{"id":3708,"date":"2026-07-13T07:42:28","date_gmt":"2026-07-13T07:42:28","guid":{"rendered":"https:\/\/naaia.ai\/?p=3708"},"modified":"2026-07-13T07:53:40","modified_gmt":"2026-07-13T07:53:40","slug":"high-risk-ai-system-classification-ai-act-guidelines","status":"publish","type":"post","link":"https:\/\/naaia.ai\/en\/high-risk-ai-system-classification-ai-act-guidelines\/","title":{"rendered":"High-risk AI system classification: key changes introduced by the new EU guidelines"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">On 19 May 2026, the European Commission published <strong>draft guidelines<\/strong> on the classification of high-risk AI systems under Article 6 of the <strong>AI Act<\/strong>. Open for consultation until 23 July 2026, these guidelines have a clear objective: to help providers, deployers, and competent authorities determine more concretely whether an AI system falls within the scope of the high-risk regime. Although they are not legally binding, they currently reflect the Commission\u2019s interpretation of the AI Act and are expected to guide supervisory authorities in its application.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The obligations applicable to high-risk AI systems will be introduced progressively, with a first major compliance milestone on <strong>2 December 2027<\/strong> for systems covered by <strong>Annex III<\/strong>, followed by <strong>2 August 2028<\/strong> for AI systems integrated into products regulated under <strong>Annex I<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Commission further explains that the guidelines are intended to promote a <strong>consistent application of Article 6 of the AI Act across the European Union<\/strong>. To support this objective, they rely on practical examples designed to facilitate interpretation and help organizations assess their obligations more effectively.\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>I- The Two Classification Scenarios Under Article 6<\/strong>\u00a0<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>1. First\u00a0scenario:\u00a0Article 6(1) and Annex I<\/strong>\u00a0<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">An AI system&nbsp;is&nbsp;classified&nbsp;as&nbsp;<strong>high-risk<\/strong>&nbsp;when&nbsp;it&nbsp;meets&nbsp;<strong>three&nbsp;cumulative&nbsp;conditions<\/strong>:&nbsp;<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li>It is intended to be used as a\u00a0<strong>safety\u00a0component\u00a0of a\u00a0product<\/strong>, or\u00a0is itself such a product.\u00a0<\/li>\n<\/ol>\n\n\n\n<ol start=\"2\" class=\"wp-block-list\">\n<li>The\u00a0product\u00a0is\u00a0covered\u00a0by one of the EU harmonisation\u00a0laws\u00a0listed\u00a0in\u00a0<strong>Annex I<\/strong>.\u00a0<\/li>\n<\/ol>\n\n\n\n<ol start=\"3\" class=\"wp-block-list\">\n<li>The\u00a0product\u00a0is\u00a0subject\u00a0to a\u00a0<strong>third-party\u00a0conformity\u00a0assessment<\/strong>.\u00a0<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">In other words, the mere presence of AI within a regulated product is not sufficient to trigger a high-risk classification. Such classification requires a connection to a product safety function and an interaction with existing European conformity assessment regimes. The guidelines\u00a0also\u00a0reiterate\u00a0that\u00a0the AI\u00a0Act\u00a0itself\u00a0does\u00a0not\u00a0determine\u00a0the applicable\u00a0conformity\u00a0assessment\u00a0procedures.\u00a0Those\u00a0procedures\u00a0remain\u00a0governed\u00a0by the relevant\u00a0sector-specific\u00a0EU\u00a0harmonisation\u00a0legislation.\u00a0<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>2. Second\u00a0scenario:\u00a0Article 6(2) and Annex III<\/strong>\u00a0<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The second scenario concerns AI systems that fall within one of the <strong>use cases listed in Annex III of the AI Act<\/strong>. In this case, the assessment is not centred on a product but rather on a specific use of AI in areas considered particularly sensitive. The guidelines emphasize a fundamental point: the categories covered by <strong>Annexes I and III are exhaustive<\/strong>. As a result, the fact that an AI system is used in a sensitive sector does not automatically make it high-risk if its specific use case is not expressly listed in Annex I or Annex III of the AI Act.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Commission identifies&nbsp;eight&nbsp;broad&nbsp;areas&nbsp;covered&nbsp;by Annex&nbsp;III:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Biometrics;\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Critical\u00a0infrastructure;\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Education and\u00a0vocational\u00a0training;\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Employment,\u00a0worker\u00a0management and\u00a0access\u00a0to self-employment;\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Access to essential\u00a0private\u00a0services, public services and essential social\u00a0benefits;\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Law\u00a0enforcement;\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Migration,\u00a0asylum\u00a0and border control\u00a0management;\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Administration of justice and\u00a0democratic\u00a0processes.\u00a0<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>II-\u00a0The\u00a0Decisive\u00a0Role\u00a0of the\u00a0System\u2019s\u00a0Intended\u00a0Purpose<\/strong>\u00a0<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>1. The\u00a0need\u00a0to\u00a0define\u00a0the\u00a0system\u2019s\u00a0intended\u00a0purpose<\/strong>\u00a0<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The classification of an AI system as high-risk depends not only on its technical capabilities, but also on how its intended purpose is described by the provider in the technical documentation, contractual materials, terms of use, and promotional and marketing content.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This point is particularly important for <strong>general-purpose or multi-purpose AI systems<\/strong>. Where an AI system is intended to be used across a wide range of contexts and applications, without a clear limitation excluding high-risk uses, such uses may be considered part of its intended purpose if they are reasonably foreseeable. The guidelines therefore clarify that it is not sufficient to formally state that certain high-risk uses are excluded if, in practice, the product description suggests or promotes multiple uses that include such use cases. In other words, the assessment is not based solely on disclaimers, but on how the system is objectively presented and can reasonably be expected to be used.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>2. A\u00a0system\u00a0does\u00a0not\u00a0need\u00a0to\u00a0be\u00a0already\u00a0in\u00a0use to\u00a0be\u00a0classified\u00a0as\u00a0high-risk<\/strong>\u00a0<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The guidelines further clarify that an AI system may be classified as high-risk even before it is actually used. What matters is its intended purpose prior to being placed on the EU market or put into service. Providers must therefore assess the system\u2019s classification at that stage and, where applicable, prepare to comply with the requirements applicable to high-risk AI systems.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>III- Clarifications on the Concept of a \u201cSafety\u00a0Component\u201d<\/strong>\u00a0<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The guidelines provide a dual interpretation of the concept of a\u00a0<strong>safety\u00a0component.<\/strong>\u00a0<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>1. An\u00a0intent-based\u00a0approach:\u00a0the\u00a0safety\u00a0function<\/strong>\u00a0<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">An AI system qualifies as a safety\u00a0component\u00a0when, according to the purpose defined by the provider, it is intended to prevent or mitigate risks to the health or safety of persons\u00a0or to\u00a0property.\u00a0This definition is autonomous and applies independently of existing sector-specific definitions. It covers, for example, functions aimed at detecting anomalies,\u00a0identifying\u00a0critical maintenance needs, preventing unsafe operation, limiting the effects of a risk, or triggering safety measures.\u00a0<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>2. A\u00a0risk-based\u00a0approach:\u00a0failure or\u00a0malfunction<\/strong>\u00a0<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">An AI system may also qualify as a safety component where its failure or malfunction is capable of endangering the health or safety of persons or property. This approach encompasses situations such as false positives, false negatives, loss of functionality, performance instability, model drift, or classification errors that may lead to unsafe decisions. By contrast, reputational harm, financial losses, minor damage, or inconvenience are expressly excluded from this notion of endangerment.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>IV- Article 6(3): Clarifications on the \u201cFiltering Mechanism\u201d<\/strong>\u00a0<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Article 6(3)&nbsp;establishes&nbsp;a filtering mechanism that allows an AI system to be exempted from classification as high-risk where its intended purpose falls within a use case listed in Annex III, but the system does not present a significant risk of harm.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This exemption is subject to strict conditions. It applies only where the system does not pose a significant risk of harm to health, safety, or fundamental rights, and where it meets at least one of the four conditions set out in the AI Act. The guidelines further emphasize that this mechanism is based on a central principle: the system must not materially influence the outcome of the decision-making process.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>1. A\u00a0strictly\u00a0conditional\u00a0exemption<\/strong>\u00a0<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The filtering mechanism is not a general derogation that allows high-risk classification to be easily disregarded. Rather, it is an interpretative exception that requires <strong>a concrete assessment of the system\u2019s purpose, its context of use, and its actual influence on decision-making<\/strong>. The guidelines clarify that providers must carefully assess the tasks the system is intended to perform. This assessment is directly linked to the system\u2019s <strong>intended purpose<\/strong>, its conditions of use, and the decision-making framework within which it operates.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>2. The\u00a0four\u00a0conditions of the\u00a0filtering\u00a0mechanism<\/strong>\u00a0<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The mechanism is based on\u00a0<strong>four clearly defined situations<\/strong>\u00a0in\u00a0which an AI system\u00a0remains\u00a0in a supporting role and does not materially influence the final decision. These conditions are\u00a0<strong>alternative rather than cumulative<\/strong>, but they must be interpreted narrowly.\u00a0<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" style=\"font-size:clamp(0.875rem, 0.875rem + ((1vw - 0.48rem) * 0.298), 1rem);\"><strong>a. Performing a\u00a0narrow\u00a0procedural\u00a0task<\/strong>\u00a0<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The system performs a task that is so limited in scope that it gives rise only to a low level of risk. Such tasks are inherently narrow and well-defined, meaning that the associated risks remain limited, even when they arise within a use case covered by Annex III. These tasks typically involve support functions such as the organization, structuring, or processing of information. However, the guidelines make clear that this condition does not apply to all categorization systems. Where a system makes <strong>value judgments regarding information relevant to a decision-making process<\/strong>, it can no longer be considered purely procedural.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" style=\"font-size:clamp(0.875rem, 0.875rem + ((1vw - 0.48rem) * 0.298), 1rem);\"><strong>b. Improving the\u00a0result of a\u00a0previously\u00a0completed\u00a0human\u00a0activity<\/strong>\u00a0<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The system adds a layer of improvement to an activity that has already been completed by a human, without replacing it or fundamentally reviewing it. This condition is based on three cumulative requirements: a human activity must have been carried out, that activity must have produced an identifiable result, and the AI system must intervene solely to improve that result. The system must therefore neither substantially revise the underlying work nor substitute its own assessment for that of the human. Its role is limited to enhancing the quality, presentation, or effectiveness of an existing outcome. The underlying rationale is that the system remains a direct extension of the initial human intervention.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" style=\"font-size:clamp(0.875rem, 0.875rem + ((1vw - 0.48rem) * 0.298), 1rem);\"><strong>c. Detecting\u00a0consistent\u00a0decision-making\u00a0patterns or\u00a0deviations from\u00a0established\u00a0decision-making\u00a0practices<\/strong>\u00a0<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In this scenario, the system operates ex post by analyzing decisions that have already been made, without replacing or influencing the initial human assessment in the absence of appropriate oversight. Three cumulative conditions must be satisfied: the human assessment must already have been completed, the system must be limited to a <strong>retrospective comparative analysis<\/strong>, and it must not be intended to replace or influence the original assessment. The system therefore serves as a monitoring or analytical function, for example by identifying inconsistencies, anomalies, or recurring trends in decision-making practices. However, it does not participate in the decision itself and does not directly steer future decisions.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" style=\"font-size:clamp(0.875rem, 0.875rem + ((1vw - 0.48rem) * 0.298), 1rem);\"><strong>d. Performing a\u00a0preparatory\u00a0task for a\u00a0relevant\u00a0assessment<\/strong>\u00a0<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The system prepares, organizes, or facilitates the information required for a subsequent assessment, without altering the logic or outcome of that assessment. Such preparatory activity takes place upstream of any decision-making process and is limited to organizing information relevant to the evaluation. It must not modify the substance, purpose, or reasoning of the subsequent assessment. Furthermore, the system must not directly contribute to the decision itself. Its role is limited to preparing the inputs required for the assessment, without materially influencing the final outcome. It must not make decisions or classify individuals or situations for decision-making purposes.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>3. The profiling exception: three cumulative criteria to assess<\/strong>\u00a0<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">To determine whether a system actually performs <strong>profiling<\/strong>, three conditions must be met cumulatively: the system must involve <strong>automated processing<\/strong>, that processing must relate to personal data, and its purpose must be <strong>to evaluate certain personal aspects of a natural person<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Accordingly, the mere use of personal data is not sufficient. Likewise, the classification or segmentation of individuals based on personal characteristics (such as age or sex) does not necessarily constitute profiling where the purpose is not to draw conclusions, make predictions, or assess the individuals concerned.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By contrast, where a system uses personal data to analyze, predict, or assess characteristics such as a person&#8217;s professional performance, reliability, preferences, interests, or likely behavior, it does constitute profiling.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, an AI system used in a recruitment process to assess recruiters&#8217; decisions and behaviors in order to identify deviations from a company&#8217;s hiring policies performs profiling, as it evaluates personal characteristics of the individuals concerned on the basis of personal data. Conversely, a system used by customs authorities to assess the risk of non-compliant goods based on information relating to shipments and economic operators does not evaluate personal aspects of natural persons and therefore does not constitute profiling.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>4. AI systems embedded in complex architectures must be assessed as a whole<\/strong>\u00a0<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The AI Act guidelines clarify that the classification of a high-risk AI system cannot be assessed solely on the basis of each individual component considered in isolation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Where an AI system consists of multiple systems or interacts with other AI systems within a more complex architecture, it is the <strong>combined configuration<\/strong> and its overall intended purpose that must be assessed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Accordingly, where several AI systems jointly contribute to an individual decision or are intended to be used within a high-risk use case, the entire configuration may qualify as a high-risk AI system, even if certain components, considered separately, could benefit from an exemption under Article 6(3).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This approach also applies to interconnected architectures and agentic AI systems coordinating multiple actions or tools. Where these elements collectively pursue a high-risk intended purpose, they must be assessed as a whole.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>V- What\u00a0Obligations\u00a0Remain when a\u00a0System\u00a0Benefits from the\u00a0Filtering\u00a0Mechanism?<\/strong>\u00a0<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Exemption from the high-risk classification does not mean a complete absence of obligations. A provider that decides to rely on the filtering mechanism must carry out a documented self-assessment before placing the system on the market or putting it into service. This documentation must, in particular, describe:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>the system\u2019s intended purpose;\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>the reasons why it falls within the scope of Article 6(2);\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>the reasons justifying the application of one of the conditions set out in the filtering mechanism under Article 6(3);\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>the\u00a0reasons why the system does not perform profiling.\u00a0<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">In addition, the system must be registered in the European Union database&nbsp;established&nbsp;under Article 71 of the AI Act.&nbsp;Market surveillance authorities may review the classification, require corrective measures where necessary, and impose penalties where a system has been incorrectly classified&nbsp;in order to&nbsp;circumvent the applicable regulatory requirements.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Conclusion<\/strong>\u00a0<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">With these new guidelines, the message is clear:\u00a0<strong>classifying an AI system as high-risk requires a structured, documented, and context-specific assessment<\/strong>\u00a0that combines an analysis of the system\u2019s intended purpose, actual functionalities, operating environment, level of influence on decision-making, and, where relevant, the existence of profiling or integration within a broader AI system.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For organizations, an incorrect classification may lead to an underestimation of applicable obligations, weaken AI governance frameworks, and increase the risk of non-compliance.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\ud83d\udc49 Need to classify your AI systems and structure your compliance with the AI Act?<br>Discover our AI management platform, designed to help you centralize your AI use cases and operationalize compliance by managing your obligations over time within a framework that integrates directly with your existing ecosystem.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>On 19 May 2026, the European Commission published draft guidelines on the classification of high-risk AI systems under Article 6 of the AI Act. Open for consultation until 23 July&hellip; <a href=\"https:\/\/naaia.ai\/en\/high-risk-ai-system-classification-ai-act-guidelines\/\">Lire la suite<\/a><\/p>\n","protected":false},"author":9,"featured_media":3724,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"naaia_last_modified":"","footnotes":""},"categories":[46],"tags":[],"class_list":["post-3708","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-governance-blog"],"_links":{"self":[{"href":"https:\/\/naaia.ai\/en\/wp-json\/wp\/v2\/posts\/3708","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/naaia.ai\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/naaia.ai\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/naaia.ai\/en\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/naaia.ai\/en\/wp-json\/wp\/v2\/comments?post=3708"}],"version-history":[{"count":5,"href":"https:\/\/naaia.ai\/en\/wp-json\/wp\/v2\/posts\/3708\/revisions"}],"predecessor-version":[{"id":3720,"href":"https:\/\/naaia.ai\/en\/wp-json\/wp\/v2\/posts\/3708\/revisions\/3720"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/naaia.ai\/en\/wp-json\/wp\/v2\/media\/3724"}],"wp:attachment":[{"href":"https:\/\/naaia.ai\/en\/wp-json\/wp\/v2\/media?parent=3708"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/naaia.ai\/en\/wp-json\/wp\/v2\/categories?post=3708"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/naaia.ai\/en\/wp-json\/wp\/v2\/tags?post=3708"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}