August 25, 2026
Building an Audit-Ready AI Environment: What You Need to Be Able to ShowMost explanations of the EU AI Act's high-risk rules stop at the same place. They list the eight categories in Annex III, biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and the administration of justice, and leave the reader to conclude that landing in one of these categories settles the question.
It does not. Category membership is only half the test, and the half most guidance skips is the one that actually decides whether a system carries the Act's heaviest obligations or almost none of them.
A system only counts as high-risk under the Annex III route if it does two things at once. First, it falls into one of the eight listed categories. Second, it performs the specific function that category's text describes, in a way that poses a significant risk to a person's health, safety, or fundamental rights.
That second part matters more than it looks. An AI tool can sit inside a high-risk category by subject matter and still fail to meet the risk threshold, and a provider is allowed to reach that conclusion itself, provided the assessment is documented properly rather than assumed.
Biometrics covers identification and categorisation of people using biometric data, along with emotion recognition. Critical infrastructure covers AI used as a safety component in managing digital infrastructure, road traffic, or the supply of water, gas, heating, or electricity. Education and vocational training covers systems that determine access to education or assess learning outcomes. Employment covers hiring, performance evaluation, promotion, and termination decisions. Essential services covers things like credit scoring and eligibility for public assistance. Law enforcement, migration and border control, and the administration of justice make up the remaining three, each covering AI used in ways that materially affect a person's legal standing or liberty.
None of this list is new information. It is the part that comes next that most summaries leave out.
Article 6(3) sets out four specific situations where a system that would otherwise sit in an Annex III category is not treated as high-risk, provided it does not materially influence the outcome of a decision. A system performing a narrow procedural task. A system improving the result of an activity a human has already completed. A system detecting patterns or deviations without replacing human judgement. A system carrying out preparatory work ahead of a human decision.
There is a catch that overrides all four, and it is worth being precise about. If the system profiles individuals, in the sense of automatically evaluating personal aspects such as behaviour, preferences, or characteristics, none of those four exceptions apply. The system is high-risk regardless, even if it otherwise looks like it is only doing a narrow, preparatory, or supporting task.
This is where a genuine amount of enterprise AI sits. A tool that scores CVs to help a recruiter shortlist candidates, rather than making the hiring decision itself, might look like it falls under "improving the result of a human activity." If it profiles candidates by their characteristics to produce that score, the exception does not rescue it. It is high-risk.
A provider who concludes their system qualifies for one of the four exceptions still has to document that assessment before putting the system on the market or into service, and register it in the EU database. Concluding you are not high-risk is not the same as having no obligation at all. It is a different, lighter obligation, not an absence of one.
The Annex III high-risk obligations were originally due to apply from 2 August 2026. Following the Digital Omnibus on AI, adopted by the European Parliament in June 2026, that date has moved to 2 December 2027. The separate Annex I route, covering AI that is a safety component of products already regulated under EU product law such as medical devices or machinery, now applies from 2 August 2028. What has not moved is worth knowing too: the prohibitions on unacceptable-risk AI have applied since February 2025, and the transparency obligations under Article 50 have applied since August 2025. Aligne has covered the full detail of what shifted and what did not separately, and it is worth reading alongside this piece rather than in place of it.
A system assessed as falling under one of the Article 6(3) exceptions today can drift out of that exception without anyone deciding it should. A CV-screening tool introduced as a narrow scoring aid can quietly become the de facto hiring decision once recruiters stop reviewing every result individually. A system that was preparatory at launch can end up materially influencing outcomes eighteen months later, simply because it proved useful and nobody revisited the original assessment. This is the same gap that sits between design-time review and what a system does once it is live, and Annex III classification is a clean example of it. The classification made at launch is a snapshot. Whether it still holds is a question that needs asking again, not assumed to remain true indefinitely.
For each AI system in use, two questions in sequence tend to surface the real answer faster than reading the Annex III text again. Does this system sit inside one of the eight categories, by subject matter, regardless of how it is used. If yes, does it profile individuals, or materially influence the outcome of a decision affecting them, rather than performing a narrow, preparatory, or purely supporting role. A yes to both is a high-risk system under the Act. A yes to the first and a properly documented no to the second is not, but still needs that documentation to exist.
Most organisations have never asked the second question in writing, because most summaries of Annex III never mention that it exists.
If my AI system is not on the Annex III list at all, does that mean no EU AI Act obligations apply? Not necessarily. Systems outside Annex III can still trigger transparency obligations under Article 50, for example where a person is interacting with an AI system or where content is AI-generated. Annex III determines the high-risk tier specifically, not the entire Act.
Can the list of eight categories change? Yes. The European Commission can amend Annex III through delegated acts as new use cases emerge, under the process set out in Article 7. Today's list is not guaranteed to be tomorrow's.
Who decides whether a system meets the significant risk threshold, the provider or a regulator? The initial assessment is the provider's responsibility, documented before the system goes to market. That documentation is what a regulator would examine if the classification were later challenged, which is precisely why an undocumented assumption is a weak position to be in.
If your organisation has assumed that sitting inside an Annex III category automatically means high-risk, or the reverse, that a system outside those categories carries no obligations at all, both assumptions are common and both are worth checking properly rather than carrying forward unexamined. Aligne's platform, Altrum AI, is built to keep that classification current as systems evolve, rather than treating it as a decision made once and filed away. You can see how that works here.
Stay Informed: Engage with our Blog for Expert Analysis, Industry Updates, and Insider Perspectives
.png)
.png)
.png)
let’s design the governance framework your AI strategy deserves
.webp)
Let's Talk