Annex III — High-risk AI systems
Which AI applications count as high-risk? Annex III of the EU AI Act lists eight areas, from biometrics to justice.
What does Annex III cover?
Annex III of Regulation (EU) 2024/1689 (EU AI Act) defines application areas where an AI system may be classified as high-risk. Art. 6 refers to this list. That triggers a much stricter duty set than Art. 50 (transparency/labeling).
For marketing, shop content, or social labeling, Art. 50 is usually the relevant module, not Annex III. High-risk cases more often involve HR screening, credit scoring, medical diagnostics, biometric identification, or critical infrastructure.
Full high-risk obligations (including risk management, technical documentation, CE marking) apply to most Annex III cases from 2 August 2027.
The 8 Annex III areas
- None / unsure. Typical marketing, shop, or content use
- Biometrics & facial recognition (Annex III point 1). Identification, categorization, emotion recognition
- Critical infrastructure (Annex III point 2). Energy, water, transport, digital infrastructure
- Education & training (Annex III point 3). Access, assessment, exam proctoring
- Employment / HR (Annex III point 4). Recruiting, evaluation, promotion, termination
- Essential services (Annex III point 5). Credit scoring, insurance, social benefits
- Law enforcement (Annex III point 6). Risk assessment, evidence, profiling
- Migration & asylum (Annex III point 7). Visa, residence, border control
- Justice & democratic processes (Annex III point 8). Legal assistance, influence on elections
Art. 6 — Classification as high-risk
An AI system is high-risk when used in an Annex III area and meets the conditions of Art. 6 (e.g. impact on individuals or safety-critical contexts).
Conformity assessment, human oversight, and CE marking are central duties. Details depend on the specific deployment.
How this differs from Art. 50 (labeling)
Art. 50 requires visible transparency for published AI content (deepfakes, chatbots, AI text). Often relevant for marketing and e-commerce.
Annex III goes further: systemic risks to fundamental rights, safety, or essential services. Not labeling duties for individual posts or images.
Both can apply in parallel: a shop chatbot may trigger Art. 50; AI-assisted hiring screening may additionally fall under Annex III.
Official sources
Start high-risk screening
In the checker, choose the “High-risk screening” module. Classify your use case and EU market in a few steps.
Start checkAnnex III — FAQ
- Does Annex III apply to every marketing AI tool?
- Usually not. Typical content, shop, or campaign use is mostly outside Annex III. It becomes relevant for HR decisions, scoring, medicine, biometrics, or critical infrastructure.
- When do high-risk duties apply?
- For most Annex III systems from 2 August 2027. Art. 50 transparency starts earlier (2 August 2026).
- Does this overview replace conformity advice?
- No. Orientation guide for classification, not conformity advice. For high-risk deployments, involve a qualified lawyer or certified compliance advisor.
Key dates & fines (overview)
Phased application of the EU AI Act (Regulation (EU) 2024/1689). Not legal advice.
Prohibitions (Art. 5)
Prohibited AI practices. Early application
GPAI rules
Duties for general-purpose AI models
Art. 50 transparency
Label deepfakes, chatbots, AI texts (operators)
High-risk (Annex III)
Conformity assessment, CE marking, etc.
Marking transition
Machine-readable marking. Legacy systems (providers)
Fine orientation (max.)
- Prohibited practices (Art. 5)EUR 35M / 7% turnover
- High-risk / systemic GPAIEUR 15M / 3% turnover
- Transparency (Art. 50)EUR 15M / 3% turnover
- Incorrect informationEUR 7.5M / 1% turnover
As of 2026-07-31 · Regulation (EU) 2024/1689
Orientation based on the EU AI Act (Art. 50). Not legal advice. For borderline cases consult a qualified lawyer. Effective from 02.08.2026 · ai-act-checker.com