CSOAI - Annex III

What counts as high-risk AI?

The EU AI Act's heaviest obligations fall on high-risk systems. These are the eight Annex III categories - if your AI lands in one, the full regime applies.

1Biometrics

Remote biometric identification, biometric categorisation, and emotion recognition.

2Critical infrastructure

AI as a safety component in road traffic, water, gas, heating, and electricity.

3Education + vocational training

Admissions, scoring of exams, and monitoring of prohibited behaviour during tests.

4Employment + worker management

Recruitment, CV screening, promotion, termination, and task allocation.

5Access to essential services

Credit scoring, insurance pricing, public benefits, and emergency-call dispatch.

6Law enforcement

Risk assessments of individuals, evidence reliability, and profiling.

7Migration, asylum + border control

Visa and asylum risk assessment, document verification.

8Justice + democratic processes

Assisting judicial decisions and influencing elections or voting behaviour.

In a category? The full high-risk regime applies - risk management, data governance, documentation, logging, human oversight, and conformity assessment. The Council builds and signs that evidence.
Ask the Sovereign — EU AI Act Annex III high-risk AI systems
Governed answer · AI governance & cybersecurity only · signed to Layer 0
Open the full AI OS →