From the journal

European Commission Publishes Draft High-Risk AI Classification Guidelines Under EU AI Act, May 2026

On 19 May 2026, the European Commission published draft guidelines on classifying high-risk AI systems under Article 6 of Regulation (EU) 2024/1689, the EU AI Act. The guidelines adopt an expansive interpretation of the high-risk conformity assessment test and are supported by a targeted consultation open until 23 July 2026. The application deadline for Article 6(2) Annex III use cases has been postponed from 2 August 2026 to 2 December 2027.

3 min read

On 19 May 2026, the European Commission published draft guidelines on the classification of high-risk AI systems, acting under Article 96(1) of Regulation (EU) 2024/1689, the EU AI Act. The guidelines address both routes to high-risk classification under Article 6: use as a safety component of a product covered by Annex I harmonisation legislation, and inclusion within an Annex III use-case category. A targeted consultation on the draft guidelines runs until 23 July 2026. The Commission expects to adopt final guidelines by the end of 2026.

Article 6(1) of the EU AI Act applies where an AI system serves as a safety component of a product subject to Annex I EU harmonisation legislation, covering medical devices, machinery, civil aviation equipment, and similar regulated products. Article 6(2) applies where an AI system falls within an Annex III category, which includes biometric identification, critical infrastructure management, employment and recruitment decision-support, access to essential services, law enforcement, migration control, and administration of justice. The Commission has postponed the Article 6(2) application deadline from 2 August 2026 to 2 December 2027, and the Article 6(1) deadline from 2 August 2027 to 2 August 2028.

AI system providers, developers, and deployers operating in the EU must assess their systems against the draft criteria to determine whether high-risk conformity obligations apply. The Commission's expansive interpretation means providers of AI systems integrated into regulated products, including medical devices, machinery, and civil aviation equipment, face broader scope than a plain reading of the Act implies. AI deployers in employment, education, banking, and public-sector contexts face classification scrutiny under Annex III. Systems that fall within scope must meet conformity assessment, technical documentation, and human oversight requirements.

The draft guidelines represent the Commission's preliminary position and may shift before final adoption following the targeted consultation. Providers whose systems sit on the borderline of Annex III categories should submit responses to the consultation before 23 July 2026 to influence the final classification criteria. Providers should also monitor whether their national market surveillance authority interprets the draft expansively or narrowly, as implementation may vary across member states before the Commission finalises its position.

Licentium advises AI developers and deployers on EU AI Act compliance obligations, including high-risk classification analysis, conformity assessment preparation, and technical documentation review. Our team and partner network are available to assist organisations reviewing AI system portfolios ahead of the December 2027 Article 6(2) deadline. Work we undertake includes EU AI Act classification assessments, targeted consultation submissions, conformity assessment support, and advice on harmonised standards applicable to high-risk AI systems.

Source: European Commission, Draft Commission Guidelines on the Classification of High-Risk AI Systems under the EU AI Act, Article 96(1) of Regulation (EU) 2024/1689, 19 May 2026

AI Regulatory

More from the journal

See all
Illia Prokopiev

From Cloud Concentration to AI Dependence: The UK’s Critical Third Parties Regime

The United Kingdom now directly oversees designated technology suppliers whose service failures could threaten financial stability. The question is whether the first cloud designations show a legal expansion toward AI-model providers, and what the present regime requires. This analysis assumes the quoted statement concerns the UK financial-services Critical Third Parties regime and assesses the law through 14 July 2026.

Alberta Regulated iGaming Market Launched on 13 July 2026 with 22 Operators

Alberta's regulated private iGaming market launched on 13 July 2026, making Alberta the second Canadian province to permit private online gambling operators after Ontario. The Alberta Gaming, Liquor and Cannabis Commission serves as market regulator and the Alberta iGaming Corporation oversees commercial operations and operator contracts. Twenty-two operator sites went live on day one, including FanDuel, DraftKings, BetMGM, and BetRivers. Operators must fully launch or exit the Alberta market by 13 October 2026.

European Commission Presents Cybersecurity and AI Action Plan on 7 July 2026

On 7 July 2026, the European Commission presented an Action Plan on Cybersecurity and Artificial Intelligence. The plan directs the Commission and ENISA to evaluate advanced AI models before they reach the EU market, establish a secure testing platform for critical-sector organisations, and launch an EU Grand Challenge on AI-powered cybersecurity solutions. It operates alongside the AI Act, NIS2 Directive, DORA, Cyber Resilience Act, and Cyber Solidarity Act, and introduces no new directly binding obligations.