Library
What Counts as High-Risk Under Annex III
Annex III is a use-case list, not a model list. Most Lathestone clients who over-classify do it because the tool is 'AI'; most who under-classify miss internal HR and customer-decision systems. Article 6(3) exemptions exist. They are narrow, and profiling is not one of them.
Last reviewed
MikeFounder & developer
- EU AI Act
- AI governance
- Compliance
On this page
Who this is for
- Operators trying to decide whether an internal or customer-facing tool is high-risk under the EU AI Act
- People who have been told “if it uses a foundation model, it is high-risk” (it is not)
- People who have been told “internal tools don't count” (they can)
- Readers mapping a system against the current timeline
How classification actually works
High-risk under the Act is not a property of the model. It is a property of the use.
Two routes (Article 6 of Regulation (EU) 2024/1689):
- Article 6(1) / Annex I: the system is a safety component of a product (or is itself a product) already covered by listed Union product-safety law (medical devices, machinery, toys, vehicles, and the rest of Annex I). Those duties apply from 2 August 2028 after Regulation (EU) 2026/1744.
- Article 6(2) / Annex III: the system is used in one of the listed areas below. Those duties apply from 2 December 2027.
A general-purpose model sitting underneath is classified separately under Chapter V. Using GPT-class software in a recruitment workflow can make the system high-risk under Annex III point 4 without making you a GPAI provider. See GPAI model obligations.
The Annex III list, in plain language
Status: Annex III as in 2024/1689. The Omnibus did not rewrite this list. Article 7 still lets the Commission amend it by delegated act. Treat the categories as current as of 13 August 2026, not permanent.
| Point | Area | What it catches in practice | Lathestone-shaped example |
|---|---|---|---|
| 1 | Biometrics | Remote biometric identification; biometric categorisation by sensitive attributes; emotion recognition. Not simple “is this person who they claim to be” verification. | A visitor-management camera that identifies staff at the gate without a claimed identity. A “mood” layer on a support call. |
| 2 | Critical infrastructure | Safety components in digital infrastructure, road traffic, water, gas, heating, electricity. | Rare for a typical SME. A utilities client using AI to trip a safety interlock would sit here. |
| 3 | Education | Admission, assigning people to institutions, evaluating learning outcomes, assessing the level a person will receive, monitoring cheating in tests. | An academy using a model to score applications or to flag “cheating” on remote exams. |
| 4 | Employment | Targeted job ads, analysing and filtering applications, evaluating candidates; decisions on terms, promotion, termination; task allocation based on behaviour or traits; monitoring and evaluating performance. | The common one. An internal HR tool that ranks CVs, a vendor ATS with an “AI match” score used to drop candidates, a warehouse system that allocates shifts from a productivity score. |
| 5 | Essential private and public services | Public benefits eligibility; creditworthiness / credit scores (except fraud detection); life and health insurance risk and pricing; emergency-call triage and dispatch. | A lender's affordability score; a broker's life-insurance pricing model; a council tool that ranks benefit claims. A shop's fraud-detection model is the named exception. |
| 6 | Law enforcement | Victim-risk, polygraphs, reliability of evidence, reoffending risk, profiling in investigations, by or for law-enforcement authorities. | Out of scope for most commercial clients. In scope if you sell into police or justice. |
| 7 | Migration, asylum, borders | Risk assessment of entrants, asylum/visa examination, identification (not travel-document checks), polygraphs. | Same: public authorities and their vendors. |
| 8 | Justice and democratic processes | Assisting a judicial authority (or ADR) on facts and law; systems intended to influence election or referendum outcomes. Campaign logistics tools that voters never see are excluded. | A firm selling “case outcome” software to a court. A voter-targeting engine aimed at changing a vote. |
Emotion recognition in the workplace or education is also a prohibited practice under Article 5 in most cases. Do not “classify” a banned use as high-risk and carry on. Stop.
The exemptions: Article 6(3)
An Annex III system is not high-risk where it does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision-making. Article 6(3) treats that as the case where the system is intended to:
- perform a narrow procedural task; or
- improve the result of a previously completed human activity; or
- detect patterns or deviations from prior human decision-making, without replacing or influencing that assessment without proper human review; or
- perform a preparatory task to an assessment relevant to an Annex III use.
Profiling of natural persons is not exempt. If the system profiles people, Article 6(3) does not save it.
The Omnibus kept the duty to register a 6(3) self-assessment in the EU database. Do not treat the filter as a silent opt-out.
Lathestone judgement (not the law): most “AI that drafts a job advert for a human to edit” can be argued as preparatory. Most “AI that ranks candidates and the shortlist is what the panel sees” is high-risk. The difference is whether a person still does the assessment, or the model has already decided who exists.
Over-classifying and under-classifying
Over-classifying. A staff Copilot that summarises a meeting is not Annex III. A website chatbot that answers opening hours is not Annex III (it may be Article 50). Putting every model in the high-risk bucket produces binders nobody owns.
Under-classifying. Internal HR tools are the usual miss. “It's only for us” is not an exemption. Customer-facing decision systems (who gets the loan, the quote, the queue priority) are the other miss. Vendor tools count. If the ATS vendor “handles compliance”, you are still the deployer of the system you put into use.
Start with the inventory. Then write a one-paragraph rationale per row: which Annex III point, or why none, or why 6(3). Human oversight design for the ones that stay high-risk: Human Oversight by Design.
Questions
If we use a foundation model, are we high-risk?
Not by that fact alone. High-risk follows the use in Annex III or Annex I. The model provider has Chapter V duties. You may be a deployer of a high-risk system built on their model.
Does a CV-ranking tool count if a human still interviews?
Usually yes, if the ranking filters who gets interviewed. Annex III point 4(a) covers analysing and filtering applications and evaluating candidates. A human at the end does not automatically pull you out of 6(2). It may help Article 14 oversight later. It is not an exemption.
What about fraud detection on payments?
Annex III point 5(b) expressly excepts AI systems used to detect financial fraud from the creditworthiness high-risk category. Other points can still apply. Do not generalise the exception to all “risk” scores.
When do the high-risk duties apply?
For Annex III systems: 2 December 2027. For Annex I product-safety systems: 2 August 2028. Public-authority high-risk systems: 2 August 2030. Dates from Regulation (EU) 2026/1744. See the timeline.
What changed
- 13 August 2026: First publication. Cadence: medium (90–180 days). Next review due 9 January 2027. Off-cycle if the Commission amends Annex III under Article 7.
Note: This is compliance consulting and training, not legal advice. We work alongside your legal counsel, translating regulation into operational reality rather than replacing them. For a structured pass, see AI compliance.
Was this helpful?
Also in the library
- EU AI Act: Timeline & Current StatusAs of 13 August 2026, Regulation (EU) 2026/1744 has moved Annex III high-risk duties to 2 December 2027 and Annex I product-safety high-risk duties to 2 August 2028. Article 5 prohibitions, GPAI Chapter V, and Article 50 transparency are not part of that deferral.
- GPAI Model Obligations, ExplainedIf you did not train and place the model on the market, you are probably a deployer, not a GPAI provider, and Chapter V is not your chapter. Providers have been on the clock since 2 August 2025: transparency, copyright policy, a training-content summary, and extra duties above 10^25 FLOPs.
- The AI Vendor Risk ChecklistA procurement list you can actually use. Data handling, training-on-your-data, sub-processors, audit rights, and model-change notifications: the clauses that decide whether a vendor is safe to put on a live path.