From the journal

EU Commission Publishes Draft High-Risk AI Classification Guidelines Under AI Act, May 2026

On 19 May 2026, the European Commission published draft guidelines under Article 6(5) of the EU AI Act (Regulation 2024/1689) to help providers, deployers, and market surveillance authorities determine when an AI system qualifies as high-risk. The guidelines cover two classification routes: systems used as safety components in products subject to Annex I harmonisation legislation, and systems falling within the Annex III use-case list. A targeted consultation closes 23 June 2026.

3 min read

On 19 May 2026, the European Commission published draft guidelines on the classification of high-risk AI systems under Article 6(5) of Regulation (EU) 2024/1689, the EU AI Act. The document is at the consultation stage. The Commission has invited input from providers, deployers, and market surveillance authorities until 23 June 2026 at 22:00 CET. Following that deadline, the guidelines will be revised before adoption as a non-binding Commission interpretive instrument.

Article 6 of the AI Act establishes two routes for high-risk classification. Under the Annex I route, a system qualifies as high-risk if it functions as a safety component of a product covered by EU harmonisation legislation listed in that Annex and the product must undergo third-party conformity assessment. Under the Annex III route, a system qualifies if it falls within one of the eight enumerated use-case areas, unless the provider demonstrates under Article 6(3) that it poses no significant risk to health, safety, or fundamental rights. The draft guidelines interpret each element of these tests, including the meaning of 'safety component,' 'intended purpose,' and the conditions for invoking the Article 6(3) exception.

AI system providers and deployers operating in the EU will use these guidelines to determine conformity assessment obligations, registration requirements in the EU AI Act database, and post-market monitoring duties that attach to high-risk classification. Market surveillance authorities in each Member State will reference the guidelines when assessing compliance. Providers of AI used in recruitment, credit scoring, critical infrastructure, biometric identification, and law enforcement face the most immediate classification questions under Annex III.

The guidelines are not legally binding; the Commission's interpretation does not foreclose readings by national courts or the Court of Justice. The Article 6(3) exception, allowing providers to self-assess that an Annex III system poses no significant risk, remains a contested mechanism. The draft sets out criteria for its application, but providers and deployers may argue the test is too narrow or too broad. Ambiguous cases involving general-purpose AI integration and downstream fine-tuning are not fully resolved in the draft.

Licentium advises AI providers, deployers, importers, and regulated-sector clients on EU AI Act classification, conformity assessment preparation, and regulatory strategy. We may assist directly or connect clients with specialist EU regulatory counsel through our partner network. Work we undertake includes AI Act compliance mapping, high-risk classification analysis, conformity assessment support, and regulatory submissions to Commission consultations.

Source: European Commission, Draft Guidelines on the Classification of High-Risk AI Systems, Article 6(5) EU AI Act (Regulation 2024/1689), 19 May 2026

AI Regulatory

More from the journal

See all
Illia Prokopiev

Crypto Vaults and Lending Strategies Under U.S. Federal Securities Law

Commissioner Hester M. Peirce’s July 22, 2026 statement does not establish binding law, but it identifies the principal federal securities-law questions raised by crypto vaults and onchain lending strategies. This analysis examines when vault interests, lending claims, receipt tokens, and related service-provider activities may trigger the Securities Act, Exchange Act, Investment Company Act, and Investment Advisers Act.

MiCAR Transitional Regime for CASPs Expires Across the EU, July 2026

On 1 July 2026, the MiCAR transitional period under Article 143(3) of Regulation (EU) 2023/1114 expired across the EU. Former virtual asset service providers operating under national registrations must now hold a MiCAR crypto-asset service provider authorisation or cease providing crypto-asset services. In Luxembourg, the CSSF confirmed that VASP registration under the 2004 AML Law no longer provides a sufficient legal basis for market activity.

EDPB Adopts Final GDPR Guidelines on Blockchain Data Processing, EU, 8 July 2026

On 8 July 2026, the European Data Protection Board adopted the final version of Guidelines 02/2025 on the processing of personal data through blockchain technologies. The guidelines confirm that encrypted and hashed on-chain data remains personal data under the GDPR and that blockchain immutability does not override data subjects' right to erasure under Article 17. Controllers must address architecture choices and data minimisation before any on-chain recording of personal data.