Skip to main content
v2026.11,610 entries · CC-BY 4.0
Dictionary termTrack DProposedv2026.1

EU AI Act Annex III (High-Risk Use Cases)

A system falls under EU AI Act Annex III when it (1) is one of the eight listed use-case categories -- biometrics, critical infrastructure, education and vocational training, employment, essential services, law enforcement, migration, or administration of justice -- and (2) performs the specific function that category text describes (e.g., for education: admissions/access decisions, evaluating learning outcomes, assessing appropriate education level, or monitoring prohibited test behaviour). Matching both conditions triggers high-risk status under Article 6(2), subject to the narrow Article 6(3) exception, which itself never applies if the system profiles natural persons.

ByCASRAI Editorial Board
· Last updated 30 Jul 2026

Ask about EU AI Act Annex III (High-Risk Use Cases)

Answers are drawn from this dictionary entry and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

Examples

Worked examples

  • Is an instance

    A university admissions platform that algorithmically ranks or filters applicants for undergraduate or graduate programs -- matches Annex III point 3(a) (access/admission decisions).

  • Is an instance

    Automated remote-exam proctoring software that flags students for suspected cheating during online tests -- matches Annex III point 3(d) (monitoring/detecting prohibited test behaviour), directly relevant to academic-integrity determinations.

Counter-examples

Looks similar, but isn't

  • Not an instance

    A generative AI writing assistant researchers use to draft manuscripts or grant proposals performs none of the Annex III point 3 functions (no admission, evaluation, or assessment role) and is not high-risk under Annex III on that basis, though other Act provisions such as Article 50 transparency rules can still apply.

Editorial commentary

Annex III of the EU AI Act (Regulation (EU) 2024/1689) lists the eight functional categories of AI system — including biometrics, education, employment, law enforcement, migration, and the administration of justice — that trigger high-risk status under the Article 6(2) use-case classification route.

This differs from the Article 6(1) route, which instead covers AI that is itself, or a safety component of, a product already regulated under separate EU product-safety law. Landing inside one of the eight Annex III categories is necessary but not sufficient on its own: the system must also perform one of the specific functions that category’s text lists, and even then Article 6(3) provides a narrow exception — unless the system profiles natural persons, in which case high-risk status applies unconditionally, with no exception available.

The eight Annex III categories

Annex III groups high-risk use cases into eight areas:

  1. Biometrics
  2. Critical infrastructure
  3. Education and vocational training
  4. Employment, workers’ management, and access to self-employment
  5. Access to and enjoyment of essential private services and essential public services and benefits
  6. Law enforcement
  7. Migration, asylum, and border control management
  8. Administration of justice and democratic processes

How Annex III fits into the Article 6 classification test

Article 6 is the operative provision; Annex III is the list it points to. A system is high-risk under the Annex III route only if (a) it falls within one of the eight categories above, and (b) it performs the specific function that category’s Annex III text describes for it — the categories are headings, not the operative test themselves. Article 6(3) then narrows this: a listed system is not high-risk if it performs only a narrow procedural task, improves the result of a previously completed human activity, detects decision-making patterns without replacing or influencing a prior human assessment without proper review, or performs a preparatory task to an Annex III assessment. That exception has a hard override, though — an AI system that profiles natural persons (automated processing of personal data to evaluate aspects such as work performance, economic situation, health, preferences, reliability, or behaviour) is always high-risk, regardless of whether it would otherwise qualify for the Article 6(3) exception. A provider relying on the exception must document that assessment before placing the system on the market and register it under Article 49(2); Article 6(5) additionally directs the European Commission to issue classification guidelines with practical examples.

Education and vocational training (category 3): what it actually covers

Annex III point 3 lists four specific functions, and an AI system used in education or vocational training is only high-risk under this category if it performs one of them:

  • (a) Access, admission, or assignment — AI systems used to determine access or admission, or to assign natural persons, to educational and vocational training institutions at any level.
  • (b) Evaluating learning outcomes — including where those outcomes are then used to steer a person’s subsequent learning process.
  • (c) Assessing appropriate level of education — determining the level of education an individual will receive or can access, within or in the context of an institution.
  • (d) Monitoring and detecting prohibited behaviour during tests — automated proctoring and exam-integrity systems used within or in the context of an institution.

Why this matters for research institutions specifically

Universities and research institutions sit inside several Annex III categories at once, not just education. Admissions-screening tools that rank, filter, or score applicants fall under 3(a). Automated exam proctoring and remote-invigilation software that flags students for suspected cheating falls under 3(d) — a directly relevant category for academic-integrity workflows, since AI-assisted plagiarism or exam-integrity determinations that affect a student’s standing are exactly the kind of automated evaluation Annex III targets. AI-assisted grading or automated assessment tools that determine whether a student progresses or what level of instruction they’re placed into can fall under 3(b) or 3(c). Separately, AI used in faculty or staff recruitment, performance monitoring, or promotion/tenure-adjacent evaluation can fall under the employment category (4), and research-integrity or misconduct-adjudication tools with a justice-adjacent function could implicate category 8. An institution deploying any such system is a ‘deployer’ under the Act with its own obligations (human oversight, use in accordance with instructions, log-keeping) even where a commercial vendor is the ‘provider’ carrying the primary conformity-assessment burden.

Where compliance timing currently stands

Annex III high-risk obligations were originally due to apply from 2 August 2026. A Digital Omnibus proposal under discussion in 2026 would defer stand-alone Annex III obligations further, alongside a separate deferral track for Annex I (product-safety) obligations — but as of this writing that timeline had not been finalised through Official Journal publication. Institutions building compliance programs around Annex III should verify the current applicability date against the official EUR-Lex text or the European Commission’s AI Office guidance rather than treating any single deferral date as settled, since the schedule has moved during the legislative process.

Frequently asked questions

Does Annex III apply to public universities the same way it applies to companies?

Yes. The Act’s high-risk obligations attach to the function an AI system performs, not to whether the deployer is public or private, for-profit or nonprofit. A public university using an admissions-screening or exam-proctoring system that matches an Annex III function has deployer obligations under the Act in the same way a commercial vendor selling that system has provider obligations.

Is every AI tool used in education automatically high-risk?

No. Only systems performing one of the four specific functions in Annex III point 3 are captured. A generative AI writing assistant researchers use to draft a manuscript or grant proposal, for example, performs none of those functions and is not high-risk under Annex III on that basis — though other Act provisions, such as the Article 50 transparency/disclosure rules for AI-generated content, can still apply to it.

What is the difference between Annex III and Article 5?

Article 5 lists AI practices that are banned outright — they cannot be placed on the market or used in the EU at all, regardless of safeguards. Annex III (via Article 6) instead lists use cases that are permitted but subject to the full high-risk compliance regime — conformity assessment, risk management, human oversight, and the rest of Articles 8–49. Being outside Article 5’s prohibited list and inside an Annex III category are two different, sequential questions in the same classification exercise.

Related terms

Machine-readable encodings

Use in your systems

JATS XML <role> element
xml
<role vocab="credit"
      vocab-identifier="https://casrai.org/dictionary/"
      vocab-term="EU AI Act Annex III (High-Risk Use Cases)"
      vocab-term-identifier="https://casrai.org/dictionary/term/eu-ai-act-annex-iii-high-risk-use-cases" />
Schema.org DefinedTerm (JSON-LD)
json
{
  "@context": "https://schema.org",
  "@type": "DefinedTerm",
  "@id": "https://casrai.org/dictionary/term/eu-ai-act-annex-iii-high-risk-use-cases",
  "name": "EU AI Act Annex III (High-Risk Use Cases)",
  "identifier": "https://casrai.org/dictionary/term/eu-ai-act-annex-iii-high-risk-use-cases",
  "description": "A system falls under EU AI Act Annex III when it (1) is one of the eight listed use-case categories -- biometrics, critical infrastructure, education and vocational training, employment, essential services, law enforcement, migration, or administration of justice -- and (2) performs the specific function that category text describes (e.g., for education: admissions/access decisions, evaluating learning outcomes, assessing appropriate education level, or monitoring prohibited test behaviour). Matching both conditions triggers high-risk status under Article 6(2), subject to the narrow Article 6(3) exception, which itself never applies if the system profiles natural persons.",
  "inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
  "url": "https://casrai.org/dictionary/term/eu-ai-act-annex-iii-high-risk-use-cases",
  "sameAs": [],
  "license": "https://creativecommons.org/licenses/by/4.0/",
  "publisher": {
    "@id": "https://casrai.org/#organization"
  },
  "dateModified": "2026-07-30T05:45:37",
  "inLanguage": "en"
}

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →