Home · Glossary · Annex III high-risk AI
Enterprise AI glossary · Compliance & Regulation

Annex III high-risk AI

The schedule in the EU AI Act listing AI use cases automatically classified as high-risk — biometric ID, credit scoring, HR screening, healthcare diagnostic support, critical infrastructure, education, justice.

Definition

What Annex III high-risk AI means in practice

Annex III of the EU AI Act enumerates the AI use cases that are automatically classified as high-risk, triggering the full Articles 9–15 obligation stack. The categories include: biometric identification and categorisation, management of critical infrastructure, education and vocational training, employment and worker management, access to essential services (credit scoring is the canonical example), law enforcement, migration and border control, and the administration of justice and democratic processes. Healthcare diagnostic-support systems are high-risk via Annex III plus the Medical Devices Regulation route. Across MindMap's EU-exposed customer base, 30–50% of the enterprise AI portfolio sits in Annex III high-risk — substantially higher than the 5–10% leadership teams have typically been signalling internally.

Go deeper
EU AI Act compliance architecture →

All 62 terms, in plain language

Sovereign AI, RAG, agentic AI, IDP, MLOps and the regulations that shape enterprise AI.

Browse the glossary →Talk to an engineer →