Annex III §1
EU AI Act Annex III §1 — Biometrics (High-Risk)
Biometrics AI systems are high-risk under Annex III §1 of Regulation (EU) 2024/1689. What's covered, the obligations triggered, and what providers and deployers must do.
Source: Regulation (EU) 2024/1689 on EUR-Lex · Last published 2026-04-28 · Draft pending human review
Why this category is high-risk
Annex III §1 of Regulation (EU) 2024/1689 designates biometrics AI systems as high-risk. Annex III §1 covers AI systems intended to be used for remote biometric identification (RBI), AI systems intended to be used for biometric categorisation according to sensitive or protected attributes, and AI systems intended to be used for emotion recognition. The category sits at the highest fundamental-rights sensitivity in the Regulation: real-time RBI in publicly accessible spaces is generally prohibited under Article 5(1)(h) for law enforcement, with narrow Article 5(2)–(7) exceptions. Where RBI is permitted, Article 27 layered duties apply.
What is covered
Examples in scope:
- Real-time and post-remote biometric identification systems used by law enforcement under the narrow Article 5(2) exceptions.
- Biometric categorisation according to sensitive attributes (race, political opinion, trade-union membership, religious or philosophical belief, sex life or sexual orientation) — prohibited under Article 5(1)(g) when used for inferring such attributes from biometric data, with limited carve-outs.
- Emotion recognition systems in employment and education contexts — prohibited under Article 5(1)(f), with medical or safety reasons carve-out.
Examples out of scope of §1: access-control verification of a single individual's identity (1:1 biometric authentication) is generally not §1 RBI; it is treated under Annex III §1 last paragraph carve-out + GDPR.
Why §1 is special
§1 systems trigger the Annex VII notified-body conformity assessment where harmonised standards are not applied in full — unlike most Annex III categories. They also trigger the Article 14(5) two-person rule: no action or decision based on identification may be taken unless verified and confirmed by at least two natural persons.
For deployers of real-time RBI under Article 5(2)–(7) exceptions, additional safeguards apply (judicial / independent administrative authorisation, time and geographic limits, Article 26(10) deployer obligations).
What providers must do — biometric specifics
- Validate accuracy disaggregated by demographic groups likely to suffer mis-identification (well-documented disparate impact on darker skin tones in face-recognition systems is a known Article 10(2)(f)–(g) issue).
- Cybersecurity-test against face-spoofing, liveness-detection bypass, and adversarial-perturbation attacks under Article 15(5).
- Document the legal basis under GDPR Article 9 (special-category data) and the Article 10(5) strict-necessity dossier where biometric data is processed for bias detection.
What deployers must do — biometric specifics
- Public-sector deployers operating real-time RBI under Article 5(2) exceptions need authorisation from a judicial or independent administrative authority, except in justified cases of urgency where authorisation can be sought immediately after.
- Strict logging of every identification under Article 26(6).
- Notify the relevant market surveillance authority and Member State data-protection authority of each use under Article 5(7).
Obligations triggered
A system falling under §1 triggers the full Chapter III Section 2 + Section 3 stack:
- Article 9 — risk management system.
- Article 10 — data and data governance.
- Article 11 — technical documentation per Annex IV.
- Article 12 — automatic logging.
- Article 13 — transparency, instructions for use.
- Article 14 — human oversight.
- Article 15 — accuracy, robustness, cybersecurity.
- Article 16 — provider obligations.
- Article 17 — quality management system.
- Article 26 — deployer obligations.
- Article 43 — conformity assessment (Annex VI internal control for §1 except where stated otherwise).
- Article 47 — EU declaration of conformity.
- Article 48 — CE marking where applicable.
- Article 49 — EU Database registration.
Where the deployer is a public-sector body, a private entity providing public services, a credit-decision deployer (Annex III §5(b)), or a life/health insurance pricing deployer (Annex III §5(c)), the deployer also owes a FRIA under Article 27. Annex III §2 critical infrastructure is excluded from FRIA.
What providers must do
- Run the Article 9 risk management cycle continuously, with category-specific risks identified up-front (see "Worked risk rows" below in the related pages).
- Document the Article 10 data governance with disaggregated bias examination across sub-groups particular to this category.
- Build Article 14 human oversight measures into the system before placement.
- Validate Article 15 accuracy with disaggregated metrics.
- Complete the Annex IV technical file before placement.
- Sign the Article 47 declaration and register in the EU Database under Article 49.
- For non-EU providers: designate an authorised representative under Article 22 before placement.
What deployers must do
- Use the system in accordance with the Article 13 instructions for use.
- Assign Article 14 / Article 26(2) human oversight to competent, trained, authorised persons.
- Ensure deployer-controlled input data is relevant and representative.
- Monitor operation; inform the provider of incidents under Article 26(5).
- Where Article 27 applies, perform a FRIA.
- For public-sector deployers, register the deployment under Article 49 + Article 26(8).
- Inform workers of high-risk AI systems used at the workplace under Article 26(7) before put-into-service.
Inline crosswalk
- ISO/IEC 42001:2023 Annex A.5.2 — AI system impact assessment.
- ISO/IEC 42001:2023 Annex A.9.2 — Human oversight.
- NIST AI RMF MAP 1.1 — Intended purposes and context understood.
- NIST AI RMF MAP 5.1 — Likelihood and magnitude of impacts characterised.
Penalties
Article 99(4) — up to €15 million or 3% of worldwide annual turnover, whichever is higher.
Disclaimer. Reference; not legal advice. Verify with counsel. Reg text from Regulation (EU) 2024/1689.
Reference checklist
From the Governancer 30-item EU AI Act checklist. Each item joins to the ISO 42001 + NIST AI RMF crosswalk table below.
Article 11 · Starter tier · critical
Draft technical documentation (system purpose, design, risk)
Required for all high-risk AI systems before market placement. Our template covers the eight mandatory sections in one .docx.
Article 9 · Starter tier · high
Establish risk management system
A continuous iterative process. Identify foreseeable risks, estimate impact, document mitigations, review at least quarterly.
Article 14 · Starter tier · high
Document human oversight measures and operator training
Operators must be able to interpret outputs, decide to override, and stop the system when needed. Write it down.
ISO 42001 + NIST AI RMF crosswalk
Pulled live from the Governancer crosswalk module. Mapping reference; not a substitute for ISO 42001 certification audit or NIST AI RMF self-attestation.
ISO/IEC 42001:2023
| Checklist item | ISO 42001 control | Rationale |
|---|---|---|
art11-tech-docs | ISO/IEC 42001:2023 Clause 7.5 — Documented information | Article 11 technical file is the AIMS-required documented information evidencing AI system design, purpose, and risk decisions. |
art11-tech-docs | ISO/IEC 42001:2023 Annex A.6.2 — AI system life cycle documentation | Annex A.6.2 requires lifecycle documentation; the Article 11 technical file is its EU AI Act manifestation. |
art9-risk-mgmt | ISO/IEC 42001:2023 Clause 6.1.2 — AI risk assessment | A continuous Article 9 risk management process is the EU-AI-Act realisation of Clause 6.1.2 risk assessment. |
art9-risk-mgmt | ISO/IEC 42001:2023 Clause 6.1.3 — AI risk treatment | Article 9 mitigation, residual-risk recording and quarterly review provide the risk-treatment evidence required by Clause 6.1.3. |
art14-oversight | ISO/IEC 42001:2023 Annex A.9.2 — Human oversight of AI systems | Article 14 oversight measures + operator competence map directly to Annex A.9.2 human-oversight controls. |
NIST AI RMF 1.0
| Checklist item | NIST AI RMF subcategory | Rationale |
|---|---|---|
art11-tech-docs | NIST AI RMF MAP 4.1 — Approaches and metrics for measurement of AI risks are followed; documentation includes purpose, intended use, users, and limitations | Article 11 technical file documents purpose, design and limitations — the system-context output expected by MAP 4.1. |
art11-tech-docs | NIST AI RMF GOVERN 1.4 — The risk management process is documented and is regularly reviewed | Maintaining a living technical file is the documented and regularly reviewed risk-management evidence under GOVERN 1.4. |
art9-risk-mgmt | NIST AI RMF GOVERN 1.1 — Legal and regulatory requirements involving AI are understood, managed, and documented | EU AI Act Article 9 risk management explicitly captures the regulatory requirements GOVERN 1.1 wants documented. |
art9-risk-mgmt | NIST AI RMF MANAGE 1.3 — Responses to the AI risks deemed high priority are developed, planned, and documented | Article 9 mitigation plans for residual high-priority risks are exactly the responses MANAGE 1.3 expects. |
art14-oversight | NIST AI RMF GOVERN 3.2 — Policies and procedures define and differentiate roles and responsibilities for human-AI configurations | Article 14 documented oversight measures and operator roles map directly to GOVERN 3.2 human-AI role definition. |
art14-oversight | NIST AI RMF MEASURE 2.8 — Risks associated with transparency and accountability are examined and documented | Operator override paths and stop-controls are the accountability mechanisms MEASURE 2.8 examines. |
Related
Pro feature
Generate Article 11 with AI
LLM-assisted draft of all eight Annex IV sections, pre-filled from your system intake. 5 drafts/month on Pro.
Pro template
Download FRIA template
15-page Article 27 FRIA template (.docx) with the six elements pre-structured and a worked example.
Get the 30-item EU AI Act compliance checklist
Free PDF. No spam. Maps every Article and Annex IV section we ship to a ready-to-action checklist row.
Reference; not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text quoted from the Official Journal version of Regulation (EU) 2024/1689. Published by Agonist Development AB.