Examples
Worked examples
- Is an instance
A university admissions platform that algorithmically ranks or filters applicants for undergraduate or graduate programs -- matches Annex III point 3(a) (access/admission decisions).
- Is an instance
Automated remote-exam proctoring software that flags students for suspected cheating during online tests -- matches Annex III point 3(d) (monitoring/detecting prohibited test behaviour), directly relevant to academic-integrity determinations.
Counter-examples
Looks similar, but isn't
- Not an instance
A generative AI writing assistant researchers use to draft manuscripts or grant proposals performs none of the Annex III point 3 functions (no admission, evaluation, or assessment role) and is not high-risk under Annex III on that basis, though other Act provisions such as Article 50 transparency rules can still apply.
Editorial commentary
Annex III of the EU AI Act (Regulation (EU) 2024/1689) lists the eight functional categories of AI system — including biometrics, education, employment, law enforcement, migration, and the administration of justice — that trigger high-risk status under the Article 6(2) use-case classification route.
This differs from the Article 6(1) route, which instead covers AI that is itself, or a safety component of, a product already regulated under separate EU product-safety law. Landing inside one of the eight Annex III categories is necessary but not sufficient on its own: the system must also perform one of the specific functions that category’s text lists, and even then Article 6(3) provides a narrow exception — unless the system profiles natural persons, in which case high-risk status applies unconditionally, with no exception available.
The eight Annex III categories
Annex III groups high-risk use cases into eight areas:
- Biometrics
- Critical infrastructure
- Education and vocational training
- Employment, workers’ management, and access to self-employment
- Access to and enjoyment of essential private services and essential public services and benefits
- Law enforcement
- Migration, asylum, and border control management
- Administration of justice and democratic processes
How Annex III fits into the Article 6 classification test
Article 6 is the operative provision; Annex III is the list it points to. A system is high-risk under the Annex III route only if (a) it falls within one of the eight categories above, and (b) it performs the specific function that category’s Annex III text describes for it — the categories are headings, not the operative test themselves. Article 6(3) then narrows this: a listed system is not high-risk if it performs only a narrow procedural task, improves the result of a previously completed human activity, detects decision-making patterns without replacing or influencing a prior human assessment without proper review, or performs a preparatory task to an Annex III assessment. That exception has a hard override, though — an AI system that profiles natural persons (automated processing of personal data to evaluate aspects such as work performance, economic situation, health, preferences, reliability, or behaviour) is always high-risk, regardless of whether it would otherwise qualify for the Article 6(3) exception. A provider relying on the exception must document that assessment before placing the system on the market and register it under Article 49(2); Article 6(5) additionally directs the European Commission to issue classification guidelines with practical examples.
Education and vocational training (category 3): what it actually covers
Annex III point 3 lists four specific functions, and an AI system used in education or vocational training is only high-risk under this category if it performs one of them:
- (a) Access, admission, or assignment — AI systems used to determine access or admission, or to assign natural persons, to educational and vocational training institutions at any level.
- (b) Evaluating learning outcomes — including where those outcomes are then used to steer a person’s subsequent learning process.
- (c) Assessing appropriate level of education — determining the level of education an individual will receive or can access, within or in the context of an institution.
- (d) Monitoring and detecting prohibited behaviour during tests — automated proctoring and exam-integrity systems used within or in the context of an institution.
Why this matters for research institutions specifically
Universities and research institutions sit inside several Annex III categories at once, not just education. Admissions-screening tools that rank, filter, or score applicants fall under 3(a). Automated exam proctoring and remote-invigilation software that flags students for suspected cheating falls under 3(d) — a directly relevant category for academic-integrity workflows, since AI-assisted plagiarism or exam-integrity determinations that affect a student’s standing are exactly the kind of automated evaluation Annex III targets. AI-assisted grading or automated assessment tools that determine whether a student progresses or what level of instruction they’re placed into can fall under 3(b) or 3(c). Separately, AI used in faculty or staff recruitment, performance monitoring, or promotion/tenure-adjacent evaluation can fall under the employment category (4), and research-integrity or misconduct-adjudication tools with a justice-adjacent function could implicate category 8. An institution deploying any such system is a ‘deployer’ under the Act with its own obligations (human oversight, use in accordance with instructions, log-keeping) even where a commercial vendor is the ‘provider’ carrying the primary conformity-assessment burden.
Where compliance timing currently stands
Annex III high-risk obligations were originally due to apply from 2 August 2026. A Digital Omnibus proposal under discussion in 2026 would defer stand-alone Annex III obligations further, alongside a separate deferral track for Annex I (product-safety) obligations — but as of this writing that timeline had not been finalised through Official Journal publication. Institutions building compliance programs around Annex III should verify the current applicability date against the official EUR-Lex text or the European Commission’s AI Office guidance rather than treating any single deferral date as settled, since the schedule has moved during the legislative process.
Frequently asked questions
Does Annex III apply to public universities the same way it applies to companies?
Yes. The Act’s high-risk obligations attach to the function an AI system performs, not to whether the deployer is public or private, for-profit or nonprofit. A public university using an admissions-screening or exam-proctoring system that matches an Annex III function has deployer obligations under the Act in the same way a commercial vendor selling that system has provider obligations.
Is every AI tool used in education automatically high-risk?
No. Only systems performing one of the four specific functions in Annex III point 3 are captured. A generative AI writing assistant researchers use to draft a manuscript or grant proposal, for example, performs none of those functions and is not high-risk under Annex III on that basis — though other Act provisions, such as the Article 50 transparency/disclosure rules for AI-generated content, can still apply to it.
What is the difference between Annex III and Article 5?
Article 5 lists AI practices that are banned outright — they cannot be placed on the market or used in the EU at all, regardless of safeguards. Annex III (via Article 6) instead lists use cases that are permitted but subject to the full high-risk compliance regime — conformity assessment, risk management, human oversight, and the rest of Articles 8–49. Being outside Article 5’s prohibited list and inside an Annex III category are two different, sequential questions in the same classification exercise.
Related terms
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="EU AI Act Annex III (High-Risk Use Cases)"
vocab-term-identifier="https://casrai.org/dictionary/term/eu-ai-act-annex-iii-high-risk-use-cases" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/eu-ai-act-annex-iii-high-risk-use-cases",
"name": "EU AI Act Annex III (High-Risk Use Cases)",
"identifier": "https://casrai.org/dictionary/term/eu-ai-act-annex-iii-high-risk-use-cases",
"description": "A system falls under EU AI Act Annex III when it (1) is one of the eight listed use-case categories -- biometrics, critical infrastructure, education and vocational training, employment, essential services, law enforcement, migration, or administration of justice -- and (2) performs the specific function that category text describes (e.g., for education: admissions/access decisions, evaluating learning outcomes, assessing appropriate education level, or monitoring prohibited test behaviour). Matching both conditions triggers high-risk status under Article 6(2), subject to the narrow Article 6(3) exception, which itself never applies if the system profiles natural persons.",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
"url": "https://casrai.org/dictionary/term/eu-ai-act-annex-iii-high-risk-use-cases",
"sameAs": [],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"dateModified": "2026-07-30T05:45:37",
"inLanguage": "en"
}






