AI Governance, Risk & Red Teaming
Aware · M2 · lesson 2 of 18 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Annex III in Plain English - The Eight High-Risk Categories
📖
now learning

Annex III in Plain English - The Eight High-Risk Categories

15 min

Annex III is eight pages of EU regulation that determine the next three years of a hundred billion dollars of enterprise AI compliance spend. Read it badly and you over-tier a marketing analytics tool into a full Annex IV technical file project. Read it well and you find the credit-scoring model the data science team built last quarter that everybody forgot is now Annex III §5(b). This lesson is the slow walk through all eight categories: what they actually cover, what they explicitly exclude, where the deployer-side traps live, and how to map a real Fortune-500 portfolio against them in an afternoon. The stand-alone Annex III applicability date moved to Dec 2, 2027 under Omnibus VII. The intake form, the FRIA capability, the notified-body relationship, the model-card backlog, and the inventory all need to be operational well before that date.

The Structure of Annex III - Eight Categories, Many Sub-Categories, One Pattern

Annex III is organized into eight numbered categories. Each category has one or more sub-categories that name specific use cases. The pattern across all eight: the category names the domain; the sub-categories name the functional uses within that domain. A system falls into Annex III by matching a specific sub-category, not by merely operating in the domain. A bank's customer-service chatbot is not Annex III §5(b) just because the bank deploys it, only a system that scores creditworthiness is. A school's IT helpdesk AI is not Annex III §3 just because the school deploys it, only a system that determines admission or evaluates learning outcomes is. The deployer-side discipline is to read the sub-category text against the actual function, not the deployer's industry.

The eight categories with their broad domain framing:

  1. §1 Biometrics: Remote biometric identification, non-prohibited biometric categorization, non-prohibited emotion recognition.
  2. §2 Critical infrastructure: Safety components in management and operation of critical digital infrastructure, road traffic, water, gas, heating, electricity.
  3. §3 Education and vocational training: Access/admission, learning-outcome evaluation, level-of-education assessment, proctoring during tests.
  4. §4 Employment, workers' management, access to self-employment: Recruitment, candidate selection, promotion/termination, task allocation, performance and behavior monitoring.
  5. §5 Essential private and public services, Five sub-categories: §5(a) public-assistance benefits; §5(b) creditworthiness scoring; §5(c) life/health insurance pricing; §5(d) emergency dispatching; §5(e) other public services.
  6. §6 Law enforcement: Risk assessment, polygraph-like tools, evidence-reliability evaluation, predictive policing based on profiling, profiling in investigation.
  7. §7 Migration, asylum, border control: Polygraph-like tools, risk assessment of entrants, application examination assistance, identification.
  8. §8 Administration of justice and democratic processes, Judicial decision support, election-outcome influencing (with administrative/logistical carve-out).

The Article 6(3) carve-out narrows the high-risk tier within Annex III when a system performs only a narrow procedural task, only improves the result of a previously completed human activity, only detects patterns without replacing human assessment, or only performs preparatory tasks. The carve-out collapses on profiling. For most enterprise-deployed Annex III systems, profiling is unavoidable, so the carve-out is theoretical.

§1 Biometrics - The Border Between High-Risk and Article 5 Prohibition

Annex III §1 covers three sub-categories that all sit close to the Article 5 prohibitions but do not cross into them:

  • Remote biometric identification systems, Excludes the Article 5(1)(h) real-time remote biometric identification in publicly accessible spaces for law-enforcement use. Includes everything else: post-event remote biometric ID; remote biometric ID for non-law-enforcement uses (facility access, border control by non-LE agencies, time-and-attendance, age verification at scale).
  • Biometric categorization systems based on sensitive or protected attributes: Article 5(1)(g) prohibits biometric categorization that deduces race, political opinion, trade-union membership, religious or philosophical beliefs, sex life, or sexual orientation. Annex III §1 covers categorization that uses biometric data but does not deduce protected attributes: for example, age-band classification, gender classification at coarse resolution for demographic-reporting purposes (with separate GDPR overlay).
  • Emotion-recognition systems outside the workplace/education prohibition, Article 5(1)(f) prohibits emotion recognition in workplaces and educational institutions with narrow medical/safety carve-outs. Annex III §1 covers emotion-recognition in other contexts: customer-experience analytics in retail, healthcare-adjacent emotion analysis with proper consent, automotive driver-state monitoring, content-moderation tooling.

The deployer-side traps in §1 are the lines between Annex III and Article 5. A retail-analytics camera classifying age-band is Annex III §1, unless it also infers race or sexual orientation, in which case it crosses into Article 5(1)(g) prohibition. A customer-service voice-agent inferring caller mood is Annex III §1, unless it is applied to employee calls, in which case it crosses into Article 5(1)(f) workplace prohibition. The tiering memo for §1 systems should make the Article 5 negative-assurance attestation explicit, because the line is narrow.

§1 systems also typically require notified-body assessment under Annex VII Module H, not internal control under Annex VI. Most Annex III categories allow internal control; §1 biometric ID is the principal exception. This drives a longer conformity-assessment timeline and a more material cost for §1 systems compared to other Annex III categories.

§2 Critical Infrastructure - Safety Components in Essential Services

Annex III §2 covers AI systems intended to be used as safety components in the management and operation of critical infrastructure:

  • Critical digital infrastructure (data centers, network operations, internet exchange points).
  • Road traffic (traffic signal optimization, intelligent transport systems, smart-city traffic management).
  • Supply of water, gas, heating, electricity (load balancing, control loops, demand forecasting in operational closed loops).

The phrase safety component is doing the work. Annex III §2 captures AI that, if it fails, could cause physical harm to people or property or could disrupt the essential service. A demand-forecasting model used for budgeting purposes is not a safety component. A real-time control loop that throttles a grid load to prevent blackouts is. The deployer-side discipline is to read the operational role, not the data-flow diagram.

§2 systems sit at the intersection of the AI Act and the NIS 2 Directive (network and information security). Critical-infrastructure operators are already subject to NIS 2 cybersecurity requirements; the AI Act overlay adds Article 9 risk-management-system, Article 14 human oversight, and Article 15 robustness/cybersecurity claims specific to the AI component. The NIS 2 + AI Act integrated compliance posture is a 2026-2027 build for operators in the sector.

The 2026 NIST AI RMF Critical Infrastructure Profile concept note (April 7, 2026) is the U.S. analog. Operators with cross-Atlantic footprint will read NIST CI Profile and EU AI Act §2 against each other to produce a single risk-management artifact.

§3 Education and Vocational Training - The Quietly Large Category

Annex III §3 covers four sub-categories of AI in education:

  • Access or admission to educational institutions at all levels: university admission scoring, K-12 admission ranking, vocational training enrollment decisions.
  • Evaluation of learning outcomes: automated essay scoring, automated test grading, language-proficiency assessment tools.
  • Assessment of the appropriate level of education: placement tests, adaptive-learning placement engines, gifted-and-talented identification tools.
  • Detection of prohibited behavior during tests: proctoring tools (face-direction monitoring, audio analysis, browser activity monitoring, screen-share analysis).

The proctoring sub-category is the one that catches the most enterprise programs off-guard. Certification testing vendors (Pearson VUE, Prometric, ProctorU), corporate learning platforms with assessment functions, and any tool used to monitor candidate behavior during a high-stakes exam falls within §3. The Article 6(3) carve-out is unavailable for proctoring because the tool performs behavioral profiling.

Education systems also have a strong overlap with §4 employment where the tool is used in a hybrid context, for example, a corporate-learning platform that determines internal-promotion eligibility based on course-completion scores. The dominant classification often becomes §4 employment in those cases.

§4 Employment, Workers' Management, Access to Self-Employment - The Biggest Enterprise Category

Annex III §4 is the category where most Fortune-500 enterprises will find the bulk of their high-risk inventory. The sub-categories:

  • Recruitment or selection of natural persons: resume screening, candidate ranking, interview analysis, skills assessment, video-interview emotion or sentiment analysis, sourcing tools.
  • Decisions affecting terms of work-related relationships, promotion, or termination: promotion-recommendation engines, attrition-risk scoring, automated termination workflows.
  • Allocation of tasks based on individual behavior or personal traits: task-assignment algorithms in gig-work platforms, schedule optimization that considers individual preferences or traits, sales-territory assignment AI.
  • Monitoring and evaluation of performance and behavior: productivity-scoring tools, sales-call sentiment analysis, employee-engagement-measurement tools (with Article 5(1)(f) prohibition for workplace emotion recognition still controlling).

The deployer-side trap in §4: every HR-tech vendor in the market is selling into this category. Workday, Eightfold, Beamery, Phenom, Paradox, HiredScore, Greenhouse, Lever, Ashby, Gem, the list runs to hundreds of vendors. Most will argue they are not "AI" or that they are not "high-risk." Most are wrong. The provenance test from Article 3(1) and the sub-category text from §4 control. A vendor's marketing claim does not.

The U.S. overlay is substantial for §4 systems:

  • NYC Local Law 144 AEDT: annual independent bias audit, 10-business-day candidate notice, public bias-audit summary, alternative-assessment offer, four-fifths-rule analysis. Post-Comptroller-audit enforcement (Dec 2025) signals more rigorous DCWP enforcement in 2026.
  • Texas TRAIGA HB 149: effective Jan 1, 2026, intent-based discrimination prohibition (disparate impact alone insufficient), AG-only enforcement, $10K-$200K per-violation civil penalty, $2K-$40K per-day continuing violation penalty.
  • Colorado AI Act SB 24-205: federal court stay (Apr 27, 2026), SB 189 replacement passed May 7-9, 2026 (notice-and-transparency framework, effective Jan 1, 2027 if signed by Governor Polis, enforcement contingent on AG rulemaking).
  • EEOC AI guidance, Title VII disparate impact framework applies to AI-driven employment decisions.
  • FTC Section 5, unfair or deceptive AI practices in hiring tools sold across state lines.

A multinational deploying an HR resume-ranker into the EU + NYC + Texas + California must reconcile EU AI Act Annex III §4 + NYC LL 144 + Texas TRAIGA + EEOC + FTC + state-specific overlays into a single Article 27 FRIA + multi-state bias-audit + candidate-notice program. The §4 program is the operational center of gravity for L3 and L4 work.

§5 Essential Private and Public Services - The Five Sub-Categories

Annex III §5 covers essential services that affect individuals' basic welfare. The five sub-categories:

  • §5(a) Public-assistance benefits and services: eligibility decisions, benefit-amount calculations, application-routing for public-assistance programs.
  • §5(b) Creditworthiness scoring and credit-score evaluation: loan-decisioning models, credit-card-approval algorithms, mortgage-risk scoring. Carve-out for fraud-detection use only (no creditworthiness flow-through).
  • §5(c) Life and health insurance risk assessment and pricing: underwriting AI for life insurance, health-insurance pricing models, claims-adjudication AI in life/health lines.
  • §5(d) Dispatching or prioritizing emergency-response services: 911 / 999 / 112 dispatch optimization, ambulance routing, emergency triage AI.
  • §5(e) Public services such as access to those services: citizen-service portals with AI routing or eligibility check, public-housing application AI, naturalization-assistance AI.

The critical 2026 detail: Article 27 FRIA applies to deployers of §5(b) creditworthiness and §5(c) life/health insurance systems regardless of public-body status. This means private-sector banks deploying credit-scoring AI and private-sector insurers deploying pricing AI carry FRIA obligations on the Aug 2, 2026 track regardless of the stand-alone Annex III date slip under Omnibus VII. The FRIA capability for §5(b)/§5(c) deployers must be operational by Aug 2, 2026; the FRIA artifacts for individual systems should be in the backlog.

The Article 86 right-to-explanation overlay also applies to §5(b) credit-scoring decisions in particular. Individuals subject to automated credit-scoring decisions have a right to an explanation of the decision's main parameters and the role the AI system played. Building the explanation pathway is a non-trivial engineering effort and should be sequenced into the 2026 FRIA work.

§6 Law Enforcement - Tight Constraints, National Variation

Annex III §6 covers AI used by or on behalf of law-enforcement authorities. The qualifier "by or on behalf of" is important, a private vendor's AI does not fall under §6 unless it is deployed by an LE agency or by a private contractor acting on behalf of LE. The sub-categories:

  • Risk assessment of natural persons: Becoming a victim of crime, becoming a perpetrator of crime, recidivism risk scoring.
  • Polygraph or similar tools, Lie-detection AI in interrogation contexts.
  • Evaluation of the reliability of evidence, Forensic AI for evidence reliability, witness-statement consistency analysis.
  • Prediction of occurrence or recurrence of criminal offense based on profiling, Predictive policing systems (with Article 5(1)(d) prohibition for predictive policing based solely on profiling or assessment of personality traits; §6 covers more nuanced predictive use cases that combine multiple data sources).
  • Profiling of natural persons in detection, investigation, or prosecution, Pattern-detection AI used during active criminal investigations.

National implementing law is heavy for §6 systems. Many Member States have additional national rules on police AI use that supplement the AI Act baseline. France, Germany, the Netherlands, and the Nordics have particularly developed national frameworks. Enterprise vendors selling §6 systems must navigate the AI Act baseline plus the Member State overlay.

§7 Migration, Asylum, Border Control - Government Contract Focus

Annex III §7 covers AI used by or on behalf of migration, asylum, and border-control authorities. The sub-categories:

  • Polygraph or similar tools in migration contexts.
  • Risk assessment of natural persons entering territory: irregular migration risk, public-safety risk, public-health risk assessment.
  • Assistance with examining applications for asylum, visa, residence permit: application-routing, credibility-scoring, supporting-evidence-reliability evaluation.
  • Detection, recognition, identification of natural persons in the migration context, non-prohibited biometric identification at borders, document-authenticity AI.

The deployer base is dominated by government and contractor-to-government. Private-sector exposure is limited unless the company is a government contractor. Where it does apply, the conformity-assessment work is among the most rigorous in the AI Act because of the fundamental-rights stakes.

§8 Administration of Justice and Democratic Processes - Narrow but Sensitive

Annex III §8 covers two sub-categories:

  • AI used to assist a judicial authority in researching and interpreting facts and the law and applying the law to a concrete set of facts: judicial-decision-support AI, sentencing-recommendation AI, case-management AI used in adjudication.
  • AI used in influencing the outcome of an election or referendum or the voting behavior of natural persons: with a carve-out for tools that organize, optimize, or structure political campaigns from an administrative or logistical perspective.

The carve-out for administrative/logistical campaign tools matters. A campaign-management platform that routes volunteer assignments, tracks fundraising, or manages canvassing logistics is carved out. A platform that performs micro-targeted persuasion based on inferred psychographic profiles is not, the latter is §8 high-risk and may also raise Article 5(1)(a) manipulation concerns.

Private-sector exposure to §8 is limited to political-tech vendors and to legal-tech vendors that sell into judicial workflows. Most enterprises will have zero or one §8 row in their inventory.

The Portfolio Mapping Exercise - Building the Annex III Row Set

The L1 artifact for this lesson is an Annex III mapping: a per-system row that names the system, the deployment surface, the Annex III sub-category that applies (or "none: not Annex III"), the Article 6(3) carve-out analysis, the Article 27 FRIA applicability, the U.S. state-law overlay, the conformity-assessment route (internal control under Annex VI or notified body under Annex VII), and the post-Omnibus-VII applicability date.

A representative mapping for a Fortune-500 portfolio might look like:

  • Workday Talent Acquisition AI - Annex III §4 employment; FRIA on Dec 2, 2027 (private-sector deployer); NYC LL 144 + Texas TRAIGA + Title VII overlays; Annex VI internal control; Dec 2, 2027.
  • In-house XGBoost credit decisioning at regulated bank: Annex III §5(b); FRIA on Aug 2, 2026 (§5(b) on Aug 2, 2026 track); Article 86 right to explanation; SR 11-7 model risk overlay; Annex VI internal control; Dec 2, 2027.
  • Life-insurance underwriting AI at private insurer: Annex III §5(c); FRIA on Aug 2, 2026; state-insurance regulation overlay; Annex VI internal control; Dec 2, 2027.
  • Education proctoring tool used in customer certification program: Annex III §3 (proctoring sub-category); FRIA on Dec 2, 2027; Annex VI internal control; Dec 2, 2027.
  • Grid-load-balancing AI at regional utility, Annex III §2 (electricity supply safety component); NIS 2 overlay; Annex VI internal control; Dec 2, 2027. (May also be Annex I if the safety component is integrated with a CE-marked product, separate Annex I analysis.)
  • Facility biometric-ID system at office buildings: Annex III §1 (remote biometric ID, non-LE use); GDPR Article 35 DPIA + Article 27 FRIA combined; Annex VII Module H notified-body; Dec 2, 2027.
  • Adobe Firefly used for marketing creative, NOT Annex III; Article 50(2) marking and Article 50(4) deepfake disclosure trigger; Dec 2, 2026.
  • Internal Microsoft 365 Copilot deployment, NOT Annex III; Article 26 deployer obligations; Article 4 literacy.
  • Naive Bayes spam filter (legacy), NOT Annex III; minimal-risk; Article 4 literacy for operators; legacy carve-out preserved if no substantial modification.
  • K-means marketing segmentation, NOT Annex III (unless used to deduce protected attributes); minimal-risk; Article 5(1)(g) negative-assurance attestation.

Ten rows, ten classifications, ten distinct FRIA / conformity / U.S.-overlay / Article 50 considerations. The mapping is the artifact that anchors L2 model-card work, L3 conformity-package work, and L4 governance-program reporting.

Common Annex III Mistakes - And How to Catch Them

Mistake 1 - Tiering by Industry Instead of by Function

A bank's customer-service chatbot is not Annex III §5(b) because the bank deploys it. A school's IT helpdesk AI is not Annex III §3 because the school deploys it. The sub-category text controls, not the deployer's industry. Read the function against the sub-category description.

Mistake 2 - Missing the §5(b)/§5(c) FRIA Acceleration

Article 27 FRIA capability for §5(b) creditworthiness and §5(c) life/health insurance deployers is on the Aug 2, 2026 track regardless of stand-alone Annex III timing. Programs that defer all FRIA work to Dec 2, 2027 will be in violation for these specific deployer categories.

Mistake 3 - Confusing Article 5(1)(f) Workplace Emotion-Recognition Prohibition with Annex III §4 Employment High-Risk

Article 5(1)(f) prohibits emotion recognition in workplaces with narrow medical/safety carve-outs. Annex III §4 covers employment-related high-risk AI more broadly. A tool that uses emotion recognition to evaluate employee performance is both 5(1)(f) prohibited and §4 high-risk, Article 5 takes precedence; the dominant classification is prohibited.

Mistake 4 - Overestimating the Article 6(3) Carve-Out

The narrow-task carve-out collapses on profiling. HR screening profiles. Credit scoring profiles. Insurance pricing profiles. Proctoring profiles. Most Annex III enterprise systems profile by definition; the carve-out is theoretical for them.

Mistake 5 - Skipping the Annex I Overlap for §2 Critical-Infrastructure Systems

An AI safety component integrated into a CE-marked harmonized product (under MDR, Machinery Directive, etc.) falls on the Annex I track, not Annex III. The Annex I track has a different applicability date (Aug 2, 2028 post-Omnibus VII) and integrates with the existing harmonized-product conformity machinery. For §2 systems specifically, the Annex I overlap is common, confirm classification before sequencing the work.

Mistake 6 - Missing the "By or On Behalf of" Qualifier for §6 and §7

Annex III §6 (law enforcement) and §7 (migration) apply to AI used by or on behalf of the relevant authorities. A private-sector vendor's AI is not in §6 or §7 unless deployed by an LE agency or by a contractor acting on behalf of LE/migration authorities. Don't over-tier private-sector AI into §6 or §7.

Key Takeaways

  • Annex III is structured by domain and function. The category names the domain; the sub-categories name the functional uses. Match the sub-category text, not the deployer's industry.
  • Eight categories, with the post-Omnibus VII applicability date of Dec 2, 2027. Biometrics (§1), critical infrastructure (§2), education (§3), employment (§4), essential services (§5), law enforcement (§6), migration (§7), justice and democratic processes (§8).
  • §4 employment is the biggest enterprise category. Every HR-tech vendor sells into it. The U.S. overlay (NYC LL 144, Texas TRAIGA, Colorado SB 24-205/SB 189, EEOC, FTC) is substantial.
  • §5(b) creditworthiness and §5(c) life/health insurance carry Aug 2, 2026 FRIA capability obligations regardless of stand-alone Annex III timing. Programs deferring all FRIA work to Dec 2, 2027 are in violation for these deployer categories.
  • §1 biometrics typically requires notified-body assessment under Annex VII Module H. Other Annex III categories allow internal control under Annex VI. The cost and timeline differ materially.
  • §2 critical-infrastructure systems often overlap with Annex I. Confirm whether the AI safety component is integrated with a CE-marked harmonized product; if yes, the Annex I track applies (Aug 2, 2028 applicability) instead of Annex III.
  • The Article 6(3) carve-out collapses on profiling. Most Annex III enterprise systems profile by definition; the carve-out is theoretical for HR screening, credit scoring, insurance pricing, proctoring.
  • §6 law enforcement and §7 migration apply only to AI used by or on behalf of the relevant authorities. Private-sector vendor AI is not in §6 or §7 unless deployed by LE / migration / asylum / border-control bodies or by contractors acting on their behalf.
  • The Article 86 right-to-explanation overlay applies to §5(b) credit-scoring decisions. Build the explanation pathway as part of the 2026 FRIA work.
  • The portfolio mapping is the L1 artifact. Per-system row with sub-category, FRIA applicability, U.S. overlay, conformity-assessment route, and applicability date. It anchors L2 model-card work, L3 conformity-package work, and L4 governance-program reporting.