Skip to content
Amended. Regulation (EU) 2026/1744 entered into force 27 July 2026. See what moved →
EU AI Act ChecklistIndependent reference
Chapter III · Article 6 & Annex III

High-risk AI systems under Annex III

Annex III is a list of intended purposes, not a list of sectors. That single distinction resolves most classification arguments, and it is why a bank can run AI entirely outside the high-risk regime while a software company with no regulated status runs something squarely inside it.

Art. 6(2)Annex IIIapplies 2 Dec 2027
When this applies. This is a Chapter III obligation on providers of high-risk AI systems. Following Regulation (EU) 2026/1744 it applies from 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for high-risk AI embedded in Annex I regulated products. Full timeline →

Two routes into high-risk

Article 6(1) — the product route

The AI system is a safety component of a product, or is itself a product, covered by the Union harmonisation legislation in Annex I: medical devices, machinery, toys, vehicles and others, and that product is required to undergo third-party conformity assessment.

Applies from 2 August 2028.

Article 6(2) — the use-case route

The AI system falls within one of the eight areas listed in Annex III, subject to the Article 6(3) derogation.

Applies from 2 December 2027.

The two routes have different dates

Medical device AI is Annex I, at 2 August 2028. Recruitment AI is Annex III, at 2 December 2027. Any summary giving a single high-risk date for both is wrong. Full timeline →

Where this usually goes next

Three situations account for most people reading this page. Each has a different answer.

A deal is blocked on an AI questionnaire

Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.

How this works for AI companies →

You need ISO/IEC 42001 documentation

23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.

Free gap assessment →
See the three tiers →

You are not sure what reaches you

Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.

Book a free 20-minute call →

This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →

The eight Annex III domains

PointDomainStructureArt. 27 FRIA
1Biometrics3 sub-pointsSituational
2Critical infrastructure1 sub-pointSituational
3Education & vocational training4 sub-pointsYes
4Employment & worker management2 sub-pointsSituational
5Essential public & private services4 sub-pointsYes
6Law enforcement4 sub-pointsYes
7Migration, asylum & border control4 sub-pointsYes
8Administration of justice & democratic processes2 sub-pointsYes

Each guide gives the sub-points, a derogation analysis, and a worked classification edge case for that domain.

The classification sequence

  1. Is it an AI system? Article 3(1), and the inference test. Definition →
  2. Is it prohibited? Article 5 comes before everything. Several practices adjacent to Annex III domains are banned outright. Article 5 →
  3. Annex I or Annex III? Different tests, different dates.
  4. Which described purpose? Match the system's intended purpose to a sub-point, not your sector to a heading.
  5. Does Article 6(3) apply? Threshold gate, four conditions, absolute profiling override. Derogation →
  6. What role are you in? Provider and deployer owe different things, and Article 25 can move you. Roles →
  7. Document it. Article 6(4) requires the assessment before market placement.

Do not let 2027 hide what is live

The deferral covers Chapter III. It does not cover Article 50 transparency, Article 49 registration, or Article 4 AI literacy. An Annex III system that also talks to people owes Article 50 today.

Status labels on this page

Verified fact: The two Article 6 routes, the eight Annex III domains and their application dates, and the Article 6(3) and 6(4) mechanics.

Expert analysis: The classification sequence and the sector-versus-purpose framing.

Unsettled: The Commission's Annex III guidelines remain in draft and out for consultation; several domain scopes may narrow.

Next step

Classify every system, then build once

Eight domains, one method. The organisations that find this tractable did the inventory first and classified against described purposes system by system, rather than trying to answer the question at company level.

Not sure where you sit?

The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.

Run the classifier →

Frequently asked

What are the 8 high-risk categories in Annex III?

Annex III lists eight areas: biometrics; critical infrastructure; education and vocational training; employment, workers management and access to self-employment; access to and enjoyment of essential private services and essential public services and benefits; law enforcement; migration, asylum and border control management; and administration of justice and democratic processes. Each contains sub-points describing specific intended purposes, and classification turns on those described purposes rather than on the sector an organisation operates in.

When do Annex III high-risk obligations apply?

From 2 December 2027 for stand-alone Annex III high-risk AI systems, following Regulation (EU) 2026/1744. High-risk AI embedded as a safety component in products regulated under Annex I legislation applies from 2 August 2028. Article 50 transparency, Article 49 registration and Article 4 AI literacy are not deferred and apply now.

Does being in an Annex III sector make our AI high-risk?

No. Annex III describes intended purposes, not sectors. A utility, a bank or a school can operate AI systems that fall entirely outside Annex III, and an organisation in no listed sector can operate a system squarely inside it. The question is always what the system is intended to do.

Can an Annex III system avoid high-risk classification?

Yes, through the Article 6(3) derogation, where the system does not pose a significant risk of harm to health, safety or fundamental rights and meets one of four conditions. An Annex III system is always high-risk where it performs profiling of natural persons, which removes the derogation for most systems that evaluate individuals. A provider claiming the derogation must document the assessment before placing the system on the market and still registers under Article 49.