Annex III of the EU AI Act (Regulation 2024/1689) enumerates the deployment contexts that make an AI system "high-risk" regardless of how well it performs: biometric identification and categorization, critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services (including creditworthiness scoring and health/life insurance pricing), law enforcement, migration and border control, and administration of justice. These are precisely the domains where a differential error rate stops being a metric and starts being discrimination.
High-risk classification triggers binding obligations under Chapter III: risk management across the lifecycle, data governance aimed at "examining in view of possible biases," technical documentation, logging, human oversight, and accuracy/robustness requirements. Article 10 requires that training, validation, and testing data sets be examined for biases likely to affect health, safety, or fundamental rights — and permits processing special-category personal data where strictly necessary to detect and correct that bias.
Notably, the Act treats outcome rather than intent as the trigger. A provider cannot discharge its obligation by showing that no protected attribute was used as an input feature; it must show the system was tested for the effects it actually produces.