Insights · Risk classification
Annex III High-Risk AI: Classification Guide
A practical guide to Annex III high-risk AI categories, intended purpose, exceptions, and the route from classification to conformity assessment.
Annex III of the EU AI Act enumerates domains where AI systems are presumed to be high-risk when they affect health, safety, or fundamental rights in specified ways — for example biometrics, critical infrastructure, education, vocational training, employment, access to essential services, law enforcement, migration, and justice. Your compliance task is to connect the product you actually ship to those descriptions with traceable evidence, then document exceptions only where the law truly allows.
Intended purpose drives classification
Regulators assess AI systems against the intended purpose given by the provider, including the provider’s marketing and technical documentation. A general-purpose foundation model embedded in your app is still evaluated in the concrete deployment you enable: which prompts, which user flows, which data flows, and which decisions affect people.
Common Annex III touchpoints for software companies
- Biometric identification and categorisation — remote live systems face extra scrutiny; emotion inference in workplaces and schools is largely restricted or prohibited in defined forms.
- Education and vocational training — systems that determine access or outcomes (e.g. admissions, grading that affects progression).
- Employment, workers management, and self-employed — recruitment, promotion, termination, task allocation, monitoring.
- Essential private and public services — creditworthiness, emergency services dispatch, certain insurance contexts.
- Law enforcement, migration, justice — high sensitivity; often overlaps with fundamental rights impact assessments.
From high-risk classification to CE marking (product-safety style AI)
Where an AI system is high-risk and not excluded, providers must implement Article 8–15 obligations and prepare Annex IV technical documentation. Depending on the conformity route, a notified body may be involved before affixing the CE marking — the exact module mirrors product-safety logic familiar from machinery or medical devices, adapted for AI.
Operational takeaway
Maintain a classification memo per AI system: facts, legal theory, dissenting views, and sign-off. Agent Mai accelerates the technical side — gap lists, remediation drafts, and exportable JSON — while your legal team owns the final legal position.
Use a repeatable high-risk classification test
The classification record should show the facts and the reasoning in sequence. First confirm that the software meets the Act's AI-system definition and is within territorial scope. Then assess the Annex I route for safety components or regulated products that require third-party conformity assessment. Separately assess the Annex III route by matching the intended purpose to a listed use case. Do not jump from an industry label such as healthcare or HR directly to a conclusion.
- Describe the decision or output the AI supports and whether it materially influences access, ranking, eligibility, safety, or legal effects.
- Identify the natural persons affected, including workers, candidates, students, customers, patients, migrants, and members of the public.
- Capture marketing claims, instructions for use, configuration defaults, and foreseeable deployment patterns because these help define intended purpose.
- Test every relevant Annex III category and record why close categories do or do not apply.
- Where relying on Article 6(3), record the statutory condition, the harm analysis, profiling status, approver, and evidence reviewed.
- Set a reassessment trigger for new features, customers, jurisdictions, data, model versions, and substantial modifications.
What changes after a high-risk decision
Classification starts a lifecycle programme. Providers need coordinated risk management, data and data-governance practices where relevant, technical documentation, records and logging, instructions for deployers, human-oversight design, accuracy, robustness, cybersecurity, quality management, conformity assessment, registration, and post-market monitoring. Deployers have their own operational duties, including use according to instructions, oversight, monitoring, record retention in defined circumstances, and impact-assessment obligations where applicable.
Classification memo template
A useful memo contains the system identifier and version, intended purpose, role analysis, scope analysis, Annex I and Annex III tests, Article 6 exception analysis, affected persons, sources relied on, uncertainties, decision, accountable approver, date, and reassessment triggers. Link the memo to the system register rather than saving it as an isolated PDF.
Deployer impact assessments and human review
High-risk classification also affects deployment governance. Public bodies and certain private deployers providing public services may need a fundamental rights impact assessment before use, while GDPR may separately require a data protection impact assessment. Employment deployments can trigger worker-information duties. Map these reviews together, but keep their legal tests and approvals distinct. The operational design should show who reviews outputs, what information they receive, when they can override or stop the system, and how interventions are recorded.
Frequently asked questions
Is every AI system used in employment high-risk?
No. Annex III identifies specified employment and worker-management uses, such as recruitment, selection, decisions affecting work relationships, task allocation based on personal traits, and performance monitoring. Classification depends on the intended purpose and the exact statutory conditions.
Can an Annex III system avoid high-risk classification?
Article 6 provides a limited route where an Annex III system does not pose a significant risk of harm and meets specified conditions, but profiling of natural persons remains high-risk. Providers relying on the exception should document the assessment before placing the system on the market or putting it into service.
When do the high-risk rules apply?
Following the 2026 political agreement on the AI Omnibus, the Commission describes 2 December 2027 for specified stand-alone high-risk areas and 2 August 2028 for systems embedded in regulated products. Teams should verify adoption and the current official timeline before relying on a date.
Related articles
- What Is the EU AI Act? 2026 Guide for Product TeamsA practical 2026 guide to EU AI Act scope, provider and deployer roles, risk classification, high-risk systems, GPAI, controls, and evidence.
- EU AI Act Article 4: AI Literacy RequirementsUnderstand the EU AI Act Article 4 AI literacy requirement, the people in scope, role-based learning, and practical evidence for providers and deployers.
- EU AI Act Article 50: Transparency RequirementsA practical guide to EU AI Act Article 50 transparency obligations for AI interactions, AI-generated content, deepfakes, and the evidence teams should retain.
Educational content only — not legal advice. Verify obligations with qualified counsel.