Annex III §5

EU AI Act Annex III §5 — Essential Private and Public Services (High-Risk)

Essential Private and Public Services AI systems are high-risk under Annex III §5 of Regulation (EU) 2024/1689. What's covered, the obligations triggered, and what providers and deployers must do.

Source: Regulation (EU) 2024/1689 on EUR-Lex · Last published 2026-04-28 · Draft pending human review

Why this category is high-risk

Annex III §5 of Regulation (EU) 2024/1689 designates essential private and public services AI systems as high-risk. Annex III §5 covers AI used by public authorities to evaluate eligibility for essential public assistance benefits and services (health, social security, etc.); AI used to evaluate creditworthiness or establish credit scores (with a fraud-detection carve-out); AI used for risk assessment and pricing in life and health insurance; AI used to dispatch or establish priority for emergency services. Most §5 deployers owe a FRIA under Article 27.

What is covered

Examples in scope (point a) — public benefits:

  • AI for social-housing eligibility scoring.
  • AI for unemployment-benefits triage.
  • AI for healthcare-priority queue placement.

Examples in scope (point b) — credit:

  • Consumer and business loan decisioning.
  • Buy-now-pay-later approvals.
  • Mortgage scoring.
  • Out of scope: systems used exclusively for fraud detection.

Examples in scope (point c) — life and health insurance:

  • Underwriting models for life or health policies.
  • Premium-pricing models for life or health policies.

Examples in scope (point d) — emergency services:

  • AI dispatch prioritisation for police, fire, ambulance.
  • AI triage for emergency-department admissions.

Why §5 is the FRIA epicentre

Article 27(1) explicitly names §5(b) credit deployers and §5(c) insurance deployers as FRIA-required regardless of whether they are public-sector. Combined with public-sector deployers under §5(a), this is the largest practical FRIA population.

What providers must do — §5 specifics

  • Disaggregated metrics across socio-economic deciles, age bands, geographic regions.
  • Detailed Article 13 instructions for use for the deployer's FRIA section (d): identified risks of harm, evidenced from validation runs.
  • Where the system makes decisions on natural persons under Article 22 GDPR, ensure compatibility with the GDPR right to obtain human intervention.

What deployers must do — §5 specifics

Obligations triggered

A system falling under §5 triggers the full Chapter III Section 2 + Section 3 stack:

Where the deployer is a public-sector body, a private entity providing public services, a credit-decision deployer (Annex III §5(b)), or a life/health insurance pricing deployer (Annex III §5(c)), the deployer also owes a FRIA under Article 27. Annex III §2 critical infrastructure is excluded from FRIA.

What providers must do

What deployers must do

  • Use the system in accordance with the Article 13 instructions for use.
  • Assign Article 14 / Article 26(2) human oversight to competent, trained, authorised persons.
  • Ensure deployer-controlled input data is relevant and representative.
  • Monitor operation; inform the provider of incidents under Article 26(5).
  • Where Article 27 applies, perform a FRIA.
  • For public-sector deployers, register the deployment under Article 49 + Article 26(8).
  • Inform workers of high-risk AI systems used at the workplace under Article 26(7) before put-into-service.

Inline crosswalk

  • ISO/IEC 42001:2023 Annex A.5.2 — AI system impact assessment.
  • ISO/IEC 42001:2023 Annex A.9.2 — Human oversight.
  • NIST AI RMF MAP 1.1 — Intended purposes and context understood.
  • NIST AI RMF MAP 5.1 — Likelihood and magnitude of impacts characterised.

Penalties

Article 99(4) — up to €15 million or 3% of worldwide annual turnover, whichever is higher.


Disclaimer. Reference; not legal advice. Verify with counsel. Reg text from Regulation (EU) 2024/1689.

Reference checklist

From the Governancer 30-item EU AI Act checklist. Each item joins to the ISO 42001 + NIST AI RMF crosswalk table below.

  • Article 11 · Starter tier · critical

    Draft technical documentation (system purpose, design, risk)

    Required for all high-risk AI systems before market placement. Our template covers the eight mandatory sections in one .docx.

  • Article 9 · Starter tier · high

    Establish risk management system

    A continuous iterative process. Identify foreseeable risks, estimate impact, document mitigations, review at least quarterly.

  • Article 14 · Starter tier · high

    Document human oversight measures and operator training

    Operators must be able to interpret outputs, decide to override, and stop the system when needed. Write it down.

ISO 42001 + NIST AI RMF crosswalk

Pulled live from the Governancer crosswalk module. Mapping reference; not a substitute for ISO 42001 certification audit or NIST AI RMF self-attestation.

ISO/IEC 42001:2023

Checklist itemISO 42001 controlRationale
art11-tech-docsISO/IEC 42001:2023 Clause 7.5 — Documented informationArticle 11 technical file is the AIMS-required documented information evidencing AI system design, purpose, and risk decisions.
art11-tech-docsISO/IEC 42001:2023 Annex A.6.2 — AI system life cycle documentationAnnex A.6.2 requires lifecycle documentation; the Article 11 technical file is its EU AI Act manifestation.
art9-risk-mgmtISO/IEC 42001:2023 Clause 6.1.2 — AI risk assessmentA continuous Article 9 risk management process is the EU-AI-Act realisation of Clause 6.1.2 risk assessment.
art9-risk-mgmtISO/IEC 42001:2023 Clause 6.1.3 — AI risk treatmentArticle 9 mitigation, residual-risk recording and quarterly review provide the risk-treatment evidence required by Clause 6.1.3.
art14-oversightISO/IEC 42001:2023 Annex A.9.2 — Human oversight of AI systemsArticle 14 oversight measures + operator competence map directly to Annex A.9.2 human-oversight controls.

NIST AI RMF 1.0

Checklist itemNIST AI RMF subcategoryRationale
art11-tech-docsNIST AI RMF MAP 4.1 — Approaches and metrics for measurement of AI risks are followed; documentation includes purpose, intended use, users, and limitationsArticle 11 technical file documents purpose, design and limitations — the system-context output expected by MAP 4.1.
art11-tech-docsNIST AI RMF GOVERN 1.4 — The risk management process is documented and is regularly reviewedMaintaining a living technical file is the documented and regularly reviewed risk-management evidence under GOVERN 1.4.
art9-risk-mgmtNIST AI RMF GOVERN 1.1 — Legal and regulatory requirements involving AI are understood, managed, and documentedEU AI Act Article 9 risk management explicitly captures the regulatory requirements GOVERN 1.1 wants documented.
art9-risk-mgmtNIST AI RMF MANAGE 1.3 — Responses to the AI risks deemed high priority are developed, planned, and documentedArticle 9 mitigation plans for residual high-priority risks are exactly the responses MANAGE 1.3 expects.
art14-oversightNIST AI RMF GOVERN 3.2 — Policies and procedures define and differentiate roles and responsibilities for human-AI configurationsArticle 14 documented oversight measures and operator roles map directly to GOVERN 3.2 human-AI role definition.
art14-oversightNIST AI RMF MEASURE 2.8 — Risks associated with transparency and accountability are examined and documentedOperator override paths and stop-controls are the accountability mechanisms MEASURE 2.8 examines.

Pro feature

Generate Article 11 with AI

LLM-assisted draft of all eight Annex IV sections, pre-filled from your system intake. 5 drafts/month on Pro.

Pro template

Download FRIA template

15-page Article 27 FRIA template (.docx) with the six elements pre-structured and a worked example.

Get the 30-item EU AI Act compliance checklist

Free PDF. No spam. Maps every Article and Annex IV section we ship to a ready-to-action checklist row.


Reference; not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text quoted from the Official Journal version of Regulation (EU) 2024/1689. Published by Agonist Development AB.