EU AI Act · use case
EU AI Act for Migration, Asylum and Border Control AI: High-Risk Obligations
AI used by authorities to assess migration risk, examine asylum applications or support border checks is high-risk under Annex III(7). What GovTech and border-tech vendors must document.
Classify my system in 3 minutesFree, no account. Pre-filled for this use case.
Risk tier
High-risk
High-risk (Annex III, point 7)
When it applies
High-risk obligations apply from 2 December 2027.
Regulation (EU) 2024/1689, Annex III(7)(a)-(d); Art. 5 general prohibitions still apply; Art. 27 fundamental rights impact assessment
AI used by or on behalf of competent public authorities in migration, asylum and border control management is high-risk under the EU AI Act. This covers risk-assessment tools that flag security, irregular-migration or health risks associated with a person, tools that examine asylum, visa or residence-permit applications, and systems used to support the detection, recognition or identification of individuals in a migration context, distinct from general biometric identification covered elsewhere.
This page is for GovTech and border-technology vendors, and for public authorities deploying automated triage or risk-scoring in migration and asylum casework. As with public benefits, the people affected typically have limited ability to challenge an automated outcome in real time, which is exactly why the Act treats this area with the same weight as law enforcement.
Classification
Why this classification applies
Annex III, point 7 lists AI systems intended to be used by or on behalf of competent public authorities, or by EU institutions, bodies or agencies, in migration, asylum and border control management for: (a) polygraphs or similar tools; (b) assessing a risk, including a security, irregular-migration or health risk, posed by a natural person who intends to enter or has entered a Member State; (c) examining applications for asylum, visa or residence permits, and associated complaints, with regard to eligibility; and (d) detecting, recognising or identifying natural persons in the context of migration, asylum or border-control management, other than verification of travel documents.
The exclusion for travel-document verification matters in practice: software that checks whether a passport or visa document is genuine, without profiling or risk-scoring the traveller, sits outside this specific entry. Software that scores a traveller’s likely intentions or risk level, or that decides how an asylum application should be handled, is squarely inside it.
General AI Act prohibitions under Article 5 are not suspended in this context: social-scoring-style practices and non-medical emotion recognition remain banned, and the narrow, judicially-authorised exception for real-time remote biometric identification by law enforcement is the only carve-out for that specific practice.
Obligations
What you have to do
- Risk management system with explicit attention to discrimination based on nationality, ethnicity or country of origin, which is a documented risk area in this sector (Art. 9).
- Data governance examining representativeness and bias in training data drawn from historical migration or asylum casework (Art. 10).
- Technical documentation and automatic logging sufficient for administrative and judicial review of individual decisions (Arts. 11, 12).
- Human oversight that keeps the actual asylum, visa or entry decision with a trained official, with the AI output presented as a documented input (Art. 14).
- Conformity assessment, EU declaration of conformity, CE marking, EU database registration, again noting that some entries in this domain can be subject to restricted public access (Arts. 43, 47, 48, 49).
- Fundamental rights impact assessment before deployment, given the direct link to asylum and non-refoulement obligations under international and EU law (Art. 27).
- A clear, accessible route for the affected person to obtain an explanation and to contest an automated or AI-supported outcome (Art. 86).
Paperwork
Documents to have on file
Get these documents drafted for your system
Run the free assessment, then unlock the Compliance Pack: a PDF report plus editable first drafts of every required document and a 90-day plan. €49 one-time, no subscription.
Common mistakes
Where companies get this wrong
- Assuming document-verification software is automatically exempt. The exemption is narrow — verifying that a document is genuine — and does not extend to risk-scoring the person presenting it.
- Training risk models on historical enforcement data without checking whether it embeds bias by nationality or route of entry, which is one of the most scrutinised risk areas in this domain.
- No documented fundamental-rights impact assessment before go-live, despite the direct link between these systems and asylum and non-refoulement obligations.
- Treating an EU-agency deployment (for example in support of a Member State’s border authority) as outside scope. Annex III(7) explicitly includes AI used by EU institutions, bodies and agencies in this domain.
FAQ
Frequently asked questions
Does verifying a passport chip against a database count as high-risk?
Pure authenticity verification of a travel document is excluded from Annex III(7)(d). If the same system also scores the traveller’s risk or intent, that additional function is high-risk even if the document check itself is not.
Are visa-processing chatbots covered?
A chatbot that only answers procedural questions is limited-risk under Article 50. If its output feeds into, or effectively decides, eligibility for a visa or residence permit, it moves into Annex III(7)(c).
How does this interact with the biometric-identification page?
Biometric identification used specifically for migration, asylum or border-control detection and identification falls under Annex III(7)(d); the same technology used for other purposes, such as retail or workplace access, falls under Annex III(1) instead. The legal basis and specific carve-outs differ, so treat the migration context as its own analysis.
This page is general information about Regulation (EU) 2024/1689, updated 2026-09-25. It is not legal advice; classifications depend on the exact intended purpose of a system. Deadlines reflect the Digital Omnibus adopted in June 2026.