High-Risk AI in Migration, Asylum and Border Control: the Annex III Category
9 min read · updated August 11, 2026
Annex III point 7 regulates AI at the border: risk assessment of people intending to enter, assistance with asylum and visa applications, detection and identification of individuals, and systems used as polygraphs. It is the category with the least plain-English coverage and the longest transition period.
The four uses in Annex III(7)
Point 7 of Annex III to Regulation (EU) 2024/1689 covers migration, asylum and border control management, again qualified by “in so far as their use is permitted under relevant Union or national law”. It lists AI systems intended to be used by or on behalf of competent public authorities, or by Union institutions, bodies, offices or agencies:
- (a) as polygraphs or similar tools;
- (b) to assess a risk — including a security risk, a risk of irregular migration, or a health risk — posed by a natural person who intends to enter or who has entered the territory of a Member State;
- (c) to assist competent public authorities in examining applications for asylum, visa or residence permits and associated complaints, with regard to the eligibility of the persons applying, including related assessments of the reliability of evidence;
- (d) in the context of migration, asylum or border control management, to detect, recognise or identify natural persons, with the exception of the verification of travel documents.
The polygraph entry, and why it is there
Point 7(a) — systems used as polygraphs or similar tools — appears in identical terms in Annex III point 6(b) for law enforcement. It is the only technology the Act names twice as a high-risk use in its own right, and the reason is that deception-detection systems inferring truthfulness from face, voice or physiological signals were the subject of EU-funded border research, most visibly the iBorderCtrl project run under Horizon 2020, which drew sustained criticism and litigation about access to its documents. The provision is a legislative response to a specific class of tool rather than an abstract category.
What Annex III does not do is validate the technology. Classifying AI polygraphs as high-risk means that if such a system is placed on the Union market it must meet Chapter III Section 2, be documented, be overseen and be registered. It says nothing about whether deception detection from biometric signals works, and the scientific position on that is contested. The Act also leaves the harder question open: Article 15 requires a declared accuracy level and metric, and it is not clear what a defensible accuracy declaration for a deception-detection system would even look like, or whether a notified body or market surveillance authority would accept one.
Note the interaction with Article 5(1)(f). The prohibition on emotion inference is limited to the areas of workplace and education institutions, so it does not reach border deployments. A system inferring emotional state at a border is high-risk, not prohibited — a boundary that has been criticised and that the co-legislators drew deliberately.
The identification limb and its travel-document carve-out
Point 7(d) is broad: detecting, recognising or identifying natural persons in the migration, asylum or border control context. The exception is narrow and precise — the verification of travel documents. Checking that a passport is genuine, or that its chip matches the person presenting it, is outside the point; identifying an unknown person against a database is inside it.
That carve-out is doing the same work as the one-to-one verification exclusion in Annex III point 1(a), and the two should be read together. A border gate that confirms a claimed identity is verification. The same hardware, run against a watchlist to establish who somebody is, is identification, and is then simultaneously an Annex III(1)(a) remote biometric identification system and an Annex III(7)(d) system — with the Article 14(5) two-person confirmation rule engaged, subject to the disapplication for border and asylum uses where Union or national law considers it disproportionate. See the biometrics category.
Registration follows the law-enforcement pattern: under Article 49(4), high-risk systems in Annex III points 1, 6 and 7 used in the areas of law enforcement, migration, asylum and border control are registered in a secure non-public section of the EU database, visible only to the Commission and to national market surveillance authorities.
Annex X: the 2030 tail for EU databases
This is the provision that makes the category’s timetable unlike every other. Article 111(1) provides that AI systems which are components of the large-scale IT systems established by the legal acts listed in Annex X, and which have been placed on the market or put into service before 2 August 2027, must be brought into compliance with the Regulation by 31 December 2030.
Annex X lists the Union’s own border and migration information systems — the Schengen Information System, the Visa Information System, Eurodac, the Entry/Exit System, the European Travel Information and Authorisation System, ECRIS-TCN and the interoperability regulations that connect them. The effect is that the systems with the widest reach over migrants and asylum seekers have a compliance deadline more than four years later than the commercial systems in the same annex point.
Article 111(1) adds that the requirements of the Regulation are to be taken into account in the evaluation of each of those systems provided for in the relevant acts and where those acts are replaced or amended. So the mechanism is a scheduled review rather than a cliff edge. Whether that produces substantive change by 2030 is an open question and not one this page can answer.
What the category does not cover
Three limits are worth stating because they are where the category ends.
First, Article 2(3): the Regulation does not apply to systems used exclusively for military, defence or national security purposes. Border security sits close to that line, and where a Member State characterises a deployment as national security the applicability of the Act is contestable rather than settled.
Second, point 7 addresses systems used by or on behalf of public authorities and Union bodies. A commercial carrier’s own passenger screening tool is not in point 7 unless it is operated on behalf of such an authority — though it may be caught elsewhere, and it is caught by the GDPR regardless.
Third, logistics and administration are not decisions. A translation system used in an asylum interview, or a case-management scheduler, is not assessing eligibility or reliability of evidence and is not in point 7(c) — though the accuracy of interpretation in an asylum procedure has obvious fundamental rights consequences, and a system that summarises testimony for a caseworker is closer to 7(c) than its vendor will usually accept.
The consolidated text is on EUR-Lex, and the phase-in is set out in the timeline.