Annex III EU AI Act: which systems count as high risk and what that means technically.
Annex III of the EU AI Act defines the eight use cases in which AI systems are classified as high risk. For companies in these areas, concrete documentation, transparency and testing obligations arise. This page explains the classification logic, the technical transparency requirements from Art. 50, and the infrastructure evidence an audit requires.
This page serves technical orientation purposes. Not legal advice. The assessment of regulatory obligations in a specific case is the responsibility of qualified legal and compliance advisors.
When an AI system counts as high risk
The EU AI Act uses a two-part classification approach. An AI system counts as high risk if it is used in one of the eight areas listed in Annex III and thereby has a potentially significant impact on the health, safety or fundamental rights of natural persons.
The classification applies regardless of company size, company location, and whether the system is developed in-house or sourced from a third-party provider. Companies that deploy high-risk AI systems as a deployer carry the deployer's obligations. Companies that develop or place such systems on the market carry the provider's obligations.
Another practically relevant dimension: companies acting as suppliers or software providers within a supply chain that feeds a high-risk system may be indirectly affected through the supply-chain integrity requirements.
The complete classification
Biometric identification and categorization
AI systems for the remote identification of natural persons in real time or retrospectively, and systems for biometric categorization. Covers access control systems, surveillance systems and identification platforms.
Infrastructure relevance: Systems processing biometric data are subject to particularly strict requirements on data integrity and access protection. The infrastructure layer is the first checkpoint in the conformity assessment.
Critical infrastructure
AI systems in the management and operation of critical infrastructure in energy, water, transport, waste management and digital infrastructure. Covers control systems, forecasting platforms and anomaly detection systems.
Infrastructure relevance: Operators of critical infrastructure are simultaneously subject to NIS2 requirements. The infrastructure layer of their AI systems is a subject of both requirement frameworks.
Education and vocational training
AI systems that decide access to educational institutions or the assessment of learners. Covers admission systems, exam evaluation platforms and adaptive learning systems with a scoring function.
Infrastructure relevance: Systems in this area process personal data in decision processes with long-term effect. Data source integrity is a central testing parameter.
Employment and personnel management
AI systems for candidate selection, promotion decisions, performance monitoring and termination. Covers ATS systems, matching algorithms and performance management platforms.
Infrastructure relevance: HR AI systems integrating external data sources such as job boards, LinkedIn or skills databases are subject to elevated data source validation requirements. Enterprise customers increasingly demand a demonstrable compliance status in the supply chain.
Essential private services and social benefits
AI systems in credit scoring, creditworthiness assessment, risk classification in insurance, and the allocation of social benefits. Covers banks, insurers, financial service providers and public authorities.
Infrastructure relevance: Financial service providers are simultaneously subject to DORA requirements. The technical infrastructure layer is a subject of both requirement frameworks. Systems integrating external market data, news feeds or third-party APIs are subject to elevated data source integrity requirements.
Law enforcement
AI systems for crime prediction, witness evaluation, lie-detection functions and evidence assessment. Covers public authorities and their technology suppliers.
Infrastructure relevance: Systems in this area are subject to the highest requirements for traceability and documentation. The cryptographic signature of the infrastructure evidence is a reliable anchor in testing processes.
Migration, asylum and border control
AI systems for the risk assessment of individuals, document verification, and support for asylum decisions. Covers public authorities and their technology suppliers.
Infrastructure relevance: Public authorities and their technology partners are under direct audit pressure. A verified infrastructure status is a robust proof point towards supervisory bodies, courts of audit and parliamentary oversight.
Justice and democratic processes
AI systems supporting judicial decisions, mediation, and influencing democratic political decision-making processes.
Infrastructure relevance: Systems in this area are subject to the most far-reaching requirements for transparency and traceability. Infrastructure documentation is the foundation of every external review procedure.
What Art. 50 technically requires for AI systems
Art. 50 EU AI Act defines the transparency obligations — disclosure of AI use (para. 1) and machine-readable labeling of AI-generated content (para. 2, only for providers of generative AI systems) — which apply from 2 August 2026. The requirements are anchored at the infrastructure layer.
Machine-readable labeling
AI-generated content must be labeled as artificially generated in a machine-readable format under Art. 50(2). Machine-readable declarations, DNS configuration and cryptographic signature infrastructure are audit-relevant parameters.
Traceable provenance
The origin and authenticity of the labeling is part of the regulatory requirement. Machine-readable declarations, verifiable data source configuration and consent declaration integrity are components of the transparency documentation.
Disclosure of AI use
AI systems that interact with natural persons or generate content must clearly disclose the AI use. HTTP security headers, DNSSEC, TLS certificate chain and CAA records form the testable base layer of verifiable disclosure.
Documented evidence
Fulfilment of the Art. 50 requirements must be documented. A conformity assessment requires a structured evidence document that can be handed to an external auditor or a notified body.
What a conformity assessment procedure requires
The Conformity Assessment Dossier for high-risk AI systems under Annex III requires several components. The technical infrastructure evidence is one of them.
A complete dossier includes the technical documentation of the system, the risk assessment, the description of the quality management systems, the data management documentation, and the proof of technical infrastructure integrity.
CERTavia delivers the technical infrastructure component for this dossier: a PDF audit report with a structured presentation of the tested infrastructure parameters, cryptographic signature and Sovereign Vault link. The report can be integrated into the Conformity Assessment Dossier as a self-contained, traceable process step.
Preparing a complete Conformity Assessment Dossier requires qualified legal and compliance advice. CERTavia expressly does not replace this advice.
Is your system affected?
The CERTavia EU AI Act quick test evaluates the Annex III risk in under two minutes. Cross-industry and sector-specific screening for financial service providers, healthcare, HR and the public sector. No form, no registration.
Further reading
Risk classes, enforcement phases and technical infrastructure implications at a glance.
NIS2 and DORA: regulatory overlaps →Where the EU AI Act, NIS2 and DORA meet at the same infrastructure layer.
CERTavia offers and pricing →From the free Quick Scan to the Enterprise package with API access.
CERTavia for compliance teams →Structured documentation for audits under the EU AI Act, NIS2 and DORA.
Scan your domain for free →No form, no registration. Result in 90 seconds.
EU AI Act Article 50 – transparency obligations from August 2026 →What chatbot labeling, deepfake declaration and AI content marking concretely mean.
NIS2 and high-risk AI: who is affected? (Blog) →Which industries fall under NIS2 and how Annex III classification and NIS2 scope overlap.
Does your AI system fall under Annex III? Check it in 2 minutes.
The free quick test assesses, based on your sector and use case, whether your system falls under the high-risk obligations of the EU AI Act — no login, no registration.
Go to the Annex III quick test Go directly to the domain checkQuestions about Annex III and high-risk AI
What are high-risk AI systems under Annex III?
High-risk AI systems under Annex III EU AI Act are AI applications in eight defined areas: biometrics, critical infrastructure, education, employment, financial and social services, law enforcement, migration and justice. Companies that operate or place AI on the market in these areas are subject to expanded documentation, transparency and testing obligations under Art. 9-15 EU AI Act — regardless of company size or location.
What risk tiers does the EU AI Act define?
The EU AI Act distinguishes four tiers: 1) Unacceptable risk — banned (social scoring, biometric mass surveillance). 2) High risk (Annex III) — comprehensive obligations under Art. 9-15, incl. Conformity Assessment Dossier. 3) Limited risk — transparency obligations under Art. 50 (chatbots, deepfakes). 4) Minimal risk — no separate regulatory obligations. Annex III systems carry the most far-reaching requirements.
Which industries are particularly affected by Annex III?
Particularly affected are: financial service providers (credit scoring, creditworthiness assessment), healthcare (diagnostic AI, triage systems), HR software providers (candidate selection, performance monitoring), operators of critical infrastructure (energy, water, transport), and B2B SaaS providers whose systems are used by EU companies in high-risk areas. The Annex III quick test checks applicability for your specific use case.
From when do the high-risk obligations under Annex III apply?
The AI Omnibus (finally adopted by the Council on 29 June 2026) postponed application of the high-risk obligations: Annex III applies from 2 December 2027, Annex I from 2 August 2028. From 2 August 2026, the transparency obligations under Art. 50 apply first. National market surveillance in Germany is being built up via the AI Market Surveillance and Innovation Act (KI-MIG), whose draft bill designates the BNetzA as the central authority. Companies should use the transition period to build a complete Conformity Assessment Dossier. Breaches of the high-risk obligations can be sanctioned under Art. 99 EU AI Act with fines of up to 15 million euros or 3 % of global annual turnover (whichever is higher); the higher framework of 35 million euros or 7 % applies exclusively to prohibited practices under Art. 5.
Is this an official certification?
No. CERTavia does not issue an officially recognized certificate. The SOVP evidence delivers the technical infrastructure part of the Conformity Assessment Dossier — cryptographically signed and directly verifiable by auditors. More in the glossary →
What happens if my infrastructure changes?
A SOVP scan is a snapshot at the time of testing. In case of substantial infrastructure changes, we recommend a new scan — especially before audits and after major changes such as hosting migration, new certificates or DNS changes.
What is the difference between the quick test and a domain scan?
The quick test assesses, based on sector membership and use case, whether your AI system falls under Annex III — that is a regulatory classification, not a technical measurement. The domain scan checks the technical infrastructure of your domain against 80+ parameters and delivers the cryptographically signed evidence for Art. 50.
Infrastructure evidence for Annex III systems
CERTavia delivers the technical infrastructure component for the conformity documentation of high-risk AI systems. The Full Scan produces a PDF audit report with cryptographic signature and Sovereign Vault link in 90 to 120 seconds.
Scan your domain now
Full Scan with PDF audit report, cryptographic signature and Sovereign Vault link. In 90 to 120 seconds.
Scan your domain now – freeEnterprise & custom requirements
For complex organizational structures or custom requirements, the contact form is available.
Get in touchCERTavia analyzes technical infrastructure signals. The result is a machine-readable finding, not a legal opinion and not a certification in the sense of the EU AI Act conformity assessment under Article 43. For legally binding compliance assessments, consult an accredited conformity assessment body.
This page serves technical orientation purposes. Not legal advice. The description of the EU AI Act and Annex III reflects the state of knowledge at the time of publication. Regulatory requirements continue to evolve. The full classification and the assessment of specific obligations in individual cases are the responsibility of qualified legal and compliance advisors. CERTavia delivers technical infrastructure validation based on the Sovereign Validation Protocol (SOVP, Patent Pending No. 64/005,737).