EU AI Act High-Risk AI Systems: Annex III & Classification
Under the European Union Artificial Intelligence Act (EU AI Act), a high-risk AI system is defined as an AI system used as a safety component of a product subject to third-party conformity assessment under EU health and safety rules (Annex I), or a standalone AI system operating within one of eight specific, sensitive use-case domains enumerated in Annex III. These domains encompass critical areas such as biometric identification, critical infrastructure, education, employment, access to essential services, law enforcement, migration, and the administration of justice. Classification as high-risk triggers mandatory, comprehensive requirements across the system's entire lifecycle, including robust risk management, data governance, technical documentation, human oversight, and continuous monitoring—obligations that closely mirror the standard controls of an ISO/IEC 42001 AI Management System (AIMS).
Dual Criteria for High-Risk AI Classification
Article 6 of the EU AI Act establishes a two-pronged mechanism for AI classification. To determine whether an AI system falls under the high-risk tier, organizations must evaluate its technical role and intended purpose:
- Annex I Systems (Regulated Product Safety Components): The AI system is intended to be used as a safety component of a product—or is itself a product—covered by existing EU harmonization legislation (such as medical devices, aviation safety, machinery, or toys) and requires a third-party conformity assessment under those laws.
- Annex III Systems (High-Risk Standalone Use Cases): The AI system operates within high-stakes social or economic activities that pose significant risks to fundamental rights, health, or safety.
The 8 Annex III High-Risk AI Categories
Annex III specifically designates eight distinct operational areas where AI deployment naturally carries high potential for harm:
- Biometrics: Remote biometric identification, biometric categorization based on sensitive attributes, and emotion recognition systems used in workplaces or educational institutions.
- Critical Infrastructure: AI used as safety components in the management and operation of critical digital infrastructure, road traffic, or the supply of water, gas, heating, and electricity.
- Education and Vocational Training: Systems determining access or admission to educational institutions, evaluating learning outcomes, or monitoring student behavior during tests.
- Employment and Worker Management: Systems used for recruitment, screening candidates, making hiring or promotion decisions, task allocation, or evaluating worker performance.
- Access to Essential Private and Public Services: AI used to evaluate eligibility for public assistance benefits, credit scoring/creditworthiness assessments (excluding fraud detection), and health/life insurance risk pricing.
- Law Enforcement: Polygraphs, risk assessment of individuals, profiling during criminal investigations, or evaluating the reliability of evidence.
- Migration, Asylum, and Border Control: Systems assessing security risks, examining visa or asylum applications, or performing automated identity verification at borders.
- Administration of Justice and Democratic Processes: AI intended to assist judicial authorities in researching and interpreting facts and the law, or systems designed to influence election outcomes.
Exceptions Under Article 6(3): The Derogation Test
Even if an AI system falls under an Annex III category, it is not considered high-risk if it does not pose a significant risk of harm to health, safety, or fundamental rights. To qualify for this exception, the system must satisfy at least one of four narrow conditions:
- It performs a narrow procedural task.
- It is intended to improve or optimize the result of a previously completed human activity.
- It detects decision patterns or deviations from prior human patterns without replacing or influencing human assessment.
- It performs only a preparatory task to an assessment relevant to the Annex III domain.
Crucial Caveat: If the system performs profiling of natural persons (automated processing to evaluate personal aspects like performance, economic situation, or health), it is automatically classified as high-risk with no derogations permitted.
Bridging EU AI Act Compliance with ISO/IEC 42001
Deploying or developing a high-risk AI system mandates formal governance mechanisms before the system can enter the EU market. Adopting ISO/IEC 42001, the international standard for AI Management Systems, creates a structured operational model to fulfill these legal demands:
- Risk and Impact Assessments: ISO/IEC 42001 Clause 6 (Planning) and Annex A.5 require systematic assessment of risks and impacts on individuals, groups, and society, satisfying the risk management obligations of Article 9 in the EU AI Act.
- Data Governance: Annex A.7 controls establish standards for data quality, bias detection, and dataset curation, aligning with EU AI Act data quality requirements.
- Lifecycle & Documentation: Clause 8 (Operation) and Annex A.6 mandate lifecycle controls, technical documentation, and record-keeping that align directly with EU conformity requirements.
- Human Oversight & System Transparency: Annex A.8 (Information for interested parties) and Annex A.9 (Use of AI systems) establish parameters for human oversight and continuous post-market monitoring.
Organizations preparing for EU AI Act compliance can utilize platform solutions to streamline readiness. While an accredited certification body with independent auditors (guided by ISO/IEC 42006) grants official ISO/IEC 42001 certification, an intelligent governance platform like DoAIRight helps organizations assess gaps, execute required controls, and ensure full certification readiness.
Steps to Determine Your System's Risk Level
To align your AI operations with European regulatory expectations:
- Map out all active and planned AI deployment use cases across your enterprise.
- Cross-reference your inventory against the Annex I safety rules and Annex III domains.
- Evaluate any potential Article 6(3) exemptions and document the technical justification.
- Establish an ISO/IEC 42001 management system to implement required risk, operational, and data governance controls.
Assess your organization's AI governance posture today with DoAIRight's free readiness assessment to identify regulatory gaps and streamline your path to responsible compliance.
Frequently asked
What happens if an organization fails to comply with EU AI Act high-risk rules?
Non-compliance with obligations for high-risk AI systems can result in severe administrative fines under Article 99, reaching up to €15 million or 3% of total worldwide annual turnover, whichever is higher.
Are general-purpose AI (GPAI) models classified as high-risk under Annex III?
GPAI models have their own regulatory tier under the EU AI Act. However, if a general-purpose model is integrated into a system designed for an Annex III use case (e.g., automated recruitment screening), the resulting application is regulated as a high-risk AI system.
Does ISO/IEC 42001 certification automatically guarantee EU AI Act compliance?
While ISO/IEC 42001 certification proves an organization operates a formal AI Management System, it is not a legal substitute for an EU conformity assessment. However, harmonized ISO/IEC standards are expected to provide a presumption of conformity for key requirements under the Act.
Who grants official ISO/IEC 42001 certification?
Certification is granted exclusively by an accredited third-party certification body employing independent human auditors (under ISO/IEC 42006 standards). Software tools like DoAIRight prepare organizations to achieve and sustain this readiness.