Most explanations of the EU AI Act's high-risk rules stop at the same place. They list the eight categories in Annex III, biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and the administration of justice, and leave the reader to conclude that landing in one of these categories settles the question.

It does not. Category membership is only half the test, and the half most guidance skips is the one that actually decides whether a system carries the Act's heaviest obligations or almost none of them.

The test has two parts, not one

A system only counts as high-risk under the Annex III route if it does two things at once. First, it falls into one of the eight listed categories. Second, it performs the specific function that category's text describes, in a way that poses a significant risk to a person's health, safety, or fundamental rights.

That second part matters more than it looks. An AI tool can sit inside a high-risk category by subject matter and still fail to meet the risk threshold, and a provider is allowed to reach that conclusion itself, provided the assessment is documented properly rather than assumed.

The eight categories, briefly

Biometrics covers identification and categorisation of people using biometric data, along with emotion recognition. Critical infrastructure covers AI used as a safety component in managing digital infrastructure, road traffic, or the supply of water, gas, heating, or electricity. Education and vocational training covers systems that determine access to education or assess learning outcomes. Employment covers hiring, performance evaluation, promotion, and termination decisions. Essential services covers things like credit scoring and eligibility for public assistance. Law enforcement, migration and border control, and the administration of justice make up the remaining three, each covering AI used in ways that materially affect a person's legal standing or liberty.

None of this list is new information. It is the part that comes next that most summaries leave out.

The exception most guidance does not mention

Article 6(3) sets out four specific situations where a system that would otherwise sit in an Annex III category is not treated as high-risk, provided it does not materially influence the outcome of a decision. A system performing a narrow procedural task. A system improving the result of an activity a human has already completed. A system detecting patterns or deviations without replacing human judgement. A system carrying out preparatory work ahead of a human decision.

There is a catch that overrides all four, and it is worth being precise about. If the system profiles individuals, in the sense of automatically evaluating personal aspects such as behaviour, preferences, or characteristics, none of those four exceptions apply. The system is high-risk regardless, even if it otherwise looks like it is only doing a narrow, preparatory, or supporting task.

This is where a genuine amount of enterprise AI sits. A tool that scores CVs to help a recruiter shortlist candidates, rather than making the hiring decision itself, might look like it falls under "improving the result of a human activity." If it profiles candidates by their characteristics to produce that score, the exception does not rescue it. It is high-risk.

The documentation burden does not disappear either way

A provider who concludes their system qualifies for one of the four exceptions still has to document that assessment before putting the system on the market or into service, and register it in the EU database. Concluding you are not high-risk is not the same as having no obligation at all. It is a different, lighter obligation, not an absence of one.

Where this sits on the calendar now

The Annex III high-risk obligations were originally due to apply from 2 August 2026. Following the Digital Omnibus on AI, adopted by the European Parliament in June 2026, that date has moved to 2 December 2027. The separate Annex I route, covering AI that is a safety component of products already regulated under EU product law such as medical devices or machinery, now applies from 2 August 2028. What has not moved is worth knowing too: the prohibitions on unacceptable-risk AI have applied since February 2025, and the transparency obligations under Article 50 have applied since August 2025. Aligne has covered the full detail of what shifted and what did not separately, and it is worth reading alongside this piece rather than in place of it.

Classification is not a one-time exercise

A system assessed as falling under one of the Article 6(3) exceptions today can drift out of that exception without anyone deciding it should. A CV-screening tool introduced as a narrow scoring aid can quietly become the de facto hiring decision once recruiters stop reviewing every result individually. A system that was preparatory at launch can end up materially influencing outcomes eighteen months later, simply because it proved useful and nobody revisited the original assessment. This is the same gap that sits between design-time review and what a system does once it is live, and Annex III classification is a clean example of it. The classification made at launch is a snapshot. Whether it still holds is a question that needs asking again, not assumed to remain true indefinitely.

A short test worth running against your own AI inventory

For each AI system in use, two questions in sequence tend to surface the real answer faster than reading the Annex III text again. Does this system sit inside one of the eight categories, by subject matter, regardless of how it is used. If yes, does it profile individuals, or materially influence the outcome of a decision affecting them, rather than performing a narrow, preparatory, or purely supporting role. A yes to both is a high-risk system under the Act. A yes to the first and a properly documented no to the second is not, but still needs that documentation to exist.

Most organisations have never asked the second question in writing, because most summaries of Annex III never mention that it exists.

Common questions

If my AI system is not on the Annex III list at all, does that mean no EU AI Act obligations apply? Not necessarily. Systems outside Annex III can still trigger transparency obligations under Article 50, for example where a person is interacting with an AI system or where content is AI-generated. Annex III determines the high-risk tier specifically, not the entire Act.

Can the list of eight categories change? Yes. The European Commission can amend Annex III through delegated acts as new use cases emerge, under the process set out in Article 7. Today's list is not guaranteed to be tomorrow's.

Who decides whether a system meets the significant risk threshold, the provider or a regulator? The initial assessment is the provider's responsibility, documented before the system goes to market. That documentation is what a regulator would examine if the classification were later challenged, which is precisely why an undocumented assumption is a weak position to be in.

If your organisation has assumed that sitting inside an Annex III category automatically means high-risk, or the reverse, that a system outside those categories carries no obligations at all, both assumptions are common and both are worth checking properly rather than carrying forward unexamined. Aligne's platform, Altrum AI, is built to keep that classification current as systems evolve, rather than treating it as a decision made once and filed away. You can see how that works here.

Blog

Our latest news

Stay Informed: Engage with our Blog for Expert Analysis, Industry Updates, and Insider Perspectives

All Posts
Services Image
Building an Audit-Ready AI Environment: What You Need to Be Able to Show
Being able to govern AI and being able to prove it are different problems. Here is what UAE institutions need to evidence and why reconstructing it afterwards does not work.
Read Details
Services Image
Model Risk Management for UAE Banks and Insurers: What Changes When the Model Is AI
UAE financial institutions already have model risk frameworks. The CBUAE has now brought AI expressly within them. Here is where existing MRM holds, and where it strains.
Read Details
Services Image
Why Runtime AI Governance Is the Missing Layer in UAE Enterprise AI Strategy
Most UAE organisations govern AI up to the point of launch and stop. Here is why that gap is now the main obstacle to scaling AI, and what the missing layer looks like.
Read Details

Ready to Take the First Step?

let’s design the governance framework your AI strategy deserves

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
bg elementbg elementLet's Talk