Essential Private & Public Services , Annex III Point 5 High-Risk AI
AI used to evaluate eligibility for public benefits and services, assess creditworthiness of natural persons (except detection of financial fraud), set life and health insurance risk and pricing, or dispatch and establish priority in emergency response is high-risk under Annex III Point 5.
Scope, Definitions and Boundary with Prohibited Practices
Annex III Point 5 covers four commercially distinct but legally aligned AI applications: public benefits and services eligibility, consumer creditworthiness, life and health insurance risk assessment and pricing, and emergency dispatch (including medical triage, fire and police first response). These have been grouped because each involves AI materially affecting an individual's access to a service essential to their wellbeing.
Point 5 carries one of the heaviest additional obligations: deployer FRIA under Article 27 is mandatory for Point 5(b) (credit) and Point 5(c) (insurance) deployments, not only for public authorities. This is a narrower obligation than many deployers realise: most Annex III points trigger the FRIA only for public-authority deployers, but for consumer credit and insurance the private-sector deployer must do one.
Example Systems Under Annex III Point 5
Illustrative examples, each Member State's market surveillance authority may refine classification guidance over time.
Example
Automated welfare benefits eligibility scoring
Point 5(a) high-risk. Public-authority deployer → FRIA mandatory under Article 27.
Example
Consumer credit scoring AI at a bank
Point 5(b) high-risk. Private deployer also triggers Article 27 FRIA.
Example
Life-insurance premium-setting algorithm using wearable data
Point 5(c) high-risk. Private deployer triggers FRIA.
Example
AI-driven 112 emergency call triage
Point 5(d) high-risk, dispatch priority in emergency response.
Example
Fraud-detection engine at a bank (out of 5(b) scope)
Point 5(b) explicitly carves out fraud detection, but systems that double as credit scoring are in scope.
The Articles That Apply
High-risk classification under Annex III triggers the full Chapter III, Section 2 obligation set. Deployers pick up additional obligations under Chapter III, Section 4.
| Article | Obligation | What It Means in Practice |
|---|---|---|
| Art. 9 | Risk Management System | Must address disparate-impact risk across protected groups. For credit scoring, EU anti-discrimination case law (including the SCHUFA judgment) applies alongside. |
| Art. 10 | Data Governance | Data minimisation and proportionality are reinforced by GDPR Article 5 where personal data is processed. Many Point 5 deployments are already regulated under sectoral law (CCD II, Solvency II, GDPR), the AI Act stacks on top. |
| Art. 13 | Transparency | Instructions for use must specify accuracy ranges across demographic subgroups where relevant to the deployment context. |
| Art. 14 | Human Oversight | For credit denials and insurance refusals, meaningful human review at the appeal stage is the minimum expected implementation. |
| Art. 27 | FRIA, MANDATORY | FRIA is mandatory for all deployers of Point 5(b) and Point 5(c) systems, not just public authorities. This is the widest private-sector FRIA obligation in the Act. |
| Art. 26(11) & Art. 86 | Right to Explanation | Individuals refused credit, priced out of insurance, or denied public benefits may invoke the right to explanation of individual decision-making. Combines with GDPR Article 22 automated-decision rights. |
| Art. 49 | EU Database Registration | Standard. |
| GDPR Art. 22 | Automated Decisions | Decisions based solely on automated processing with legal or similarly significant effects on individuals trigger GDPR Article 22 in parallel. |
Pitfalls to Avoid on Annex III Point 5
Recurrent patterns seen in pre-enforcement readiness assessments.
Treating fraud detection as carve-out for credit scoring
Point 5(b) carves out 'detection of financial fraud', but if the same model drives credit decisions, the credit function is in scope regardless of the fraud label.
Private-sector deployer ignoring FRIA
Point 5(b) and 5(c) are the exceptions where private deployers must do an FRIA. Many insurance and lending compliance programmes have not yet absorbed this.
Over-relying on GDPR Article 22 framework
GDPR Article 22 and AI Act Article 26(11)/86 are complementary, not redundant. The AI Act right to explanation applies regardless of whether the decision is 'solely' automated.
Emergency triage AI with no registered EU presence
Dispatch AI supplied to EU emergency services from a non-EU provider must designate an authorised representative under Article 22, frequently missed.
Operationalise Point 5 Compliance
The Full Readiness Bundle gives your legal and compliance teams the 58-Point Compliance Checklist, Annex III Classification Matrix, FRIA template, Annex IV Technical Documentation Checklist, and 7 more documents, all aligned to the Annex III high-risk regime (now applying from 2 December 2027 under the May 2026 Omnibus deal).
one-time · instant download
Get the Full Bundle →Also available: Checklist Pack $149 · White-Label $999/yr
Next Steps
Deadline Planning
15-week compliance work plan for the EU AI Act's phased timeline.
Week-by-Week Plan →