# Annex III High-Risk AI Categories — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/annex-iii-high-risk-categories
> Sources are cited per item. Verify against the official texts before relying on them.

The classification rules reference specific categories of high-risk AI systems listed in Annex III, which warrant a dedicated topic to address the enumerated use cases and application domains that trigger high-risk classification.

## Overview

## Legal Framework

Annex III of the AI Act enumerates specific use-case categories that automatically trigger high-risk classification, including biometric identification and categorisation, critical infrastructure management, education and vocational training, employment and worker management, access to essential services, law enforcement, migration and border control, and administration of justice. These categories sit below the absolute prohibitions in [Article 5](/laws/ai-act/art-5), which bars practices such as social scoring and manipulative techniques. The distinction matters: a system that crosses from high-risk into prohibited territory faces the most severe sanctions.

The sanctions regime in [Article 99](/laws/ai-act-nl/art-99) establishes a tiered penalty structure. Prohibited practice violations carry fines up to EUR 35 million or 7% of global annual turnover, while other non-compliance—including breaches of high-risk obligations—caps at EUR 15 million or 3%.

> "De sancties moeten doeltreffend, evenredig en afschrikkend zijn."
> — [AI Act Art. 99(1)](/laws/ai-act-nl/art-99#par-10)

## Key Developments

The boundary between prohibited and high-risk AI turns on the system's purpose and effect. Article 5(d) prohibits criminal risk assessment based solely on profiling, but risk-prediction tools that incorporate additional factors beyond profiling may fall within Annex III's law enforcement categories rather than facing prohibition.

Biometric categorisation is a core Annex III domain. Recital 16 clarifies its scope:

> "assigning natural persons to specific categories on the basis of their biometric data"
> — [AI Act Recital 16](/laws/ai-act/rec-16)

However, purely ancillary biometric features—such as marketplace filters that cannot function independently of a principal service—fall outside the regulation's scope. This ancillary exemption provides a narrow but significant carve-out for e-commerce and social media applications.

Market surveillance under [Article 74](/laws/ai-act-nl/art-74) delegates enforcement to sectoral authorities for high-risk AI embedded in products covered by Annex I harmonisation legislation, ensuring specialised oversight.

## Practical Guidance

- **Map each use case against the Annex III categories first**, then verify it does not cross into Article 5 prohibited territory—particularly social scoring, manipulative techniques, and solely profiling-based criminal risk assessment.
- **Assess biometric categorisation features for the ancillary exemption**: if the feature cannot technically function without the principal service, document the objective technical dependency to support exclusion from high-risk classification.
- **Prepare for sectoral enforcement**: where high-risk AI is embedded in regulated products, identify the relevant Annex I market surveillance authority, as enforcement will follow sectoral lines rather than general AI authority oversight.
- **Budget compliance against the penalty tiers**: prohibited-practice exposure (7% of turnover) is more than double the high-risk non-compliance ceiling (3%), making the classification boundary a material risk-management decision.

## Legislation (full text of key provisions)

### Recital 30 — prohibited biometric categorisation systems

*Source: AI Act, aiact-rec-30-en, 2024-06-12 — https://overview.legal/posts/93742*

Biometric categorisation systems that are based on natural persons’ biometric data, such as an individual person’s face or fingerprint, to deduce or infer an individuals’ political opinions, trade union membership, religious or philosophical beliefs, race, sex life or sexual orientation should be prohibited. That prohibition should not cover the lawful labelling, filtering or categorisation of biometric data sets acquired in line with Union or national law according to biometric data, such as the sorting of images according to hair colour or eye colour, which can for example be used in the area of law enforcement.

### Recital 16 — definition of biometric categorisation

*Source: AI Act, aiact-rec-16-en, 2024-06-12 — https://overview.legal/posts/93714*

The notion of ‘biometric categorisation’ referred to in this Regulation should be defined as assigning natural persons to specific categories on the basis of their biometric data. Such specific categories can relate to aspects such as sex, age, hair colour, eye colour, tattoos, behavioural or personality traits, language, religion, membership of a national minority, sexual or political orientation. This does not include biometric categorisation systems that are a purely ancillary feature intrinsically linked to another commercial service, meaning that the feature cannot, for objective technical reasons, be used without the principal service, and the integration of that feature or functionality is not a means to circumvent the applicability of the rules of this Regulation. For example, filters categorising facial or body features used on online marketplaces could constitute such an ancillary feature as they can be used only in relation to the principal service which consists in selling a product by allowing the consumer to preview the display of the product on him or herself and help the consumer to make a purchase decision. Filters used on online social network services which categorise facial or body features to allow users to add or modify pictures or videos could also be considered to be ancillary feature as such filter cannot be used without the principal service of the social network services consisting in the sharing of content online.

### Recital 96 — fundamental rights impact assessment deployers

*Source: AI Act, aiact-rec-96-en, 2024-06-12 — https://overview.legal/posts/93874*

In order to efficiently ensure that fundamental rights are protected, deployers of high-risk AI systems that are bodies governed by public law, or private entities providing public services and deployers of certain high-risk AI systems listed in an annex to this Regulation, such as banking or insurance entities, should carry out a fundamental rights impact assessment prior to putting it into use. Services important for individuals that are of public nature may also be provided by private entities. Private entities providing such public services are linked to tasks in the public interest such as in the areas of education, healthcare, social services, housing, administration of justice. The aim of the fundamental rights impact assessment is for the deployer to identify the specific risks to the rights of individuals or groups of individuals likely to be affected, identify measures to be taken in the case of a materialisation of those risks. The impact assessment should be performed prior to deploying the high-risk AI system, and should be updated when the deployer considers that any of the relevant factors have changed. The impact assessment should identify the deployer’s relevant processes in which the high-risk AI system will be used in line with its intended purpose, and should include a description of the period of time and frequency in which the system is intended to be used as well as of specific categories of natural persons and groups who are likely to be affected in the specific context of use. The assessment should also include the identification of specific risks of harm likely to have an impact on the fundamental rights of those persons or groups. While performing this assessment, the deployer should take into account information relevant to a proper assessment of the impact, including but not limited to the information given by the provider of the high-risk AI system in the instructions for use. In light of the risks identified, deployers should determine measures to be taken in the case of a materialisation of those risks, including for example governance arrangements in that specific context of use, such as arrangements for human oversight according to the instructions of use or, complaint handling and redress procedures, as they could be instrumental in mitigating risks to fundamental rights in concrete use-cases. After performing that impact assessment, the deployer should notify the relevant market surveillance authority. Where appropriate, to collect relevant information necessary to perform the impact assessment, deployers of high-risk AI system, in particular when AI systems are used in the public sector, could involve relevant stakeholders, including the representatives of groups of persons likely to be affected by the AI system, independent experts, and civil society organisations in conducting such impact assessments and designing measures to be taken in the case of materialisation of the risks. The European Artificial Intelligence Office (AI Office) should develop a template for a questionnaire in order to facilitate compliance and reduce the administrative burden for deployers.

### Recital 159 — biometric AI surveillance authority powers

*Source: AI Act, aiact-rec-159-en, 2024-06-12 — https://overview.legal/posts/94000*

Each market surveillance authority for high-risk AI systems in the area of biometrics, as listed in an annex to this Regulation insofar as those systems are used for the purposes of law enforcement, migration, asylum and border control management, or the administration of justice and democratic processes, should have effective investigative and corrective powers, including at least the power to obtain access to all personal data that are being processed and to all information necessary for the performance of its tasks. The market surveillance authorities should be able to exercise their powers by acting with complete independence. Any limitations of their access to sensitive operational data under this Regulation should be without prejudice to the powers conferred to them by Directive (EU) 2016/680. No exclusion on disclosing data to national data protection authorities under this Regulation should affect the current or future powers of those authorities beyond the scope of this Regulation.

### Recital 40 — Ireland exemption police judicial cooperation

*Source: AI Act, aiact-rec-40-en, 2024-06-12 — https://overview.legal/posts/93762*

In accordance with Article 6a of Protocol No 21 on the position of the United Kingdom and Ireland in respect of the area of freedom, security and justice, as annexed to the TEU and to the TFEU, Ireland is not bound by the rules laid down in Article 5(1), first subparagraph, point (g), to the extent it applies to the use of biometric categorisation systems for activities in the field of police cooperation and judicial cooperation in criminal matters, Article 5(1), first subparagraph, point (d), to the extent it applies to the use of AI systems covered by that provision, Article 5(1), first subparagraph, point (h), Article 5(2) to (6) and Article 26(10) of this Regulation adopted on the basis of Article 16 TFEU which relate to the processing of personal data by the Member States when carrying out activities falling within the scope of Chapter 4 or Chapter 5 of Title V of Part Three of the TFEU, where Ireland is not bound by the rules governing the forms of judicial cooperation in criminal matters or police cooperation which require compliance with the provisions laid down on the basis of Article 16 TFEU.

### Recital 41 — Denmark Protocol No 22 exemption position

*Source: AI Act, aiact-rec-41-en, 2024-06-12 — https://overview.legal/posts/93764*

In accordance with Articles 2 and 2a of Protocol No 22 on the position of Denmark, annexed to the TEU and to the TFEU, Denmark is not bound by rules laid down in Article 5(1), first subparagraph, point (g), to the extent it applies to the use of biometric categorisation systems for activities in the field of police cooperation and judicial cooperation in criminal matters, Article 5(1), first subparagraph, point (d), to the extent it applies to the use of AI systems covered by that provision, Article 5(1), first subparagraph, point (h), (2) to (6) and Article 26(10) of this Regulation adopted on the basis of Article 16 TFEU, or subject to their application, which relate to the processing of personal data by the Member States when carrying out activities falling within the scope of Chapter 4 or Chapter 5 of Title V of Part Three of the TFEU.

### Recital 61 — high-risk AI in justice and democracy

*Source: AI Act, aiact-rec-61-en, 2024-06-12 — https://overview.legal/posts/93804*

Certain AI systems intended for the administration of justice and democratic processes should be classified as high-risk, considering their potentially significant impact on democracy, the rule of law, individual freedoms as well as the right to an effective remedy and to a fair trial. In particular, to address the risks of potential biases, errors and opacity, it is appropriate to qualify as high-risk AI systems intended to be used by a judicial authority or on its behalf to assist judicial authorities in researching and interpreting facts and the law and in applying the law to a concrete set of facts. AI systems intended to be used by alternative dispute resolution bodies for those purposes should also be considered to be high-risk when the outcomes of the alternative dispute resolution proceedings produce legal effects for the parties. The use of AI tools can support the decision-making power of judges or judicial independence, but should not replace it: the final decision-making must remain a human-driven activity. The classification of AI systems as high-risk should not, however, extend to AI systems intended for purely ancillary administrative activities that do not affect the actual administration of justice in individual cases, such as anonymisation or pseudonymisation of judicial decisions, documents or data, communication between personnel, administrative tasks.

### Recital 60 — high-risk AI migration border control

*Source: AI Act, aiact-rec-60-en, 2024-06-12 — https://overview.legal/posts/93802*

AI systems used in migration, asylum and border control management affect persons who are often in particularly vulnerable position and who are dependent on the outcome of the actions of the competent public authorities. The accuracy, non-discriminatory nature and transparency of the AI systems used in those contexts are therefore particularly important to guarantee respect for the fundamental rights of the affected persons, in particular their rights to free movement, non-discrimination, protection of private life and personal data, international protection and good administration. It is therefore appropriate to classify as high-risk, insofar as their use is permitted under relevant Union and national law, AI systems intended to be used by or on behalf of competent public authorities or by Union institutions, bodies, offices or agencies charged with tasks in the fields of migration, asylum and border control management as polygraphs and similar tools, for assessing certain risks posed by natural persons entering the territory of a Member State or applying for visa or asylum, for assisting competent public authorities for the examination, including related assessment of the reliability of evidence, of applications for asylum, visa and residence permits and associated complaints with regard to the objective to establish the eligibility of the natural persons applying for a status, for the purpose of detecting, recognising or identifying natural persons in the context of migration, asylum and border control management, with the exception of verification of travel documents. AI systems in the area of migration, asylum and border control management covered by this Regulation should comply with the relevant procedural requirements set by the Regulation (EC) No 810/2009 of the European Parliament and of the Council (32), the Directive 2013/32/EU of the European Parliament and of the Council (33), and other relevant Union law. The use of AI systems in migration, asylum and border control management should, in no circumstances, be used by Member States or Union institutions, bodies, offices or agencies as a means to circumvent their international obligations under the UN Convention relating to the Status of Refugees done at Geneva on 28 July 1951 as amended by the Protocol of 31 January 1967. Nor should they be used to in any way infringe on the principle of non-refoulement, or to deny safe and effective legal avenues into the territory of the Union, including the right to international protection.

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **High-Risk AI Classification** — https://overview.legal/topics/high-risk-ai-classification
  The content specifically addresses classification rules for high-risk AI systems under the AI Act, which is a distinct regulatory concept requiring its own dedi
- **Biometric Data** — https://overview.legal/topics/biometrie
  Unique physical characteristics used for identification
- **Biometric Data** — https://overview.legal/topics/biometric-data
  Processing of biometric data for identification
- **Types of Special Categories of Personal Data** — https://overview.legal/topics/special-categories-data-types
  A dedicated topic is needed to comprehensively cover the specific types and definitions of special categories of personal data, including racial/ethnic origin, 
- **Annex III Amendments** — https://overview.legal/topics/annex-iii-amendments
  This new topic is needed because amendments to Annex III represent specific regulatory changes to the AI Act's classification framework that warrant dedicated t

---
Generated by overview.legal · https://overview.legal/topics/annex-iii-high-risk-categories · 2026-08-22
