Annex III high-risk AI
The schedule in the EU AI Act listing AI use cases automatically classified as high-risk — biometric ID, credit scoring, HR screening, healthcare diagnostic support, critical infrastructure, education, justice.
What Annex III high-risk AI means in practice
Annex III of the EU AI Act enumerates the AI use cases that are automatically classified as high-risk, triggering the full Articles 9–15 obligation stack. The categories include: biometric identification and categorisation, management of critical infrastructure, education and vocational training, employment and worker management, access to essential services (credit scoring is the canonical example), law enforcement, migration and border control, and the administration of justice and democratic processes. Healthcare diagnostic-support systems are high-risk via Annex III plus the Medical Devices Regulation route. Across MindMap's EU-exposed customer base, 30–50% of the enterprise AI portfolio sits in Annex III high-risk — substantially higher than the 5–10% leadership teams have typically been signalling internally.
Related terms
EU AI Act →
The European Union's AI Act — risk-tiered regulation of AI systems, with high-risk-system requirements that effectively mandate auditability, human oversight and conformity assessment.
Article 14 (Human Oversight) →
The EU AI Act provision requiring high-risk AI systems to be designed for effective human oversight, including the human's ability to fully understand, decide not to use, and override the system's output.
Article 25 (Provider vs Deployer) →
The EU AI Act provision that converts a deployer of an AI system into a provider — and therefore subject to the full Articles 9–15 stack — when they make substantial modifications, rebrand, or change the intended purpose.
GPAI (General-Purpose AI) →
The EU AI Act category covering general-purpose AI models (foundation LLMs) — Article 53 sets baseline obligations on every provider, Article 55 adds systemic-risk obligations above a 10^25 FLOP training-compute threshold.
More in this category
All 62 terms, in plain language
Sovereign AI, RAG, agentic AI, IDP, MLOps and the regulations that shape enterprise AI.