Guide
High-risk AI systems under Annex III: classification examples
Annex III lists the domains in which an AI system is presumptively high-risk: biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration and border control, and administration of justice. But falling into one of these domains isn't automatic — the Act also allows a narrow-task carve-out under Article 6(3) for systems that only perform a limited procedural task, improve a completed human decision, detect patterns without replacing human judgment, or do preparatory work, without profiling individuals.
Below are simplified, side-by-side examples in each domain — one that's likely high-risk, and one that likely qualifies for the narrow-task carve-out. Real classification depends on the specific system's design and role, not just its domain.
Employment
Likely high-risk: An AI system that screens or ranks job applicants' CVs for a recruiter.
Likely narrow-task / not high-risk: An AI system that only checks CVs for spelling errors before a human reviews them.
Credit and essential services
Likely high-risk: An AI system that determines an individual's creditworthiness for a loan decision.
Likely narrow-task / not high-risk: An AI system that flags potentially fraudulent transactions for a human analyst to investigate.
Education
Likely high-risk: An AI system used to evaluate students in a way that affects their access to education.
Likely narrow-task / not high-risk: An AI system that generates practice quiz questions from a textbook, with no bearing on grades.
Law enforcement / migration
Likely high-risk: An AI system used to assess the risk of an individual reoffending.
Likely narrow-task / not high-risk: An AI system used for administrative case-routing with no assessment of individuals.
Critical infrastructure
Likely high-risk: An AI system acting as a safety component in the management of critical digital infrastructure.
Likely narrow-task / not high-risk: An AI system generating internal engineering documentation with no operational control role.
If your system sits in one of these domains and doesn't clearly qualify for the narrow-task carve-out, it's worth treating it as high-risk for planning purposes and starting on Annex IV documentation — see our Annex IV explainer for what that involves.
Get a directional read on your own system
The free risk checker walks through Article 5 and Annex III in a few minutes — no signup required.
Check now →