Skip to content
Topic Developing

Annex III High-Risk AI Categories

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

The classification rules reference specific categories of high-risk AI systems listed in Annex III, which warrant a dedicated topic to address the enumerated use cases and application domains that trigger high-risk classification.

8 linked items 8 Laws

Overview

4 sources · Jul 15, 2026

Legal Framework

Annex III of the AI Act enumerates specific use-case categories that automatically trigger high-risk classification, including biometric identification and categorisation, critical infrastructure management, education and vocational training, employment and worker management, access to essential services, law enforcement, migration and border control, and administration of justice. These categories sit below the absolute prohibitions in Article 5, which bars practices such as social scoring and manipulative techniques. The distinction matters: a system that crosses from high-risk into prohibited territory faces the most severe sanctions.

The sanctions regime in Article 99 establishes a tiered penalty structure. Prohibited practice violations carry fines up to EUR 35 million or 7% of global annual turnover, while other non-compliance—including breaches of high-risk obligations—caps at EUR 15 million or 3%.

"De sancties moeten doeltreffend, evenredig en afschrikkend zijn."
AI Act Art. 99(1)

Key Developments

The boundary between prohibited and high-risk AI turns on the system's purpose and effect. Article 5(d) prohibits criminal risk assessment based solely on profiling, but risk-prediction tools that incorporate additional factors beyond profiling may fall within Annex III's law enforcement categories rather than facing prohibition.

Biometric categorisation is a core Annex III domain. Recital 16 clarifies its scope:

"assigning natural persons to specific categories on the basis of their biometric data"
AI Act Recital 16

However, purely ancillary biometric features—such as marketplace filters that cannot function independently of a principal service—fall outside the regulation's scope. This ancillary exemption provides a narrow but significant carve-out for e-commerce and social media applications.

Market surveillance under Article 74 delegates enforcement to sectoral authorities for high-risk AI embedded in products covered by Annex I harmonisation legislation, ensuring specialised oversight.

Practical Guidance

  • Map each use case against the Annex III categories first, then verify it does not cross into Article 5 prohibited territory—particularly social scoring, manipulative techniques, and solely profiling-based criminal risk assessment.
  • Assess biometric categorisation features for the ancillary exemption: if the feature cannot technically function without the principal service, document the objective technical dependency to support exclusion from high-risk classification.
  • Prepare for sectoral enforcement: where high-risk AI is embedded in regulated products, identify the relevant Annex I market surveillance authority, as enforcement will follow sectoral lines rather than general AI authority oversight.
  • Budget compliance against the penalty tiers: prohibited-practice exposure (7% of turnover) is more than double the high-risk non-compliance ceiling (3%), making the classification boundary a material risk-management decision.
Everything on this topic, by type links go to the exact provision / paragraph / section