Is my use case a high-risk AI system? Applying the Commission’s guidelines and next steps

· Source: Data Protection Report · Field: Legal & Regulatory — Compliance & Risk Management, Regulatory Affairs & Government Relations · Depth: Intermediate, medium

Summary

The EU Commission published draft guidelines on high-risk AI systems on May 19, 2026, clarifying their classification under the EU AI Act. These guidelines, covering general principles, standalone (Annex III), and embedded (Annex I) AI systems, detail the application of the Article 6(3) derogation and provide examples for employment-related high-risk purposes. A key clarification states that human involvement does not exempt an AI system from high-risk classification. The four conditions for Article 6(3) derogation, such as performing a narrow procedural task or improving a completed human activity, must be interpreted narrowly and are exhaustive. Profiling AI systems remain high-risk regardless of these conditions. Providers face extensive obligations, including risk management, technical documentation, conformity assessment, and EU database registration, while deployers must manage usage risks and ensure human oversight. Specific employment examples illustrate high-risk scenarios like automated job matching and dynamic compensation, contrasting with systems like CV parsers that may qualify for Article 6(3) derogation. Compliance obligations for high-risk AI systems are set to apply from December 2, 2027.

Key takeaway

For Directors of AI/ML or legal professionals overseeing product development, you must proactively assess your AI systems against the EU AI Act's high-risk guidelines. Begin embedding compliance processes, including risk management and technical documentation, throughout your product lifecycle now, rather than attempting retrospective retrofitting. Deployers should implement technical controls and contractual protections to prevent inadvertently assuming provider obligations, especially when using general-purpose AI tools for high-risk applications. Your organization's compliance hinges on early, documented adherence to these strict requirements before December 2, 2027.

Key insights

The EU AI Act's high-risk classification is strict, with narrow derogations and significant obligations for providers and deployers.

Principles

Method

Providers must document an assessment for Article 6(3) reliance, detailing why the system is high-risk, which condition applies, and why it avoids profiling.

In practice

Topics

Best for: CTO, VP of Engineering/Data, Executive, Legal Professional, Consultant, Director of AI/ML

Related on AIssential

Open in AIssential →

Editorial summary, takeaway, and curation by AIssential. Original article published by Data Protection Report.