What are the EU AI Act's Annex III high-risk domains?
Annex III of the EU AI Act lists eight domains in which an AI system is classified as high-risk, triggering obligations including Annex IV technical documentation, a conformity assessment, and ongoing monitoring.
The eight domains
1) Biometric identification or categorization of people. 2) Management or operation of critical infrastructure (energy, water, transport, digital infrastructure). 3) Education or vocational training — e.g. exam scoring, admissions decisions, monitoring students. 4) Employment, worker management, and access to self-employment — e.g. CV screening, promotion or termination decisions. 5) Access to essential private and public services — credit scoring, insurance pricing, benefits eligibility, emergency dispatch. 6) Law enforcement (outside the separately-prohibited real-time biometric identification use case). 7) Migration, asylum, and border control management. 8) Administration of justice and democratic processes.
The narrow-task exception
Article 6(3) allows a system that falls within one of these domains to avoid high-risk classification if it only performs a narrow procedural task, improves the result of an already-completed human decision, detects patterns without replacing human judgment, or does preparatory work — without profiling individuals. This is a real exception worth checking carefully, not a loophole to assume applies by default.
Current compliance timeline
Following the 2026 Digital Omnibus amendment (Regulation (EU) 2026/1744), the compliance deadline for Annex III high-risk obligations is now December 2, 2027 — pushed back from the original August 2026 date. Annex I (product-embedded) high-risk systems have until August 2, 2028.