High-risk (Annex III use case) — EU AI Act
Stand-alone AI whose use case matches one of the eight Annex III domains AND performs a listed function (Article 6(2)). Full high-risk obligation set.
Which use cases are high-risk (Annex III)
A system is high-risk under Article 6(2) if its use case matches one of these eight domains and it performs a listed function:
- Biometrics — Remote biometric identification, biometric categorisation according to sensitive/protected attributes, and…
- Critical infrastructure — AI used as a safety component in the management and operation of critical digital infrastructure, road…
- Education & vocational training — AI determining access or admission, evaluating learning outcomes, assessing the appropriate level of…
- Employment & worker management — AI for recruitment or selection (targeting, screening, evaluating candidates), and for decisions on terms,…
- Access to essential services — AI evaluating eligibility for public assistance benefits, creditworthiness / credit scoring, risk assessment…
- Law enforcement — AI used by or for law-enforcement authorities for individual risk assessment, as polygraphs, to evaluate…
- Migration, asylum & border control — AI as polygraphs, for risk assessment (security, irregular migration, health), to examine applications for…
- Justice & democratic processes — AI intended to assist a judicial authority in researching and interpreting facts and the law and applying it,…
Obligations in this category
- Declare accuracy metrics in instructions for use — Provider, from 2027-12-02
- Evidence robustness / resilience — Provider, from 2027-12-02
- Evidence AI-specific cybersecurity — Provider, from 2027-12-02
- Run a lifecycle risk-management system — Provider, from 2027-12-02
- Govern training, validation and test data — Provider, from 2027-12-02
- Assign human oversight and use per instructions (deployer) — Deployer, from 2027-12-02
- Draw up & maintain the Annex IV technical file — Provider, from 2027-12-02
- Classify the system against Article 6 / Annex III — Provider, Deployer, from 2027-12-02
- Register in the EU database — Provider, Deployer, from 2027-12-02
- Complete conformity assessment before market — Provider, from 2027-12-02
Legal source
Stay audit-ready as the Act changes
EU AI Regulation Decoded tracks each obligation and the evidence auditors expect — one practitioner email a week.
Subscribe — free, weeklyNot legal advice. This is a practitioner reference generated from a cited knowledge base built on the primary legal text and official Commission guidance. Verify against the cited primary sources before relying on it for a compliance decision. See editorial standards & methodology.