AI Act — Annex III high-risk areas and provider obligations, deep dive
In one paragraph
Annex III of the EU AI Act lists the areas where an AI system is considered high-risk. Providers, deployers, importers,
and distributors of such systems carry the bulk of AI Act obligations. This article walks each Annex III area, explains
the provider-side expectations, and maps each to the evidence NexCyber tracks.
The eight Annex III areas
Annex III defines eight areas where an AI system is high-risk. The exact wording follows the regulation; the working
summary below is for orientation.
1. Biometrics
Remote biometric identification systems; biometric categorisation; emotion recognition. Narrow exceptions apply for
verification.
NexCyber tracks: data governance, accuracy and bias testing, oversight, fundamental-rights impact assessment.
2. Critical infrastructure
Safety components of management or operation of critical digital infrastructure, road traffic, supply of water, gas,
heating, or electricity.
NexCyber tracks: risk management for safety, robustness testing, post-market monitoring, integration with NIS2
obligations where the operator is also an essential entity.
3. Education and vocational training
Determining access, admission, assignment to educational institutions; evaluating learning outcomes; assessing the
appropriate level of education; monitoring and detecting prohibited behaviour of students during tests.
NexCyber tracks: data quality and representativeness, human oversight, transparency to learners and educators, accuracy
testing.
4. Employment, workers management, and access to self-employment
Recruitment or selection; making decisions about promotion or termination; allocating tasks; monitoring and evaluating
performance.
NexCyber tracks: fairness testing, transparency to candidates and workers, oversight, technical documentation.
5. Access to and enjoyment of essential private and public services and benefits
Eligibility for public assistance benefits and services; creditworthiness; risk assessment for life and health
insurance; dispatching of emergency services.
NexCyber tracks: accuracy and bias testing, human oversight, transparency to applicants, appeal mechanisms in the
design.
6. Law enforcement
Profiling; assessing risk of becoming a victim or offender; lie detection; evaluating reliability of evidence;
predicting recurrence; profiling for prevention or investigation.
NexCyber tracks: legal-basis documentation, oversight, data minimisation, accuracy testing, transparency to the extent
allowed.
7. Migration, asylum, and border control management
Lie detection; risk assessment; verification of authenticity of travel documents; examination of applications.
NexCyber tracks: legal-basis documentation, accuracy testing, oversight, fundamental-rights impact assessment.
8. Administration of justice and democratic processes
Researching and interpreting facts and the law; influencing the outcome of an election or referendum.
NexCyber tracks: legal-basis documentation, oversight, transparency, accuracy testing.
Provider obligations — the seven workstreams
Whichever Annex III area applies, providers of high-risk AI systems carry seven workstreams. NexCyber tracks each as a
section in the AI Act assessment workspace.
Risk management
A continuous risk management system across the lifecycle. Not a one-off document; a living process.
Evidence: risk management policy, risk register, mitigation plans, post-incident review records.
Data and data governance
Training, validation, and testing datasets must meet quality, representativeness, and integrity expectations.
Evidence: dataset provenance, quality criteria, bias and representativeness tests, data labelling guidelines, data
versioning.
Technical documentation
A documented description of the system, its components, lifecycle, datasets, training, validation, and testing
methodology, performance metrics, and known limitations.
Evidence: technical file, model card, change log, training pipeline diagram, performance reports.
Record-keeping and logs
Automatic logs over the lifetime of the system.
Evidence: logging architecture, retention policy, audit log samples, integrity controls.
Transparency and information to deployers
Instructions for use, performance characteristics, intended purpose, human oversight measures, expected lifetime,
foreseeable misuse.
Evidence: instructions for use, model card published to deployers, change notices.
Human oversight
The system must be designed to allow humans to oversee its operation, intervene, and override where necessary.
Evidence: oversight design document, escalation and override mechanisms, training of oversight roles, test of overrides.
Accuracy, robustness, and cybersecurity
The system must achieve appropriate levels of accuracy, robustness, and cybersecurity, and behave consistently against
errors, faults, attacks, and inconsistencies.
Evidence: accuracy reports, adversarial robustness tests, threat model, cybersecurity controls, post-deployment
monitoring.
Deployer obligations
Deployers carry their own obligations: using the system in accordance with instructions, monitoring its operation,
ensuring human oversight, keeping logs, conducting fundamental-rights impact assessment in some cases, and informing
affected persons where required.
NexCyber tracks deployer-side evidence alongside provider-side, so a customer using a partner's high-risk system can
demonstrate appropriate use.
GPAI considerations
General-Purpose AI models carry model-level obligations even outside the Annex III high-risk areas (technical
documentation, copyright policy, training data summary). Systemic-risk GPAI carry additional obligations (model
evaluation, systemic risk assessment, incident reporting, cybersecurity protection).
If your estate includes GPAI components, NexCyber surfaces the model-level obligations in the AI Act assessment.
Conformity assessment
High-risk providers must run conformity assessment before placing the system on the market. The route depends on the
area and on the use of harmonised standards. NexCyber prepares the technical file and tracks the assessment artefacts;
it does not perform the assessment.
Fundamental-rights impact assessment
For some high-risk AI systems, deployers must perform a fundamental-rights impact assessment (FRIA). NexCyber tracks the
FRIA artefacts and the link to the underlying risk management system.
Post-market monitoring
High-risk systems require a post-market monitoring plan: how field data is collected, evaluated, and fed back into the
risk management system. NexCyber tracks the monitoring plan, the field telemetry inventory, and the periodic monitoring
reports.
Reporting of serious incidents
Providers must report serious incidents to market surveillance authorities within tight timelines. NexCyber offers the
playbook scaffold; the report itself remains your filing.
What the AI Act does NOT do via NexCyber
- It does not issue conformity certificates.
- It does not interpret whether your system is high-risk for a specific borderline case (we flag for human regulatory
triage).
- It does not perform testing — NexCyber tracks evidence of testing you have done.
Common pitfalls
- Treating risk management as a one-off document.
- Skipping representativeness testing on datasets.
- Logging without an integrity story.
- Human oversight in the architecture but no training for the oversight role.
- Post-market monitoring plans with no telemetry.
Related articles
- AI Act basics — wider picture.
- What evidence should I prepare? — cross-regulation evidence list.
- What NexCyber does NOT replace — boundary with legal advice.
Next step
Confirm your Annex III area in scope, open the AI Act assessment, and attach evidence per workstream.