# Annex III Amendments — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/annex-iii-amendments
> Sources are cited per item. Verify against the official texts before relying on them.

This new topic is needed because amendments to Annex III represent specific regulatory changes to the AI Act's classification framework that warrant dedicated tracking and analysis separate from general AI Act compliance.

## Overview

## Legal Framework

Annex III of the AI Act enumerates specific high-risk AI systems subject to stringent regulatory obligations. The European Commission holds the power to amend Annex III through delegated acts, modifying the classification framework by adding, removing, or redefining high-risk categories. This dynamic mechanism ensures the regulatory perimeter adapts to technological evolution. Systems listed in Annex III trigger core compliance duties, including registration in the EU database under Article 71, rigorous post-market monitoring under Article 72, and adherence to real-world testing protocols under Article 60. 

Article 71 mandates that providers of Annex III high-risk systems register them in an EU-wide database before market placement. Article 72 requires providers to establish and maintain a post-market monitoring plan proportionate to the AI system's nature and risks. Article 60 permits testing of high-risk systems in real-world conditions outside regulatory sandboxes, provided strict safeguards, informed consent, and human oversight are maintained. Any amendment to Annex III directly expands or contracts the scope of these obligations.

## Key Developments

The delegated act mechanism for Annex III amendments introduces a moving target for compliance. While the Commission must consult an advisory forum and respect fundamental rights impact assessments before proposing amendments, the pace of technological change—particularly in generative AI and biometric identification—creates persistent regulatory uncertainty. Civil society and rights groups have actively lobbied against weakening safeguards. For instance, in February 2026, rights advocates called on EU legislators to reject proposals that would delete transparency safeguards within the AI Act framework, underscoring the tension between industry flexibility demands and fundamental rights protection. Practically, organizations must monitor the Commission's delegated act pipeline, as an amendment reclassifying a currently unregulated AI system into Annex III instantly imposes Article 71, 72, and 60 requirements.

## Practical Guidance

- **Monitor Delegated Acts:** Establish a regulatory watch process to track proposed and adopted amendments to Annex III, as these changes directly alter the high-risk classification of your AI systems.
- **Pre-emptive Risk Assessment:** Conduct internal audits of AI systems not currently listed in Annex III to identify those likely to be reclassified, ensuring readiness to comply with Article 71 registration and Article 72 post-market monitoring obligations.
- **Database Registration Readiness:** For any system falling under Annex III, ensure technical and procedural readiness to register in the EU database mandated by Article 71 before deployment.
- **Post-Market Monitoring Plans:** Draft scalable post-market monitoring plans compliant with Article 72 that can be rapidly adapted if an Annex III amendment captures your product.
- **Real-World Testing Compliance:** If conducting real-world testing under Article 60, ensure informed consent protocols and human oversight mechanisms are robust, as Annex III amendments may subject previously untested systems to these strict conditions.

## Legislation (full text of key provisions)

### EU database for high-risk AI systems listed in Annex III

*Source: AI Act, aiact-art-71-en, 2024-06-12 — https://overview.legal/posts/93161*

### Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes

*Source: AI Act, aiact-art-60-en, 2024-06-12 — https://overview.legal/posts/92962*

### Fundamental rights impact assessment for high-risk AI systems

*Source: AI Act, aiact-art-27-en, 2024-06-12 — https://overview.legal/posts/92424*

### Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems

*Source: AI Act, aiact-art-72-en, 2024-06-12 — https://overview.legal/posts/93175*

### Procedure for dealing with AI systems classified by the provider as non-high-risk in application of Annex III

*Source: AI Act, aiact-art-80-en, 2024-06-12 — https://overview.legal/posts/93332*

### Obligations of deployers of high-risk AI systems

*Source: AI Act, aiact-art-26-en, 2024-06-12 — https://overview.legal/posts/92382*

### Classification rules for high-risk AI systems

*Source: AI Act, aiact-art-6-en, 2024-06-12 — https://overview.legal/posts/92035*

### Obligations of providers of high-risk AI systems

*Source: AI Act, aiact-art-16-en, 2024-06-12 — https://overview.legal/posts/92242*

Providers of high-risk AI systems shall:

### Authorised representatives of providers of high-risk AI systems

*Source: AI Act, aiact-art-22-en, 2024-06-12 — https://overview.legal/posts/92312*

### Amendments to Annex III

*Source: AI Act, aiact-art-7-en, 2024-06-12 — https://overview.legal/posts/92063*

## Guidance

### Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework

*Source: EDPB, statement-32024-on-data-protection-authorities-role-in-the-en, 2024-07-16 — https://overview.legal/posts/125732 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-32024-on-data-protection-authorities-role-in-the_en*

Final 1 Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework Adopted on 16 July 2024 The European Data Protection Board has adopted the following statement: 1 BACKGROUND AND PURPO SE OF THIS STATEMENT 1. On 12 July 2024, Regulation (EU) 2024/1689 laying down harmonised rules on a rtificial i ntelligence (Artificial Intelligence Act, hereinafter the “ AI Act ”) and amending certain Union Legislative Acts was published in the Official Journal 1 . 2.…

### Statement on the Digital Services Package and Data Strategy

*Source: EDPB, statement-on-the-digital-services-package-and-data-en, 2021-11-18 — https://overview.legal/posts/125982 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-on-the-digital-services-package-and-data_en*

1 Adopted Statement on the D igital Services Package and Data Strategy Adopted on 18 November 2021 The European Data Protection Board has adopted the following statement: Since November 2020 , the European Commission has presented several legislative proposals as part of its digital and data strategies, most notably the Digital Services Act (DSA), the Digital Markets Act (DMA), the Data Governance Act (DGA) and the Regulation on a European appr oach for A rtificial I ntelligence (AIR). A fifth…

## Recent developments

### A call to EU legislators: protect rights and reject the call to delete transparency safeguard in AI Act

*Source: Access Now, 2026-02-10 — https://overview.legal/posts/52552 — original: https://www.accessnow.org/press-release/a-call-to-eu-legislators-protect-transparency-safeguard-in-ai-act/*

We, the undersigned organisations and individuals, urge you in the strongest possible terms to reject the deletion of the Article 49(2) transparency safeguard for high-risk AI systems that is proposed in the AI Omnibus. This transparency safeguard ensures that providers of AI systems cannot circumvent the core obligations of the AI Act.

### The AI Act isn&#8217;t enough: closing the dangerous loopholes that enable rights violations

*Source: European Digital Rights, 2025-11-13 — https://overview.legal/posts/49203 — original: https://edri.org/our-work/the-ai-act-isnt-enough-closing-the-dangerous-loopholes-that-enable-rights-violations/*

While the EU's AI Act aims to regulate high-risk AI systems, it is undermined by major loopholes that allow their unchecked use in the context of national security and law enforcement. These exemptions risk enabling, among others, mass surveillance of protests and discriminatory migration practices. To prevent this, EDRi affiliate Danes je nov dan has published recommendations for Slovenia to adopt stricter national safeguards and transparent oversight mechanisms. The post The AI Act isn&#8217;t

### The AI law is not sufficient: we must address the dangerous loopholes that enable abuse and violate people's rights.

*Source: European Digital Rights, 2025-11-13 — https://overview.legal/posts/52095*

While the EU's AI legislation aims to regulate high-risk AI systems, it is undermined by significant exceptions that allow for their uncontrolled application in the context of national security and law enforcement. These exceptions risk, among other things, enabling mass surveillance of protests and discriminatory migration practices. To prevent this, the EDRi partner Danes je nov has published recommendations for Slovenia to implement stricter national safeguards and transparent oversight mechanisms. The post "The AI legislation is not..."

## Literature

### Artificial Intelligence in Decision-making: A Test of Consistency between the “EU AI Act” and the “General Data Protection Regulation”

*Source: Athens Journal of Law, 2025-01-02 — https://overview.legal/posts/132443 — original: https://doi.org/10.30958/ajl.11-1-3*

The recent Regulation that sets down harmonised rules on Artificial Intelligence in the European Union, known as the "AI Act," includes a significant requirement for human oversight in high-risk AI systems during their use (art. 14). This requirement embodies the "human-in-command" approach, ensuring both legal and ethical compliance. The AI Act is intended to complement the General Data Protection Regulation (hereinafter GDPR), thereby forming a consistent and comprehensive legal framework. Thi

### The Classification of High-Risk AI Systems Under the EU Artificial Intelligence Act

*Source: Journal of AI Law and Regulation, 2024-01-01 — https://overview.legal/posts/132436 — original: https://doi.org/10.21552/aire/2024/3/4*

### REGULATION OF APPLIED ARTIFICIAL INTELLIGENCE IN BIOMEDICAL ENGINEERING AS A HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM IN THE EU AI ACT

*Source: AFMN Biomedicine, 2026-07-13 — https://overview.legal/posts/132435 — original: https://doi.org/10.65641/afmnai-2026-075*

lt;p style= quot;text-align: justify; quot; gt; lt;span class= quot;a_GcMg font-feature-liga-off font-feature-clig-off font-feature-calt-off text-decoration-none text-strikethrough-none quot; gt;Artificial intelligence (AI) represents a global phenomenon changing all spheres of human life. Biomedical engineering is no exception, as many AI systems are applied to biomedical engineering inventions. The European Union has enacted the new EU AI Act, one of the world amp;rsquo;s first laws on AI. The

### AI data governance – overlaps between the AI Act and the GDPR

*Source: Law Innovation and Technology, 2026-01-02 — https://overview.legal/posts/53845 — original: https://doi.org/10.1080/17579961.2026.2633677*

This article examines the overlaps between the AI Act and the GDPR, analysing their overall relationship, conceptual similarities and differences, as well as specific provisions in the AI Act that explicitly overlap with the GDPR. The primary focus of this article lies on AI data governance, with a detailed analysis of the requirements set out in Article 10 AI Act. This provision establishes quality criteria for data and data governance in high-risk AI systems that rely on training AI models wit

### Regulating Algorithm-Based Contracts: How the Eu Artificial Intelligence Act Is Reshaping Risk Allocation in International B2b Transactions

*Source: American Journal Of Social Sciences And Humanity Research, 2026-06-22 — https://overview.legal/posts/132566 — original: https://doi.org/10.37547/ajsshr/volume06issue06-20*

This article examines how the EU Artificial Intelligence Act (the “EU AI Act”) transforms the allocation of risk in cross-border B2B contracts built on algorithmic and automated decision-making systems. Drawing on doctrinal and comparative legal analysis of the EU AI Act, related EU instruments - the Model Contractual Clauses for AI Procurement and initiatives of the European Law Institute - and UNCITRAL’s Model Law on Automated Contracting, the study shows that before the EU AI Act, risk distri

## Related topics

- **High-Risk AI Classification** — https://overview.legal/topics/high-risk-ai-classification
  The content specifically addresses classification rules for high-risk AI systems under the AI Act, which is a distinct regulatory concept requiring its own dedi
- **AI Risk Assessment** — https://overview.legal/topics/ai-risk-assessment
  The AI Act employs a risk-based regulatory approach to determine which practices are prohibited, requiring assessment and classification of AI system risks, whi
- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection
- **AI Value Chain Actors and Roles** — https://overview.legal/topics/ai-value-chain-actors
  The content focuses on responsibilities distributed across different actors in the AI value chain. A dedicated topic for understanding the various actors, their
- **Provider Obligations for AI Systems** — https://overview.legal/topics/provider-obligations-ai
  The content specifically addresses obligations imposed on providers of high-risk AI systems, which is a distinct and important category of requirements that des
- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals

---
Generated by overview.legal · https://overview.legal/topics/annex-iii-amendments · 2026-08-22
