Judicial research tools, arbitration, election influence — administration of justice and democratic processes is the eighth of the Annex III high-risk areas, and the most commonly over-read. Here is what it actually catches, what it deliberately leaves out, and why most legal-tech falls outside it.
Point 8 is narrower than its name suggests. It catches AI used by a judicial authority or on their behalf to research and interpret facts and law and apply law to a concrete set of facts — plus the same thing in alternative dispute resolution where the outcome has legal effect. A law firm’s own research copilot is not point 8, because the firm argues the case rather than deciding it. Court administration is explicitly carved out: anonymising judgments, internal communication and scheduling are not high-risk. A separate limb, point 8(b), catches AI meant to influence how people vote.
Justice sits in Annex III for a reason recital 61 states plainly: these systems have a “potentially significant impact on democracy, the rule of law, individual freedoms as well as the right to an effective remedy and to a fair trial”. But the same recital draws an unusually clear boundary around what counts — and a great deal of what people assume is caught is not.
Point 8 (“Administration of justice and democratic processes”) has two limbs that have almost nothing to do with each other. The first is about adjudication:
“AI systems intended to be used by a judicial authority or on their behalf to assist a judicial authority in researching and interpreting facts and the law and in applying the law to a concrete set of facts, or to be used in a similar way in alternative dispute resolution”
Regulation (EU) 2024/1689, Annex III, point 8(a)Three conditions have to line up: a judicial authority (or someone acting on its behalf), the substantive work of deciding — researching and interpreting facts and law, applying law to facts — and, for alternative dispute resolution, an outcome with legal effect. Miss any one of them and point 8(a) does not apply.
The second limb is about voting:
“AI systems intended to be used for influencing the outcome of an election or referendum or the voting behaviour of natural persons in the exercise of their vote in elections or referenda. This does not include AI systems to the output of which natural persons are not directly exposed, such as tools used to organise, optimise or structure political campaigns from an administrative or logistical point of view”
Regulation (EU) 2024/1689, Annex III, point 8(b)Note the drafting shared with the rest of Annex III: “intended to be used”. Classification follows the purpose the system serves, not the product category it is sold under. And under Article 6(2), landing on this list is the default route to high-risk — the burden sits on showing an exception applies.
Verdicts follow the text of the Regulation (Annex III point 8, Article 6(3) with recital 53) and recitals 61 and 62, which are unusually specific about the boundaries here. Where the answer genuinely turns on configuration, the row says borderline rather than forcing a bucket.
| Use case | Verdict | Why |
|---|---|---|
| Case-law research and analysis deployed by a court to assist judges | High-risk | Point 8(a): used by a judicial authority to assist in researching and interpreting facts and the law |
| AI drafting decision or judgment proposals for a judge | High-risk | Point 8(a) — applying the law to a concrete set of facts. Recital 61: AI may support judicial decision-making but “should not replace it” |
| Sentencing or recidivism risk scoring used in proceedings | High-risk | Point 8(a) where used by or for the court. Law-enforcement uses of the same technique are separately caught by Annex III point 6 |
| Arbitration or ADR analysis where the award has legal effect | High-risk | Point 8(a) covers “a similar way in alternative dispute resolution”; recital 61 ties it to outcomes that “produce legal effects for the parties” |
| AI generating or micro-targeting persuasive content shown to voters | High-risk | Point 8(b): intended to influence the outcome of an election or voting behaviour, with voters directly exposed to the output |
| Legal research or drafting copilot used by a private law firm | Not point 8 | Not used by or on behalf of a judicial authority — the firm represents a party. Other duties still apply; see below |
| Contract review, due diligence, e-discovery in commercial practice | Not point 8 | No judicial authority, no adjudication. Check point 4 if the same platform touches hiring or workforce decisions |
| Anonymisation or pseudonymisation of judgments and case documents | Not high-risk | Recital 61 names this verbatim as a purely ancillary administrative activity that does not affect the administration of justice in individual cases |
| Court scheduling, docket management, internal communication | Not high-risk | Recital 61: “communication between personnel, administrative tasks” |
| Campaign CRM, canvassing logistics, internal turnout analytics | Not high-risk | Point 8(b) carve-out: natural persons are not directly exposed to the output |
| Hearing transcription and translation for a court | Borderline — assess under Art 6(3) | Plausibly a preparatory task under Art 6(3)(d), which names translation. It stops being preparatory once it summarises, weighs or characterises evidence — document the assessment (Art 6(4)) |
| Chatbot on a court website answering procedural questions | Not point 8 | No interpretation or application of law to a concrete case. Article 50 disclosure applies — people must be told they are talking to a machine |
The same product, two verdicts. A legal research platform sold to both law firms and courts falls outside point 8 in the first deployment and is high-risk in the second — the deciding factor is who deploys it and for what, not what it does technically. Vendors selling into the public sector should expect the court, as deployer, to ask for the provider-side evidence stack; firms buying the same product will not. Classify per deployment, and record which one you are.
This is where most classification errors happen, in both directions. The phrase is “used by a judicial authority or on their behalf” — the possessive points back at the judicial authority. It reaches a supplier or service provider operating a system for the court: a hosted research service the court subscribes to, a contractor running analysis for the registry, a vendor whose tool is embedded in the judicial workflow.
It does not reach a party to the proceedings. A law firm using AI to build its own argument is doing advocacy, not adjudication, however sophisticated the tool. That is a statement about Article 6 scope, not a general clearance:
Recital 62 frames this limb as protection against “undue external interference with the right to vote enshrined in Article 39 of the Charter”, and it applies without prejudice to Regulation (EU) 2024/900 on the transparency and targeting of political advertising — two regimes running in parallel, not one replacing the other.
The dividing line is direct exposure. If a natural person sees, hears or reads the system’s output as part of an attempt to shape how they vote, point 8(b) is in play. If the system only helps a campaign organise itself — routing volunteers, structuring a database, forecasting turnout for internal planning — the Annex text and recital 62 both put it outside. Note that deepfakes and synthetic political content carry Article 50(4) labelling duties on top, and those duties apply from 2 August 2026 regardless of the high-risk timeline.
Annex III listing is the default, not the final word. Under Article 6(3), a listed system is not high-risk if it does not pose a significant risk of harm to health, safety or fundamental rights — “including by not materially influencing the outcome of decision making” — and meets at least one of four conditions: a narrow procedural task; improving the result of a previously completed human activity; detecting decision-making patterns or deviations without replacing or influencing a completed human assessment absent proper review; or a preparatory task to an assessment.
In a justice setting the fourth condition does real work — recital 53 names indexing, searching, translation and file handling as preparatory tasks, which is much of what court IT actually runs. But the bar is materially influencing the outcome, and a research tool that surfaces which authorities matter is already shaping the decision. The honest test: if a judge would reach a different conclusion without the tool, the exception is gone.
The profiling trap. None of the four conditions helps if the system profiles natural persons: “an AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons” (Art 6(3), final subparagraph). Recidivism scoring, litigant risk assessment and voter-persuasion targeting are all profiling — automated evaluation of personal aspects — so the derogation is closed to them before the four conditions are even reached.
Claiming the exception is a documented act, not an opinion. Under Article 6(4), a provider that considers its Annex III system not high-risk must document that assessment before the system is placed on the market or put into service, register it in the EU database under Article 49(2), and produce the documentation to national authorities on request.
Courts and traditional ADR bodies mostly buy rather than build, which makes them deployers under Article 26: use per instructions, assign human oversight to people with the necessary competence, training and authority, control input data quality where you control the inputs, monitor operation and report serious incidents, and keep the automatically generated logs for at least six months.
Fundamental rights impact assessment (FRIA): unlike most of Annex III, this is where the FRIA duty genuinely bites. Article 27(1) requires a FRIA from deployers that are bodies governed by public law and from private entities providing public services — a category recital 96 illustrates with education, healthcare, social services, housing and administration of justice. A court deploying a point 8(a) system is squarely in scope; so is a private body running adjudicative functions as a public service. The FRIA must cover the deployment processes, the period and frequency of use, the categories of people affected, the specific risks of harm to them, the human-oversight measures and the governance arrangements if risks materialise.
Registration in the EU database. Public-sector deployers carry a duty most private companies never meet. Under Article 49(3), deployers that are public authorities, Union institutions, bodies, offices or agencies, or persons acting on their behalf must register themselves, select the system, and register its use in the EU database before putting a high-risk system into service. For a court, that means the deployment becomes a matter of public record — a materially different exposure from a private company’s internal file.
The affected person’s right to an explanation. Article 86 gives any person subject to a decision the deployer takes on the basis of an Annex III system’s output — where it produces legal effects or similarly significantly and adversely affects them — the right to obtain “clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision taken”. In an adjudicative setting that is not a customer-service nicety: it is adjacent to the right to a reasoned decision, and it means the court has to be able to reconstruct what the tool contributed, long after the hearing.
Recital 61 also sets a substantive limit that no amount of paperwork satisfies: the use of AI tools “can support the decision-making power of judges or judicial independence, but should not replace it: the final decision-making must remain a human-driven activity”. Human oversight here is not a review checkbox — it is the constitutional point of the exercise.
If you build, resell, or put your name on such a system (Article 25), you carry the provider stack instead: risk management (Art 9), technical documentation, transparency to deployers (Art 13), human-oversight design (Art 14), conformity assessment and registration.
That catches more organisations here than the “courts buy, vendors build” picture suggests. A state court will not be writing adjudicative models, but tech-first online dispute resolution platforms — automated e-commerce arbitration and similar — routinely develop their own. Building a system and deploying it yourself is not a way to stay a mere deployer: “putting into service” is defined as supply for first use to a deployer or for own use (Article 3(11)), and a body that develops an AI system and puts it into service under its own name is a provider (Article 3(3)). Such a platform carries both stacks at once — the full provider obligations and, because it also operates the system, the Article 26 deployer duties on top.
The Regulation as enacted set 2 August 2026 for the Annex III obligations. The Digital Omnibus on AI — Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026 — moved that date to 2 December 2027. What did not move: the Article 5 prohibitions (in force since February 2025), the Article 4 literacy duty, and Article 50 transparency, which applies from 2 August 2026. For public-sector procurement cycles, December 2027 is not a long runway.
The unit of compliance is the use case, and in this area the same tool routinely lands on both sides of the line depending on who deploys it. That makes the reasoning — not just the verdict — the thing worth keeping: which limb of point 8 was considered, whether the deployer is a judicial authority or acting on its behalf, whether an Article 6(3) condition was claimed and why, and who signed it off. When the vendor ships an update that turns search into summarisation, that record is what tells you the classification needs revisiting.
Model Inventory for Jira turns each AI system into a work item in the Jira your team already uses, with a built-in EU AI Act category field and dynamic risk tiering. Record the Annex III verdict, the Article 6(3) rationale and the sign-off, with an immutable change history behind it. The legal judgement stays with your counsel; the inventory makes sure no system skips the question.
See how it worksTwo things. Point 8(a): AI used by a judicial authority or on their behalf to assist in researching and interpreting facts and the law and applying law to a concrete set of facts, and the equivalent in alternative dispute resolution. Point 8(b): AI intended to influence the outcome of an election or referendum, or voting behaviour — excluding systems whose output voters are not directly exposed to.
Not under point 8. The point is drafted around use by or on behalf of a judicial authority, and a firm represents a party rather than deciding the case. The same product becomes a point 8 system the moment a court deploys it to assist its judges. Article 50 transparency, Article 4 literacy duties and national professional rules apply either way.
No. Recital 61 names anonymisation and pseudonymisation of judicial decisions, documents or data as purely ancillary administrative activity, alongside communication between personnel and administrative tasks.
It can be. Point 8(a) extends to AI used in a similar way in alternative dispute resolution, and recital 61 limits that to proceedings whose outcomes “produce legal effects for the parties”. Analysis feeding a binding award is in scope; scheduling and document exchange are not.
Only where voters are directly exposed to the output. Campaign administration and logistics are explicitly carved out by point 8(b) itself. Systems producing or targeting persuasive material shown to voters are in scope, and synthetic political content also carries Article 50(4) labelling duties from August 2026.
Annex III high-risk obligations: 2 December 2027, moved from 2 August 2026 by the Digital Omnibus (Regulation (EU) 2026/1744, in force since 27 July 2026). Prohibitions: since February 2025. Article 50 transparency: from 2 August 2026.
This page is a practical explanation, not legal advice. Always confirm classification against the official text of Regulation (EU) 2024/1689 and, where the stakes warrant it, qualified counsel.