EuroComply
Free assessment

EU AI Act · use case

EU AI Act for Predictive Policing and Law Enforcement AI: High-Risk and Prohibited Lines

AI that assesses reoffending risk, evaluates evidence or profiles suspects is high-risk under Annex III(6); some profiling-only risk tools are prohibited outright under Article 5.

Classify my system in 3 minutes

Free, no account. Pre-filled for this use case.

Risk tier

Depends on use

High-risk (Annex III, point 6); a narrow profiling-only configuration is prohibited (Art. 5(1)(d))

When it applies

Prohibitions apply since 2 February 2025. High-risk obligations apply from 2 December 2027.

Regulation (EU) 2024/1689, Annex III(6)(a)-(e); Art. 5(1)(d); Art. 27 fundamental rights impact assessment

Law enforcement is one of the most tightly regulated areas of the EU AI Act, and the entry point is different from most other use cases: the same category that makes these tools high-risk also contains one of the Act’s few outright prohibitions. This page covers AI used by or on behalf of police and criminal justice authorities to assess offending risk, evaluate evidence, profile suspects, or act as a polygraph-style tool, and is distinct from the biometric-identification page, which covers face and voice matching specifically.

The line to hold in mind throughout: predicting risk from objective, verifiable facts directly linked to criminal activity, to support a human assessment, is high-risk. Predicting risk from personality traits or profiling alone, with no such factual anchor, is prohibited.

Classification

Why this classification applies

Annex III, point 6 lists AI systems intended to be used by or on behalf of law-enforcement authorities, or by EU agencies in support of them, for: (a) assessing the risk of a natural person becoming a victim of criminal offences; (b) polygraphs or similar tools; (c) evaluating the reliability of evidence in a criminal investigation or prosecution; (d) assessing the risk of a person offending or re-offending, otherwise than based solely on profiling under Art. 3(4) GDPR-style profiling or personality traits; and (e) profiling in the course of detection, investigation or prosecution of criminal offences.

Article 5(1)(d) prohibits AI systems that assess or predict the risk of a natural person committing a criminal offence based solely on profiling or on assessing personality traits and characteristics, without those predictions being supported by objective, verifiable facts directly linked to a criminal activity. The exact position of a risk-scoring tool therefore depends on its inputs: a model built on documented prior convictions, verified incident reports or similar factual records is a candidate for the high-risk Annex III(6)(d) route; a model that infers risk mainly from demographic or behavioural profiling, without that factual anchor, risks the prohibition.

Evidence-reliability tools (forensic AI, digital-evidence triage) and profiling tools used during an investigation are high-risk under points (c) and (e) even when they do not touch predictive risk scoring at all, because assessing evidence or profiling a suspect has direct consequences for someone’s liberty.

Obligations

What you have to do

  • Run the Art. 5(1)(d) test first and document it: is any risk prediction anchored in objective, verifiable facts linked to criminal activity, and does it support rather than replace a human assessment? Do not deploy a configuration that fails this test.
  • Risk management system covering wrongful-flag and discriminatory-impact risks, given the severity of consequences for people under investigation (Art. 9).
  • Data governance examining whether training data (arrest records, charge data, investigative records) embeds historical enforcement bias, with documented mitigation (Art. 10).
  • Technical documentation and automatic logging sufficient for judicial and oversight review (Arts. 11, 12).
  • Human oversight that keeps investigative and charging decisions with a human, with the AI output clearly presented as one input among several (Art. 14).
  • Conformity assessment, EU declaration of conformity, CE marking, EU database registration — note that some law-enforcement, migration and biometric high-risk systems have non-public or restricted EU database entries (Arts. 43, 47, 48, 49).
  • Fundamental rights impact assessment before deployment by the law-enforcement authority (Art. 27).

Paperwork

Documents to have on file

Art. 5(1)(d) prohibition test memo
Annex IV technical documentation
Risk management file with bias analysis on enforcement data
Data governance records
Human oversight procedure for investigators
Fundamental rights impact assessment (Art. 27)
EU declaration of conformity and EU database registration (restricted entry where applicable)

Get these documents drafted for your system

Run the free assessment, then unlock the Compliance Pack: a PDF report plus editable first drafts of every required document and a 90-day plan. €49 one-time, no subscription.

Start free assessment

Common mistakes

Where companies get this wrong

  • Marketing a tool as predicting “risk of reoffending” built mainly on demographic and behavioural profiling, without a documented factual anchor. This is the precise scenario Article 5(1)(d) targets.
  • Treating evidence-reliability or forensic-triage tools as “back office” and therefore low-risk. Annex III(6)(c) puts them squarely in the high-risk tier regardless of how technical or unglamorous the task looks.
  • Selling into law enforcement without recognising that some conformity or registration steps differ from the standard commercial route (partly non-public database entries, additional national security carve-outs to check).
  • Assuming EU institutions and agencies (Europol, Frontex-adjacent tooling) are exempt. Annex III(6) explicitly includes AI used by EU agencies in support of law-enforcement authorities.

FAQ

Frequently asked questions

Is a tool that predicts victimisation risk (not offending risk) treated the same way?

It sits in the same Annex III(6)(a) high-risk entry but is not covered by the Article 5(1)(d) prohibition, which is specifically about predicting a person committing an offence. It still needs the full high-risk documentation set.

We build a records-management system that happens to surface a risk score computed elsewhere. Are we in scope?

If your system generates, materially shapes, or is the first point where the risk score is presented for operational use, you are likely a provider or, at minimum, need to understand your role carefully. Passive storage of a score computed and controlled entirely by another system is a narrower case; document the analysis.

Does this cover private security firms, not just police?

Annex III(6) is about AI used by or on behalf of law-enforcement authorities. A private security firm’s own risk tooling for its private clients is generally outside this specific entry, though other Annex III points (such as biometric identification) can still apply.

This page is general information about Regulation (EU) 2024/1689, updated 2026-09-25. It is not legal advice; classifications depend on the exact intended purpose of a system. Deadlines reflect the Digital Omnibus adopted in June 2026.

Related use cases

Depends on use

Biometric identification & categorisation

Read →

High-risk

Migration, asylum & border control AI

Read →

High-risk

Legal tech & judicial assistance AI

Read →

Guide

EU AI Act compliance guide

Read →