Complete List of High-Risk AI (Annex III)

The eight Annex III categories, with software examples.

Annex III lists the use cases the EU considers high-risk. If your system falls into one of these areas — even as a small feature — high-risk obligations likely apply.

The eight categories

  1. Biometrics — remote biometric identification, biometric categorisation, emotion recognition (where not prohibited outright).
  2. Critical infrastructure — safety components in traffic, water, gas, heating, electricity, and critical digital infrastructure.
  3. Education and vocational training — admission decisions, evaluating learning outcomes, exam proctoring, assigning students.
  4. Employment and worker management — CV screening, ranking candidates, promotion and termination decisions, task allocation, monitoring performance. *This catches most HR-tech.*
  5. Essential services — credit scoring, life and health insurance pricing, emergency call triage, eligibility for public benefits. *This catches most fintech.*
  6. Law enforcement — risk assessments, evidence evaluation, profiling.
  7. Migration, asylum and border control — application examination, risk assessments, verification of documents.
  8. Administration of justice and democratic processes — assisting judicial decisions, influencing elections.

The nuance

A system in these areas can escape the high-risk label if it performs a narrow procedural task or purely assists human review without replacing it (Art. 6(3)) — but you must document that assessment. Guardia AI's classifier asks the Art. 6(3) questions and records your reasoning either way.

Didn't find what you need?

Guardia AI provides compliance tooling, not legal advice. For official regulatory text, see EU Regulation 2024/1689.