Annex III quick check
Three questions to test whether an AI system falls into one of the eight Annex III high-risk domains. For a full assessment covering Articles 5, 6, 50 and general-purpose AI, use the 12-question classifier.
Question 1, does the intended purpose match a domain?
Annex III lists intended purposes, not sectors. Match what the system is for.
| Point | Domain | Typical systems |
|---|---|---|
| 1 | Biometrics | Remote identification, biometric categorisation, emotion recognition |
| 2 | Critical infrastructure | Safety components in digital infrastructure, road traffic, water, gas, heating, electricity |
| 3 | Education | Admissions, marking, learning-outcome evaluation, exam proctoring |
| 4 | Employment | Screening, evaluation, task allocation, performance monitoring, targeted job ads |
| 5 | Essential services | Benefits eligibility, credit scoring, life and health insurance pricing, emergency dispatch and triage |
| 6 | Law enforcement | Evidence reliability, risk of offending, investigative profiling |
| 7 | Migration & borders | Visa and asylum assessment, border risk assessment, identification |
| 8 | Justice & democracy | Judicial decision support, systems influencing voting behaviour |
No match? Check the Annex I route instead — AI inside a regulated product such as a medical device or machinery is high-risk through Article 6(1), at 2 August 2028. Both routes →
Question 2, does it profile people?
If the system evaluates personal aspects of identified individuals, performance at work, economic situation, health, reliability, behaviour, preferences, location — that is profiling under GDPR Article 4(4).
Profiling ends the analysis
Article 6(3) provides that an Annex III system is always high-risk where it performs profiling of natural persons. If the answer to question 1 was yes and the answer here is yes, the derogation is unavailable and question 3 does not arise.
Question 3 — is the derogation available?
Two layers, and the first is usually decisive. The threshold gate asks whether the system poses no significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision-making. A score, rank or recommendation that a decision-maker is expected to use materially influences the outcome.
Only if the gate is passed do the four conditions arise: a narrow procedural task; improving the result of a previously completed human activity; detecting decision-making patterns without replacing or influencing a prior human assessment without proper review; or a preparatory task.
Whatever you conclude, document it
Article 6(4) requires a provider concluding that an Annex III system is not high-risk to document that assessment before the system is placed on the market. You still register under Article 49, and Article 80 gives a market surveillance authority a procedure to challenge the classification. The derogation in full →
What is live regardless of the answer
The 2 December 2027 date applies to Chapter III. It does not defer:
- Article 50 transparency: if the system interacts with people or generates synthetic content. Since 2 August 2026.
- Article 4 AI literacy: every provider and deployer, every tier. Since 2 February 2025.
- Article 49 registration: since 2 August 2026.
Status labels on this page
Verified fact: The eight Annex III domains, the Art. 6(3) threshold gate and four conditions, the profiling override, and the Art. 6(4) documentation duty.
Expert analysis: The framing of the three questions and the ordering.
Unsettled: The Commission's Annex III guidelines remain in draft and may narrow several domain scopes.
Twelve questions, full coverage
This check covers Annex III only. The full classifier also tests the Article 3(1) definition, Article 2 scope, the Article 5 prohibitions, Chapter V general-purpose AI, and all four limbs of Article 50.
Not sure where you sit?
The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.
Frequently asked
How do I know if my AI system is high-risk?
There are two routes. Article 6(1) covers AI that is a safety component of, or is itself, a product under the Annex I harmonisation legislation requiring third-party conformity assessment, applying from 2 August 2028. Article 6(2) covers AI whose intended purpose falls within one of the eight areas in Annex III, applying from 2 December 2027, subject to the Article 6(3) derogation. Classification turns on intended purpose, not on the sector the organisation operates in.
What are the eight Annex III areas?
Biometrics; critical infrastructure; education and vocational training; employment, workers management and access to self-employment; access to and enjoyment of essential private services and essential public services and benefits; law enforcement; migration, asylum and border control management; and administration of justice and democratic processes.
Can an Annex III system avoid high-risk classification?
Through the Article 6(3) derogation, where the system does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision-making, and meets one of four conditions. An Annex III system is always high-risk where it performs profiling of natural persons, which removes the derogation for most systems that evaluate individuals.