 2 December 2027.

The eight Annex III points read at the use-case level. The classification turns on what the system does, who it serves, and what decision it informs.

I want to walk through what each Annex III category actually covers, where the most common enterprise deployments fall inside the scope, and how the classification triggers the downstream obligations on logging, monitoring, and disclosure.

TL;DR

  • Annex III names eight high-risk AI-use-case categories under Article 6(2).
  • Article 6(3) can exclude limited procedural or preparatory uses after a documented assessment.
  • Standalone Annex III systems have a 2 December 2027 application date under Regulation (EU) 2026/1744.

The eight Annex III categories

The eight points below define the affected activity. A familiar industry label alone does not settle classification.

Point 1: Biometrics

The biometrics category names remote biometric identification, sensitive-attribute categorisation, and emotion recognition. Its scope is narrower than commonly assumed: not every biometric authentication deployment is high-risk under Annex III. A login flow that compares a face to a stored template for identity verification falls outside remote biometric identification unless it operates at scale on a population without their direct cooperation. The scope expands when the technology infers attributes such as political opinion, sexual orientation, or religion, or when it claims to detect emotion.

Point 2: Critical infrastructure

The critical infrastructure category covers safety components of critical digital infrastructure, road traffic management, and the supply of water, gas, heating, and electricity. The scope is the safety function. An AI system that optimizes scheduling for a power grid is in scope when the system's output affects the safety of the supply, and out of scope when the system runs purely commercial dispatch decisions. The classification follows the safety relevance, not the commercial relevance.

Point 3: Education and vocational training

The education category covers AI systems that determine access to educational and vocational training institutions, evaluate learning outcomes, assess the appropriate level of education a person should receive, and monitor prohibited behavior during tests. Admissions screening falls inside the category. Proctoring has the same classification. High-stakes grading by an adaptive-learning product also belongs here. Tutoring that produces non-binding suggestions sits at the edge of scope, with the classification depending on whether the output feeds a decision that affects access.

Point 4: Employment, workers management, and access to self-employment

The employment category covers AI systems used to recruit or select candidates, screen applications, evaluate applicants during interviews, make decisions affecting terms of employment, allocate tasks based on personal traits or behaviour, and monitor worker performance and behaviour. The category captures most of the recruitment AI stack from sourcing through performance management. The August 2, 2026 deadline means deployers using AI in HR pipelines face the full Article 12 logging and Article 26 monitoring obligation in less than two months.

Point 5: Access to essential private and public services

Point 5 has four sub-categories with broad enterprise impact. Public-benefit eligibility appears in 5(a). Creditworthiness evaluation and credit scores appear in 5(b), with an explicit financial-fraud exception. Life and health-insurance risk assessment and pricing sit in 5(c). Emergency-service dispatch and emergency-healthcare triage sit in 5(d).

Point 5(b) is the category financial-services deployers will face most directly. A credit score or creditworthiness assessment used in underwriting is explicitly named in Annex III. The system still needs an Article 6 classification assessment and current implementation-date tracking; see the dedicated EU AI Act credit-scoring guide for the operational evidence questions.

Point 6: Law enforcement

The law enforcement category covers risk assessments for individuals likely to commit a crime, polygraph and similar deception detection, evidence reliability evaluation, profile-based crime prediction, and AI used to assist law enforcement decisions during investigations. The category is narrow in scope but high in regulatory attention. Deployments by private contractors supporting law enforcement agencies inherit the high-risk obligations through the deployer role.

Point 7: Migration, asylum, and border control

The migration category covers AI systems used by competent authorities to assess security risks, examine applications, detect false documents, and inform decisions in migration and asylum proceedings. The category is concentrated in government deployers, with private-sector contractors in the supply chain.

Point 8: Administration of justice and democratic processes

The justice category covers AI systems intended to assist judicial authorities in researching and interpreting facts and the law, and AI systems used to influence the outcome of elections or voters' behaviour. The scope is limited in current commercial deployments, with the most active area being the use of AI in legal research and case preparation for judicial proceedings.

The obligation chain that Annex III classification triggers

Once an AI system is classified as high-risk under Annex III, the provider obligations under Articles 8 through 17 attach to the entity that puts the system on the market. The deployer obligations under Article 26 attach to the entity that uses the system in operation. The chain includes risk management, data governance, technical documentation, automatic record-keeping, transparency to deployers, human oversight, and accuracy or security. Article 43 adds the conformity-assessment route.

Article 26 requires deployers to use the system according to the provider's instructions, ensure human oversight by competent natural persons, monitor operation, and retain automatically generated logs for at least six months under Article 26(6). Provider access to logs is addressed separately in Article 19. Serious-incident reporting follows Article 73.

The Article 12 logging obligation is where the operational evidence layer for the entire chain sits. Whatever the provider designs into the system at conformity assessment, the deployer has to operate in a way that produces records of how the system was used and what decisions it informed.

The exception that limits scope

Article 6(3) provides an exception to the Annex III classification when the AI system performs only a narrow procedural task, improves the result of a previously completed human activity, detects decision-making patterns without replacing the human assessment, or performs preparatory tasks for assessments relevant to the listed use cases. The exception is meant to keep low-stakes AI tooling out of the high-risk regime.

Providers that want to rely on the exception have to assess the AI system, document the assessment, and register the system in the EU database under Article 49. The competent authorities can disagree with the assessment and reclassify the system as high-risk during market surveillance. In practice, most enterprise AI deployments in HR, credit scoring, and access decisions have failed to qualify for the exception, since the system's output typically informs the human decision rather than merely organizing it.

DeepInspect

This is the architecture the Annex III obligation chain expects. DeepInspect sits at the AI request boundary as a stateless proxy between the application and the LLM. For a high-risk system that routes its LLM traffic through the proxy, it can produce per-decision audit records that support Article 12 automatic recording. Providers remain responsible for Article 19 retention, and deployers retain their Article 26(6) log-retention duty. The records include the verified identity of the natural person, the data classification, the policy version in effect, the decision outcome, and a timestamp.

For Article 14 human oversight, the proxy can enforce the policy that defines what the human reviewer has to approve and what the AI system can do without review. For Article 26 deployer monitoring, it can produce request-path evidence while the deployer retains responsibility for the wider monitoring program. The Annex III classification is the upstream signal that the obligation chain applies. The architecture has to operate at the per-decision level the chain requires. See what Article 12 logging requires for the evidence design.

For an AI system in an Annex III category, verify the Article 6 classification, the applicable implementation date, and the evidence each provider or deployer duty requires. A per-decision request record can support the HTTP AI-traffic portion of that evidence. Book a demo today.

Frequently asked questions

Is a credit-scoring system high-risk under Annex III even if it does not make the final lending decision?

Yes. Point 5(b) covers AI used to evaluate the creditworthiness of natural persons or establish their credit score, regardless of whether the system makes the final lending decision. A credit-scoring system that produces an input for a human underwriter still falls inside Point 5(b). The exception under Article 6(3) does not cover credit scoring in most enterprise deployments, since the score materially influences the human decision.

How does Annex III interact with the AI Liability Directive?

Annex III is the classification driver under the AI Act. The AI Liability Directive proposal sits alongside the Act and addresses non-contractual civil liability for damages caused by AI systems. The Directive references the AI Act classifications, so an Annex III high-risk system inherits the heightened liability framing under the proposed Directive when adopted. The Liability Directive proposal has progressed slowly through the EU legislative process and is not in force at the time of writing.

Does an internal-only AI system used by employees fall under Annex III?

The classification depends on what the system does, not on whether the users are employees. An internal hiring-decision system falls under Point 4. Performance-evaluation outputs also fall under Point 4 when they influence an employment decision. A productivity assistant with no role in a listed decision requires its own classification assessment, because Annex III scope follows the use case rather than the employee-only setting.

What happens if a deployer uses an AI system in a high-risk use case the provider did not anticipate?

Article 25 covers the case where a deployer's use of an AI system substantially modifies the intended purpose declared by the provider. The deployer in that case takes on the provider obligations for the new intended purpose, including the conformity assessment. This pathway catches AI systems that are sold for general use but deployed for a high-risk Annex III use case. The deployer's procurement and assessment process has to surface the substantial modification before it goes into production.

Will Annex III be expanded by the Commission?

Article 7 gives the Commission the power to add new use cases to Annex III through delegated acts, after consultation. The Commission has signalled interest in monitoring generative AI deployments in sensitive sectors and may propose additions where market surveillance identifies risks the current Annex III does not cover. Deployers should monitor the Commission's annual review of Annex III for any additions that affect their deployments.