● Annex III Point 1 · High-Risk

Biometrics , Annex III Point 1 High-Risk AI

Remote biometric identification, biometric categorisation by sensitive attributes, and emotion recognition systems are explicitly listed as high-risk AI under Annex III Point 1. Article 5 also prohibits several specific biometric uses outright, the line between prohibited and high-risk is narrow, and both carry significant penalties.

Regulation EU 2024/1689 2 Dec 2027, Annex III (post-Omnibus) Article 6(2) + Annex III Point 1
→ Not sure how this affects your AI system?

Take the free 5-minute Risk Classifier, article-grounded scoring against Article 5, 6, Annex III, and Article 50.

Run the classifier →
What Annex III Point 1 Covers

Scope, Definitions and Boundary with Prohibited Practices

Annex III Point 1 covers three distinct but related categories of biometric AI: remote biometric identification systems, biometric categorisation systems that classify natural persons based on sensitive or protected attributes, and emotion recognition systems. Each carries the full weight of the high-risk obligations under Chapter III, Section 2 of the Regulation.

Crucially, the boundary with Article 5's prohibited practices is not bright. Real-time remote biometric identification in publicly accessible spaces for law enforcement purposes is prohibited except in narrowly defined circumstances (targeted search for specific victims, prevention of imminent terrorist threats, identification of suspects of serious crimes). Emotion recognition in workplaces and educational institutions is also prohibited under Article 5, but permitted in other contexts as high-risk. Organisations deploying any biometric AI must first establish which side of this line they fall on.

Not legal advice. This page summarises the relevant Articles and Annex III provisions of Regulation (EU) 2024/1689 for orientation. Always consult qualified legal counsel before making compliance decisions.
In Scope / Out of Scope

Example Systems Under Annex III Point 1

Illustrative examples, each Member State's market surveillance authority may refine classification guidance over time.

Example

Facial recognition at airport e-gates

Remote biometric identification, identifies travellers by face matching against passport photos.

Example

Voice-based gender classification in call centres

Biometric categorisation by protected attribute, inferring gender or age from vocal features.

Example

Customer sentiment analysis via webcam

Emotion recognition outside the workplace or education, permitted as high-risk with full compliance burden.

Example

Biometric authentication for employee login

Generally not in scope if used solely to confirm identity of a specific natural person, carve-out under Article 6(3).

Example

Real-time face search in train stations (law enforcement)

Prohibited under Article 5 unless falling within the narrow targeted-search exceptions.

Compliance Obligations

The Articles That Apply

High-risk classification under Annex III triggers the full Chapter III, Section 2 obligation set. Deployers pick up additional obligations under Chapter III, Section 4.

ArticleObligationWhat It Means in Practice
Art. 9Risk Management SystemDocument iterative risk identification, estimation, and mitigation across the full lifecycle. For biometric systems, demographic performance disparities must be specifically addressed.
Art. 10Data GovernanceTraining, validation and testing datasets must be examined for possible biases, including those affecting fairness across demographic groups. Data governance is enforced more strictly for biometric systems given the sensitive-attribute exposure.
Art. 13Transparency to DeployersInstructions for use must include accuracy, robustness and cybersecurity metrics per demographic subgroup where relevant. Vague system-level accuracy figures are insufficient.
Art. 14Human OversightMeasures must be designed into the system so that a natural person can override, ignore or reverse the output. For real-time biometric systems this raises non-trivial UX constraints.
Art. 15Accuracy, Robustness and CybersecurityDeclared accuracy metrics must be disclosed in the instructions and reproducible in deployment. Systems must be resilient to adversarial inputs (e.g. presentation attacks).
Art. 26Deployer ObligationsDeployers must use the system in accordance with instructions, assign human oversight to competent persons, and monitor for incidents. Public-authority deployers of biometric AI also trigger an FRIA under Article 27.
Art. 27Fundamental Rights Impact Assessment (FRIA)Public authorities and private deployers providing public services must conduct and submit an FRIA. Biometric systems are among the most frequent FRIA triggers.
Art. 49EU Database RegistrationAll Annex III high-risk systems must be registered in the EU public database before placement on the market or putting into service.
Common Failure Modes

Pitfalls to Avoid on Annex III Point 1

Recurrent patterns seen in pre-enforcement readiness assessments.

Pitfall

Assuming identification equals categorisation

Categorisation (inferring gender, ethnicity, political orientation) is a distinct legal category from identification (matching a face to a known identity), and has a different prohibition surface under Article 5.

Pitfall

Treating emotion recognition as limited-risk

Emotion recognition outside workplaces and education is high-risk, not limited-risk. The Article 50 transparency duty applies on top of, not instead of, the Annex III obligations.

Pitfall

Over-relying on vendor conformity declarations

The deployer's obligations under Article 26 are not discharged by the provider's CE marking. A self-declared conformity assessment does not absolve the deployer.

Pitfall

Missing the workplace/education prohibition

Emotion recognition in 'areas of workplace and education institutions' is prohibited under Article 5(1)(f). Productivity-monitoring tools inferring emotional state fall here even if not marketed as such.

Professional Documentation

Operationalise Point 1 Compliance

The Full Readiness Bundle gives your legal and compliance teams the 58-Point Compliance Checklist, Annex III Classification Matrix, FRIA template, Annex IV Technical Documentation Checklist, and 7 more documents, all aligned to the Annex III high-risk regime (now applying from 2 December 2027 under the May 2026 Omnibus deal).

$499

one-time · instant download

Get the Full Bundle →

Also available: Checklist Pack $149  ·  White-Label $999/yr

Related Reading

Next Steps

Classify Your System

Interactive 3-question quiz to confirm Annex III scope.

Run Classifier →

All 8 Annex III Domains

Overview of every Annex III high-risk category.

Annex III Overview →

Deadline Planning

15-week compliance work plan for the EU AI Act's phased timeline.

Week-by-Week Plan →