Article 6 · Annex III

Is my AI system high-risk under the EU AI Act?

Possibly — but industry labels are not enough. High-risk classification depends on the legal route, intended purpose, affected use case and the Act's qualifications.

Updated and legally reviewed: 29 September 2026.

Direct answer

Classify the use case, not the company.

A bank, employer, hospital or software company can operate many AI systems without every system being high-risk. For Annex III, the intended purpose must be mapped to a listed use case and Article 6 must then be applied.

Employment

Specified recruitment, selection, employment-management and worker-related uses appear in Annex III. The exact intended purpose matters.

Essential services

Specified creditworthiness and certain insurance uses are listed, while the text also contains important boundaries such as the financial-fraud exception.

Education & public services

Specified access, evaluation and decision-support use cases can fall within Annex III.

Biometrics, migration & justice

Annex III also lists specified biometric, migration/border, law-enforcement and administration-of-justice uses, subject to the statutory text.

Current timetable

Annex III readiness now points to 2 December 2027.

The amended timetable gives organisations additional implementation time, but classification, inventory, governance and evidence work should precede the application date.

Free classification screen

Check your intended purpose against Annex III.

Use the checker to identify listed areas and the questions that still need legal classification.