Compyl
GRC Your Way

EU AI Act High-Risk Categories: The Complete List

Last updated: August 13, 2026

The EU AI Act defines high-risk AI in two ways: AI systems that are safety components of products already regulated under EU product safety law (Annex I), and standalone AI systems used in eight sensitive areas listed in Annex III. The Annex III list covers biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and border control, and the administration of justice and democratic processes. High-risk classification triggers the Act’s most demanding obligations, from risk management and technical documentation to conformity assessment and registration.

Below is the full list of categories with examples, the exception that lets some Annex III systems escape the high-risk label, and the deadlines that now apply after the Digital Omnibus. For how these rules fit into a wider program, start with our AI governance guide.

Key takeaways

  • There are two routes to high-risk status: safety components of Annex I regulated products, and standalone systems in the eight Annex III use case areas.
  • Common business tools land in Annex III more often than teams expect. Resume screening, credit scoring, insurance pricing, and exam proctoring are all named use cases.
  • An Annex III system can avoid high-risk classification if it does not pose a significant risk to health, safety, or fundamental rights, but profiling of individuals always stays high risk.
  • After the Digital Omnibus, Annex III high-risk obligations apply from December 2, 2027, and Annex I embedded AI obligations from August 2, 2028.
  • Providers carry most high-risk obligations, but deployers have their own duties, including human oversight and monitoring.

How does the EU AI Act classify risk?

The Act sorts AI into four tiers. Prohibited practices, such as social scoring and manipulative techniques that cause significant harm, are banned outright and have been since February 2, 2025. High-risk systems are permitted but heavily regulated. Limited-risk systems face transparency duties, such as telling users they are interacting with a chatbot or labeling AI-generated content. Minimal-risk systems, the vast majority, face no new obligations. Who holds which obligations depends on your role in the value chain, which we cover in who the EU AI Act applies to.

What are the two routes to high-risk classification?

Route one is Annex I: the AI system is a product, or a safety component of a product, covered by existing EU harmonisation legislation that requires third-party conformity assessment. Think machinery, medical devices, in vitro diagnostics, toys, lifts, radio equipment, and vehicles. An AI module that controls braking in a car or interprets scans in a diagnostic device is high risk through this route.

Route two is Annex III: the system is standalone software used in one of eight listed areas that the EU legislator considers sensitive for health, safety, or fundamental rights. Most SaaS and enterprise AI exposure comes through this route.

What are the eight Annex III high-risk categories?

CategoryWhat it coversExample systems
1. BiometricsRemote biometric identification, biometric categorisation by sensitive attributes, emotion recognitionFace recognition in public venues, emotion detection in interviews
2. Critical infrastructureSafety components in the management of critical digital infrastructure, road traffic, water, gas, heating, electricityAI controlling grid load balancing or traffic signals
3. Education and vocational trainingAdmission, assessment, level assignment, and monitoring of prohibited behavior during testsAutomated admissions scoring, AI exam proctoring
4. Employment and worker managementRecruitment, screening, evaluation, promotion, termination, task allocation, monitoringResume ranking tools, performance evaluation algorithms
5. Essential private and public servicesEligibility for public benefits, creditworthiness, life and health insurance pricing, emergency call triageCredit scoring models, insurance risk pricing
6. Law enforcementRisk assessments, evidence evaluation, profiling in criminal investigationsRecidivism risk scoring, deepfake detection for evidence
7. Migration, asylum, and border controlApplication examination, risk assessments, verification of travel documentsVisa application triage, border risk screening
8. Administration of justice and democratic processesAssisting judicial authorities in researching and interpreting facts and law, influencing electionsJudicial research assistants, election-targeting systems

The categories describe use cases, not technologies. A general-purpose model is not high risk in itself, but the moment it is deployed to rank job applicants or score credit applications, that deployment falls into Annex III territory.

When is an Annex III system not high risk?

Article 6(3) provides a filter. An Annex III system is not high risk if it does not pose a significant risk of harm to health, safety, or fundamental rights, for example because it only performs a narrow procedural task, improves the result of a previously completed human activity, detects decision-making patterns without replacing human assessment, or performs a purely preparatory task. There is a hard limit: a system that profiles natural persons is always high risk. Providers who rely on this exception must document their assessment and be prepared to defend it to regulators.

What obligations come with high-risk classification?

Providers of high-risk systems must operate a risk management system across the lifecycle, apply data governance and quality criteria to training and testing data, maintain technical documentation, build in logging, ensure transparency to deployers, enable human oversight, meet accuracy, robustness, and cybersecurity thresholds, pass a conformity assessment, affix CE marking, and register the system in the EU database. Deployers must use systems per the provider’s instructions, assign trained human oversight, monitor operation, retain logs, and in some cases complete a fundamental rights impact assessment. Our overview of EU AI Act compliance for GRC teams walks through how to stand these controls up.

When do the high-risk rules take effect?

The original deadline of August 2, 2026 was moved by the Digital Omnibus, which entered into force on July 27, 2026. Standalone Annex III high-risk obligations now apply from December 2, 2027, and obligations for high-risk AI embedded in Annex I regulated products apply from August 2, 2028. The deferral does not touch the rules already in force: prohibited practices (February 2025), general-purpose AI model obligations (August 2025), and Article 50 transparency duties (August 2026). The full schedule is in our EU AI Act compliance timeline.

The extra time is a planning window, not a reprieve. Conformity assessment, data governance remediation, and documentation take quarters, not weeks, and many organizations are using a management system standard such as ISO 42001 to structure the work so that one program satisfies both the AI Act and customer assurance demands.

Frequently asked questions

Is our HR screening tool really high risk?

If it is used to advertise roles, filter applications, or evaluate candidates in the EU, yes, it sits squarely in Annex III category 4. The provider carries the heavier obligations, but as a deployer your organization still owes human oversight, monitoring, and worker notification.

Are chatbots high risk?

Not by default. A customer service chatbot is typically limited risk, carrying a transparency duty to disclose that users are talking to AI. It becomes high risk only if used for an Annex III purpose, such as triaging emergency calls or assessing benefit eligibility.

Who decides whether our system is high risk?

The provider makes the initial classification and documents it. Regulators can challenge that assessment, and the Article 6(3) exception requires a documented justification. Deployers should verify a vendor’s classification rather than take it on faith.

Do high-risk obligations apply to systems already on the market?

High-risk systems placed on the market before the applicability date are generally caught when they undergo a significant change in design, and public authority-operated systems have their own transition periods. New systems placed on the market after the deadlines must comply from day one.

What are the penalties for non-compliance?

Violations of the high-risk requirements can draw fines of up to 15 million euros or 3 percent of global annual turnover, and prohibited practices up to 35 million euros or 7 percent. Supplying misleading information to authorities carries fines up to 7.5 million euros or 1 percent.

Compyl gives compliance teams a single place to inventory AI systems, classify them against Annex I and Annex III, and run the controls that high-risk classification demands. If you are building toward a certifiable program, see how Compyl supports ISO 42001 compliance end to end.

By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies