Annex III: the eight areas separately
Annex III names eight areas in which an AI system can be high-risk under Article 6(2). This object publishes those eight areas as separate objects, so that a question about recruitment, assessment, creditworthiness or border control lands on the point that names it rather than on the list as a whole.
The introductory sentence of Annex III reads: High-risk AI systems pursuant to Article 6(2) are the AI systems listed in any of the following areas.
Praxikon tracks Annex III: the eight areas separately under the EU AI Act, checked against the official source on 14 August 2026, citing the source for every statement.
- Status
- Upcoming
- Application date
- 2 December 2027
- Version
- 1.0.0
- Last reviewed
- 14 August 2026
Review status: placed against the official source (14 August 2026). Next check due by 10 February 2027. The check date is the knowledge date of this version; no later recheck has been recorded.
From source to evidence
Why this obligation applies, what it asks of you, and what you show for it.
Applies
Upcoming · 2 December 2027
For whom
- Deployer
- Provider of an AI system
What you do
Map every system to a point of Annex III
What you record
Record of the mapping to a point of Annex III
Official source
Who this is relevant to
When this applies
Deployer
An organisation using an AI system under its authority, excluding personal non-professional use.
Provider of an AI system
A party that develops or has an AI system developed and places it on the market under its own name.
- 1Applies where the intended purpose of the AI system falls within one of the eight areas listed in Annex III: biometrics, critical infrastructure, education and vocational training, employment and workers management, access to essential private and public services, law enforcement, migration and border control management, or administration of justice and democratic processes.
- 2Classification follows Article 6(2). For points 1, 6 and 7 the text adds the condition that the use is permitted under relevant Union or national law. We read that condition as meaning that a prohibition under Article 5 comes before the question whether the system is high-risk; that is our reading and not the literal text, which states the condition without naming the order.
- 3The duty rests on the provider, but the role can shift. Under Article 25(1) a distributor, importer, deployer or third party becomes a provider itself where it puts its name or trademark on the system, makes a substantial modification, or changes the intended purpose such that the system becomes high-risk under Article 6. From that moment it carries the mapping to a point of Annex III itself.
What the official source establishes
Annex III is not fixed. Article 7(1) empowers the Commission to add or amend use cases in Annex III by delegated act, and Article 7(3) to remove them. Article 7(1)(a) requires the system to be intended for use in one of the areas listed in Annex III. The eight areas are therefore the stable layer; the lettered subpoints inside them can change without the Regulation itself being revised.
Our interpretation
The official source remains authoritative. This general interpretation is not legal advice.
Seven of the eight areas are subdivided into lettered subpoints in the text: point 1 into (a) to (c), point 3 into (a) to (d), point 4 into (a) and (b), point 5 into (a) to (d), point 6 into (a) to (e), point 7 into (a) to (d) and point 8 into (a) and (b). Point 2 has no lettered subpoints. We therefore count twenty-four lettered subpoints across seven areas. That number appears nowhere in the Regulation: it is our count of the text as it stands at our knowledge date, and a delegated act under Article 7 can silently make it stale.
Reading Annex III as one block leads to the wrong question. The question is not whether your organisation works in one of the eight areas, because nearly everyone does: a hospital touches point 5, a school point 3, and every employer point 4. The question is whether the intended purpose of this one system coincides with the description of a lettered subpoint. A CV parser that only deduplicates repeat applications does something other than a system that evaluates candidates, and yet both get filed under recruitment in practice. Note the order too. Points 1, 6 and 7 carry the condition that the use must be permitted, and that is where Article 5 comes first. Emotion recognition in the workplace and in education is prohibited under Article 5(1)(f), except where the system is placed on the market or put into service for medical or safety reasons; whoever reverses that builds a conformity file for something that is not allowed. Finally, the area also determines which duties then weigh heavily. Article 86 gives a right to an explanation for decisions based on any system listed in Annex III other than point 2, and Article 27 requires bodies governed by public law and private providers of public services to carry out a fundamental rights impact assessment on every Annex III route other than point 2, with point 5(b) and (c) extending that duty to any deployer. For systems already on the market before the application date, the separate transitional rule of Article 111(2) applies as well.
What you can do now
For every AI system, record in your register not that it falls under Annex III but which point and which lettered subpoint it touches, with the intended purpose in your own words alongside. The eight area objects sit in the graph under the slugs annex-iii-area-1-biometrics through annex-iii-area-8-justice-and-democratic-processes; refer to those rather than to Annex III as a whole. Add four fields: is the use permitted, and if not, why is Article 5 not engaged; has the Article 6(3) test been carried out, which of the four conditions was met, and has the assessment been documented and the system registered under Article 6(4) and Article 49(2); does the system perform profiling, because the exception then falls away; and who carries the provider role after Article 25. Repeat that record on every change to the intended purpose.
- 01
Map every system to a point of Annex III
Determine per AI system which of the eight areas and which lettered subpoint the intended purpose touches, or establish with reasons that no point applies. Then run the Article 6(3) test and record the outcome as Article 6(4) requires. Do so at the level of the intended purpose and not at the level of the department or the sector.
What to retain
Record of the mapping to a point of Annex III
Per system: the intended purpose in your own words, the chosen point and lettered subpoint, the reasoning, the outcome of the Article 6(3) assessment with the condition it rests on, whether the system performs profiling, and for a reasoned no also the documentation and registration required by Article 6(4) and Article 49(2). Plus who assessed it and when. This is the document with which you later explain why the system was out of scope.
Control and reassessment
Reassessment on a change of intended purpose
The control that ensures a change of intended purpose, a new vendor feature, a new use inside the organisation or a delegated act under Article 7 triggers a fresh assessment of the mapping to a point of Annex III, instead of the first record standing for years while the system or the list moves.
Public tools
Full text of Annex III
The full text of Annex III, with all eight areas and their lettered subpoints, in the public AI Act Explorer and on EUR-Lex.
Conditions and exceptions
- Article 6(3) takes a system listed in Annex III back outside high-risk where it does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision making, and one of four conditions is met: the system performs a narrow procedural task, it improves the result of a previously completed human activity, it detects decision making patterns or deviations from prior patterns without replacing or influencing the previously completed human assessment without proper human review, or it performs a preparatory task to an assessment relevant for the purposes of the use cases listed in Annex III. A system that performs profiling of natural persons is always high-risk.
- The derogation is not free. Article 6(4) requires a provider who considers that a system referred to in Annex III is not high-risk to document its assessment before the system is placed on the market or put into service, subjects that provider to the registration obligation in Article 49(2), and requires it to provide the documentation to national competent authorities on request.
Official sources and locators
EU Artificial Intelligence Act 2024/1689
European Parliament and Council | original-oj-2024-07-12
Source locator: Annex III, points 1 to 8
EU Artificial Intelligence Act 2024/1689
European Parliament and Council | original-oj-2024-07-12
Source locator: Article 7(1) and (3)
EU Artificial Intelligence Act 2024/1689
European Parliament and Council | original-oj-2024-07-12
Source locator: Article 5(1)(f), Article 27(1), Article 86(1), Article 111(2) and Annex III
EU Artificial Intelligence Act 2024/1689
European Parliament and Council | original-oj-2024-07-12
Source locator: Article 6(2)-(4), Article 25(1), Article 49(2) and Annex III
Referring to this object
Citation block
Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.
Reference
Praxikon, "Annex III: the eight areas separately", praxikon:eu:ai-act:obligation:annex-iii-eight-areas@1.0.0, dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0 (schema 1.5.0), effective_at 2026-07-27T00:00:00.000Z, known_at 2026-08-14T00:00:00.000Z, sha256 fefd34d9142cbbda7f5ba59c3a3ec858bd9f1101363c0e874cf8b071780790e6, https://www.praxikon.com/en/verplichtingen/annex-iii-eight-areas (https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aannex-iii-eight-areas&effective_at=2026-07-27&known_at=2026-08-14&lang=en, accessed 2026-09-15)
Short form
praxikon:eu:ai-act:obligation:annex-iii-eight-areas@1.0.0 (sha256 fefd34d9)
BibTeX
@misc{praxikon-eu-ai-act-obligation-annex-iii-eight-areas-1-0-0,
author = {{Praxikon}},
title = {Annex III: the eight areas separately},
year = {2026},
version = {1.0.0},
number = {praxikon:eu:ai-act:obligation:annex-iii-eight-areas},
howpublished = {AI Act Change \& Evidence Graph, dataset 2.2.0, schema 1.5.0},
note = {effective_at 2026-07-27T00:00:00.000Z; known_at 2026-08-14T00:00:00.000Z; sha256 fefd34d9142cbbda7f5ba59c3a3ec858bd9f1101363c0e874cf8b071780790e6},
url = {https://www.praxikon.com/en/verplichtingen/annex-iii-eight-areas},
urldate = {2026-09-15},
language = {en}
}CSL JSON
[
{
"id": "praxikon:eu:ai-act:obligation:annex-iii-eight-areas@1.0.0",
"type": "dataset",
"title": "Annex III: the eight areas separately",
"container-title": "AI Act Change & Evidence Graph",
"publisher": "Praxikon",
"version": "1.0.0",
"number": "praxikon:eu:ai-act:obligation:annex-iii-eight-areas",
"URL": "https://www.praxikon.com/en/verplichtingen/annex-iii-eight-areas",
"language": "en",
"issued": {
"date-parts": [
[
2026,
8,
14
]
]
},
"accessed": {
"date-parts": [
[
2026,
9,
15
]
]
},
"note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0; schema 1.5.0; effective_at 2026-07-27T00:00:00.000Z; known_at 2026-08-14T00:00:00.000Z; sha256 fefd34d9142cbbda7f5ba59c3a3ec858bd9f1101363c0e874cf8b071780790e6; retrieved_from https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aannex-iii-eight-areas&effective_at=2026-07-27&known_at=2026-08-14&lang=en; licence https://www.praxikon.com/nl/legal/terms"
}
]How to verify a reference later is set out in the methodology. Terms
Version history
v1.0.0
27 July 2026
Annex III: the eight areas separately
Annex III names eight areas in which an AI system can be high-risk under Article 6(2). This object publishes those eight areas as separate objects, so that a question about recruitment, assessment, creditworthiness or border control lands on the point that names it rather than on the list as a whole.
Corrections to this obligation
No substantive correction to this object has been recorded.
Open the correction logHelp with implementation
Zahed Ashkara, jurist and freelance AI & Privacy Consultant, supports implementation with your team through Embed AI.
View AI governance at Embed AIFor AI agents and integrations
This page and the machine output derive from the same versioned object. Use the API for deterministic filters by role, topic and time.
