Skip to content

High-Risk AI in Law Enforcement: the Annex III Category

10 min read · updated August 11, 2026

If you are counting the law-enforcement entries in Annex III and getting seven, you are reading the European Commission’s 2021 proposal. The adopted Regulation lists five, and the two that were dropped are the ones people most often plan around.

The five uses in the adopted text

Point 6 of Annex III to Regulation (EU) 2024/1689 covers AI systems intended to be used by or on behalf of law enforcement authorities, or by Union institutions, bodies, offices or agencies in support of law enforcement authorities or on their behalf:

  • (a) to assess the risk of a natural person becoming the victim of criminal offences;
  • (b) as polygraphs or similar tools;
  • (c) to evaluate the reliability of evidence in the course of the investigation or prosecution of criminal offences;
  • (d) to assess the risk of a natural person offending or re-offending not solely on the basis of profiling as referred to in Article 3(4) of Directive (EU) 2016/680, or to assess personality traits and characteristics or past criminal behaviour of natural persons or groups;
  • (e) for the profiling of natural persons as referred to in Article 3(4) of Directive (EU) 2016/680 in the course of the detection, investigation or prosecution of criminal offences.

Point (a) is the one readers misread most often. It is about victims, not suspects — vulnerability and repeat victimisation models, domestic abuse risk scoring, and similar tools sit here. Point (d) is about offending risk, and the words “not solely on the basis of profiling” are the hinge between this category and the Article 5 prohibition below.

Not legal advice, and this area in particular is one where national law decides most of the practical questions. Whether a police force may deploy a given system at all is a matter of the Member State’s own legislation and of Directive (EU) 2016/680; Annex III only classifies the risk tier. Take advice on the specific deployment.

Why summaries say seven

The Commission’s April 2021 proposal listed more law-enforcement uses than the final text, including systems for detecting deepfakes, systems for crime analytics allowing the search of large complex datasets, and a separate entry on individual risk assessment. Those were removed or merged during the trilogue negotiations, and the version published in the Official Journal on 12 July 2024 has points (a) to (e) only.

This matters beyond pedantry. A force planning compliance around “crime analytics is high-risk” is planning around a classification that was not enacted — which does not make such a system unregulated, because the GDPR, Directive (EU) 2016/680 and national police law all still apply, but it does mean the Annex III obligation set is not the source of the constraint. Always read the annex from the Official Journal text on EUR-Lex, not from a summary that predates the trilogue.

The qualifier that opens the category

Like point 1, point 6 opens with “in so far as their use is permitted under relevant Union or national law”. Annex III does not create a power to use any of these systems. If national law does not authorise a police force to run offending-risk assessment, the fact that the Act classifies such a system as high-risk gives no authorisation whatsoever.

Two exclusions further narrow the field. Article 2(3) provides that the Regulation does not apply to AI systems placed on the market, put into service or used, with or without modification, exclusively for military, defence or national security purposes, whoever carries out the activity. Where the boundary between national security and ordinary law enforcement falls is not settled, and it is precisely the boundary that decides whether the Act applies to some intelligence-adjacent policing tools at all. That question will be answered by national courts and, eventually, by the Court of Justice, not by the text. Article 2(6) separately excludes systems developed and put into service for the sole purpose of scientific research and development, which covers pilots that stay in the lab and not pilots run on the street.

Where Article 5 stops it

Article 5(1)(d) prohibits placing on the market, putting into service for this specific purpose, or using an AI system for making risk assessments of natural persons in order to assess or predict the risk of a natural person committing a criminal offence, based solely on the profiling of a natural person or on assessing their personality traits and characteristics. The same provision states that the prohibition does not apply to AI systems used to support the human assessment of a person’s involvement in criminal activity where that assessment is already based on objective and verifiable facts directly linked to a criminal activity.

Set that against Annex III(6)(d), which covers offending and re-offending risk assessment “not solely on the basis of profiling”. The two provisions are a matched pair: prediction from profile alone is prohibited; prediction that rests on verifiable facts about conduct, with the profile as one input among others, is permitted and high-risk. Everything therefore turns on what “solely” means in a system with a dozen features, and there is no authority on that yet. Anyone who tells you the line is clear is guessing. See the predictive policing prohibition.

Article 5(1)(h) separately prohibits real-time remote biometric identification in publicly accessible spaces for law enforcement purposes, subject to three narrowly drawn objectives and to a prior authorisation regime. Post-remote biometric identification is not prohibited, but Article 26(10) requires the deployer to request authorisation from a judicial or independent administrative authority, in principle in advance and in any event without undue delay and at the latest within 48 hours, with the data deleted if authorisation is refused. See the remote biometric identification exceptions.

Two rules that apply only here

Registration is not public. Article 49(4) provides that high-risk AI systems referred to in Annex III points 1, 6 and 7, used in the areas of law enforcement, migration, asylum and border control management, are registered in a secure non-public section of the EU database, accessible only to the Commission and to the relevant national market surveillance authorities. The public accountability the database provides for other categories is deliberately absent here, and the practical consequence is that civil society oversight of these deployments continues to depend on national transparency law and on litigation rather than on the Act. See EU database registration.

The four-eyes rule can be switched off. Article 14(5) requires that for Annex III point 1(a) remote biometric identification systems, no action or decision be taken unless separately verified and confirmed by at least two competent, trained and authorised natural persons — and then disapplies that requirement, for systems used for law enforcement, migration, border control or asylum purposes, where Union or national law considers its application disproportionate. Whether Member States legislate for that, and how narrowly, is unresolved and is the thing to watch in national implementing acts. See Article 14 in detail.

Finally, the data protection regime here is not the GDPR. Processing by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences falls under Directive (EU) 2016/680, the Law Enforcement Directive, which has its own rules on automated individual decision-making in Article 11 and its own transposition in each Member State.

Dates. Annex III obligations were to apply from 2 August 2026 under Article 113; the digital omnibus on AI, Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force from 27 July 2026, moves stand-alone Annex III high-risk obligations to 2 December 2027 and Annex I embedded high-risk to 2 August 2028. The Article 5 prohibitions discussed above, including Article 5(1)(d) and 5(1)(h), have applied since 2 February 2025 and were not moved — so the prohibited practices are already enforceable while the high-risk obligations on the permitted ones are not. Nothing else on this page is attributed to that amending Regulation.