Skip to content
C50 Clause50EU AI Act transparency — made auditable.EU AI Act evidence, made auditable
Resources · High-risk

High-risk systems: Annex III, and the technical file Annex IV asks for

Annex III says which systems are high-risk. Annex IV says what the technical file has to contain. Between them sits the fact that decides whether you can comply at all: most of that file is a record of things that already happened.

Annex III high-risk obligations apply from 2 December 2027; high-risk systems embedded in products already regulated under Union harmonisation legislation follow on 2 August 2028.

The argument, before the detail

Annex IV evidence is retrospective. Design decisions, data provenance and change history can only be produced by someone who was recording them at the time.

A company that starts preparing in 2027 is not doing a project — it is reconstructing 2026 from memory. It will be asked what data the model was trained on, which design alternatives were rejected and why, what changed in March, and who signed off. The honest answers are in commit logs, ticket systems and people’s heads, and none of those is a technical file.

That is the whole case for starting now, and it is not a deadline argument. The deadline is when you are asked; the recording had to start earlier.

Two routes into high-risk

Article 6(1) — Annex I

A safety component of a regulated product

  • Your AI is a safety component of a product covered by the Union harmonisation legislation listed in Annex I — machinery, medical devices, lifts, toys, vehicles and the rest.
  • Or the AI system is such a product, and that product must undergo a third-party conformity assessment.
  • This route applies from 2 August 2028.
Article 6(2) — Annex III

A use case in one of eight areas

  • Your system is used for one of the eight areas listed below.
  • Article 6(3) carves back out: a listed system is not high-risk if it does not pose a significant risk of harm — because it performs a narrow procedural task, improves the result of a previously completed human activity, detects patterns in decision-making without replacing the human assessment, or performs a preparatory task.
  • But that carve-out never applies where the system performs profiling of natural persons. And a provider relying on it must document the assessment before placing the system on the market.

The applicability check screens for these routes, including the Article 5 prohibited practices that sit above them — a banned system is not a high-risk system with extra paperwork, it is a system you may not place on the market at all.

Annex III — the eight areas

Read these as uses, not as industries. The same model can be minimal-risk in one product and high-risk in another; what the Annex lists is what the system is used to decide.

  • 1. BiometricsRemote biometric identification, biometric categorisation according to sensitive or protected attributes, and emotion recognition — in each case only where the use is not already prohibited outright by Article 5.
  • 2. Critical infrastructureSafety components in the management and operation of critical digital infrastructure, road traffic, and the supply of water, gas, heating and electricity.
  • 3. Education and vocational trainingDeciding admission or assignment, evaluating learning outcomes, assessing the appropriate level of education a person will receive, and monitoring for prohibited behaviour during tests.
  • 4. Employment and worker managementRecruitment and selection (including targeted job ads and screening applications), decisions on promotion or termination, allocating tasks, and monitoring or evaluating performance and behaviour.
  • 5. Essential private and public servicesEligibility for public assistance benefits, creditworthiness and credit scoring, risk assessment and pricing in life and health insurance, and the classification and dispatch of emergency calls.
  • 6. Law enforcementAssessing the risk of offending or re-offending, polygraphs, evaluating the reliability of evidence, and profiling in the course of detecting, investigating or prosecuting offences.
  • 7. Migration, asylum and border controlPolygraphs, risk assessments on people entering a Member State, assisting the examination of applications for asylum, visa or residence permits, and detecting or identifying people.
  • 8. Administration of justice and democratic processesAssisting a judicial authority in researching and interpreting facts and the law, and influencing the outcome of an election or referendum or the voting behaviour of natural persons.

Annex IV — the nine points of the technical file

Article 11(1) requires the technical documentation to be drawn up before the system is placed on the market and kept up to date. Annex IV fixes its contents:

  1. General description of the systemIntended purpose, the provider, the version, how it interacts with hardware and software it is not part of, the hardware it runs on, what it looks like, and the instructions for use given to the deployer.
  2. Detailed description of its elements and developmentMethods and steps followed, design specifications, system architecture, data requirements and datasheets, human-oversight measures, pre-determined changes, and validation and testing procedures.
  3. Monitoring, functioning and controlCapabilities and limitations, accuracy for specific persons or groups, foreseeable unintended outcomes and sources of risk, the human oversight needed, and input-data specifications.
  4. Appropriateness of the performance metricsWhy the metrics you chose are the right ones for this system and this intended purpose — not merely what they measured.
  5. The risk management system (Article 9)A detailed description of the risk management system: the risks identified, the measures adopted, and how they were tested — maintained across the whole lifecycle, not written once.
  6. Relevant changes made through the lifecycleWhat changed, when, and why. This is a history, and a history cannot be written after the fact.
  7. Harmonised standards appliedA list of the harmonised standards applied in full or in part, with references — or, where none were applied, a description of the solutions adopted to meet the requirements instead.
  8. A copy of the EU declaration of conformityThe declaration under Article 47, signed by the provider, naming the system and the legislation it is declared to conform with.
  9. Post-market performance evaluation (Article 72)A detailed description of the system in place to evaluate performance in the post-market phase, including the post-market monitoring plan itself.

Points 2, 3, 6 and 9 are the retrospective ones — development process, monitoring, lifecycle changes and post-market performance. Each is a record of what happened over time, and each is the reason a technical file cannot be written in a quarter.

Which of these Clause50 assembles evidence toward today is derived from our rule pack and published on the coverage page, so it is never a number typed on a marketing page.

What a technical file is not

The technical file is one deliverable among several, and it is easy to assume it covers the rest. It does not. Alongside it, a provider of a high-risk system carries a quality management system (Article 17), a conformity assessment (Article 43), registration in the EU database (Articles 49 and 71), and — for certain deployers — a fundamental rights impact assessment (Article 27). Post-market monitoring (Article 72) is a process you run, not a document you file.

We say the same thing about our own scope on the coverage page, in the same words.

Start recording before you are asked

If your system is likely to land in Annex III, the useful thing to do in 2026 is not to plan a 2027 project — it is to start keeping the record that the 2027 file will be made of. Clause50 does that continuously, from the systems you already run.

Official sources

Not yet reviewed by counsel. This page explains our reading of Regulation (EU) 2024/1689 and is kept deliberately close to the regulation’s own wording, but it has not been through legal review. Clause50 produces compliance documentation; it is not legal advice and does not by itself make any system compliant — the obligations described here remain yours. Verify anything you rely on against the primary regulation or your own counsel. See our terms.