EU AI Act — High-Risk systems (Annex III)

Annex III lists eight categories of AI systems that are high-risk by virtue of their use. High-risk systems have strict obligations on data, documentation, transparency, human oversight, accuracy, robustness, cybersecurity, and conformity assessment.

The eight categories

  1. Biometrics — biometric identification and categorisation, emotion recognition (with limited exceptions).
  2. Critical infrastructure — safety components in critical infrastructure (water, gas, electricity, traffic).
  3. Education and vocational training — admissions, evaluation, monitoring of cheating.
  4. Employment, workers management, self-employment — recruitment, selection, task allocation, monitoring, evaluation, promotion.
  5. Access to essential private and public services and benefits — credit scoring, insurance pricing, emergency dispatch, public benefits.
  6. Law enforcement — risk assessment, polygraphs, evidence reliability, profiling.
  7. Migration, asylum, border control — risk assessment, application examination, identity verification.
  8. Administration of justice and democratic processes — judicial decision support, electoral processes.

Obligations for high-risk systems

Conformity assessment

Before placing a high-risk system on the market, the provider must subject it to a conformity assessment. Most Annex III systems can use the internal-control route (Article 43) — see Article 43, with evidence for the mechanics of credible self-assessment.

Some systems (e.g. remote biometric identification, CNI-critical) require a notified body assessment. CSOAI is not a notified body.

What CSOAI provides for high-risk systems

What we do not provide