Knowledge Centre
Annex IIITrust & Compliance··4 min read

Annex III of the EU AI Act, in plain English

Most of the EU AI Act’s weight hangs on a list. Not a definition of intelligence, not a threshold of computing power: a list of uses, sitting in an annex near the back of the law. If your AI does something on the list, nearly everything the Act demands applies to you. If it does not, very little does. That makes Annex III the page most worth reading, and it is considerably more readable than its name suggests.

What the list covers, in ordinary language

Annex III names the use cases the EU treats as high risk. In plain terms it covers: biometric systems that identify or categorise people or infer their emotions; AI running safety functions of critical infrastructure such as power, water and transport; education, where AI decides admissions, grades work or watches over exams; employment and the management of workers; access to essential services, public and private, where AI helps decide who gets benefits, credit or certain kinds of insurance, and how emergency calls are triaged; law enforcement; migration and border control; and the administration of justice and elections. The thread joining them is not a technology. It is a situation: a person on the receiving end of an institutional decision they cannot easily contest, made or shaped by a system they cannot see.

Why employment is on the list

The employment entry covers AI used to recruit and select people: placing targeted job advertisements, screening and filtering applications, evaluating candidates. It equally covers AI used on people already in work: informing decisions on promotion or termination, allocating tasks on the basis of behaviour or personal traits, monitoring and evaluating performance. The reasoning is not mysterious. Work is how most people secure their livelihood; the power balance between an applicant and an algorithmic filter is entirely one-sided; and a biased screening model does not make one unfair decision, it makes the same unfair decision at scale, silently. For people businesses (recruitment firms, staffing providers, outsourcers) this entry is the reason the Act is not someone else’s regulation. Screening, matching, evaluating and scheduling people is the product.

The honest question: in scope, and says who?

Annex III does not answer the question that matters inside a firm; it poses it. The Act allows that a system operating in a listed area may still fall outside high risk if it does not materially shape the outcome: if it performs a narrow procedural step, tidies work a human has already completed, or flags patterns for a human who retains the real assessment. But profiling of people keeps a system firmly in the high-risk tier, and the judgement that a system falls outside must itself be documented and defensible. Annex III is not a verdict on your technology. It is a question addressed to your organisation: does what we do with this system appear on the list, and who here decided our answer? A firm that cannot name the person who made that call, the date, and the reasoning has not made a scoping decision; it has made an assumption, and assumptions are not documentation. None of this is legal advice, and scope calls at the boundary deserve a lawyer. What no lawyer can supply is the inventory of uses and the record of who decided what. That part is on the firm.

One concrete example

Clearly illustrative, with no customer implied. A staffing firm uses one product that does two things: it parses CVs into structured fields, and it ranks the parsed candidates against the role. Asked whether the tool is in scope, the honest answer is two answers. Parsing a CV into fields is arguably a narrow procedural task that shapes no outcome. Ranking candidates is candidate evaluation, in the employment entry’s own words. The firm records both conclusions, names the operations director who made them, notes the grounds, gates the ranking behind human review, and diaries the assessment for re-examination when the vendor next ships a model change. That is what readiness looks like: not certainty, but a decision with a name and a date on it.

Annex III and decision intelligence

The discipline Annex III forces on a firm (know your uses, decide their status, record who decided, revisit) is decision provenance applied to your own tools. The scope call is a decision like any consequential decision: it deserves its evidence, its owner and its audit trail. ONX takes the strict reading for its own platform: candidate matching in Hiring is treated as high risk, with human review gates, and its AI is kept explainable and challengeable, precisely so the oversight the Act asks for has something real to work on. That is decision intelligence pointed at the decisions a firm makes about its own machines.

Common questions

What is Annex III of the EU AI Act?

Annex III is the list of use cases the EU AI Act treats as high risk. It covers biometric systems, safety functions of critical infrastructure, education, employment and worker management, access to essential public and private services such as credit and benefits, law enforcement, migration and border control, and the administration of justice and elections. AI used in these areas is permitted but must meet the Act’s high-risk obligations, such as risk management, logging and human oversight.

Why are recruitment and employment decisions listed in Annex III?

Because work is how most people secure their livelihood, the power balance between an applicant or employee and an algorithmic system is one-sided, and an unfair screening or monitoring model repeats its unfairness at scale. The employment entry covers AI that places targeted job adverts, screens or filters applications and evaluates candidates, and AI used in decisions on promotion, termination, task allocation and performance monitoring.

Can a system used in an Annex III area avoid being high risk?

Sometimes. The Act allows that a system in a listed area may fall outside high risk if it does not materially influence the outcome, for example because it performs a narrow procedural task or supports a human who retains the real assessment. Profiling of people always remains high risk, and the conclusion that a system is out of scope must be documented and defensible. This is educational context, not legal advice.

Who decides whether our use of AI falls under Annex III?

The organisation itself must take that position and be able to defend it; regulators do not pre-clear each tool. In practice that means keeping an inventory of AI uses, assessing each against the listed use cases, naming the person who made each call, recording the grounds, and revisiting the assessment when the tool or its use changes. A scope decision nobody owns and nobody wrote down is an assumption, not an assessment.

Part of the pillarEnterprise Decision Intelligence, the complete philosophy in one essay

Related reading