Biometrics
For organisations that need to classify biometric AI without mixing up prohibited practices, high-risk rules and privacy risk.
EU AI Act high-risk map
A practical overview of biometrics, critical infrastructure, education, HR, essential services, law enforcement, migration, justice and democratic processes.
Built on the Commission draft guidelines of 19 May 2026.
Each domain page links use cases to Article 6, Annex III and evidence.
Expert pages explain where classification and governance need extra attention in each domain.
The route to high-risk
8 domains · 24 use cases · from 2 December 2027
A domain being listed in Annex III does not by itself make a system high-risk. This is the order in which that question gets answered, and where it can turn out differently.
Before classification comes into play, the system must meet the definition of an AI system in Article 3(1). Not every software application and not every automated decision-making system falls within the AI Act.
Off-rampNo: the regulation does not reach the system.
Intended purpose determines whether a system is high-risk. That purpose is set not only by the technical documentation but also by the instructions for use, promotional materials, sales materials and statements by the provider. Reasonably foreseeable misuse falls by definition outside the intended purpose.
Off-rampNot on the list: the Annex I route is what remains.
As soon as the system profiles, the Article 6(3) exemption is ruled out. The draft guidelines give three cumulative elements against which you test this.
Off-rampYes: the exception is closed.
A system that falls within an Annex III use case can still escape high-risk classification if it meets one of four conditions. The draft guidelines make clear this is not a broad escape route.
No · Outcome
The Chapter III obligations apply in full.
Yes · Outcome
Not a pass on the work: you must be able to show the exception.
High-risk does not mean prohibited, and not high-risk does not mean permitted
Use this overview to assess which AI systems may be high-risk in each domain, which questions to answer and what evidence is needed.
For organisations that need to classify biometric AI without mixing up prohibited practices, high-risk rules and privacy risk.
For operators, vendors and public or private infrastructure managers using AI where failures can affect safety and access to essential services.
For education institutions, EdTech providers and L&D teams using AI for admission, assessment, level assignment or student monitoring.
For organisations using AI in recruitment, selection, work terms, task allocation, monitoring or performance evaluation.
For banks, insurers, public service providers and emergency services where AI can affect access to basic services or financial opportunities.
A trust-led overview for AI systems in law enforcement, focused on legal basis, fundamental rights and proportionality.
A legal and fundamental-rights driven overview for AI systems in migration, asylum and border control.
For legal organisations, public institutions and civic tech teams using AI around legal assessment or democratic decision-making.
Short answers for classification, evidence and next steps under Annex III.
Annex III lists the high-risk AI domains that need to be assessed alongside Article 6. It covers biometrics, critical infrastructure, education, work, essential services, law enforcement, migration and justice.
No. First confirm that the system is an AI system, then assess whether its intended purpose falls under Article 6(2) and a specific Annex III point. The Article 6(3) filter can still matter unless profiling or rights impact blocks that route.
Start with the domain closest to the intended purpose, check the use cases from the guidelines, document the classification reason and then connect provider and deployer obligations to the evidence file.