From the journal

European Commission Publishes Draft Guidelines on High-Risk AI System Classification, June 2026

The European Commission published draft guidelines to help providers and deployers of artificial intelligence systems determine whether a given system qualifies as high-risk under Annex III of Regulation (EU) 2024/1689, the EU AI Act. A targeted industry consultation was open until 23 June 2026, with the deadline extended to 23 July 2026. The Commission plans to adopt final guidelines by the end of 2026.

3 min read

The European Commission published draft guidelines clarifying how providers and deployers of artificial intelligence systems should determine whether a given system qualifies as high-risk under Regulation (EU) 2024/1689, the EU AI Act. The draft was open for targeted industry consultation, with the original deadline of 23 June 2026 extended to 23 July 2026. Final guidelines are expected by the end of 2026.

Under Article 6 and Annex III of the EU AI Act, an AI system qualifies as high-risk if it satisfies one of two criteria. First, it functions as a safety component of a product subject to EU harmonisation legislation that requires third-party conformity assessment. Second, it falls within one of the use cases listed in Annex III, covering eight sectors: biometric identification and categorisation of natural persons; management of critical infrastructure; education and vocational training; employment and workers management; access to essential private and public services and benefits; law enforcement; migration and border control management; and administration of justice and democratic processes. The draft guidelines supply practical examples for each Annex III category to assist providers in making the classification assessment.

Providers that classify an AI system as high-risk must complete a conformity assessment before placing the system on the EU market, register the system in the EU database under Article 71, and meet the requirements of Articles 9 to 15, covering data governance, technical documentation, record-keeping, transparency toward deployers, human oversight, accuracy, robustness, and cybersecurity. Deployers using high-risk AI systems in employment decisions, educational assessments, or for access to essential services must conduct fundamental rights impact assessments under Article 27. Providers building AI products for any Annex III sector should treat the draft guidelines as the operative interpretation of Article 6 for current compliance planning.

The draft guidelines cover classification only, not conformity assessment procedures or enforcement. The Commission is separately preparing guidelines on Article 50 transparency obligations, on serious incident reporting, and on the full set of high-risk requirements for providers and deployers. Under Article 7, the Commission can expand Annex III by delegated act to add further high-risk use cases, so the final scope of the high-risk category may differ from the current Annex III text.

Licentium advises AI developers, technology companies, and deployers on EU AI Act compliance, including high-risk classification analyses, conformity assessment preparation, and fundamental rights impact assessments. We help clients determine whether their systems fall within Annex III scope and prepare for the applicable obligations. Contact us to discuss your EU AI Act compliance position. Work we undertake includes AI system classification assessment, conformity assessment support, AI regulatory strategy, EU AI Act implementation planning, and general-purpose AI model regulatory analysis.

Source: European Commission, Draft Guidelines on the Classification of High-Risk Artificial Intelligence Systems (EU AI Act, Annex III), consultation extended to 23 July 2026

AI Regulatory

More from the journal

See all
Illia Prokopiev

From Cloud Concentration to AI Dependence: The UK’s Critical Third Parties Regime

The United Kingdom now directly oversees designated technology suppliers whose service failures could threaten financial stability. The question is whether the first cloud designations show a legal expansion toward AI-model providers, and what the present regime requires. This analysis assumes the quoted statement concerns the UK financial-services Critical Third Parties regime and assesses the law through 14 July 2026.

Alberta Regulated iGaming Market Launched on 13 July 2026 with 22 Operators

Alberta's regulated private iGaming market launched on 13 July 2026, making Alberta the second Canadian province to permit private online gambling operators after Ontario. The Alberta Gaming, Liquor and Cannabis Commission serves as market regulator and the Alberta iGaming Corporation oversees commercial operations and operator contracts. Twenty-two operator sites went live on day one, including FanDuel, DraftKings, BetMGM, and BetRivers. Operators must fully launch or exit the Alberta market by 13 October 2026.

European Commission Presents Cybersecurity and AI Action Plan on 7 July 2026

On 7 July 2026, the European Commission presented an Action Plan on Cybersecurity and Artificial Intelligence. The plan directs the Commission and ENISA to evaluate advanced AI models before they reach the EU market, establish a secure testing platform for critical-sector organisations, and launch an EU Grand Challenge on AI-powered cybersecurity solutions. It operates alongside the AI Act, NIS2 Directive, DORA, Cyber Resilience Act, and Cyber Solidarity Act, and introduces no new directly binding obligations.