The EU AI Act does not define "high-risk AI" by what a system does or how sophisticated it is. It defines it by where the system is used. Annex III is the list of those contexts — and if your AI falls within it, you face the full weight of Articles 9 through 17.
This is the complete reference guide to every high-risk AI use case in Annex III, with the compliance implications that matter most for enterprise teams.
What Is Annex III?
Annex III to the EU AI Act lists eight categories of AI systems that are classified as high-risk when used in the contexts specified. High-risk classification triggers the most demanding compliance obligations in the Act: risk management systems, data governance requirements, technical documentation, automatic logging, transparency requirements, human oversight, and accuracy/robustness standards.
Critically, Annex III classification is context-dependent, not capability-dependent. An AI system that summarises documents is minimal risk when used in a law firm's knowledge management tool. The same system becomes high-risk the moment it is used to support an employment decision, a creditworthiness assessment, or a law enforcement investigation.
The Eight High-Risk Domains
1. Critical Infrastructure
AI systems used as safety components in the management and operation of critical infrastructure — road traffic, water supply, gas, heating, electricity. The concern is cascading failure: an AI error in managing electricity distribution has consequences that extend far beyond the enterprise that deployed it.
Compliance implication: Any AI used in operational technology (OT) environments for infrastructure management requires the full Article 9–17 treatment, including tamper-evident logging of every operational decision.
2. Education and Vocational Training
AI used to determine access to educational institutions, assess students, evaluate the level of a natural person's education, or make admissions decisions. This covers AI-assisted marking, automated admissions screening, and proctoring tools that influence academic outcomes.
Compliance implication: If your institution uses AI in any part of the student assessment or admissions workflow, you are in Annex III. The human oversight requirements (Article 14) are particularly demanding in this context.
3. Employment and Workers Management
AI used for recruitment and selection (CV screening, interview assessment), task allocation, monitoring and evaluation of performance, and promotion or termination decisions. This is one of the most commercially significant Annex III categories because AI hiring tools are widespread.
Compliance implication: Every stage of an AI-assisted hiring workflow — from CV ranking to interview scoring to offer decision support — is within scope. The evidence logging requirement means your AI hiring platform must create a tamper-evident record of every candidate ranking, scoring, and filter applied.
4. Essential Private Services and Public Benefits
AI used to evaluate creditworthiness or credit scoring (including risk assessments used to vary insurance premiums), and AI used to assess applications for public benefits, emergency services, and social services. This is the most commercially exposed category for financial institutions.
Compliance implication: Credit scoring AI — including alternative data models, behavioral scoring, and AI-assisted underwriting — is squarely within Annex III. Every model decision, input feature weighting, and human override must be logged with integrity protection.
5. Law Enforcement
AI used by law enforcement for risk assessment of individuals (recidivism prediction, crime hotspot mapping), polygraph-equivalent tools, detection of emotional states, and face recognition in the context of law enforcement. The prohibitions on real-time biometric surveillance interact with this category.
Compliance implication: Technology vendors selling to law enforcement face the highest compliance burden in this category. The technical documentation requirements effectively require a full audit trail of model behaviour from development through deployment.
6. Migration, Asylum, and Border Control
AI used for risk assessment of asylum applicants, verification of travel documents, supporting decisions on asylum and visa applications. The use of AI in migration and border contexts has received significant attention from regulators and civil society.
Compliance implication: Government bodies and technology vendors supplying these systems face full Annex III compliance, with particular attention to the non-discrimination requirements embedded in the data governance obligations of Article 10.
7. Administration of Justice and Democratic Processes
AI used to support courts in fact research and case law retrieval that influences judicial decisions, and AI used in elections and referenda (influencing voters, analysing political discourse). This is a narrow but symbolically significant category.
Compliance implication: Legal technology vendors providing AI tools to courts must be particularly attentive to the transparency and human oversight requirements — any AI that "assists" a judicial decision must preserve meaningful human control over the outcome.
8. Biometric Identification and Categorisation
AI systems intended for remote biometric identification of natural persons — including face recognition, gait recognition, and other biometric systems — with some specific uses prohibited outright (real-time remote biometric surveillance in public spaces).
Compliance implication: Even post-hoc biometric identification (identifying a person from recorded footage) triggers Annex III compliance when used in law enforcement contexts. Commercial facial recognition vendors must have Article 12-compliant logging of every query made against their systems.
Why Financial Services Bears the Heaviest Burden
Of the eight Annex III domains, financial services is where the commercial exposure is largest and the compliance requirements most operationally demanding. Category 4 (Essential Private Services) captures virtually every credit, insurance, and lending AI in the market. A bank that uses AI in any of the following workflows is operating a high-risk AI system under Annex III:
- Consumer credit scoring and approval
- Insurance underwriting and premium calculation
- AML/fraud risk scoring
- Mortgage decisioning and affordability assessment
- Investment product suitability assessment
- Loan restructuring and forbearance decisions
The EU AI Act does not create a carve-out for systems already regulated under banking or insurance frameworks. Compliance with existing financial regulation is a floor, not a ceiling — high-risk AI obligations layer on top of existing regulatory requirements.
The First Step for Every Organisation
The compliance journey for Annex III AI systems begins with a complete inventory. Every AI system your organisation uses, develops, or deploys must be mapped against the eight Annex III categories. Systems that fall within a category require immediate initiation of the Article 9–17 compliance programme.
For organisations with AI in financial services, employment, or healthcare, the inventory will almost certainly reveal multiple high-risk systems — and the evidence logging requirement (Article 12) means that every day without a tamper-evident record is a day of compounding evidentiary debt.
The compliance clock for Annex III does not start at December 2027. It starts with the first decision your high-risk AI makes that you cannot prove, with integrity-protected evidence, when a regulator asks.
Transform your AI logs into regulatory evidence.
Provara seals every AI decision into a tamper-evident, cryptographically-chained ledger — producing signed evidence packets pre-mapped to EU AI Act, ISO 42001, NIST AI RMF, and SOC 2 requirements.
Request a 30-minute technical demo →