The EU AI Act's most significant obligations fall on high-risk AI systems — but determining whether your AI qualifies as high-risk is not always straightforward. This guide covers every category listed in Annex III of the Regulation, with real-world examples of what counts and what does not.
Deadline: 2 December 2027 — full compliance required for Annex III high-risk AI systems (deferred from August 2026 by the May 2026 AI Omnibus provisional agreement). Start your compliance programme now: 18 months is not much time for organisations that are starting from zero.
What Makes an AI System "High-Risk"?
Under the EU AI Act, an AI system is classified as high-risk if it falls into one of two categories:
- Annex I — AI embedded in products already regulated by EU product safety law (medical devices, machinery, aviation, vehicles, etc.). These have an earlier deadline of August 2028.
- Annex III — standalone AI systems in eight sensitive domains, regardless of the product or service they are part of. Deadline: December 2027.
This guide focuses on Annex III, which applies to the widest range of businesses.
The Eight Annex III Categories
1. Biometric Identification and Categorisation
AI systems used to identify individuals remotely, in real time or post hoc, in publicly accessible spaces. Also covers systems that categorise people by protected characteristics (race, gender, political opinion, religion, sexual orientation) based on biometric data.
Examples: facial recognition at airports or events; AI that infers emotion or demographic from CCTV footage; voice biometric authentication that also categorises speakers.
2. Critical Infrastructure Management
AI systems used as safety components in the management and operation of critical infrastructure, including road traffic, water supply, gas, heating, and electricity networks.
Examples: AI predictive maintenance for power grids; traffic flow optimisation systems with safety implications; AI-controlled water treatment decisions.
3. Education and Vocational Training
AI systems that determine access to, or progression within, educational and vocational training institutions. Also includes AI used to assess learners.
Examples: AI admissions tools that score or rank applicants; automated grading or assessment systems; AI proctoring tools that flag suspected cheating; platforms that adapt learning pathways in ways that affect progression.
4. Employment, Workers Management, and Access to Self-Employment
AI used for recruitment, candidate screening, performance evaluation, promotion decisions, and termination. This is one of the most commercially significant categories.
Examples: CV screening tools that rank or filter candidates; AI interview analysis platforms that score body language or speech; workforce management systems that automatically assign tasks or flag underperformance; AI tools that recommend pay rises, promotions, or redundancies.
5. Access to Essential Private and Public Services
AI used to evaluate creditworthiness or establish credit scores, and AI used to evaluate eligibility for public benefits, services, or emergency services.
Examples: credit scoring models used by banks and lenders; AI that determines insurance premiums based on behaviour; systems that assess eligibility for social housing, benefits, or healthcare priority queuing.
6. Law Enforcement
AI used by law enforcement authorities to assess the risk of an individual becoming a criminal, for polygraph tests, to evaluate the reliability of evidence, to assess recidivism risk, or to profile individuals during investigations.
Examples: predictive policing tools; AI risk assessment tools used in criminal justice sentencing recommendations; tools that analyse evidence or assess witness credibility.
7. Migration, Asylum, and Border Control
AI used to assess the risk posed by individuals crossing borders, to assist in asylum, visa, or residence permit applications, or to detect fraudulent documents.
Examples: AI border control interview analysis tools; automated visa rejection or flagging systems; document authenticity verification that triggers enforcement action.
8. Administration of Justice and Democratic Processes
AI used to assist courts in researching and interpreting facts and the law, and AI used to influence elections or voter behaviour.
Examples: AI legal research tools used in court proceedings to summarise or recommend outcomes; AI targeting systems for political advertising; content recommendation systems influencing voter opinion.
What If My AI Touches One of These Areas?
Classification as high-risk triggers a full set of obligations. These must be in place before the system is placed on the market or put into service:
| Obligation | What it requires |
|---|---|
| Risk management system | Ongoing process to identify, analyse, and mitigate risks throughout the system lifecycle |
| Data governance | Training, validation, and testing datasets must be relevant, representative, and free of errors |
| Technical documentation | Detailed records of the system's design, development, and intended purpose |
| Logging and audit trails | Automatic recording of system operations to enable post-market monitoring |
| Transparency | Instructions for use that allow deployers to understand and operate the system correctly |
| Human oversight | Mechanisms enabling humans to monitor, intervene, and override the system |
| Accuracy and robustness | Demonstrated performance, cybersecurity resilience, and accuracy metrics |
| Conformity assessment | Internal or third-party assessment before deployment; CE marking in some cases |
| EU registration | Registration in the EU AI Act database before deployment |
What Is Explicitly Not High-Risk?
The AI Act includes a built-in filter: an AI system that falls into an Annex III category is not high-risk if it does not pose a significant risk of harm. A system used for a narrow procedural purpose (e.g. spam filtering before a human makes any decision) is unlikely to qualify. The Act requires organisations to document this reasoning.
Additionally, AI systems used purely for research and development, or that are not yet placed on the market, are not subject to these obligations.
The December 2027 Deadline in Practice
18 months sounds like a long time. It is not. A typical high-risk AI compliance programme involves: initial gap assessment (1–2 months), risk management framework design (2–3 months), data governance review (2–4 months), documentation drafting and technical testing (3–6 months), conformity assessment (1–3 months), and registration. Companies starting from zero in mid-2026 will be cutting it close.
Not sure where you stand?
Our free assessment tool maps your AI systems to the relevant EU AI Act obligations in minutes.
Start free assessment