Society GUIDE

EU AI Act Annex III High-Risk Use Cases

Annex III lists specified AI system uses considered high-risk under Article 6(2), across eight headings from biometrics and critical infrastructure to justice and democratic processes.

  • 3 min read
  • Last updated
On this page3 min read
  1. Overview
  2. Deep Dive
  3. Strategic Impact
  4. The Future of EU AI Act Annex III High-Risk Use Cases
  5. Real-World Implementation
  6. Risks & Guardrails
  7. Implementation Roadmap
  8. Keep Exploring
  9. Frequently asked questions

Overview

A sector label alone does not decide classification: the intended purpose, exact listed use, Article 6 exceptions, and transition dates matter.

Deep Dive

Annex III of the EU AI Act lists specified AI system uses that are high-risk under Article 6(2). Its eight headings are biometrics; critical infrastructure; education and vocational training; employment and worker management; access to essential private or public services and benefits; law enforcement; migration, asylum and border management; and administration of justice and democratic processes. The list identifies particular intended uses rather than making every AI system in those sectors high-risk.

Representative examples include certain remote biometric identification; school admission or learning-outcome evaluation; recruitment or worker-performance decisions; public-benefit eligibility and consumer creditworthiness; specified police evidence or risk assessment; and asylum, visa, judicial-assistance, or election-influence tools. Each Annex III point has its own actors, purpose, exceptions, and conditions. One-to-one biometric verification used only to confirm a person’s claimed identity is expressly excluded from the listed remote-identification category.

Article 6(3) provides a narrow exception for an Annex III system that creates no significant risk and performs one of the specified limited functions, such as a narrow procedural task. A system that profiles natural persons remains high-risk under that paragraph. A provider concluding that a system is not high-risk must document the assessment and meet the applicable registration duty.

Regulation (EU) 2026/1744 changed the implementation calendar. The main Chapter III requirements for Article 6(2)/Annex III systems apply from December 2, 2027; the Article 6(1)/Annex I route applies from August 2, 2028. The amendment changed timing, not the Annex III headings. Check the consolidated Act and current guidance for a specific use. This guide is informational, not legal advice.

Strategic Impact

Risk and safety

Catastrophic and everyday AI harms both depend on who understands the risks and who can act.

Clearer decisions

Public and professional literacy shapes whether strong safety policy is politically possible.

Cutting through hype

Clear explanations reduce capture by hype, lab PR, and vague ethics theater.

The Future of EU AI Act Annex III High-Risk Use Cases

Annex III can be amended through delegated acts, and practical examples may change as the Commission issues guidance and authorities develop implementation practice. Regulation (EU) 2026/1744 moved application dates but preserved the list’s role in classification. Monitor consolidated EUR-Lex text, Commission guidance, and national authority material before launch or a major change in intended use. Document the version and date of each classification decision. Track Commission delegated acts and guidance because Article 7 allows future adjustments to listed use cases under defined criteria.

Real-World Implementation

A school checks whether an AI tool is used for admission, learning-outcome evaluation, education placement, or test monitoring instead of labeling every classroom tool high-risk.

An employer maps a system’s actual role in candidate screening, work allocation, or performance assessment to Annex III point 4.

A public benefits agency checks whether an AI system evaluates eligibility or helps grant, reduce, revoke, or reclaim an essential benefit under point 5(a).

A product team documents why its system’s intended purpose does or does not match a listed Annex III use and whether Article 6(3) can apply.

Risks & Guardrails

  • Treating existential risk as sci-fi while capability compounds.

  • Confusing surface product safety with alignment under high autonomy.

  • Leaving non-English and non-expert audiences with only low-quality sources.

Implementation Roadmap

  1. Separate product harms, misuse, and loss-of-control / misalignment risks.

  2. Ask what evidence would change your view on timelines and severity.

  3. Prefer primary sources and concrete evals over marketing claims.

  4. Identify one action path: career, policy, funding, or skills — not only awareness.

Keep Exploring

Free newsletter

Get the daily AI briefing

Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.

One email each weekday. Unsubscribe in one click. We never sell or share your address.

Test yourself

Take the EU AI Act Annex III High-Risk Use Cases quiz

Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.

Start quiz

Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation

Frequently asked questions

What is EU AI Act Annex III High-Risk Use Cases?

Annex III lists specified AI system uses considered high-risk under Article 6(2), across eight headings from biometrics and critical infrastructure to justice and democratic processes. A sector label alone does not decide classification: the intended purpose, exact listed use, Article 6 exceptions, and transition dates matter.

How many area headings does Annex III currently contain?

Annex III lists eight headings, each with more specific AI system uses.

Which example is expressly listed in the education heading?

Annex III point 3 includes AI systems intended to evaluate learning outcomes in educational and vocational training institutions.

Which employment use appears in Annex III?

Point 4 covers recruitment and selection, including filtering applications and evaluating candidates.

Which system fits a listed essential-services example?

Point 5(a) includes specified public-authority systems evaluating eligibility for essential public assistance benefits and services.

Does using AI in a listed sector automatically make every system high-risk under Annex III?

Annex III lists specific intended uses; the sector label alone is not enough.