Annex III Amendments
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This new topic is needed because amendments to Annex III represent specific regulatory changes to the AI Act's classification framework that warrant dedicated tracking and analysis separate from general AI Act compliance.
Overview
15 sources · Jul 23, 2026Legal Framework
Annex III of the AI Act enumerates specific high-risk AI systems subject to stringent regulatory obligations. The European Commission holds the power to amend Annex III through delegated acts, modifying the classification framework by adding, removing, or redefining high-risk categories. This dynamic mechanism ensures the regulatory perimeter adapts to technological evolution. Systems listed in Annex III trigger core compliance duties, including registration in the EU database under Article 71, rigorous post-market monitoring under Article 72, and adherence to real-world testing protocols under Article 60.
Article 71 mandates that providers of Annex III high-risk systems register them in an EU-wide database before market placement. Article 72 requires providers to establish and maintain a post-market monitoring plan proportionate to the AI system's nature and risks. Article 60 permits testing of high-risk systems in real-world conditions outside regulatory sandboxes, provided strict safeguards, informed consent, and human oversight are maintained. Any amendment to Annex III directly expands or contracts the scope of these obligations.
Key Developments
The delegated act mechanism for Annex III amendments introduces a moving target for compliance. While the Commission must consult an advisory forum and respect fundamental rights impact assessments before proposing amendments, the pace of technological change—particularly in generative AI and biometric identification—creates persistent regulatory uncertainty. Civil society and rights groups have actively lobbied against weakening safeguards. For instance, in February 2026, rights advocates called on EU legislators to reject proposals that would delete transparency safeguards within the AI Act framework, underscoring the tension between industry flexibility demands and fundamental rights protection. Practically, organizations must monitor the Commission's delegated act pipeline, as an amendment reclassifying a currently unregulated AI system into Annex III instantly imposes Article 71, 72, and 60 requirements.
Practical Guidance
- Monitor Delegated Acts: Establish a regulatory watch process to track proposed and adopted amendments to Annex III, as these changes directly alter the high-risk classification of your AI systems.
- Pre-emptive Risk Assessment: Conduct internal audits of AI systems not currently listed in Annex III to identify those likely to be reclassified, ensuring readiness to comply with Article 71 registration and Article 72 post-market monitoring obligations.
- Database Registration Readiness: For any system falling under Annex III, ensure technical and procedural readiness to register in the EU database mandated by Article 71 before deployment.
- Post-Market Monitoring Plans: Draft scalable post-market monitoring plans compliant with Article 72 that can be rapidly adapted if an Annex III amendment captures your product.
- Real-World Testing Compliance: If conducting real-world testing under Article 60, ensure informed consent protocols and human oversight mechanisms are robust, as Annex III amendments may subject previously untested systems to these strict conditions.