EU AI Act High-Risk AI Systems: EU Commission Publishes Draft Guidance

· Source: Debevoise Data Blog · Field: Legal & Regulatory — Compliance & Risk Management, Regulatory Affairs & Government Relations · Depth: Intermediate, medium

Summary

The European Commission has released draft guidance for classifying "high-risk" AI systems under the EU AI Act, including practical examples for various categories. This guidance, open for stakeholder feedback until June 23, 2026, clarifies how the Commission interprets the Act's high-risk classification rules. Its publication follows a provisional agreement to delay compliance obligations: stand-alone high-risk AI systems (Annex III) must comply by December 2, 2027, and embedded systems (Annex I) by August 2, 2028. The high-risk designation is crucial as it triggers extensive compliance requirements for providers, covering areas like risk management, data governance, and transparency, while deployers face a more limited set of duties. The guidance emphasizes that classification hinges on the AI system's intended purpose, not potential misuse, and distinguishes between administrative support and substantive influence in decision-making.

Key takeaway

For legal professionals advising on AI strategy, you should immediately integrate the EU Commission's draft guidance into your AI governance policies and risk-classification workflows. This clarifies the "intended purpose" principle and the broad interpretation of high-risk categories, which are then narrowed by the Article 6(3) filter. Ensure your organization's AI tools are clearly positioned for their intended use, especially in employment contexts, to avoid unintended "high-risk" classifications. Prioritize purpose-built AI tools for sensitive applications to better insulate your deployer clients from provider-level compliance burdens.

Key insights

EU AI Act "high-risk" classification hinges on intended purpose and substantive influence, clarified by new draft guidance.

Principles

Method

AI system classification under EU AI Act involves provider assessment of intended purpose, considering all materials, and applying Article 6(3) filter for narrowing scope.

In practice

Topics

Best for: CTO, VP of Engineering/Data, Executive, Legal Professional, Director of AI/ML, Policy Maker

Related on AIssential

Open in AIssential →

Editorial summary, takeaway, and curation by AIssential. Original article published by Debevoise Data Blog.