Annex III - High-Risk AI Systems
Training Note: This is one of the most important annexes, listing specific use cases classified as high-risk (employment, education, law enforcement, migration, justice, critical infrastructure, etc.). Organizations must check if their AI systems fall into any of these categories to determine their compliance obligations.
ANNEX III
High-Risk AI Systems Referred to in Article 6(2)
High-risk AI systems pursuant to Article 6(2) are the AI systems listed in any of the following areas:
1. Biometrics
In so far as their use is permitted under relevant Union or national law:
-
(a) Remote biometric identification systems.
This shall not include AI systems intended to be used for biometric verification the sole purpose of which is to confirm that a specific natural person is the person he or she claims to be;
-
(b) AI systems intended to be used for biometric categorisation, according to sensitive or protected attributes or characteristics based on the inference of those attributes or characteristics;
-
(c) AI systems intended to be used for emotion recognition.
2. Critical Infrastructure
AI systems intended to be used as safety components in the management and operation of:
- Critical digital infrastructure
- Road traffic
- Supply of water, gas, heating or electricity
3. Education and Vocational Training
-
(a) AI systems intended to be used to determine access or admission or to assign natural persons to educational and vocational training institutions at all levels;
-
(b) AI systems intended to be used to evaluate learning outcomes, including when those outcomes are used to steer the learning process of natural persons in educational and vocational training institutions at all levels;
-
(c) AI systems intended to be used for the purpose of assessing the appropriate level of education that an individual will receive or will be able to access, in the context of or within educational and vocational training institutions at all levels;
-
(d) AI systems intended to be used for monitoring and detecting prohibited behaviour of students during tests in the context of or within educational and vocational training institutions at all levels.
4. Employment, Workers' Management and Access to Self-Employment
-
(a) AI systems intended to be used for the recruitment or selection of natural persons, in particular to:
- Place targeted job advertisements
- Analyse and filter job applications
- Evaluate candidates
-
(b) AI systems intended to be used to make decisions affecting:
- Terms of work-related relationships
- Promotion or termination of work-related contractual relationships
- Task allocation based on individual behaviour or personal traits or characteristics
- Monitoring and evaluating the performance and behaviour of persons in such relationships
5. Access to and Enjoyment of Essential Private Services and Essential Public Services and Benefits
-
(a) AI systems intended to be used by public authorities or on behalf of public authorities to evaluate the eligibility of natural persons for:
- Essential public assistance benefits and services, including healthcare services
- To grant, reduce, revoke, or reclaim such benefits and services
-
(b) AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud;
-
(c) AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance;
-
(d) AI systems intended to evaluate and classify emergency calls by natural persons or to be used to dispatch, or to establish priority in the dispatching of:
- Emergency first response services (police, firefighters, medical aid)
- Emergency healthcare patient triage systems
6. Law Enforcement
In so far as their use is permitted under relevant Union or national law:
-
(a) AI systems intended to be used by or on behalf of law enforcement authorities, or by Union institutions, bodies, offices or agencies in support of law enforcement authorities to assess the risk of a natural person becoming the victim of criminal offences;
-
(b) AI systems intended to be used by or on behalf of law enforcement authorities or by Union institutions, bodies, offices or agencies in support of law enforcement authorities as polygraphs or similar tools;
-
(c) AI systems intended to be used by or on behalf of law enforcement authorities, or by Union institutions, bodies, offices or agencies, in support of law enforcement authorities to evaluate the reliability of evidence in the course of the investigation or prosecution of criminal offences;
-
(d) AI systems intended to be used by law enforcement authorities or on their behalf or by Union institutions, bodies, offices or agencies in support of law enforcement authorities for assessing the risk of a natural person offending or re-offending not solely on the basis of the profiling of natural persons as referred to in Article 3(4) of Directive (EU) 2016/680, or to assess personality traits and characteristics or past criminal behaviour of natural persons or groups;
-
(e) AI systems intended to be used by or on behalf of law enforcement authorities or by Union institutions, bodies, offices or agencies in support of law enforcement authorities for the profiling of natural persons as referred to in Article 3(4) of Directive (EU) 2016/680 in the course of the detection, investigation or prosecution of criminal offences.
7. Migration, Asylum and Border Control Management
In so far as their use is permitted under relevant Union or national law:
-
(a) AI systems intended to be used by or on behalf of competent public authorities or by Union institutions, bodies, offices or agencies as polygraphs or similar tools;
-
(b) AI systems intended to be used by or on behalf of competent public authorities or by Union institutions, bodies, offices or agencies to assess a risk, including:
- A security risk
- A risk of irregular migration
- A health risk
posed by a natural person who intends to enter or who has entered into the territory of a Member State;
-
(c) AI systems intended to be used by or on behalf of competent public authorities or by Union institutions, bodies, offices or agencies to assist competent public authorities for the examination of applications for asylum, visa or residence permits and for associated complaints with regard to the eligibility of the natural persons applying for a status, including related assessments of the reliability of evidence;
-
(d) AI systems intended to be used by or on behalf of competent public authorities, or by Union institutions, bodies, offices or agencies, in the context of migration, asylum or border control management, for the purpose of detecting, recognising or identifying natural persons, with the exception of the verification of travel documents.
8. Administration of Justice and Democratic Processes
-
(a) AI systems intended to be used by a judicial authority or on their behalf to assist a judicial authority in researching and interpreting facts and the law and in applying the law to a concrete set of facts, or to be used in a similar way in alternative dispute resolution;
-
(b) AI systems intended to be used for influencing the outcome of an election or referendum or the voting behaviour of natural persons in the exercise of their vote in elections or referenda. This does not include AI systems to the output of which natural persons are not directly exposed, such as tools used to organise, optimise or structure political campaigns from an administrative or logistical point of view.