AI Regulation Tracker / EU AI Act
The EU Just Told Companies How to Tell If Their AI Is High Risk
Draft, non-binding, and open for comment until July 23, 2026. On May 19, 2026, the European Commission published draft guidelines on how to classify high-risk AI systems under Article 6 of the EU AI Act, with a targeted consultation running to July 23. They are the Commission's reading of where the high-risk line sits, and they are not yet final.
The hardest question in the EU AI Act is not what high-risk systems have to do. It is which systems count as high-risk in the first place. Article 6 answers that, but it does it through cross-references to two annexes and a set of exceptions, and reasonable people have read it in very different ways. On May 19, 2026, the European Commission tried to settle the argument by publishing draft guidelines that lay out, in detail and with examples, how it thinks the classification works. A targeted consultation on the draft is open until July 23, 2026.
Read the status precisely, because it matters. These are draft guidelines, and the Commission is explicit that they are "not legally binding." The binding text is still the AI Act itself. What the guidelines do is tell you how the body that oversees the Act reads that text, which in practice is most of what a compliance team needs. The Commission says feedback from the consultation "is going to be incorporated in the final version of the guidelines before adoption," with adoption targeted before the end of the year.
What do the guidelines actually cover?
The draft is built around the two ways a system can be pulled into the high-risk regime. The first is the Annex I route, for AI that is a safety component of, or is itself, a product already covered by EU product-safety law, think machinery, medical devices, and the like. The second is the Annex III route, the list of specific use cases the Act treats as high-risk on their own terms, such as AI used in employment, education, essential services, biometrics, and critical infrastructure. The guidelines take each route in turn and give worked examples of systems that should be classified as high-risk and systems that should not.
That second half is the useful part. Article 6 also contains a filter that lets some Annex III systems out of the high-risk category when they do not pose a significant risk to health, safety, or fundamental rights, for instance because they only perform a narrow procedural task. Companies have been unsure how far that exception reaches. The draft guidelines are the Commission's attempt to draw that line with examples, which is exactly where the money and the exposure sit.
Why does a non-binding draft matter now?
Because classification is the switch that turns on everything else. If your system is high-risk, you inherit the heavy obligations, risk management, data governance, technical documentation, logging, human oversight, and conformity assessment. If it is not, most of that falls away. A company that misreads the line either over-builds compliance it did not owe or, far worse, ships a high-risk system as if it were unregulated. The guidelines are how you check your own reading against the regulator's before the obligations bite.
They also matter because the comment window is nearly closed. The consultation runs only to July 23, 2026. After that the Commission finalizes its interpretation, and the version it adopts is the one that market surveillance authorities across the twenty-seven member states will lean on. If a US company has a system sitting near the boundary, this is the last easy moment to argue that the line should fall on the right side of it.
What should US executives and counsel do?
Treat the draft as a classification worksheet, not as reading. Take your actual AI systems that touch the EU market and run each one through both routes in the guidelines, the Annex I product angle and the Annex III use-case list, and write down where it lands and why. Where a system sits near the Article 6 exception, document the specific reasoning the guidelines invite, because that reasoning is what you will show a regulator later. If a borderline call goes against you, the consultation is open until July 23 and you can still file comment. None of this is compelled by the draft itself. All of it is far cheaper to sort out now than after the high-risk obligations start applying on August 2, 2027 and the classification is no longer yours to argue.
Questions professionals are asking
Are these guidelines legally binding?
No. The Commission states the draft guidelines are not legally binding. They reflect the Commission's interpretation of Article 6 of the EU AI Act. The binding rules are in the Act itself, but market surveillance authorities are expected to rely on the guidelines when they assess classification.
What is the deadline to comment?
The targeted stakeholder consultation on the draft guidelines is open until July 23, 2026. The Commission has said feedback will be incorporated into the final version before adoption, which it is targeting before the end of 2026.
How do the guidelines say a system becomes high-risk?
Through one of two routes. The Annex I route covers AI that is a safety component of, or is itself, a product already regulated under EU product-safety law. The Annex III route covers specific listed use cases such as employment, education, essential services, biometrics, and critical infrastructure. The draft gives worked examples for both, including systems that should not be classified as high-risk.
When do high-risk obligations actually start?
The obligations for Article 6 high-risk systems begin applying from August 2, 2027, with a later date for certain systems embedded in regulated products. The guidelines are meant to be settled well before then so companies can classify their systems in advance.
RELATED BRIEFINGS
Browse the full AI Regulation News tracker
Informational analysis for working professionals, not legal advice. Confirm how any guideline or obligation applies to your situation with qualified counsel in the relevant jurisdiction.