Skip to content

High-Risk AI in Justice and Democratic Processes: the Annex III Category

9 min read · updated August 11, 2026

Point 8 of Annex III looks like two unrelated things filed together: AI that helps a judge, and AI that influences how people vote. They share a rationale — both act on the processes by which a society makes binding decisions — and they share a drafting technique, in that each is defined as much by what it excludes as by what it covers.

Two sub-points in one category

Point 8 of Annex III to Regulation (EU) 2024/1689 covers administration of justice and democratic processes, and lists AI systems intended to be used:

  • (a) by a judicial authority or on its behalf, to assist a judicial authority in researching and interpreting facts and the law and in applying the law to a concrete set of facts, or to be used in a similar way in alternative dispute resolution;
  • (b) for influencing the outcome of an election or referendum, or the voting behaviour of natural persons in the exercise of their vote in elections or referenda — not including AI systems to whose output natural persons are not directly exposed, such as tools used to organise, optimise or structure political campaigns from an administrative or logistical point of view.
Not legal advice. Whether a specific tool is “intended to be used” for one of these purposes is the whole question in this category, and it turns on how the system is designed, documented and sold. Take advice on your own facts.

8(a): assisting a judicial authority

The judicial limb is defined by the task, not by the user interface. Three activities are named: researching facts, interpreting the law, and applying the law to a concrete set of facts. A legal research system that retrieves and summarises authorities for a judge is inside; a system that drafts reasoning for a decision is plainly inside; a system that scores a party’s risk for a sentencing or bail decision is applying law to facts and is inside.

Two extensions are easy to miss. “Or on their behalf” brings in court-service vendors and judicial administration bodies, not only the judiciary itself. And the reference to alternative dispute resolution reaches arbitration and mediation platforms — including online dispute resolution run by private operators, which are not judicial authorities at all but are “used in a similar way”.

What point 8(a) does not do is authorise or forbid anything about judicial decision-making. Recital 61 records the concern the classification is meant to address: the use of AI tools can support but should not replace the decision-making power of judges, and final decision-making must remain a human-driven activity. That is a recital, so it informs interpretation without creating an obligation of its own; the binding constraints on automated adjudication come from national constitutional and procedural law, from Article 47 of the Charter, and from Article 22 GDPR — not from Annex III.

A separate and more immediate problem for legal AI is not in this Regulation at all. Courts in several jurisdictions have sanctioned lawyers for filing briefs containing citations produced by a language model that do not exist. That is a professional conduct question governed by court rules, and it arises whether or not the tool is high-risk. See fabricated citations and court sanctions and bar ethics opinions on AI use.

What is carved out of the judicial limb

Recital 61 states that the classification should not extend to AI systems intended for purely ancillary administrative activities that do not affect the actual administration of justice in individual cases — giving as examples the anonymisation or pseudonymisation of judicial decisions, documents or data, communication between personnel, and administrative tasks.

That is a workable line and it covers most of what a court actually buys: case-management scheduling, transcription and redaction, document classification for archiving, internal search over administrative records, translation of correspondence. The test is whether the output bears on the determination of an individual case.

Two borderline cases are worth naming because vendors tend to place them on the comfortable side. Automatic anonymisation of judgments for publication is expressly ancillary, but a system that also selects which judgments are published is shaping the case law available to litigants. And transcription is administrative until the transcript is the record; a transcription error in an evidential record is not an administrative inconvenience. Neither has been tested, and the honest position is that the recital’s examples do not resolve them.

8(b): influencing an election

The election limb is defined by purpose — a system intended to be used for influencing an electoral outcome or voting behaviour — and then narrowed by an exposure test: it does not include systems to whose output natural persons are not directly exposed, such as campaign tools used for administrative or logistical organisation.

So canvassing route optimisation, volunteer scheduling, donation processing and internal polling analysis are outside, because the voter never sees the output. Micro-targeted message generation, persuasion-optimised content, and systems that decide which political message a specific person receives are inside, because the voter is exposed to the output directly.

The unresolved case is the general-purpose recommender system. A social platform ranking feed does expose people directly to its output, and its output demonstrably affects what political information they see. Whether it is a system “intended to be used for influencing the outcome of an election” depends on the intended purpose the provider declares, and platforms do not declare that purpose. The natural reading is that a general ranking system falls outside point 8(b) on intended purpose while a purpose-built political persuasion system falls inside — but that reading leaves the larger real effect unregulated by this provision, which is exactly the criticism made of it. It has not been settled by any authority, and it will be settled either by the Commission’s Article 6 guidelines, by national market surveillance practice, or by litigation. Do not treat either answer as safe.

The instruments that do the rest of the work

Point 8(b) is not the Union’s main election-integrity instrument, and treating it as such misreads the architecture. Three others carry more of the load.

Regulation (EU) 2024/900 on the transparency and targeting of political advertising imposes labelling, transparency-notice and targeting-restriction duties on political advertising, with most of its provisions applicable from 10 October 2025. The text is on EUR-Lex. It regulates the advertisement rather than the system that produced it, which is why it reaches cases point 8(b) does not.

The Digital Services Act, Regulation (EU) 2022/2065, requires very large online platforms to assess and mitigate systemic risks including actual or foreseeable negative effects on civic discourse and electoral processes, and requires recommender system transparency under Article 27. That is the instrument that actually reaches platform ranking. See DSA recommender transparency.

Article 50 of the AI Act itself imposes transparency duties irrespective of risk tier: deployers of systems generating or manipulating image, audio or video content constituting a deep fake must disclose that the content has been artificially generated or manipulated, and deployers publishing AI-generated text to inform the public on matters of public interest must disclose it unless the content has undergone human review with editorial responsibility. Those transparency duties apply from 2 August 2026 — they were not deferred with the high-risk obligations — and they reach election deepfakes that point 8(b) may not. For AI systems already placed on the market before that date, the marking obligations for AI-generated content run from 2 December 2026. See the deepfake labelling duty and the public-interest text duty. The consolidated AI Act text is on EUR-Lex.

The two limbs of this category now start on different dates, which is new. Annex III point 8 obligations were to apply from 2 August 2026; the digital omnibus on AI, Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force from 27 July 2026, moves stand-alone Annex III high-risk obligations to 2 December 2027 and Annex I embedded high-risk to 2 August 2028. The Article 50 transparency duties above were not moved. So for an election running in 2027, the deepfake and public-interest-text disclosure duties apply and the point 8(b) high-risk obligations do not yet. Nothing else on this page is attributed to that amending Regulation.