Skip to content

High-Risk AI in Biometrics: the Annex III Category, Explained

10 min read · updated August 11, 2026

Biometrics is the Annex III category people get wrong most often, because the same technology appears twice in the Regulation: some uses are banned outright by Article 5 and some are permitted but high-risk under Annex III point 1. Confusing the two produces either over-compliance on a legal product or a prohibited practice with a conformity assessment attached.

What Annex III(1) actually lists

Annex III to Regulation (EU) 2024/1689 opens point 1 with a qualification that carries the whole category: in so far as their use is permitted under relevant Union or national law. Nothing in Annex III authorises anything. It classifies uses that are otherwise lawful. Within that framing, three things are listed:

  • 1(a) — remote biometric identification systems. Systems that identify a person at a distance, without their active involvement, by comparing biometric data against a reference database. The definition in Article 3 splits these into “real-time” and “post” by whether capture, comparison and identification happen without significant delay.
  • 1(b) — biometric categorisation according to sensitive or protected attributes or characteristics, based on the inference of those attributes or characteristics.
  • 1(c) — emotion recognition systems. Article 3(39) defines these as systems for identifying or inferring emotions or intentions of natural persons on the basis of their biometric data.
Not legal advice. Whether a specific product performs “identification” or “verification”, or whether an inferred attribute is a “protected” one, decides which regime applies and is a question about your system, not about the statute in the abstract. Take advice on your own facts.

The verification carve-out

Point 1(a) contains an express exclusion, and it is the most commercially significant sentence in the category: it does not include AI systems intended to be used for biometric verification whose sole purpose is to confirm that a specific natural person is the person he or she claims to be.

That is the difference between one-to-one and one-to-many. Unlocking a phone with a face, authenticating into a banking app with a fingerprint, confirming at a border gate that the person in front of the reader matches the chip in the passport they presented — these are verification. Scanning a crowd against a watchlist is identification. The Regulation treats them as different problems because they are: verification has a claimed identity to check against, and the person is participating.

Two limits on the carve-out are worth stating plainly. It applies to “sole purpose”, so a system that verifies and also builds a gallery usable for later identification has left the exclusion. And it is an exclusion from Annex III only — the system is still processing biometric data under the GDPR, with everything that follows.

Where Article 5 takes over

Four Article 5 prohibitions bite on biometric technology, and they have applied since 2 February 2025 — now nearly three years ahead of the Annex III obligations, which moved to 2 December 2027 (see the note at the foot of this page). A use inside one of these is not a high-risk use with heavier paperwork; it is unavailable.

  • Article 5(1)(e) — untargeted scraping of facial images from the internet or CCTV footage to create or expand facial recognition databases. See the scraping prohibition.
  • Article 5(1)(f) — inferring emotions of a natural person in the areas of workplace and education institutions, except where intended for medical or safety reasons. This is the rule that removes most workplace and classroom emotion analytics from the market entirely, while leaving emotion recognition elsewhere as an Annex III(1)(c) high-risk use.
  • Article 5(1)(g) — biometric categorisation systems that categorise individual natural persons on the basis of their biometric data to deduce or infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation. Note what is not on that list: age and sex categorisation are not named there, which is why they can be an Annex III(1)(b) high-risk use rather than a prohibited one, depending on whether the attribute is a protected one in the applicable law.
  • Article 5(1)(h) — real-time remote biometric identification in publicly accessible spaces for law enforcement purposes, subject to narrowly drawn exceptions and prior authorisation. See the exceptions in detail.

The clean way to hold the boundary: Article 5 asks what is being inferred, where, and by whom. Annex III asks what the system does. Emotion recognition is the clearest illustration — identical technology, prohibited in a workplace, high-risk in a call centre serving consumers from outside the employment relationship, and out of scope where no biometric data is involved at all.

The only category that can need a notified body

This is the consequence unique to biometrics and it is routinely missed. Article 43(1) provides that for high-risk systems listed in point 1 of Annex III, where the provider has applied harmonised standards or, where applicable, common specifications, it may choose the internal-control route in Annex VI. Where it has not applied them, or has applied them only in part, or where such standards do not exist, the provider must follow the conformity assessment procedure based on the involvement of a notified body under Annex VII.

Article 43(2) puts every other Annex III category — points 2 to 8 — on the internal-control route in Annex VI, with no notified body involvement at all. So biometrics is the single Annex III category where a third-party assessment can be compulsory, and because harmonised standards for the Act are still being developed, the trigger for that compulsion is presently the ordinary case rather than the exception.

Whether a harmonised standard covering these requirements has been cited in the Official Journal, and whether notified bodies have been designated in your Member State with the right scope, both change over time. Check the current position rather than relying on this page’s date. See notified bodies.

The second consequence is registration. Article 49(4) requires that high-risk systems referred to in Annex III points 1, 6 and 7 — biometrics, law enforcement, and migration — used in the areas of law enforcement, migration, asylum and border control management be registered in a secure, non-public section of the EU database, accessible only to the Commission and to national market surveillance authorities. The public transparency the database otherwise provides does not extend to these. See how EU database registration works.

Article 14(5) adds the third: for Annex III point 1(a) systems, no action or decision may be taken on the basis of an identification unless two competent, trained and authorised natural persons have separately verified and confirmed it — with a disapplication available for law enforcement, migration, border and asylum uses where Union or national law considers it disproportionate.

GDPR Article 9 does not go away

The AI Act regulates the system. The GDPR regulates the processing, and for biometric data processed for the purpose of uniquely identifying a natural person, Article 9(1) of Regulation (EU) 2016/679 sets a prohibition subject to the exhaustive list of conditions in Article 9(2). Completing an AI Act conformity assessment establishes nothing about whether such a condition is met.

In practice this means two independent gates. A remote biometric identification system can be entirely compliant as a product and unlawful to operate, because the deployer has no Article 9(2) condition and no Article 6 legal basis. Article 26(9) recognises the overlap by requiring deployers to use the information provided under Article 13 to carry out a data protection impact assessment where the GDPR requires one. See Article 9 and biometric AI and what triggers a DPIA for AI.

The consolidated text of the AI Act, including Annex III, is on EUR-Lex.

The Article 5 prohibitions have applied since 2 February 2025 and were not moved. The Annex III obligations were: they were to apply from 2 August 2026 under Article 113, and the digital omnibus on AI, Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force from 27 July 2026, moves stand-alone Annex III high-risk obligations to 2 December 2027 and Annex I embedded high-risk to 2 August 2028. The gap between the prohibition date and the high-risk date is therefore wider than the original design, which matters here because biometrics is the category where both apply to the same technology. Nothing else on this page is attributed to that amending Regulation.