Annex III §5
EU AI Act Annex III §5 — Essential Private and Public Services (High-Risk)
Essential Private and Public Services AI systems are high-risk under Annex III §5 of Regulation (EU) 2024/1689. What's covered, the obligations triggered, and what providers and deployers must do.
Source: Regulation (EU) 2024/1689 on EUR-Lex · Last published 2026-04-28 · Draft pending human review
Why this category is high-risk
Annex III §5 of Regulation (EU) 2024/1689 designates essential private and public services AI systems as high-risk. Annex III §5 covers AI used by public authorities to evaluate eligibility for essential public assistance benefits and services (health, social security, etc.); AI used to evaluate creditworthiness or establish credit scores (with a fraud-detection carve-out); AI used for risk assessment and pricing in life and health insurance; AI used to dispatch or establish priority for emergency services. Most §5 deployers owe a FRIA under Article 27.
What is covered
Examples in scope (point a) — public benefits:
- AI for social-housing eligibility scoring.
- AI for unemployment-benefits triage.
- AI for healthcare-priority queue placement.
Examples in scope (point b) — credit:
- Consumer and business loan decisioning.
- Buy-now-pay-later approvals.
- Mortgage scoring.
- Out of scope: systems used exclusively for fraud detection.
Examples in scope (point c) — life and health insurance:
- Underwriting models for life or health policies.
- Premium-pricing models for life or health policies.
Examples in scope (point d) — emergency services:
- AI dispatch prioritisation for police, fire, ambulance.
- AI triage for emergency-department admissions.
Why §5 is the FRIA epicentre
Article 27(1) explicitly names §5(b) credit deployers and §5(c) insurance deployers as FRIA-required regardless of whether they are public-sector. Combined with public-sector deployers under §5(a), this is the largest practical FRIA population.
What providers must do — §5 specifics
- Disaggregated metrics across socio-economic deciles, age bands, geographic regions.
- Detailed Article 13 instructions for use for the deployer's FRIA section (d): identified risks of harm, evidenced from validation runs.
- Where the system makes decisions on natural persons under Article 22 GDPR, ensure compatibility with the GDPR right to obtain human intervention.
What deployers must do — §5 specifics
- FRIA under Article 27 — except for §5(b) used exclusively for fraud detection.
- Public-sector deployers register under Article 49 + Article 26(8).
- Inform individuals under Article 26(11).
- Coordinate with the relevant DPA on the GDPR Article 22 / Article 35 angle.
Obligations triggered
A system falling under §5 triggers the full Chapter III Section 2 + Section 3 stack:
- Article 9 — risk management system.
- Article 10 — data and data governance.
- Article 11 — technical documentation per Annex IV.
- Article 12 — automatic logging.
- Article 13 — transparency, instructions for use.
- Article 14 — human oversight.
- Article 15 — accuracy, robustness, cybersecurity.
- Article 16 — provider obligations.
- Article 17 — quality management system.
- Article 26 — deployer obligations.
- Article 43 — conformity assessment (Annex VI internal control for §5 except where stated otherwise).
- Article 47 — EU declaration of conformity.
- Article 48 — CE marking where applicable.
- Article 49 — EU Database registration.
Where the deployer is a public-sector body, a private entity providing public services, a credit-decision deployer (Annex III §5(b)), or a life/health insurance pricing deployer (Annex III §5(c)), the deployer also owes a FRIA under Article 27. Annex III §2 critical infrastructure is excluded from FRIA.
What providers must do
- Run the Article 9 risk management cycle continuously, with category-specific risks identified up-front (see "Worked risk rows" below in the related pages).
- Document the Article 10 data governance with disaggregated bias examination across sub-groups particular to this category.
- Build Article 14 human oversight measures into the system before placement.
- Validate Article 15 accuracy with disaggregated metrics.
- Complete the Annex IV technical file before placement.
- Sign the Article 47 declaration and register in the EU Database under Article 49.
- For non-EU providers: designate an authorised representative under Article 22 before placement.
What deployers must do
- Use the system in accordance with the Article 13 instructions for use.
- Assign Article 14 / Article 26(2) human oversight to competent, trained, authorised persons.
- Ensure deployer-controlled input data is relevant and representative.
- Monitor operation; inform the provider of incidents under Article 26(5).
- Where Article 27 applies, perform a FRIA.
- For public-sector deployers, register the deployment under Article 49 + Article 26(8).
- Inform workers of high-risk AI systems used at the workplace under Article 26(7) before put-into-service.
Inline crosswalk
- ISO/IEC 42001:2023 Annex A.5.2 — AI system impact assessment.
- ISO/IEC 42001:2023 Annex A.9.2 — Human oversight.
- NIST AI RMF MAP 1.1 — Intended purposes and context understood.
- NIST AI RMF MAP 5.1 — Likelihood and magnitude of impacts characterised.
Penalties
Article 99(4) — up to €15 million or 3% of worldwide annual turnover, whichever is higher.
Disclaimer. Reference; not legal advice. Verify with counsel. Reg text from Regulation (EU) 2024/1689.
Reference checklist
From the Governancer 30-item EU AI Act checklist. Each item joins to the ISO 42001 + NIST AI RMF crosswalk table below.
Article 11 · Starter tier · critical
Draft technical documentation (system purpose, design, risk)
Required for all high-risk AI systems before market placement. Our template covers the eight mandatory sections in one .docx.
Article 9 · Starter tier · high
Establish risk management system
A continuous iterative process. Identify foreseeable risks, estimate impact, document mitigations, review at least quarterly.
Article 14 · Starter tier · high
Document human oversight measures and operator training
Operators must be able to interpret outputs, decide to override, and stop the system when needed. Write it down.
ISO 42001 + NIST AI RMF crosswalk
Pulled live from the Governancer crosswalk module. Mapping reference; not a substitute for ISO 42001 certification audit or NIST AI RMF self-attestation.
ISO/IEC 42001:2023
| Checklist item | ISO 42001 control | Rationale |
|---|---|---|
art11-tech-docs | ISO/IEC 42001:2023 Clause 7.5 — Documented information | Article 11 technical file is the AIMS-required documented information evidencing AI system design, purpose, and risk decisions. |
art11-tech-docs | ISO/IEC 42001:2023 Annex A.6.2 — AI system life cycle documentation | Annex A.6.2 requires lifecycle documentation; the Article 11 technical file is its EU AI Act manifestation. |
art9-risk-mgmt | ISO/IEC 42001:2023 Clause 6.1.2 — AI risk assessment | A continuous Article 9 risk management process is the EU-AI-Act realisation of Clause 6.1.2 risk assessment. |
art9-risk-mgmt | ISO/IEC 42001:2023 Clause 6.1.3 — AI risk treatment | Article 9 mitigation, residual-risk recording and quarterly review provide the risk-treatment evidence required by Clause 6.1.3. |
art14-oversight | ISO/IEC 42001:2023 Annex A.9.2 — Human oversight of AI systems | Article 14 oversight measures + operator competence map directly to Annex A.9.2 human-oversight controls. |
NIST AI RMF 1.0
| Checklist item | NIST AI RMF subcategory | Rationale |
|---|---|---|
art11-tech-docs | NIST AI RMF MAP 4.1 — Approaches and metrics for measurement of AI risks are followed; documentation includes purpose, intended use, users, and limitations | Article 11 technical file documents purpose, design and limitations — the system-context output expected by MAP 4.1. |
art11-tech-docs | NIST AI RMF GOVERN 1.4 — The risk management process is documented and is regularly reviewed | Maintaining a living technical file is the documented and regularly reviewed risk-management evidence under GOVERN 1.4. |
art9-risk-mgmt | NIST AI RMF GOVERN 1.1 — Legal and regulatory requirements involving AI are understood, managed, and documented | EU AI Act Article 9 risk management explicitly captures the regulatory requirements GOVERN 1.1 wants documented. |
art9-risk-mgmt | NIST AI RMF MANAGE 1.3 — Responses to the AI risks deemed high priority are developed, planned, and documented | Article 9 mitigation plans for residual high-priority risks are exactly the responses MANAGE 1.3 expects. |
art14-oversight | NIST AI RMF GOVERN 3.2 — Policies and procedures define and differentiate roles and responsibilities for human-AI configurations | Article 14 documented oversight measures and operator roles map directly to GOVERN 3.2 human-AI role definition. |
art14-oversight | NIST AI RMF MEASURE 2.8 — Risks associated with transparency and accountability are examined and documented | Operator override paths and stop-controls are the accountability mechanisms MEASURE 2.8 examines. |
Related
Pro feature
Generate Article 11 with AI
LLM-assisted draft of all eight Annex IV sections, pre-filled from your system intake. 5 drafts/month on Pro.
Pro template
Download FRIA template
15-page Article 27 FRIA template (.docx) with the six elements pre-structured and a worked example.
Get the 30-item EU AI Act compliance checklist
Free PDF. No spam. Maps every Article and Annex IV section we ship to a ready-to-action checklist row.
Reference; not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text quoted from the Official Journal version of Regulation (EU) 2024/1689. Published by Agonist Development AB.