Annex III High-Risk AI: Plain-English Checklist

Determine if your AI system falls under Annex III high-risk categories and see exactly what compliance steps are required under the EU AI Act.

2026 classification and deadline update

A system listed in Annex III is not automatically high-risk in every case. Article 6(3) provides a narrow exception when the system does not pose a significant risk to health, safety or fundamental rights; systems that profile people remain high-risk. Following the EU's 2026 political agreement, Annex III high-risk obligations are due to apply by 2 December 2027.

Check the official regulation and the European Commission high-risk guidance. This checklist is practical guidance, not a legal determination.

What counts as high-risk (quick table of areas)

Employment/HR

AI systems for recruitment, screening, ranking, interviewing, or evaluating candidates.

Credit/Finance

AI systems for creditworthiness assessment, insurance decisions, or financial risk evaluation.

Education

AI systems for grading, admissions, or determining access to educational institutions.

Healthcare

Some medical-device AI can be high-risk under Article 6(1) when it is a safety component or regulated product requiring third-party conformity assessment; healthcare use alone does not make a system Annex III.

Migration & Border

AI systems for migration control, border management, or asylum assessments.

Law Enforcement

AI systems for crime prevention, investigation, detection, or prosecution.

Critical Infrastructure

AI systems for energy grid management, transportation networks, or utility operations.

Essential Services

AI systems for access to essential private and public services.

Note on Biometrics

The Act prohibits specific biometric practices subject to defined exceptions and treats other biometric uses as high-risk. Check the exact intended purpose and Article 5 conditions rather than assuming every biometric system is banned.

Decision steps

1

Describe your AI's purpose and users

Clearly define what your AI system does and who it affects. Be specific about the use case and target users.

2

Map against the Annex III categories

Compare your AI system against the high-risk categories listed above. Check if it falls into any of these areas.

3

Test the Annex III match and Article 6(3) exception

If the intended purpose matches Annex III, document whether the narrow Article 6(3) exception could apply. Profiling systems remain high-risk. If Annex III does not apply, still check prohibited practices, product-safety high-risk rules and transparency duties.

4

Run the 60-second scan to confirm and get tasks

Use our free scanner to get a provisional risk classification and specific action items for your AI system.

Checklist (if you're high-risk)

Risk Management System (RMS)

Identify hazards/harms, implement mitigation strategies, and establish testing procedures.

Data governance

Ensure representative, relevant, and documented datasets with bias testing procedures.

Technical documentation

Create comprehensive documentation covering architecture, training data, evaluation methods, and controls.

Human oversight

Define who can intervene and how override mechanisms work in practice.

Accuracy/robustness/security

Establish targets, implement tests, and maintain comprehensive logs.

Logging

Implement comprehensive logging systems to track AI system operations and decisions.

Post-market monitoring

Monitor for incidents, collect feedback, and implement corrective actions.

Incident reporting

Establish procedures for reporting serious incidents to authorities.

Conformity assessment & CE marking (if you're the provider)

Conduct conformity assessment and apply CE marking before placing high-risk AI on the market.

Ready to check your AI risk level?

Run our free 60-second scan to get a provisional risk classification and specific action items for your AI system.