High-risk systems and Annex III

Whether a system is high-risk turns on Article 6 and the Annex III list, with an exclusion filter that can bring it back out again.

An AI system is high-risk if it is a safety component of an Annex I product, or falls in an Annex III area and is not excluded by Article 6(3). The obligations are deferred to 2 December 2027 and 2 August 2028.

High-risk is defined in Article 6 of Regulation (EU) 2024/1689, with the areas listed in Annex III. It only matters once you are within scope, so settle that first: a UK organisation with no EU customers, users or outputs used in the EU is not bound today (Article 2). The UK scope guide covers the test.

What makes a system high-risk?

Article 6 sets two routes. The first is product-embedded: an AI system that is a safety component of a product covered by the Annex I harmonisation legislation in Section A of that annex, such as medical devices, toys, lifts, radio equipment or in-vitro diagnostics, where the product needs a third-party conformity assessment. The second is stand-alone: a system used in one of the areas listed in Annex III.

Products in Section B of Annex I follow a different rule. For vehicles, aviation, marine equipment, rail and, since Regulation (EU) 2026/1744, machinery, only Article 6(1), Article 60a and Articles 102 to 112 apply (Article 2(2)), and the Act’s requirements reach the product through its own EU law. AI used only for user assistance, performance, efficiency, automation, convenience or quality control is not a safety component at all, unless its failure would endanger health or safety (Article 6(1a) and (1b)).

The two routes matter because their obligations arrive on different dates. Settle which route, if any, a system takes before you treat it as high-risk.

What is in Annex III?

Annex III lists eight areas: biometrics; critical infrastructure; education and vocational training; employment and worker management; access to essential private and public services, including creditworthiness and insurance pricing; law enforcement; migration, asylum and border control; and the administration of justice and democratic processes.

Employment is usually the area a UK organisation recognises first, because it expressly covers recruitment, screening, promotion, termination, task allocation and monitoring. The omnibus did not change the categories, so a classification you make now still holds.

What does Article 6(3) exclude?

Article 6(3) lets a system that falls in an Annex III area out of the high-risk category where it does not pose a significant risk of harm to health, safety or fundamental rights. It applies where the system performs a narrow procedural task, improves the result of a completed human activity, detects decision-making patterns without replacing or influencing a human assessment without review, or performs a preparatory task.

There is one hard override: a system that profiles natural persons is always high-risk, whatever else it does. So the exclusion is real but conditional, and any Annex III system you rely on it for should carry a recorded assessment of why it qualifies.

When do the obligations actually bite?

They are deferred, not cancelled. Annex III stand-alone high-risk obligations apply from 2 December 2027, and Annex I product-embedded high-risk obligations from 2 August 2028, under Regulation (EU) 2026/1744, a one-year deferral of the product-embedded track. Public-authority high-risk systems already in use have until 2 August 2030.

The later date is a reason to classify now, not to wait. The categories are settled, so the system that will be high-risk in 2027 is high-risk in substance today, and knowing which of yours sit on the deferred track is the work you can do before the obligations attach. The post-omnibus timeline has the dates, and you can download it as a one-page PDF.

What should you do before then?

Do the classification. For each AI system, work out whether it takes the Annex I or Annex III route, and where Annex III applies, whether Article 6(3) takes it back out and why. Watch Article 25: a deployer that substantially modifies a high-risk system, or puts its own name on it, becomes a provider and inherits the full provider obligation set.

Rather than build a separate risk-assessment spreadsheet, run the systems through the EU AI Act check: it asks the Annex III and Annex I questions and returns which of your systems sit on which track, with the dates attached. Then read the conformity assessment guide for what a high-risk classification leads to.

Common questions

What makes an AI system high-risk?
Article 6 sets two routes. A system is high-risk if it is a safety component of a product covered by the Annex I harmonisation legislation, or if it falls in one of the areas listed in Annex III. Article 6(3) then lets some Annex III systems out again where they do not pose a significant risk, unless they profile natural persons.
What is in Annex III?
Annex III lists eight areas of stand-alone high-risk use: biometrics; critical infrastructure; education and vocational training; employment and worker management; access to essential private and public services, including creditworthiness and insurance pricing; law enforcement; migration, asylum and border control; and the administration of justice and democratic processes. The omnibus did not change the categories.
When do the high-risk obligations actually apply?
They are deferred, not cancelled. Annex III stand-alone high-risk obligations apply from 2 December 2027, and Annex I product-embedded high-risk obligations from 2 August 2028, under Regulation (EU) 2026/1744. The classification test is worth doing now, because the categories have not changed and the dates arrive on schedule.