---
authoritative: false
representation: annotated-page
publisher: AstroKube
methodology: https://ai-act.astrokube.com/about/
source_verified_on: '2026-09-15'
site_content_updated_on: '2026-09-15'
title: 'Annex III: High-risk AI systems referred to in Article 6(2) | EU AI Act | AstroKube'
description: 'Annex III, EU AI Act: High-risk AI systems pursuant to Article 6(2) are the AI systems listed in any of the following areas: 1. Biometrics, in so far as…'
language: en
source: https://ai-act.astrokube.com/law/annex-iii/
---

1.  [Start](https://ai-act.astrokube.com/)
2.  [The law](https://ai-act.astrokube.com/law/)
3.  Annex III

# Annex III — High-risk AI systems referred to in Article 6(2)

▼ Primary text, verbatim. Our annotations appear below, visibly separated.

High-risk AI systems pursuant to Article 6(2) are the AI systems listed in any of the following areas:

1\. Biometrics, in so far as their use is permitted under relevant Union or national law:

(a) remote biometric identification systems.

This shall not include AI systems intended to be used for biometric verification the sole purpose of which is to confirm that a specific natural person is the person he or she claims to be;

(b) AI systems intended to be used for biometric categorisation, according to sensitive or protected attributes or characteristics based on the inference of those attributes or characteristics;

(c) AI systems intended to be used for emotion recognition.

2\. Critical infrastructure: AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, or in the supply of water, gas, heating or electricity.

3\. Education and vocational training:

(a) AI systems intended to be used to determine access or admission or to assign natural persons to educational and vocational training institutions at all levels;

(b) AI systems intended to be used to evaluate learning outcomes, including when those outcomes are used to steer the learning process of natural persons in educational and vocational training institutions at all levels;

(c) AI systems intended to be used for the purpose of assessing the appropriate level of education that an individual will receive or will be able to access, in the context of or within educational and vocational training institutions at all levels;

(d) AI systems intended to be used for monitoring and detecting prohibited behaviour of students during tests in the context of or within educational and vocational training institutions at all levels.

4\. Employment, workers’ management and access to self-employment:

(a) AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates;

(b) AI systems intended to be used to make decisions affecting terms of work-related relationships, the promotion or termination of work-related contractual relationships, to allocate tasks based on individual behaviour or personal traits or characteristics or to monitor and evaluate the performance and behaviour of persons in such relationships.

5\. Access to and enjoyment of essential private services and essential public services and benefits:

(a) AI systems intended to be used by public authorities or on behalf of public authorities to evaluate the eligibility of natural persons for essential public assistance benefits and services, including healthcare services, as well as to grant, reduce, revoke, or reclaim such benefits and services;

(b) AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud;

(c) AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance;

(d) AI systems intended to evaluate and classify emergency calls by natural persons or to be used to dispatch, or to establish priority in the dispatching of, emergency first response services, including by police, firefighters and medical aid, as well as of emergency healthcare patient triage systems.

6\. Law enforcement, in so far as their use is permitted under relevant Union or national law:

(a) AI systems intended to be used by or on behalf of law enforcement authorities, or by Union institutions, bodies, offices or agencies in support of law enforcement authorities or on their behalf to assess the risk of a natural person becoming the victim of criminal offences;

(b) AI systems intended to be used by or on behalf of law enforcement authorities or by Union institutions, bodies, offices or agencies in support of law enforcement authorities as polygraphs or similar tools;

(c) AI systems intended to be used by or on behalf of law enforcement authorities, or by Union institutions, bodies, offices or agencies, in support of law enforcement authorities to evaluate the reliability of evidence in the course of the investigation or prosecution of criminal offences;

(d) AI systems intended to be used by law enforcement authorities or on their behalf or by Union institutions, bodies, offices or agencies in support of law enforcement authorities for assessing the risk of a natural person offending or re-offending not solely on the basis of the profiling of natural persons as referred to in Article 3(4) of Directive (EU) 2016/680, or to assess personality traits and characteristics or past criminal behaviour of natural persons or groups;

(e) AI systems intended to be used by or on behalf of law enforcement authorities or by Union institutions, bodies, offices or agencies in support of law enforcement authorities for the profiling of natural persons as referred to in Article 3(4) of Directive (EU) 2016/680 in the course of the detection, investigation or prosecution of criminal offences.

7\. Migration, asylum and border control management, in so far as their use is permitted under relevant Union or national law:

(a) AI systems intended to be used by or on behalf of competent public authorities or by Union institutions, bodies, offices or agencies as polygraphs or similar tools;

(b) AI systems intended to be used by or on behalf of competent public authorities or by Union institutions, bodies, offices or agencies to assess a risk, including a security risk, a risk of irregular migration, or a health risk, posed by a natural person who intends to enter or who has entered into the territory of a Member State;

(c) AI systems intended to be used by or on behalf of competent public authorities or by Union institutions, bodies, offices or agencies to assist competent public authorities for the examination of applications for asylum, visa or residence permits and for associated complaints with regard to the eligibility of the natural persons applying for a status, including related assessments of the reliability of evidence;

(d) AI systems intended to be used by or on behalf of competent public authorities, or by Union institutions, bodies, offices or agencies, in the context of migration, asylum or border control management, for the purpose of detecting, recognising or identifying natural persons, with the exception of the verification of travel documents.

8\. Administration of justice and democratic processes:

(a) AI systems intended to be used by a judicial authority or on their behalf to assist a judicial authority in researching and interpreting facts and the law and in applying the law to a concrete set of facts, or to be used in a similar way in alternative dispute resolution;

(b) AI systems intended to be used for influencing the outcome of an election or referendum or the voting behaviour of natural persons in the exercise of their vote in elections or referenda. This does not include AI systems to the output of which natural persons are not directly exposed, such as tools used to organise, optimise or structure political campaigns from an administrative or logistical point of view.

This text is meant purely as a documentation tool and has no legal effect. The Union's institutions do not assume any liability for its contents. The authentic versions of the relevant acts, including their preambles, are those published in the Official Journal of the European Union and available in EUR-Lex.

## Scenarios that touch this provision

### A code assistant for your own engineers

Illustrative Reading still settling

An assistant suggests code in the editor and opens pull requests, running against a hosted model.

### Your role

ProviderDeployer

### Where it lands

Not classified In force 2 Aug 2026

### Decided by

No Annex III use case. The open question is Article 50(2), because the assistant generates text.

What applies

-   [AI literacy measures](https://ai-act.astrokube.com/explorer/?q=art-4-ai-literacy)
-   [Machine-readable marking of synthetic content](https://ai-act.astrokube.com/explorer/?q=art-50-synthetic-marking)

What you have to be able to produce

-   Content marking in the generation pipeline
-   Onboarding notes for AI-touching roles
-   Provenance-preservation test in CI
-   Team enablement plan for people operating AI systems

What would change the answer

-   Article 50(2) does not apply to the extent a system performs an assistive function for standard editing or does not substantially alter the input data or its semantics. Whether a generated patch is assistive editing is exactly the line this exemption draws, and it is not settled.
-   Generated code that ships inside a product covered by Annex I harmonisation legislation is a question about that product, not about the assistant.
-   Use it to evaluate engineers rather than to help them and Annex III point 4(b) applies.

[EU Art. 50(2)](https://ai-act.astrokube.com/law/art-50/ "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)") [EU Annex III, point 4(b)](https://ai-act.astrokube.com/law/annex-iii/ "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)") [EU Art. 4](https://ai-act.astrokube.com/law/art-4/ "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)") [EU Guidelines on Article 50 Commission interpretation](https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems "Guidelines on transparency obligations for providers and deployers of AI systems (Article 50)")

A scenario describes a system we made up, not yours. It is not a classification of your system and not legal advice. Pending review by a named legal reviewer.

### A credit-decision feature

Illustrative

A model scores applicants for a lending product and the score drives the decision, with a human able to override it.

### Your role

ProviderDeployer

### Where it lands

High risk Deferred 2 Dec 2027

### Decided by

Annex III, point 5(b): systems intended to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of systems used to detect financial fraud.

What applies

-   [Risk management system](https://ai-act.astrokube.com/explorer/?q=art-9-risk-management)
-   [Data and data governance](https://ai-act.astrokube.com/explorer/?q=art-10-data-governance)
-   [Technical documentation](https://ai-act.astrokube.com/explorer/?q=art-11-technical-documentation)
-   [Automatic recording of events](https://ai-act.astrokube.com/explorer/?q=art-12-logging)
-   [Human oversight](https://ai-act.astrokube.com/explorer/?q=art-14-human-oversight)
-   [Accuracy, robustness and cybersecurity](https://ai-act.astrokube.com/explorer/?q=art-15-accuracy-robustness)
-   [Deployer obligations](https://ai-act.astrokube.com/explorer/?q=art-26-deployer-obligations)
-   [Fundamental rights impact assessment](https://ai-act.astrokube.com/explorer/?q=art-27-fria)
-   [Conformity assessment](https://ai-act.astrokube.com/explorer/?q=art-43-conformity-assessment)
-   [Registration in the EU database](https://ai-act.astrokube.com/explorer/?q=art-49-registration)
-   [Right to explanation of individual decisions](https://ai-act.astrokube.com/explorer/?q=art-86-right-to-explanation)

What you have to be able to produce

-   Adversarial and injection test suite
-   Annex IV technical file
-   Bias examination report
-   Conformity route decision per system
-   Dataset cards with provenance
-   Decision factors captured per output
-   Decision-correlation IDs across services
-   Declared accuracy levels and metrics
-   Deployer-side log retention
-   Deployment instructions record per system
-   Doc generation wired into CI
-   Documentation format decision on record
-   Escalation path for emergent risk
-   Explanation request process
-   Field-risk signal feed into the register
-   Foreseeable-misuse analysis per release
-   Fundamental rights impact assessment
-   Inference event schema
-   Kill switch and override, with tests
-   Living risk register with review cadence
-   Model performance SLOs with alerts
-   Named oversight roles
-   Oversight runbook
-   Oversight UX with override path
-   Per-run lineage records
-   Registration entries per system
-   Replay runbook
-   Representativeness note for the target population
-   Risk-to-control mapping in the design docs
-   Scope determination on record
-   Stated assumptions per data set
-   Tamper-evident log storage
-   Worker information notice

What would change the answer

-   Unlike the hiring case, this one carries a fundamental rights impact assessment: Article 27(1) names Annex III point 5(b) explicitly.
-   Restricting the system to fraud detection takes it out of point 5(b). Scoring the same people for a lending decision puts it back.
-   An affected person can ask for an explanation of the individual decision under Article 86, and that explanation comes from the same records Article 12 asked you to keep.

[EU Annex III, point 5(b)](https://ai-act.astrokube.com/law/annex-iii/ "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)") [EU Art. 27(1)](https://ai-act.astrokube.com/law/art-27/ "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)") [EU Art. 86](https://ai-act.astrokube.com/law/art-86/ "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)") [EU Art. 12](https://ai-act.astrokube.com/law/art-12/ "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)")

A scenario describes a system we made up, not yours. It is not a classification of your system and not legal advice. Pending review by a named legal reviewer.

### A customer-support chatbot on your public site

Illustrative

The same stack, pointed outward: a chatbot that answers customer questions, drafts replies and escalates to a human when it cannot answer.

### Your role

ProviderDeployer

### Where it lands

Any risk level In force 2 Aug 2026

### Decided by

Article 50(1): a system intended to interact directly with natural persons. The transparency duties attach without the system being high-risk.

What applies

-   [Disclosing interaction with an AI system](https://ai-act.astrokube.com/explorer/?q=art-50-interaction-disclosure)
-   [Machine-readable marking of synthetic content](https://ai-act.astrokube.com/explorer/?q=art-50-synthetic-marking)
-   [AI literacy measures](https://ai-act.astrokube.com/explorer/?q=art-4-ai-literacy)

What you have to be able to produce

-   Content marking in the generation pipeline
-   Disclosure pattern in the design system
-   Onboarding notes for AI-touching roles
-   Provenance-preservation test in CI
-   Reusable disclosure component
-   Team enablement plan for people operating AI systems

What would change the answer

-   If the bot decides access to an essential service rather than describing it, Annex III point 5 puts it in the high-risk tier.
-   Article 50(2) marking has an exemption where the system performs an assistive function for standard editing or does not substantially alter the deployer’s input. A bot that writes the answer is not editing yours.
-   Publishing its text as an article on a matter of public interest brings Article 50(4) into play, and that duty sits on the deployer.

[EU Art. 50(1), (2)](https://ai-act.astrokube.com/law/art-50/ "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)") [EU Annex III, point 5](https://ai-act.astrokube.com/law/annex-iii/ "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)") [EU Art. 4](https://ai-act.astrokube.com/law/art-4/ "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)") [EU Guidelines on Article 50 Commission interpretation](https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems "Guidelines on transparency obligations for providers and deployers of AI systems (Article 50)")

A scenario describes a system we made up, not yours. It is not a classification of your system and not legal advice. Pending review by a named legal reviewer.

### A CV-screening feature in your product

Illustrative

You are about to ship a feature that ranks and filters job applications for the companies that use your hiring product.

### Your role

ProviderDeployer

### Where it lands

High risk Deferred 2 Dec 2027

### Decided by

Annex III, point 4(a): systems intended to be used for the recruitment or selection of natural persons, in particular to analyse and filter job applications and to evaluate candidates.

What applies

-   [Risk management system](https://ai-act.astrokube.com/explorer/?q=art-9-risk-management)
-   [Data and data governance](https://ai-act.astrokube.com/explorer/?q=art-10-data-governance)
-   [Technical documentation](https://ai-act.astrokube.com/explorer/?q=art-11-technical-documentation)
-   [Automatic recording of events](https://ai-act.astrokube.com/explorer/?q=art-12-logging)
-   [Transparency and instructions for deployers](https://ai-act.astrokube.com/explorer/?q=art-13-instructions-for-use)
-   [Human oversight](https://ai-act.astrokube.com/explorer/?q=art-14-human-oversight)
-   [Accuracy, robustness and cybersecurity](https://ai-act.astrokube.com/explorer/?q=art-15-accuracy-robustness)
-   [Conformity assessment](https://ai-act.astrokube.com/explorer/?q=art-43-conformity-assessment)
-   [EU declaration of conformity and CE marking](https://ai-act.astrokube.com/explorer/?q=art-47-48-declaration-ce-marking)
-   [Registration in the EU database](https://ai-act.astrokube.com/explorer/?q=art-49-registration)
-   [Keeping the automatically generated logs](https://ai-act.astrokube.com/explorer/?q=art-19-log-retention)
-   [Post-market monitoring](https://ai-act.astrokube.com/explorer/?q=art-72-post-market-monitoring)
-   [Serious incident reporting](https://ai-act.astrokube.com/explorer/?q=art-73-incident-reporting)

What you have to be able to produce

-   Adversarial and injection test suite
-   Annex IV technical file
-   Authority notification runbook
-   Bias examination report
-   Conformity route decision per system
-   Dataset cards with provenance
-   Decision-correlation IDs across services
-   Declared accuracy levels and metrics
-   Doc generation wired into CI
-   Documentation format decision on record
-   Escalation path for emergent risk
-   EU declaration of conformity per system
-   Field-data review cadence
-   Field-risk signal feed into the register
-   Foreseeable-misuse analysis per release
-   Incident classification with regulatory branch
-   Inference event schema
-   Instructions for use per system
-   Kill switch and override, with tests
-   Living risk register with review cadence
-   Model performance SLOs with alerts
-   Named reporting roles
-   Output metadata deployers can read
-   Oversight runbook
-   Oversight UX with override path
-   Per-run lineage records
-   Post-market monitoring plan
-   Registration entries per system
-   Replay runbook
-   Representativeness note for the target population
-   Resource, lifetime and maintenance inputs for the instructions
-   Restore test on aged logs
-   Retention budget and DPO sign-off
-   Retention policy meeting the six-month floor
-   Risk-to-control mapping in the design docs
-   Stated assumptions per data set
-   Tamper-evident log storage
-   Versioned field telemetry

What would change the answer

-   The Article 6(3) derogation is the only way out, and a system that performs profiling of natural persons never qualifies. Ranking candidates is hard to argue as a narrow procedural task.
-   Your customers are deployers of this system and carry Article 26 duties, including keeping the logs under their control and telling candidates they are subject to it.
-   A customer who puts its own brand on your feature becomes its provider under Article 25(1)(a), and you stop being it.

[EU Annex III, point 4(a)](https://ai-act.astrokube.com/law/annex-iii/ "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)") [EU Art. 6(2), (3)](https://ai-act.astrokube.com/law/art-6/ "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)") [EU Art. 16](https://ai-act.astrokube.com/law/art-16/ "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)") [EU Art. 26](https://ai-act.astrokube.com/law/art-26/ "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)") [EU Art. 25(1)](https://ai-act.astrokube.com/law/art-25/ "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)")

A scenario describes a system we made up, not yours. It is not a classification of your system and not legal advice. Pending review by a named legal reviewer.

### A product recommender in your storefront

Illustrative

A model ranks what each visitor sees, trained on browsing and purchase history.

### Your role

ProviderDeployer

### Where it lands

Not classified In force 2 Feb 2025

### Decided by

Ranking products is not an Annex III use case and not a safety component. What the system infers about people is what to watch.

What applies

-   [AI literacy measures](https://ai-act.astrokube.com/explorer/?q=art-4-ai-literacy)

What you have to be able to produce

-   Onboarding notes for AI-touching roles
-   Team enablement plan for people operating AI systems

What would change the answer

-   Price or risk-assess life and health insurance with it and Annex III point 5(c) applies; score creditworthiness and point 5(b) does.
-   Article 5 prohibits certain manipulative and exploitative practices outright. A recommender tuned to exploit the vulnerabilities of a specific group is a different object from one tuned to relevance.
-   Profiling turns the Article 6(3) escape hatch off for any Annex III system, so it matters what the model infers, not only what it displays.

[EU Annex III, points 5(b), 5(c)](https://ai-act.astrokube.com/law/annex-iii/ "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)") [EU Art. 5](https://ai-act.astrokube.com/law/art-5/ "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)") [EU Art. 6(3)](https://ai-act.astrokube.com/law/art-6/ "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)") [EU Art. 4](https://ai-act.astrokube.com/law/art-4/ "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)")

A scenario describes a system we made up, not yours. It is not a classification of your system and not legal advice. Pending review by a named legal reviewer.

### A RAG assistant over internal documents, on a vendor model

Illustrative

You wrapped a vendor model in a retrieval layer over your own wiki and runbooks, and put it in front of your own staff. Nobody outside the company can reach it.

### Your role

ProviderDeployer

### Where it lands

Not classified In force 2 Feb 2025

### Decided by

No Annex III use case, and not a safety component under Article 6(1). Putting a system into service for your own use still makes you its provider under Article 3(11).

What applies

-   [AI literacy measures](https://ai-act.astrokube.com/explorer/?q=art-4-ai-literacy)
-   [Disclosing interaction with an AI system](https://ai-act.astrokube.com/explorer/?q=art-50-interaction-disclosure)

What you have to be able to produce

-   Disclosure pattern in the design system
-   Onboarding notes for AI-touching roles
-   Reusable disclosure component
-   Team enablement plan for people operating AI systems

What would change the answer

-   Point it at a decision the Act lists. The moment it screens candidates or scores people, Annex III applies and the answer changes completely.
-   Article 50(1) asks you to tell people they are interacting with an AI system unless that is obvious. For an internal assistant behind a login it usually is; write down why you concluded that.
-   Fine-tune the vendor model and you may become the provider of the modified model, with Chapter V duties for it.

[EU Art. 3(1), (11)](https://ai-act.astrokube.com/law/art-3/ "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)") [EU Art. 6](https://ai-act.astrokube.com/law/art-6/ "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)") [EU Annex III](https://ai-act.astrokube.com/law/annex-iii/ "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)") [EU Art. 4](https://ai-act.astrokube.com/law/art-4/ "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)") [EU Art. 50(1)](https://ai-act.astrokube.com/law/art-50/ "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)")

A scenario describes a system we made up, not yours. It is not a classification of your system and not legal advice. Pending review by a named legal reviewer.

## If you would rather not read the law

The basics page explains the Regulation's own categories in order: scope, role, tier, date. The engineering view groups the obligations by the platform capability they demand.

[Start with the basics →](https://ai-act.astrokube.com/basics/) [Open the engineering view →](https://ai-act.astrokube.com/engineering/)

## About this provision

### Type

Annex

### Amended by

Not amended

### Cited capture

regulation-2024-1689/en-2026-08-18.html sha256 8f0b656302f9864c…

[Authentic text (EUR-Lex) →](http://data.europa.eu/eli/reg/2024/1689/oj) [This version (EUR-Lex) →](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02024R1689-20260727)

### Machine readable

[/law/annex-iii.md](https://ai-act.astrokube.com/law/annex-iii.md) [/api/law.json](https://ai-act.astrokube.com/api/law.json)

### Found an error?

[Write to us →](https://astrokube.com/contact)
