Annex III explained for banks and insurers: which AI agents are high-risk

Annex III of the EU AI Act, Regulation (EU) 2024/1689, makes an AI system high-risk because of what it is used for, not how it is built. Read cold, the EU AI Act high-risk Annex III list looks written for police forces, border agencies and schools, and most of it was. Two of its eight points reach banks and insurers head-on, a few reach them through the back office, and the rest do not reach them at all. Every point describes systems intended for a purpose, so classification is a decision about a use, taken per system and written down.

1. Biometrics

  1. Biometrics ...: (a) remote biometric identification systems. This shall not include AI systems intended to be used for biometric verification the sole purpose of which is to confirm that a specific natural person is the person he or she claims to be; ... (c) AI systems intended to be used for emotion recognition. (Annex III, point 1)

A selfie matched against the photo on an identity document at onboarding, or a face or voice check to open the app, is biometric verification. Its sole purpose is to confirm that the customer is who they claim to be, so it is outside point 1(a). Point 1(c) has no such exclusion. A bank whose call-centre platform scores the caller's voice for stress or deception and routes the call on that score runs an emotion recognition system, and it is high-risk. Pointing the same tool at staff is prohibited by Article 5(1)(f), which bans emotion inference in the workplace except for medical or safety reasons. For an insurer, a policyholder unlocking the claims portal by face is verification, excluded; a video claims interview analysed for facial expressions to detect a false statement is emotion recognition, high-risk.

2. Critical infrastructure

  1. Critical infrastructure: AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, or in the supply of water, gas, heating or electricity. (Annex III, point 2)

This point does not reach a bank or an insurer. Payment and policy administration systems are critical to the institution, but they are not the critical digital infrastructure this point means, and Article 6(1a) adds that a system used solely for performance optimisation, service efficiency, automation, convenience or quality control is not a safety component. Their resilience is the ground of DORA, Regulation (EU) 2022/2554, applied to financial entities since 17 January 2025.

3. Education and vocational training

  1. Education and vocational training: (a) AI systems intended to be used to determine access or admission or to assign natural persons to educational and vocational training institutions at all levels; (b) AI systems intended to be used to evaluate learning outcomes ... (Annex III, point 3)

This point does not reach a bank or an insurer as such. Every limb is tied to educational and vocational training institutions, and an internal learning platform that assigns compliance modules and marks the quiz is not one. The edge case is a group that operates a registered training body for the mandatory training of its tied agents or brokers: an agent that grades those examinations falls under point 3(b).

4. Employment and workers management

  1. Employment, workers’ management and access to self-employment: (a) AI systems intended to be used for the recruitment or selection of natural persons, in particular ... to analyse and filter job applications, and to evaluate candidates; (b) AI systems intended to be used ... to allocate tasks based on individual behaviour ... or to monitor and evaluate the performance and behaviour of persons in such relationships. (Annex III, point 4)

This point reaches every large employer. A bank whose recruiting copilot filters and scores applications before a human sees them runs a point 4(a) system; that the final choice is human does not take it out. An insurer that allocates claims files to handlers on each handler's speed and past decisions, or scores customer-service calls to feed appraisals, runs a point 4(b) system. Article 6(3) can take out a tool that only converts CVs into a structured form, not one that ranks people on inferred traits: that is profiling.

5. Access to essential private and public services

  1. Access to and enjoyment of essential private services and essential public services and benefits: ... (b) AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud; (c) AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance; ... (Annex III, point 5)

For a bank, point 5(b) covers the lending assistant that pre-approves a consumer loan in the app, the mortgage agent that returns a decision or a score, and the instalment decision at checkout. It covers natural persons: a model that rates a company is not in this point, a model that rates a sole trader is. And it excludes systems used to detect financial fraud, where transaction-fraud and anti-money-laundering models sit.

For an insurer, point 5(c) covers the underwriting agent that reads a health questionnaire and prices a term-life policy, and the pricing engine of a health cover. It is limited to life and health, and to risk assessment and pricing: a motor or home pricing model is not in it, and by the words of the text a claims agent is not either. The two limbs cross over: a bank selling life insurance at the counter deploys a point 5(c) system, and an insurer deciding whether a customer may pay the premium in instalments deploys a point 5(b) system.

6. Law enforcement

  1. Law enforcement ...: (a) AI systems intended to be used by or on behalf of law enforcement authorities ... to assess the risk of a natural person becoming the victim of criminal offences; ... (Annex III, point 6)

This point does not reach a bank or an insurer. Every limb requires use by or on behalf of a law enforcement authority. Anti-money-laundering monitoring and suspicious transaction reports are obligations the bank carries in its own name, and an insurer's fraud unit works the same way. What reaches both is Article 5(1)(d), which applies to anyone: it prohibits predicting the risk of a person committing a criminal offence from profiling or personality traits alone. A monitoring model that works from transaction facts is on the right side of that line.

7. Migration, asylum and border control

  1. Migration, asylum and border control management ...: ... (b) AI systems intended to be used by or on behalf of competent public authorities ... to assess a risk ... posed by a natural person who intends to enter or who has entered into the territory of a Member State; ... (Annex III, point 7)

This point does not reach a bank or an insurer. It is addressed to competent public authorities and those acting on their behalf. A bank reading a residence permit at onboarding does so for its own customer due diligence, and an insurer selling the health cover a visa requires is not assessing a migration risk for the state.

8. Administration of justice and democratic processes

  1. Administration of justice and democratic processes: (a) AI systems intended to be used by a judicial authority or on their behalf ..., or to be used in a similar way in alternative dispute resolution; ... (Annex III, point 8)

This point does not reach a bank or an insurer. A legal department researching case law with an agent is not a judicial authority, and a complaints unit answering customers is not alternative dispute resolution. The one place point 8(a) touches the sector is the ombudsman it funds and refers customers to: an AI system that body uses to reach its outcomes is high-risk.

The Article 6(3) derogation

Landing in point 4 or point 5 does not settle the matter: Article 6(3) can take a system out again.

By derogation from paragraph 2, an AI system referred to in Annex III shall not be considered to be high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making. The first subparagraph shall apply where any of the following conditions is fulfilled: (a) the AI system is intended to perform a narrow procedural task; (b) the AI system is intended to improve the result of a previously completed human activity; (c) the AI system is intended to detect decision-making patterns or deviations from prior decision-making patterns and is not meant to replace or influence the previously completed human assessment, without proper human review; or (d) the AI system is intended to perform a preparatory task to an assessment relevant for the purposes of the use cases listed in Annex III. Notwithstanding the first subparagraph, an AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons. (Article 6(3))

In lending and underwriting, condition (a) is an agent that extracts payslip figures into the loan file; (b) an agent that rewrites the underwriter's decision letter in plain language once the decision is taken; (c) a quality agent that flags claims decisions departing from the handler's past pattern, for a human to re-examine; (d) an agent that summarises a mortgage file before the analyst assesses it.

The last sentence matters most. A credit score is an automated evaluation of a person's economic situation and reliability, which is profiling in the GDPR sense, so the derogation does not rescue a scoring engine, and rarely a life or health pricing model. Under Article 6(4), a provider that considers an Annex III system not high-risk must document that assessment before the system is placed on the market or put into service, register it under Article 49(2), and hand it to the competent authority on request.

What high-risk means before and after December 2027

Being high-risk under Annex III does not, today, trigger the high-risk obligations. The Digital Omnibus, Regulation (EU) 2026/1744, in force since 27 July 2026, moved the date: Chapter III, Sections 1 to 3 (Articles 6 to 27) applies to Annex III stand-alone high-risk systems from 2 December 2027, and Annex I embedded systems follow on 2 August 2028. Chapter III Section 5 (Articles 40 to 49) and Article 86 are contested after the Omnibus: possibly applying now, confirm with counsel.

The Article 5 prohibitions and the Article 4 AI literacy duty have applied since 2 February 2025, so the lines drawn above on emotion recognition and profiling are live. Article 50 transparency has applied since 2 August 2026, so a customer-facing agent must already tell the customer it is an AI system. Nothing in the deferral changes what a prudential supervisor already expects: that you know which AI systems you run, that each is classified with a written reason, that someone oversees it, and that you can show it behaves as its documentation says. From 2 December 2027, a deployer of a point 5(b) or 5(c) system also carries the Article 26 deployer obligations and, under Article 27, a fundamental rights impact assessment before first use.

Vidimus turns each applicable article into tests, runs them against your live agent, records its tool calls, grades every answer with a separate grading model, has a human reviewer confirm, and issues a versioned, signed evidence pack. A pilot takes about two weeks for one agent. To classify your agent against Annex III, start with the free EU AI Act risk classifier at /tools/eu-ai-act-readiness.

Last reviewed