From the journal

European Commission Publishes Draft Guidelines on High-Risk AI Classification, 2026

The European Commission has published draft guidelines on the classification of high-risk AI systems under Article 6 of Regulation (EU) 2024/1689 (the AI Act) and opened a targeted consultation for stakeholder feedback. The consultation deadline has been extended to 23 July 2026. The guidelines, not legally binding, will guide national market surveillance authorities and providers determining whether their AI systems fall into the high-risk category.

3 min read

The European Commission published draft guidelines on the classification of high-risk AI systems under the AI Act, Regulation (EU) 2024/1689, and opened a targeted consultation for stakeholder feedback. The guidelines are in draft form and not yet final: the Commission extended the consultation deadline to 23 July 2026, after which it will finalise and publish the guidelines, with final adoption expected by end of 2026. The guidelines are intended to support providers and deployers in self-classifying AI systems and to assist national market surveillance authorities in enforcement.

Article 6 of Regulation (EU) 2024/1689 sets the criteria for classifying an AI system as high-risk. The draft guidelines address two categories: first, AI systems intended as safety components of products covered by EU harmonisation legislation listed in Annex I that must undergo third-party conformity assessment; second, AI systems falling into one of the use-case areas listed in Annex III, which covers biometric identification, critical infrastructure, education, employment, essential services, law enforcement, migration, and administration of justice. The guidelines also address the Article 6(3) exclusion allowing providers to self-determine that a listed AI system does not pose a significant risk of harm.

AI system providers, deployers, importers, and distributors placing AI systems on the EU market must determine whether their systems qualify as high-risk, as that classification triggers mandatory conformity assessment, registration in the EU database under Article 71, and ongoing post-market monitoring obligations. The draft guidelines affect developers of systems in healthcare, HR, education technology, credit scoring, biometrics, border control, and critical infrastructure, all of which are Annex III areas. Providers that incorrectly classify a high-risk system as non-high-risk face enforcement action by national market surveillance authorities.

The draft guidelines note that not all AI systems listed under an Annex III area automatically qualify as high-risk: Article 6(3) permits providers to self-determine that their system does not pose a significant risk, provided specified conditions are met and the determination is documented in the technical file. The Commission has indicated that these guidelines will be supplemented by additional guidance on obligations applying to providers and deployers of confirmed high-risk systems. Consultation responses submitted by 23 July 2026 will be published and considered before finalisation.

Licentium advises AI system providers and deployers on AI Act compliance, including high-risk classification assessments and conformity procedure preparation. Organisations seeking to respond to the consultation or to assess their products against the draft guidelines are welcome to contact us. Work we undertake includes AI Act readiness assessments, high-risk classification analysis, conformity assessment preparation, technical documentation review, and EU AI regulatory strategy.

Source: European Commission, Draft Guidelines on the Classification of High-Risk AI Systems under the AI Act (targeted consultation open to 23 July 2026)

AI Regulatory

More from the journal

See all
Illia Prokopiev

MLR Registration and the FCA Cryptoasset Gateway to 25 October 2027

This matter concerns the transition of a United Kingdom cryptoasset business from FCA registration under the Money Laundering Regulations 2017 to Part 4A permission under the Financial Services and Markets Act 2000. The question is whether MLR registration gives conversion, grandfathering, priority, or a right to continue after 25 October 2027, and what an affected firm should do before the gateway closes. This analysis assumes an existing UK-facing cryptoasset business, no relevant Part 4A permission, and an intention to continue after commencement.

Illia Prokopiev

Matched-Category Analysis of the Hong Kong Stablecoin Issuer Route and the Singapore Digital Payment Token Service Route

This matter concerns whether current licensing data supports a commercial comparison between Hong Kong’s stablecoin issuer route and Singapore’s digital payment token service route. The question is whether the proposition remains legally accurate as of 12 August 2026. “Commercially useful” is assumed to mean useful for selecting a market-entry and operating model, not proof that either regulator is more permissive.

Illia Prokopiev

ESMA's 2026 Custody Resilience CSA and the Rules That Actually Bind

ESMA’s 2026 Common Supervisory Action is a coordinated national review of digital operational resilience in crypto-asset custody. It will test whether selected crypto-asset service providers can demonstrate effective controls across six announced workstreams. The legal questions are which requirements are binding, how national competent authorities may assess control effectiveness, and what consequences may follow from a deficiency. This analysis assumes that the firm is permitted under MiCA Article 59 to provide custody and administration within Article 3(1)(17).