Vedlegg III — høyrisiko-KI-systemer
Vedlegg III lister bruksområder som inngår i høyrisikoklassifiseringen etter artikkel 6(2), blant annet biometri, kritisk infrastruktur, utdanning, arbeidsliv, viktige tjenester, politi, migrasjon og rettsvesen. Oppføring i listen er ikke alene en endelig klassifisering: artikkel 6(3) kan gjøre unntak når systemet ikke utgjør en vesentlig risiko for skade på helse, sikkerhet eller grunnleggende rettigheter, blant annet fordi det ikke påvirker beslutningsresultatet materielt, og et angitt vilkår er oppfylt. Et vedlegg III-system som profilerer fysiske personer, er alltid høyrisiko.
ANNEX III — High-risk AI systems referred to in Article 6(2): offisiell tekst
Offisiell engelsk tekst gjengitt fra EUR-Lex (forordning (EU) 2024/1689, CELEX 32024R1689); fotnotemarkører er utelatt. Den autentiske teksten i EU-tidende gjelder. Kontroller den konsoliderte, gjeldende teksten i kildene nedenfor. · Les på EUR-Lex
High-risk AI systems pursuant to Article 6(2) are the AI systems listed in any of the following areas:
1.Biometrics, in so far as their use is permitted under relevant Union or national law:
(a)remote biometric identification systems.
This shall not include AI systems intended to be used for biometric verification the sole purpose of which is to confirm that a specific natural person is the person he or she claims to be;
(b)AI systems intended to be used for biometric categorisation, according to sensitive or protected attributes or characteristics based on the inference of those attributes or characteristics;
(c)AI systems intended to be used for emotion recognition.
2.Critical infrastructure: AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, or in the supply of water, gas, heating or electricity.
3.Education and vocational training:
(a)AI systems intended to be used to determine access or admission or to assign natural persons to educational and vocational training institutions at all levels;
(b)AI systems intended to be used to evaluate learning outcomes, including when those outcomes are used to steer the learning process of natural persons in educational and vocational training institutions at all levels;
(c)AI systems intended to be used for the purpose of assessing the appropriate level of education that an individual will receive or will be able to access, in the context of or within educational and vocational training institutions at all levels;
(d)AI systems intended to be used for monitoring and detecting prohibited behaviour of students during tests in the context of or within educational and vocational training institutions at all levels.
4.Employment, workers’ management and access to self-employment:
(a)AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates;
(b)AI systems intended to be used to make decisions affecting terms of work-related relationships, the promotion or termination of work-related contractual relationships, to allocate tasks based on individual behaviour or personal traits or characteristics or to monitor and evaluate the performance and behaviour of persons in such relationships.
5.Access to and enjoyment of essential private services and essential public services and benefits:
(a)AI systems intended to be used by public authorities or on behalf of public authorities to evaluate the eligibility of natural persons for essential public assistance benefits and services, including healthcare services, as well as to grant, reduce, revoke, or reclaim such benefits and services;
(b)AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud;
(c)AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance;
(d)AI systems intended to evaluate and classify emergency calls by natural persons or to be used to dispatch, or to establish priority in the dispatching of, emergency first response services, including by police, firefighters and medical aid, as well as of emergency healthcare patient triage systems.
6.Law enforcement, in so far as their use is permitted under relevant Union or national law:
(a)AI systems intended to be used by or on behalf of law enforcement authorities, or by Union institutions, bodies, offices or agencies in support of law enforcement authorities or on their behalf to assess the risk of a natural person becoming the victim of criminal offences;
(b)AI systems intended to be used by or on behalf of law enforcement authorities or by Union institutions, bodies, offices or agencies in support of law enforcement authorities as polygraphs or similar tools;
(c)AI systems intended to be used by or on behalf of law enforcement authorities, or by Union institutions, bodies, offices or agencies, in support of law enforcement authorities to evaluate the reliability of evidence in the course of the investigation or prosecution of criminal offences;
(d)AI systems intended to be used by law enforcement authorities or on their behalf or by Union institutions, bodies, offices or agencies in support of law enforcement authorities for assessing the risk of a natural person offending or re-offending not solely on the basis of the profiling of natural persons as referred to in Article 3(4) of Directive (EU) 2016/680, or to assess personality traits and characteristics or past criminal behaviour of natural persons or groups;
(e)AI systems intended to be used by or on behalf of law enforcement authorities or by Union institutions, bodies, offices or agencies in support of law enforcement authorities for the profiling of natural persons as referred to in Article 3(4) of Directive (EU) 2016/680 in the course of the detection, investigation or prosecution of criminal offences.
7.Migration, asylum and border control management, in so far as their use is permitted under relevant Union or national law:
(a)AI systems intended to be used by or on behalf of competent public authorities or by Union institutions, bodies, offices or agencies as polygraphs or similar tools;
(b)AI systems intended to be used by or on behalf of competent public authorities or by Union institutions, bodies, offices or agencies to assess a risk, including a security risk, a risk of irregular migration, or a health risk, posed by a natural person who intends to enter or who has entered into the territory of a Member State;
(c)AI systems intended to be used by or on behalf of competent public authorities or by Union institutions, bodies, offices or agencies to assist competent public authorities for the examination of applications for asylum, visa or residence permits and for associated complaints with regard to the eligibility of the natural persons applying for a status, including related assessments of the reliability of evidence;
(d)AI systems intended to be used by or on behalf of competent public authorities, or by Union institutions, bodies, offices or agencies, in the context of migration, asylum or border control management, for the purpose of detecting, recognising or identifying natural persons, with the exception of the verification of travel documents.
8.Administration of justice and democratic processes:
(a)AI systems intended to be used by a judicial authority or on their behalf to assist a judicial authority in researching and interpreting facts and the law and in applying the law to a concrete set of facts, or to be used in a similar way in alternative dispute resolution;
(b)AI systems intended to be used for influencing the outcome of an election or referendum or the voting behaviour of natural persons in the exercise of their vote in elections or referenda. This does not include AI systems to the output of which natural persons are not directly exposed, such as tools used to organise, optimise or structure political campaigns from an administrative or logistical point of view.
Sammendrag — ikke offisiell oversettelse
Vedlegg III inneholder åtte områder. Bruk til et listet formål utløser vurdering etter artikkel 6(2), men artikkel 6(3) kan gi unntak når vilkårene er oppfylt. Et vedlegg III-system som profilerer fysiske personer, er alltid høyrisiko.
For en vanlig bedrift er punkt 4 det viktigste: KI til rekruttering og utvelgelse av søkere (4(a)), og KI som tar eller påvirker beslutninger om arbeidsforhold, fordeler oppgaver eller overvåker og vurderer ansatte (4(b)).
Pliktene som følger (artikkel 26 for brukere) gjelder i EU fra 2. desember 2027 — utsatt av Digital Omnibus (EU) 2026/1744 fra 2. august 2026. Produktinnebygde høyrisiko-systemer (vedlegg I) er utsatt til 2. august 2028.
Hva betyr dette for en norsk bedrift
Rekruttering og ansatte. Siling av CV-er, rangering av søkere og enkelte avgjørelser om ansatte kan falle inn under punkt 4. Klassifiser først etter artikkel 6(2) og 6(3); dersom et vedlegg III-system profilerer fysiske personer, er det alltid høyrisiko. Artikkel 26 gjelder bare etter en slik klassifisering og når øvrige vilkår er oppfylt.
I EU: fra 2. desember 2027 for frittstående systemer i vedlegg III (Digital Omnibus; var 2. august 2026). Vedlegg I (produktinnebygd) fra 2. august 2028.
I Norge: KI-loven er ikke vedtatt, EØS-innlemmelse gjenstår og ikrafttredelsesdato er ikke fastsatt. Mulig direkte EU-anvendelse må vurderes konkret etter artikkel 2.
Uansett, nå: KI i rekruttering kan utløse likestillings- og diskrimineringsloven og GDPR, blant annet artikkel 22 og 35 når vilkårene er oppfylt. Overvåking eller andre kontrolltiltak overfor ansatte kan i tillegg utløse arbeidsmiljøloven kapittel 9.
Tre kartleggingsspørsmål først; fortsett til full vurdering med 15 spørsmålsgrupper for åtte dokumentutkast.
Les også: Artikkel 4 — KI-kompetanse · Artikkel 5 — forbudte KI-praksiser · Artikkel 50 — åpenhetsplikt for chatboter og KI-innhold · Artikkel 26 — plikter for brukere av høyrisiko-KI · Tidslinje · Faktaregister
Kilder
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal L, 2024/1689, 12.7.2024 — https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R1689#anx_III
- AI Act — consolidated text as at 27.07.2026, EUR-Lex CELEX 02024R1689-20260727 — https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02024R1689-20260727
- AI Act Art. 26 — consolidated text, EUR-Lex — https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02024R1689-20260727#art_26
- AI Act Annex I — consolidated text, EUR-Lex — https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02024R1689-20260727#anx_I
- Digital Omnibus on AI, Regulation (EU) 2026/1744 — EUR-Lex — https://eur-lex.europa.eu/eli/reg/2026/1744/oj
- AI Act Art. 2 — consolidated text, EUR-Lex — https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02024R1689-20260727#art_2
- Arbeidsmiljøloven (LOV-2005-06-17-62) kap. 9 — Lovdata — https://lovdata.no/dokument/NL/lov/2005-06-17-62
- Likestillings- og diskrimineringsloven (LOV-2017-06-16-51) — Lovdata — https://lovdata.no/dokument/NL/lov/2017-06-16-51
- Personopplysningsloven (LOV-2018-06-15-38) / GDPR — Lovdata — https://lovdata.no/dokument/NL/lov/2018-06-15-38
- Regjeringen.no: Høring – utkast til ny lov om kunstig intelligens (30.06.2025) — https://www.regjeringen.no/no/dokumenter/3112327/id3112327/
- Halvorsen & Co (sekundærkilde): AI Act and AI legislation – what does it mean for you as an employer? (29.06.2026) — https://halvorsenco.no/en/articles/business-law/what-love-and-ai-mean-to-you-as-an-employer/