Annex III: high-risk AI
Classification route for standalone high-risk AI systems under Article 6(2) and Annex III.
The official source remains authoritative. This general interpretation is not legal advice.
- Status
- Upcoming
- Application date
- 2 December 2027
- Version
- 1.0.0
- Last reviewed
- 8 August 2026
Who this is relevant to
When this applies
Deployer
An organisation using an AI system under its authority, excluding personal non-professional use.
Provider of an AI system
A party that develops or has an AI system developed and places it on the market under its own name.
- 1The intended purpose falls within a use case listed in Annex III.
- 2Classification follows Article 6(2).
What the official source establishes
The core rules in Chapter III, Sections 1 to 3, for systems under Article 6(2) and Annex III become applicable on 2 December 2027.
Our interpretation
The later application date does not remove the classification question. An early classification record avoids design and procurement decisions without evidence.
What you can do now
Document now the intended purpose, Annex III point, Article 6(3) assessment, profiling and selected registration path.
- 01
Classify the use case and document the outcome
Assess Article 5, Article 6 and Annex III in that order and document purpose, context and any Article 6(3) exception.
What to retain
Article 6 and Annex III classification record
Traceable rationale covering intended purpose, Annex III category, Article 6(3) assessment and registration decision.
Control and reassessment
Reclassification on purpose or context change
Reopen classification when intended purpose, use context or system functionality changes materially.
Public tools
Annex III classification route
Public classifier for the high-risk use cases in Annex III.
Conditions and exceptions
- A listed Annex III system may fall outside high-risk under the strict conditions in Article 6(3), except where it profiles. The assessment and registration must be documented.
Official sources and locators
Digital Omnibus on AI 2026/1744
European Parliament and Council | official-journal-2026-07-24
Source locator: Amended Article 113, Article 6(2) and Annex III application date
EU Artificial Intelligence Act 2024/1689
European Parliament and Council | original-oj-2024-07-12
Source locator: Article 6 and Annex III
EU Artificial Intelligence Act 2024/1689
European Parliament and Council | original-oj-2024-07-12
Source locator: Article 6(2)-(4), Article 49 and Annex III
What changed in this
Moments when this obligation took effect, moved or received official guidance.
2028-08-02 | upcoming
High-risk AI embedded in regulated products
AI as a safety component of products under Annex I follows on 2 August 2028.
2027-12-02 | binding law
Annex III core rules moved to 2 December 2027
The amended application date has been binding law since 27 July 2026.
2026-05-19 | guidance
Draft guidelines on high-risk classification
The Commission explains in consultation when a system falls under Annex I or Annex III.
2025-07-29 | guidance
Guidelines on the definition of an AI system
The Commission draws the line between software that does and does not fall under the regulation.
What member states are doing with this
Dated signals from the enforcement tracker that refer to this obligation.
EU | 2026-07-27 | Europees Parlement en Raad
Digital Omnibus on AI (Regulation (EU) 2026/1744) enters into force
The Digital Omnibus on AI, adopted on 8 July 2026 and published in the Official Journal on 24 July 2026, enters into force on 27 July 2026. The regulation defers the obligations for stand-alone high-risk AI systems (Annex III) from 2 August 2026 to 2 December 2027 and for embedded high-risk systems (Annex I) from 2 August 2027 to 2 August 2028, and adds two prohibitions to Article 5 as of 2 December 2026 (non-consensual intimate imagery and AI-generated child sexual abuse material). This recalibrates the enforcement agenda of the Commission and the Member States.
France | 2023-12-27 | Commission Nationale de l’Informatique et des Libertés (CNIL)
CNIL fines Amazon France Logistique 32 million euros for employee monitoring
The CNIL fined Amazon France Logistique 32 million euros for an excessively intrusive system that tracked warehouse workers’ activity via scanners down to the second. Under the AI Act, algorithmic monitoring of workers is a high-risk use (Annex III, employment), with obligations applying from 2 December 2027.
Version history
v1.0.0
27 July 2026
Annex III: high-risk AI
Classification route for standalone high-risk AI systems under Article 6(2) and Annex III.
Execution
Record the classification in an AI register
A classification without a register and ownership is not demonstrable. Embed AI guides classification, register and reassessment in a fixed approach.
See the Embed AI approachFor AI agents and integrations
This page and the machine output derive from the same versioned object. Use the API for deterministic filters by role, topic and time.