Skip to content
Topic Developing

Annex III Classification Changes and Updates

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

The content specifically addresses amendments to Annex III, which represents a distinct regulatory mechanism for updating high-risk AI system classifications. This topic would capture the procedural and substantive aspects of how Annex III is modified over time.

7 linked items 7 Laws

Overview

4 sources · Sep 8, 2026

Legal Framework

Annex III — the catalog of stand-alone high-risk AI systems under Article 6(2) — is not static. Article 7 vests the European Commission with delegated authority to add or modify use-cases by delegated act. Two cumulative conditions govern any amendment: the AI systems are intended for use in an area already listed in Annex III, and their risk profile must be at least equivalent to those already listed.

"The Commission is empowered to adopt delegated acts in accordance with Article 97 to amend Annex III by adding or modifying use-cases of high-risk AI systems where both of the following conditions are fulfilled:"
— AI Act Art. 7(1)

The equivalence threshold is the substantive gate:

"the AI systems pose a risk of harm to health and safety, or an adverse impact on fundamental rights, and that risk is equivalent to, or greater than, the risk of harm or of adverse impact posed by the high-risk AI systems already referred to in Annex III."
— AI Act Art. 7(1)(b)

Article 7(2) then enumerates six assessment criteria — intended purpose, extent of deployment, data volume and special-category processing, autonomy and human override, documented harm, and potential intensity of harm. Article 6(3) operates as a counter-derogation: even a listed use-case escapes high-risk status where it does not pose significant harm or does not materially influence decisions.

Key Developments

No delegated acts amending Annex III have been adopted, and no CJEU or national court rulings construe Article 7's equivalence test. Enforcement practice is nascent. Practical thresholds must therefore be derived from the literal criteria in Article 7(2): documented harm reports, autonomy, and special-category data processing weigh most heavily toward reclassification. Until the Commission exercises its delegated power, providers should treat the current Annex III list as a floor, not a ceiling.

Status of the Debate

This is a developing area with no dominant doctrinal pattern yet. The Commission has not adopted amending delegated acts, and no court has interpreted the equivalence threshold in Article 7(1)(b). The debate will crystallize once the first delegated act is published and, in due course, challenged — likely before the General Court on whether the Article 7(2) criteria were adequately reasoned. The open question is whether the Commission will expand Annex III through sectoral additions or cross-sectoral harm-equivalence arguments.

Practical Guidance

  • Map intended uses against Annex III areas; treat any borderline use-case as potentially reclassifiable.
  • Maintain a live risk dossier aligned with the Article 7(2) criteria — autonomy, human override, special-category data, and documented harm.
  • Monitor the delegated acts register: an amendment triggers updated technical documentation under Article 11 and may change the conformity assessment route under Article 43.
  • Invoke the Article 6(3) derogation with care — it requires demonstrable narrow procedural scope or non-material influence on outcomes.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section