Back to Newsroom
AI Act · NexCyber Editorial

Twelve Months to AI Act Annex III — What Changes

High-risk AI system obligations under Annex III of the EU AI Act apply from August 2026, affecting deployers of recruitment, credit and worker management systems

High-risk AI obligations under Annex III apply from August 2026. Most organisations affected are deployers, not providers, and have not classified their systems.

---

The short answer

High-risk obligations under Annex III of the AI Act apply from August 2026.

The organisations most affected are not AI companies. They are ordinary employers, lenders, insurers and public bodies that bought a tool. Annex III lists use cases, not technologies — and several of them describe software that has been in normal commercial use for years.

recruitment and candidate screening
worker management, task allocation, performance evaluation
creditworthiness assessment
access to essential public services

If you use a tool for any of these, the obligation reaches you as a deployer, regardless of who built it.

---

Why deployers are the surprise

Almost all AI Act commentary addresses providers — the organisations that build and place systems on the market. The provider obligations are heavier, so they get the attention.

But deployer obligations under Article 26 exist, they are specific, and they are yours alone. Your vendor cannot discharge them for you:

  • Use the system in accordance with its instructions for use
  • Assign human oversight to people with the competence and authority to exercise it
  • Ensure input data is relevant and sufficiently representative for the intended purpose
  • Monitor operation and suspend use if a risk emerges
  • Keep logs for an appropriate period
  • Inform workers' representatives before putting a high-risk system into service in the workplace

That last one has a deadline attached to a conversation, not a document — and it is the one most likely to be discovered late.

---

The obligation that cannot be bought

Certain deployers — bodies governed by public law, and private entities providing public services, plus those using systems for creditworthiness and life or health insurance pricing — must carry out a fundamental rights impact assessment.

There is no equivalent anywhere in the CRA, NIS2 or DORA. No security artefact substitutes for it, and no vendor can produce it, because it is an assessment of *your* use in *your* context on *your* population.

A team that folds AI Act work into an existing security programme discovers this last. It is the single most common reason the assessment ends up dated after deployment — which is worse than not having it, because it evidences that the process did not exist when it mattered.

---

The reclassification trap

A deployer can become a provider without buying anything.

Under Article 25, you take on provider obligations if you put your name or trademark on a high-risk system, make a substantial modification to it, or modify its intended purpose so that it becomes high-risk.

That last route is the quiet one. Fine-tuning a general-purpose model on your own data and deploying it for candidate screening is not "using a tool" — it is placing a high-risk system into service. The obligations that follow are the heavy ones.

---

What to do in the next twelve months

1. Inventory, honestly. Not "our AI systems" — every tool that scores, ranks, filters or recommends about a person. The applicant tracking system. The credit engine. The workforce scheduler. Most of these were never called AI internally.

2. Classify each one against Annex III, and write down the reasoning with a date. Most will not be high-risk. The record that you checked is the deliverable, not the conclusion.

3. Identify whether you owe a fundamental rights impact assessment. If you do, start it — it is the longest item on this list.

4. Name the humans exercising oversight, and check they actually have the authority to override. Oversight assigned to someone who cannot stop the system is not oversight.

5. Check for reclassification risk. Anyone fine-tuning or rebranding a model needs to know what Article 25 does.

---

The deadline that already passed, while you plan for this one

Article 5 prohibitions have been in force since February 2025. Social scoring, certain emotion inference in the workplace and education, untargeted facial image scraping — prohibited, now, not in 2026.

Most organisations planning for August 2026 have never audited against Article 5. It is a shorter list and a harder rule: prohibited means prohibited, with no conformity route.

---

Classify your systems — free, no account

  • [Free readiness assessment](/assess) — whether the AI Act reaches you, and as what
  • [Compliance responsibility mapper](/resources/responsibility-mapper) — who owns oversight

---

Further reading

What is the EU AI ActAI Act risk tiersAI Act and CRA overlapOne evidence set across five EU regulations

---

*This is regulatory information, not legal advice, and nothing here constitutes a compliance guarantee. Classification under Annex III is a determination on the facts of your specific use. Verify against the current text and consult your competent authority or a qualified adviser.*

Want the regulatory deep-dive ?

Our regulatory engineering team publishes implementation guides + practical checklists for each regulatory update.

Browse Knowledge Base →