● Annex III Point 5 · High-Risk

Essential Private & Public Services , Annex III Point 5 High-Risk AI

AI used to evaluate eligibility for public benefits and services, assess creditworthiness of natural persons (except detection of financial fraud), set life and health insurance risk and pricing, or dispatch and establish priority in emergency response is high-risk under Annex III Point 5.

Regulation EU 2024/1689 2 Dec 2027, Annex III (post-Omnibus) Article 6(2) + Annex III Point 5
What Annex III Point 5 Covers

Scope, Definitions and Boundary with Prohibited Practices

Annex III Point 5 covers four commercially distinct but legally aligned AI applications: public benefits and services eligibility, consumer creditworthiness, life and health insurance risk assessment and pricing, and emergency dispatch (including medical triage, fire and police first response). These have been grouped because each involves AI materially affecting an individual's access to a service essential to their wellbeing.

Point 5 carries one of the heaviest additional obligations: deployer FRIA under Article 27 is mandatory for Point 5(b) (credit) and Point 5(c) (insurance) deployments, not only for public authorities. This is a narrower obligation than many deployers realise: most Annex III points trigger the FRIA only for public-authority deployers, but for consumer credit and insurance the private-sector deployer must do one.

Not legal advice. This page summarises the relevant Articles and Annex III provisions of Regulation (EU) 2024/1689 for orientation. Always consult qualified legal counsel before making compliance decisions.
In Scope / Out of Scope

Example Systems Under Annex III Point 5

Illustrative examples, each Member State's market surveillance authority may refine classification guidance over time.

Example

Automated welfare benefits eligibility scoring

Point 5(a) high-risk. Public-authority deployer → FRIA mandatory under Article 27.

Example

Consumer credit scoring AI at a bank

Point 5(b) high-risk. Private deployer also triggers Article 27 FRIA.

Example

Life-insurance premium-setting algorithm using wearable data

Point 5(c) high-risk. Private deployer triggers FRIA.

Example

AI-driven 112 emergency call triage

Point 5(d) high-risk, dispatch priority in emergency response.

Example

Fraud-detection engine at a bank (out of 5(b) scope)

Point 5(b) explicitly carves out fraud detection, but systems that double as credit scoring are in scope.

Compliance Obligations

The Articles That Apply

High-risk classification under Annex III triggers the full Chapter III, Section 2 obligation set. Deployers pick up additional obligations under Chapter III, Section 4.

ArticleObligationWhat It Means in Practice
Art. 9Risk Management SystemMust address disparate-impact risk across protected groups. For credit scoring, EU anti-discrimination case law (including the SCHUFA judgment) applies alongside.
Art. 10Data GovernanceData minimisation and proportionality are reinforced by GDPR Article 5 where personal data is processed. Many Point 5 deployments are already regulated under sectoral law (CCD II, Solvency II, GDPR), the AI Act stacks on top.
Art. 13TransparencyInstructions for use must specify accuracy ranges across demographic subgroups where relevant to the deployment context.
Art. 14Human OversightFor credit denials and insurance refusals, meaningful human review at the appeal stage is the minimum expected implementation.
Art. 27FRIA, MANDATORYFRIA is mandatory for all deployers of Point 5(b) and Point 5(c) systems, not just public authorities. This is the widest private-sector FRIA obligation in the Act.
Art. 26(11) & Art. 86Right to ExplanationIndividuals refused credit, priced out of insurance, or denied public benefits may invoke the right to explanation of individual decision-making. Combines with GDPR Article 22 automated-decision rights.
Art. 49EU Database RegistrationStandard.
GDPR Art. 22Automated DecisionsDecisions based solely on automated processing with legal or similarly significant effects on individuals trigger GDPR Article 22 in parallel.
Common Failure Modes

Pitfalls to Avoid on Annex III Point 5

Recurrent patterns seen in pre-enforcement readiness assessments.

Pitfall

Treating fraud detection as carve-out for credit scoring

Point 5(b) carves out 'detection of financial fraud', but if the same model drives credit decisions, the credit function is in scope regardless of the fraud label.

Pitfall

Private-sector deployer ignoring FRIA

Point 5(b) and 5(c) are the exceptions where private deployers must do an FRIA. Many insurance and lending compliance programmes have not yet absorbed this.

Pitfall

Over-relying on GDPR Article 22 framework

GDPR Article 22 and AI Act Article 26(11)/86 are complementary, not redundant. The AI Act right to explanation applies regardless of whether the decision is 'solely' automated.

Pitfall

Emergency triage AI with no registered EU presence

Dispatch AI supplied to EU emergency services from a non-EU provider must designate an authorised representative under Article 22, frequently missed.

Professional Documentation

Operationalise Point 5 Compliance

The Full Readiness Bundle gives your legal and compliance teams the 58-Point Compliance Checklist, Annex III Classification Matrix, FRIA template, Annex IV Technical Documentation Checklist, and 7 more documents, all aligned to the Annex III high-risk regime (now applying from 2 December 2027 under the May 2026 Omnibus deal).

$499

one-time · instant download

Get the Full Bundle →

Also available: Checklist Pack $149  ·  White-Label $999/yr

Related Reading

Next Steps

Classify Your System

Interactive 3-question quiz to confirm Annex III scope.

Run Classifier →

All 8 Annex III Domains

Overview of every Annex III high-risk category.

Annex III Overview →

Deadline Planning

15-week compliance work plan for the EU AI Act's phased timeline.

Week-by-Week Plan →