News and developments
Draft Commission Guidelines on the Classification of High-Risk AI Systems Published
Introduction
The EU Artificial Intelligence Act (the 'AI Act' or the 'Act'), which entered into force on 1 August 2024 and became generally applicable on 2 August 2026, subject to a series of staggered application dates, established a harmonised regulatory framework for AI systems across the Union. The Act is structured around a risk-based approach, with 'high-risk' AI systems constituting its cornerstone. Once the relevant provisions become applicable, systems falling within this category will be subject to extensive compliance obligations encompassing risk management, technical documentation, registration in the EU database, transparency requirements, and human oversight obligations.
Whilst Article 6 of the Act delineates the scope of high-risk systems, it leaves several questions unanswered as to how to assess in practice whether a given system falls within that perimeter. Through a suite of three draft guidelines published on 19 May 2026[i], the European Commission ('Commission') seeks to resolve these interpretive ambiguities. The three documents address, respectively: the general principles governing classification; systems covered by product safety legislation; and the high-risk use cases enumerated in Annex III.
Whilst the guidelines are not legally binding, they are widely expected to serve as a significant interpretive reference for supervisory authorities and market participants alike. The stakeholder consultation period, originally due to close on 23 June 2026, closed on 23 July 2026 following a one-month extension. The Commission indicated that the received would be incorporated into the final text before its adoption.
Since the publication of the draft guidelines, the application tinemtable for high-risk AI systems has also been revised. Regulation (EU) 2026/1744 (the 'AI Omnibus'), which entered into force on 27 July 2026, amended Article 113 of the AI Act. Sections 1, 2, and 3 of Chapter III, with the exception of Article 6(5), will now apply from 2 December 2027 to high-risk AI systems classified under Article 6(2) and Annex III, and from 2 August 2028 to systems classified under Article 6(1) in connection with the product legislation listed in Annex I. These dates replace the previous application dates of 2 August 2026 and 2 August 2027, respectively.
General Framework for High-Risk Classification
According to the guidelines, for a system to be characterised as high-risk, two cumulative conditions must be satisfied: first, the system must qualify as an 'AI system' within the meaning of Article 3(1) of the AI Act; and second, its intended purpose must fall within one of the use cases designated as high-risk under Article 6 of the Act.
The pivotal concept in this assessment is 'intended purpose'. Pursuant to Article 3(12) of the Act, intended purpose denotes the use for which the system is designed by the provider, encompassing the specific context and conditions of use, as specified in the instructions for use, technical documentation, and promotional or sales materials.
The guidelines further provide that, where AI systems offered for a broad range of uses - including multipurpose or general-purpose AI ('GPAI') systems - do not clearly and consistently exclude high-risk use cases, the intended purpose of the system may be treated as encompassing those scenarios as well. In conducting this assessment, general disclaimer clauses in terms of service may not be sufficient on their own; the manner in which the system is marketed, and its product positioning in the market, may equally be taken into account.
The guidelines further observe that the obligations arising from high-risk classification are not necessarily confined to the provider that originally developed the system. Pursuant to Article 25(1) of the Act, distributors, importers, and deployers who place a high-risk system on the market under their own name, effect a substantial modification to the system, or alter its intended purpose in a manner that renders it high-risk may likewise become subject to provider obligations.
Systems Covered by Product Safety Legislation
Article 6(1) of the Act establishes a distinct high-risk classification for AI systems incorporated in products subject to EU harmonisation legislation - such as machinery, lifts, medical devices, toys, radio equipment, and motor vehicles. For an AI system to be characterised as high-risk under this provision, two cumulative conditions must be satisfied. The first is that the system must constitute a safety component of a product covered by the legislation enumerated in Annex I, or must itself qualify as a product falling within the scope of that legislation. The second is that the product concerned must be subject to a mandatory third-party conformity assessment prior to being placed on the market.
Where either of these conditions is not satisfied, the system will not be characterised as high-risk within the meaning of Article 6(1). It follows that not every AI system incorporated in a product covered by Annex I is automatically subject to high-risk classification. The assessment must be conducted by considering holistically the system's relationship with the product concerned, the role it performs from a product safety perspective, and the requirements of the applicable sectoral legislation.
Physical integration of the AI system into the product is not a prerequisite. AI systems operating as software updates, add-ons, or remotely delivered services may equally fall within the ambit of Article 6(1), depending on the specific circumstances of the case. The decisive consideration is not the modality of integration into the product, but the function the system performs from a product safety standpoint.
The AI System Itself as a Product
The first variant of the first condition is that the AI system itself constitutes a product falling within the scope of the legislation enumerated in Annex I. This situation arises where the system is independently placed on the market, is designed for a specific intended purpose, and is directly regulated by the relevant sectoral legislation. The guidelines indicate that, in certain cases, software-based systems may likewise be regarded as a product directly regulated under the applicable product legislation. It is therefore necessary to assess separately whether the AI system is subject to product safety rules not only as a component of another product, but also as a stand-alone product in its own right.
The Concept of Safety Component
The second variant of the first condition is that the AI system functions as a safety component of a product falling within the scope of the legislation enumerated in Annex I. The guidelines emphasise that the concept of 'safety component' carries an autonomous definition under the AI Act and must be assessed independently of the definitions contained in the sectoral legislation enumerated in Annex I. According to the Commission, an AI system may be regarded as a safety component in either of two scenarios. In the first, the system fulfils a safety function by virtue of its intended purpose. In the second, even where the system was not designed with such a purpose, its failure or malfunction could endanger the health, safety, or property of persons.
Safety function: AI systems designed to prevent or mitigate risks to the health and safety of persons or property are considered to fulfil a safety function. The guidelines cite as examples functions such as detecting abnormal behaviour, identifying maintenance needs, preventing operation under hazardous conditions, or supervising another safety system. By contrast, functions such as performance optimisation, efficiency enhancement, user comfort, or quality control that does not serve a safety purpose generally fall outside this ambit.
Failure or malfunction endangering health and safety: Even where a system was not designed for safety purposes, it may still be characterised as a safety component if its failure or malfunction could endanger the health and safety of persons or property. The guidelines indicate that failure modes such as erroneous outputs, loss of function, performance instability, timing errors, or misclassification may be taken into account in conducting this assessment. Reputational harm, purely financial loss, or inconvenience that does not involve a safety hazard falls outside this ambit.
Third-Party Conformity Assessment
The second condition under Article 6(1) of the AI Act requires that the product concerned be subject to a third-party conformity assessment. The manner in which that assessment is to be conducted is governed not by the AI Act itself but by the sectoral legislation enumerated in Annex I. According to the guidelines, the relevant question is not which procedure the manufacturer has in fact followed, but rather whether the applicable legislation mandates a third-party conformity assessment prior to placing the product on the market.
High-Risk Use Cases under Annex III
Article 6(2) of the Act designates as high-risk — independently of the product safety legislation regime — AI systems deployed in certain use cases enumerated in Annex III. Annex III encompasses eight distinct areas: biometrics; critical infrastructure; education and vocational training; employment and workers' management; access to and enjoyment of essential private and public services and benefits; law enforcement; migration, asylum, and border control management; and the administration of justice and democratic processes.
The mere fact that a system is deployed in an area covered by Annex III is not, of itself, sufficient to give rise automatically to a high-risk classification. The decisive consideration is whether the intended purpose of the system corresponds to one of the specific use cases enumerated in Annex III. Equally, the fact that a final decision is taken by a human being does not automatically exclude the system from the ambit of high-risk classification. Classification must accordingly be conducted by reference not only to the area of activity, but also to the intended purpose of the system, its role in the decision-making process, and the specific context of deployment.
The guidelines summarise the categories of use that may give rise to high-risk classification as follows:
Biometrics: Remote biometric identification systems, biometric categorisation systems, and emotion recognition systems.
Critical infrastructure: Systems capable of affecting physical safety or the secure and safe operation of infrastructure.
Education and vocational training: Systems that influence admission, placement, the determination of educational level, examination integrity, and summative assessment outcomes.
Employment and workers' management: Systems that influence the targeting of job advertisements, the screening or ranking of candidates, recruitment, promotion, task allocation, performance monitoring, and the termination of employment or work-related contractual relationships.
Access to and enjoyment of essential private and public services and benefits: Systems relating to public assistance benefits, creditworthiness assessment, risk evaluation and pricing in life and health insurance, and the prioritisation of emergency calls.
Law enforcement: Systems used for risk assessment, evaluation of the reliability of evidence, polygraph-type instruments, and certain systems employed in the course of the detection, investigation, or prosecution of criminal offences.
Migration, asylum, and border control management: Systems deployed for risk assessment of persons seeking to enter or remain, examination of visa, asylum, or residence applications, and the detection or identification of natural persons.
Administration of justice and democratic processes: Systems intended to assist judicial authorities in researching and interpreting facts and law, or in applying the law to a concrete set of facts, as well as systems intended to influence the outcome of elections or referenda or the voting behaviour of natural persons.
Not every system falling within a use case enumerated in Annex III is automatically characterised as high-risk. Article 6(3) of the Act provides a limited exception in favour of systems that do not pose a significant risk to the health, safety, or fundamental rights of persons. This exception may apply only where the system performs a narrowly circumscribed, auxiliary, or preparatory function.
A significant constraint on this exception concerns the performance of profiling. Where a system performs profiling within the meaning of the General Data Protection Regulation ('GDPR') — that is, where it automatically processes personal data for the purpose of evaluating or predicting certain characteristics or aspects of a natural person — the exception under Article 6(3) is unavailable.
Conclusion
The Commission's draft guidelines represent the most comprehensive interpretive clarifications published to date on the classification of high-risk AI systems. Whilst the guidelines are not legally binding, it is evident that they will serve as a significant reference point for market participants and supervisory authorities alike.
The approach articulated in the guidelines makes clear that AI systems cannot be characterised as high-risk merely by reference to the headings contained in the legislation. In the context of product safety legislation, the role performed by the system and potential failure scenarios must be assessed holistically; in the context of Annex III, the intended purpose, the degree of influence on the decision-making process, and the manner in which the system is presented to users must all be evaluated in conjunction
The revised timetable affords providers and deployers additional preparation time, but does not diminish the need for early classification. It is accordingly incumbent upon companies that develop, procure, or deploy AI systems to assess those systems from legal, technical, and commercial perspectives. In particular, in sectors subject to employment, education, financial services, and product safety regulation, an accurate classification conducted at an early stage is essential for the effective management of compliance and enforcement risk.
Author: Gülnur Çakmak Ergene, Erdem & Erdem Associate
[i] European Commission, Draft Commission Guidelines on the Classification of High-Risk AI Systems under Article 6 of the AI Act — General Principles, Annex I and Annex III, 19.05.2026, https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems (D.A. 14.06.2026).
