Annex III High-Risk AI: Plain-English Checklist
Determine if your AI system falls under Annex III high-risk categories and see exactly what compliance steps are required under the EU AI Act.
2026 classification and deadline update
A system listed in Annex III is not automatically high-risk in every case. Article 6(3) provides a narrow exception when the system does not pose a significant risk to health, safety or fundamental rights; systems that profile people remain high-risk. Following the EU's 2026 political agreement, Annex III high-risk obligations are due to apply by 2 December 2027.
Check the official regulation and the European Commission high-risk guidance. This checklist is practical guidance, not a legal determination.
What counts as high-risk (quick table of areas)
AI systems for recruitment, screening, ranking, interviewing, or evaluating candidates.
AI systems for creditworthiness assessment, insurance decisions, or financial risk evaluation.
AI systems for grading, admissions, or determining access to educational institutions.
Some medical-device AI can be high-risk under Article 6(1) when it is a safety component or regulated product requiring third-party conformity assessment; healthcare use alone does not make a system Annex III.
AI systems for migration control, border management, or asylum assessments.
AI systems for crime prevention, investigation, detection, or prosecution.
AI systems for energy grid management, transportation networks, or utility operations.
AI systems for access to essential private and public services.
Note on Biometrics
The Act prohibits specific biometric practices subject to defined exceptions and treats other biometric uses as high-risk. Check the exact intended purpose and Article 5 conditions rather than assuming every biometric system is banned.
Decision steps
Describe your AI's purpose and users
Clearly define what your AI system does and who it affects. Be specific about the use case and target users.
Map against the Annex III categories
Compare your AI system against the high-risk categories listed above. Check if it falls into any of these areas.
Test the Annex III match and Article 6(3) exception
If the intended purpose matches Annex III, document whether the narrow Article 6(3) exception could apply. Profiling systems remain high-risk. If Annex III does not apply, still check prohibited practices, product-safety high-risk rules and transparency duties.
Run the 60-second scan to confirm and get tasks
Use our free scanner to get a provisional risk classification and specific action items for your AI system.
Checklist (if you're high-risk)
Risk Management System (RMS)
Identify hazards/harms, implement mitigation strategies, and establish testing procedures.
Data governance
Ensure representative, relevant, and documented datasets with bias testing procedures.
Technical documentation
Create comprehensive documentation covering architecture, training data, evaluation methods, and controls.
Human oversight
Define who can intervene and how override mechanisms work in practice.
Accuracy/robustness/security
Establish targets, implement tests, and maintain comprehensive logs.
Logging
Implement comprehensive logging systems to track AI system operations and decisions.
Post-market monitoring
Monitor for incidents, collect feedback, and implement corrective actions.
Incident reporting
Establish procedures for reporting serious incidents to authorities.
Conformity assessment & CE marking (if you're the provider)
Conduct conformity assessment and apply CE marking before placing high-risk AI on the market.
Ready to check your AI risk level?
Run our free 60-second scan to get a provisional risk classification and specific action items for your AI system.