---
title: "Annex III in Plain English — How to Tell If Your AI Is High-Risk Under the EU AI Act"
description: "Most teams I talk to know the EU AI Act exists. Far fewer can tell me, with confidence, whether the system they shipped last quarter is \"high-risk\" under it."
doc_version: 1.0.0
last_updated: 2026-10-02
date_published: 2026-05-09
canonical: https://ccx.hu/blog/eu-ai-act-annex-iii-plain-english
---

# Annex III in Plain English — How to Tell If Your AI Is High-Risk Under the EU AI Act

> Most teams I talk to know the EU AI Act exists. Far fewer can tell me, with confidence, whether the system they shipped last quarter is "high-risk" under it.

![Annex III in Plain English — How to Tell If Your AI Is High-Risk Under the EU AI Act](https://s3.us-east-1.amazonaws.com/ccx.hu/images/05-article-9-aws-bedrock.png)

Most teams I talk to know the EU AI Act exists. Far fewer can tell me, with confidence, whether the system they shipped last quarter is "high-risk" under it. That gap is about to become expensive, because the classification question is not academic — it determines whether you owe a conformity assessment, a quality management system, post-market monitoring, and a CE-style marking, or whether you owe almost none of that.

## Why this matters now

The EU AI Act entered into force on 1 August 2024, but its obligations land in waves. The wave that matters for most enterprises arrives on **2 August 2026**, when the bulk of the high-risk obligations under Title III become enforceable. If your AI system is classified as high-risk under Annex III, by that date you need a documented risk management system (Article 9), data governance practices for training and testing data (Article 10), technical documentation (Article 11), automatic logging (Article 12), human oversight controls (Article 14), and registration in the EU database (Article 49). Providers also need a conformity assessment before placing the system on the market.

Penalties scale with the violation. The headline number — up to **€35 million or 7% of worldwide annual turnover**, whichever is higher — is reserved for prohibited practices under Article 5. Breaches of obligations on operators (most of what we are discussing here) carry up to €15 million or 3% of turnover. Either tier dwarfs the cost of getting classification right early. And classification is the gate: if you misread Annex III, every downstream control is either over-engineered for a low-risk system or absent for a high-risk one.

## The eight Annex III categories, in plain language

"Annex III" is the list at the back of the Act that names the use cases the EU considers high-risk by default. There are eight categories. If your intended purpose lands in one of them, you start the conversation as high-risk and have to argue your way out via Article 6(3), not the other way around.

1. **Biometrics** — remote biometric identification, biometric categorisation by sensitive attributes, and emotion recognition (outside narrow safety/medical exceptions).
2. **Critical infrastructure** — safety components in the management and operation of digital infrastructure, road traffic, water, gas, heating, and electricity.
3. **Education and vocational training** — admissions, evaluating learning outcomes, assessing the appropriate level of education a person should receive, and monitoring prohibited behaviour during tests.
4. **Employment, workers management, and access to self-employment** — recruitment (especially CV screening, candidate filtering, interview scoring), promotion and termination decisions, task allocation based on individual behaviour, and performance monitoring.
5. **Access to and enjoyment of essential private and public services** — public benefits eligibility, creditworthiness and credit scoring (excluding fraud detection used purely for that purpose), risk assessment and pricing in life and health insurance, and emergency call dispatching.
6. **Law enforcement** — risk assessment of individuals, polygraph-type tools, evidence reliability evaluation, profiling, and crime analytics on personal data.
7. **Migration, asylum, and border control management** — polygraph-type tools, risk assessments of irregular migration or health risks, examination of applications, and detection or recognition of persons at borders (other than travel-document verification).
8. **Administration of justice and democratic processes** — assisting judicial authorities in researching and interpreting facts and the law, alternative dispute resolution, and influencing election or referendum outcomes or voting behaviour.

Two terms worth pinning down before we go further. A **provider** is whoever develops the AI system or has it developed and places it on the market under their name — vendor or in-house build team, both count. A **deployer** is the organisation using the system under its own authority. Most enterprises are deployers of vendor AI and providers of their own internal systems, simultaneously. The obligations differ, but classification is the same exercise.

## The "intended purpose" test — what it is for, not what it can do

This is where most teams stumble. Annex III triggers on the **intended purpose** of the system, defined in Article 3(12) as "the use for which an AI system is intended by the provider, including the specific context and conditions of use."

A general-purpose large language model is not, by itself, a high-risk system. The same model fine-tuned, prompted, and shipped as a CV-screening assistant for a recruitment workflow is high-risk — because the intended purpose now sits squarely in Annex III category 4. The capability did not change. The framing did.

Practically, this means classification follows the product spec, the marketing copy, the API documentation, and the deployment context — not the model card. If your internal docs describe the system as "supports recruiters in shortlisting candidates," you are providing a high-risk AI system whether you wanted to or not. Conversely, a fraud-detection model whose stated purpose is fraud detection is explicitly excluded from the credit-scoring sub-category in Annex III(5)(b) — but the moment its scores feed a credit decision engine, the deployer has put it to a high-risk use and inherits the obligations.

## The Article 6(3) carve-outs — when Annex III does not mean high-risk

Article 6(3) is the escape hatch, added late in the legislative process. An AI system listed in Annex III is **not** high-risk if it does not pose a significant risk of harm to health, safety, or fundamental rights — and it qualifies for that exemption only if it falls into one of these conditions:

- The system is intended to perform a **narrow procedural task**.
- The system is intended to **improve the result of a previously completed human activity** (e.g., reformatting, polishing).
- The system is intended to **detect decision-making patterns or deviations from prior decision-making patterns**, and is not meant to replace or influence the previously completed human assessment without proper human review.
- The system is intended to perform a **preparatory task** for an assessment relevant to an Annex III use case.

The carve-out has a hard limit: it does not apply if the system performs **profiling of natural persons** as defined in GDPR Article 4(4). And the provider must document the reasoning behind invoking 6(3) — you cannot just decide internally that you are exempt; the assessment goes in the technical file and may be reviewed by the supervisory authority.

The carve-out is narrower than it looks on first read. "Narrow procedural" rules out anything that exercises judgement on a person. "Detection only, flag for human review" rules out systems where the human review is rubber-stamping. Treat 6(3) as a serious legal argument that needs evidence, not as a default.

## A 30-minute decision tree your team can run

Pull together the product owner, an engineer who knows the data, and someone who can speak to the deployment context. Walk through these questions for a single use case. If you cannot answer one in five minutes, that itself is a finding.

| # | Question | If yes | If no |
|---|---|---|---|
| 1 | Is this an AI system as defined in Article 3(1) — i.e., a machine-based system that infers from inputs to generate outputs that influence environments? | Continue to 2 | Out of scope of the Act |
| 2 | Is the intended purpose covered by any of the eight Annex III categories? Read the actual sub-points, not the category title. | Continue to 3 | Likely not high-risk; check Article 5 prohibitions and GPAI rules separately |
| 3 | Does the system profile natural persons (GDPR Art. 4(4))? | High-risk. 6(3) carve-out unavailable. Stop. | Continue to 4 |
| 4 | Does the system fall cleanly into one of the four 6(3) exemption types (narrow procedural, polish prior human work, detect deviations for human review, preparatory task)? | Continue to 5 | High-risk. Stop. |
| 5 | Have you documented the 6(3) reasoning in a form a regulator could review? | Likely not high-risk; record the assessment | High-risk in practice until you can defend the exemption |
| 6 | Are you the provider, the deployer, or both for this system in this deployment? | Map obligations: providers carry the conformity assessment; deployers carry use-context, monitoring, and human oversight duties | n/a |

Run this for every distinct intended purpose. A single model serving three workflows is three classification exercises.

## Common misclassifications we see

- **The HR chatbot that "just answers candidate questions"** — and quietly ranks applicants by how they phrase responses. That is recruitment screening. Annex III(4). High-risk.
- **The fraud detection model whose scores are read by the credit decisioning team.** Fraud detection alone is excluded from Annex III(5)(b). The moment the same scores influence creditworthiness, the deployer has created a high-risk use, and the provider needs to know the system is being deployed that way.
- **The internal "talent insights" tool** that surfaces high performers for promotion shortlists. Marketed internally as analytics. In substance, it influences promotion decisions — Annex III(4) again.
- **Education proctoring tools** repurposed for corporate certification programs. Still Annex III(3) if the certification gates access to a role or qualification.
- **GenAI copilots embedded in essential services workflows** — claims processing, benefit eligibility triage, customer escalation routing. The general-purpose model upstream is a separate regime; the deployed system inherits the high-risk classification of its intended purpose.

The thread running through all of these: capability-led thinking ("our model just generates text") loses to purpose-led thinking ("our system decides who gets shortlisted").

## What this looks like at ccX

At ccX, we approach AI Act readiness the same way we approach any regulated workload — engineering-first, evidence-led, and senior-only on delivery. Our team is **AWS 3× Professional certified** across Solutions Architect, DevOps, and Security, plus **AWS GenAI Specialty certified**, which matters because most high-risk classification arguments today turn on how a model is integrated, not on the model itself. We are **Hungarian-domiciled and EU-native**, so the regulatory frame is the one we work in every day, not a translation exercise. A typical engagement starts with a **two-week readiness audit** that produces a defensible classification per use case, a 6(3) memo where the carve-out applies, and a gap list mapped to Articles 9 through 15. Our delivery track record spans EU institutions, Big 4 firms, and Fortune 500 enterprises operating in the EU.

## Where to go from here

Classification is the cheapest part of compliance to get right and the most expensive part to get wrong. A useful next step is reading our overview at [ccx.hu/eu-ai-act](/eu-ai-act), or if you would like a working session against your actual use cases, [get in touch](/contact) and we will scope a readiness audit.

*This article is a practical interpretation of the EU AI Act, not legal advice. Consult qualified counsel for binding compliance decisions.*

---

## Sitemap

- [Read this post on the web](https://ccx.hu/blog/eu-ai-act-annex-iii-plain-english)
- [All blog posts](https://ccx.hu/blog)
- [Full site map](https://ccx.hu/sitemap.md)
- [Home](https://ccx.hu/)
- [Services](https://ccx.hu/services)
- [EU AI Act Compliance](https://ccx.hu/eu-ai-act)
- [AWS GenAI Production Readiness](https://ccx.hu/aws-genai-review)
- [Glossary](https://ccx.hu/glossary)
- [Contact](https://ccx.hu/contact)
