Migration, Asylum & Border Control , Annex III Point 7 High-Risk AI
AI used by or on behalf of competent public authorities, or by Union institutions, in migration, asylum and border control management, including polygraph-style systems, risk assessment of entrants, and examination of visa and asylum applications, is high-risk under Annex III Point 7.
Scope, Definitions and Boundary with Prohibited Practices
Annex III Point 7 covers AI in the full migration and border-control lifecycle: polygraph-style systems used for immigration purposes, risk assessment of natural persons entering or seeking to enter a Member State, examination of applications for asylum, visa or residence permits, and detection, recognition or identification of natural persons in the context of migration, asylum and border control (excluding verification of travel documents).
This is the Annex III point with the most acute fundamental-rights intersection. The Charter of Fundamental Rights Article 18 (right to asylum), Article 19 (protection in the event of removal), and the EU asylum acquis (Qualification Directive, Procedures Directive, Dublin Regulation) all operate in parallel. The AI Act layers technical-documentation, risk-management, and human-oversight obligations on top, but does not displace any fundamental-rights protection.
Example Systems Under Annex III Point 7
Illustrative examples, each Member State's market surveillance authority may refine classification guidance over time.
Example
AI-assisted asylum claim credibility assessment
Point 7(c) high-risk. FRIA mandatory under Article 27 (public authority deployer).
Example
Visa risk-scoring at a consulate
Point 7(b) high-risk. The Schengen Information System (SIS II), VIS and EES already capture part of the workflow, the AI Act adds a distinct regulatory layer.
Example
Biometric matching at external border (EES, Entry/Exit System)
Likely falls under Point 7(d) high-risk together with Point 1. Verification of travel document authenticity is carved out.
Example
Polygraph-style deception detection in asylum interviews
Point 7(a) high-risk. Scientific validity of polygraph-style AI is disputed, Article 9 risk management must address this explicitly.
Example
Travel-document authenticity verification at border
Carved out of Point 7(d), not high-risk on this basis alone.
The Articles That Apply
High-risk classification under Annex III triggers the full Chapter III, Section 2 obligation set. Deployers pick up additional obligations under Chapter III, Section 4.
| Article | Obligation | What It Means in Practice |
|---|---|---|
| Art. 9 | Risk Management System | Must specifically address risks to fundamental rights, including non-refoulement (Article 19 CFR) and the right to asylum (Article 18 CFR). |
| Art. 10 | Data Governance | Training data from past migration decisions typically encodes discrimination by nationality, language, and origin. Article 10 addresses this but does not prescribe a specific methodology. |
| Art. 13 | Transparency | Instructions for use must disclose demographic performance variation, particularly acute for systems operating on diverse applicant populations. |
| Art. 14 | Human Oversight | Decisions affecting liberty and asylum rights cannot be delegated to AI output. Human decision-makers must retain genuine discretion. |
| Art. 27 | FRIA, MANDATORY | Mandatory. Public authority deployers must conduct and, on request, provide the FRIA to the market surveillance authority. |
| Art. 26(6) | Processing of Personal Data | Processing is typically under the LED or specialised migration regulations, the AI Act imposes logging and governance obligations on top. |
| Art. 49 | EU Database Registration | Migration-domain Annex III systems are registered in the non-public section of the EU database. |
| Qualification Directive, Procedures Directive | Sectoral Overlap | Substantive protections in the asylum acquis are unchanged by the AI Act. Procedural decisions remain bound by them. |
Pitfalls to Avoid on Annex III Point 7
Recurrent patterns seen in pre-enforcement readiness assessments.
Treating polygraph-style AI as scientifically validated
Polygraph-style AI has contested scientific validity. Article 9 risk management must document the evidence base, regulators have signalled scepticism.
Assuming border-control AI is always permitted
Real-time biometric identification at external borders is permitted as a targeted exception under Article 5(1)(h), but subject to specific authorisations and logging duties. Untargeted or persistent use remains prohibited.
Under-scoping the FRIA
FRIA for migration deployments must include a specific analysis of impact on vulnerable groups, unaccompanied minors, asylum seekers with protected characteristics, stateless persons.
Non-EU supplier shortcuts
Non-EU providers supplying migration authorities must designate an authorised representative (Article 22). The deployer cannot substitute its own legal presence.
Operationalise Point 7 Compliance
The Full Readiness Bundle gives your legal and compliance teams the 58-Point Compliance Checklist, Annex III Classification Matrix, FRIA template, Annex IV Technical Documentation Checklist, and 7 more documents, all aligned to the Annex III high-risk regime (now applying from 2 December 2027 under the May 2026 Omnibus deal).
one-time · instant download
Get the Full Bundle →Also available: Checklist Pack $149 · White-Label $999/yr
Next Steps
Deadline Planning
15-week compliance work plan for the EU AI Act's phased timeline.
Week-by-Week Plan →