Skip to content

High-Risk AI in Access to Essential Services: the Annex III Category

10 min read · updated August 11, 2026

Annex III point 5 is usually summarised as “credit scoring and insurance”. It contains four distinct uses with four different scopes, and the one most often dropped — eligibility for public assistance benefits — is the one with the widest reach into public administration.

Four sub-points, not one category

Point 5 of Annex III to Regulation (EU) 2024/1689 covers access to and enjoyment of essential private services and essential public services and benefits. It lists AI systems intended to be used:

  • (a) by or on behalf of public authorities to evaluate the eligibility of natural persons for essential public assistance benefits and services, including healthcare services, as well as to grant, reduce, revoke or reclaim such benefits and services;
  • (b) to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud;
  • (c) for risk assessment and pricing in relation to natural persons in the case of life and health insurance;
  • (d) to evaluate and classify emergency calls by natural persons, or to dispatch or establish priority in the dispatching of emergency first response services — including police, firefighters and medical aid — as well as emergency healthcare patient triage systems.
Not legal advice. Each sub-point has its own scope and its own carve-out, and whether a given system sits inside one is a question about that system’s intended purpose. Take advice on your own facts rather than reasoning from the heading of the category.

5(a): benefits eligibility, and the reclaim limb

Point 5(a) is limited to systems used by or on behalf of public authorities, which brings in outsourced administration and vendor-run eligibility engines through the words “on behalf of”. Healthcare services are expressly included, so an AI system triaging entitlement to treatment or reimbursement is in scope on the same footing as one assessing a social security claim.

The four verbs at the end are the substantive part: grant, reduce, revoke, reclaim. Recovery and overpayment detection systems are inside the category. That is not a marginal case — automated recovery systems have produced the most serious documented harms in this space, and the drafters put “reclaim” in the text rather than leaving it to be argued. In the Netherlands, the childcare benefits affair and the SyRI judgment of the District Court of The Hague in February 2020 are the reference points a Dutch reader will already have; see the Dutch position.

Because the deployer is a public authority, three further duties attach automatically: the Article 27 fundamental rights impact assessment, registration in the EU database under Article 49(3), and the Article 26(11) duty to inform affected individuals that they are subject to the use of the system.

5(b): creditworthiness and the fraud carve-out

Point 5(b) covers evaluating the creditworthiness of natural persons or establishing their credit score. Two boundaries decide most questions.

First, natural persons. Commercial credit assessment of a company is outside the point entirely. A sole trader is a natural person, so small-business lending sits awkwardly on the line and is decided by whose creditworthiness is actually being evaluated.

Second, the express exception for systems used for the purpose of detecting financial fraud. This is narrower than it is often read to be. A transaction-monitoring system that flags suspected fraud is excepted; a scoring model that treats fraud risk as one input into a lending decision is evaluating creditworthiness and is not. The distinguishing question is what the output is for, not what signals go into it.

Credit scoring is also the one Annex III use with a decided CJEU authority behind it on the data protection side. In Case C-634/21, OQ v Land Hessen, judgment of 7 December 2023, the Court of Justice held that the automated establishment by a credit reference agency of a probability value concerning a person’s ability to meet payment commitments constitutes an automated individual decision within Article 22(1) GDPR where a third party draws strongly on that value in deciding whether to contract. The judgment is on the Court’s own case register. What it decides is the classification of the scoring step; what it does not decide is which national derogations under Article 22(2)(b) are valid, which the Court left to the referring court and to national law. See what counts as a solely automated decision.

For a lender operating in the United States as well, the Equal Credit Opportunity Act and Regulation B adverse action notice requirements run in parallel and demand specific principal reasons for a denial — a different obligation from the Article 86 explanation right, with a different trigger and a different addressee. See adverse action notices for AI credit denials.

5(c): life and health insurance only

Point 5(c) is drafted narrowly and the narrowness is deliberate: risk assessment and pricing in relation to natural persons in the case of life and health insurance. Motor, home, travel, pet and commercial lines are not in Annex III at all. Claims handling is not in point 5(c) either — the point names risk assessment and pricing, which are underwriting activities, and a claims-fraud or claims-triage model is outside unless it is doing underwriting work under another name.

Insurers should not read that as an absence of regulation. The GDPR applies to health data as a special category under Article 9, national insurance supervision applies, and in the United States the NAIC model bulletin on the use of AI systems by insurers has been adopted by a large number of states with its own governance expectations. See the NAIC model bulletin.

5(d) emergency dispatch, and who owes a FRIA

Point 5(d) is the only sub-point about a service that has to happen in seconds. It covers evaluating and classifying emergency calls, dispatch and dispatch prioritisation across police, fire and medical response, and emergency healthcare patient triage systems. Note that the Article 14 oversight requirement has to be satisfiable at the tempo of the work: a human oversight design that assumes the operator has time to review a recommendation is not a design for a call-handling queue, and the honest consequence is usually oversight built into the process before and after the event — thresholds, escalation rules and audit — rather than per-decision review.

Now the duty that divides the category. Article 27 requires a fundamental rights impact assessment from two populations: deployers that are bodies governed by public law or private entities providing public services, and deployers of the high-risk AI systems referred to in points 5(b) and 5(c) of Annex III. That second limb is what makes a private bank and a private life insurer subject to the FRIA duty while a private employer deploying a hiring tool is not.

So the assessment map for point 5 is: 5(a) and typically 5(d) through the public-body limb, 5(b) and 5(c) by express naming, and nothing in Annex III point 4 unless the public-body limb applies independently. Article 27(3) allows a deployer to rely on an existing data protection impact assessment and complement it rather than duplicating it, which is the practical way to run this. See what a FRIA must contain and what triggers a DPIA.

The consolidated text is on EUR-Lex.

Dates. These obligations were to apply from 2 August 2026 under Article 113. The digital omnibus on AI, Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force from 27 July 2026, moves stand-alone Annex III high-risk obligations to 2 December 2027 and Annex I embedded high-risk to 2 August 2028. The GDPR analysis above, including the C-634/21 judgment, is unaffected: it applies now and did not depend on the AI Act timetable. Nothing else on this page is attributed to the amending Regulation.