On 19 May 2026, the European Commission published its Draft Guidelines on the classification of high-risk AI systems under Article 6. A targeted consultation runs until 23 July 2026. Final guidelines are scheduled for adoption by the end of 2026.
Two things matter operationally.
First, the Commission has now put an official operational lens on the Article 6 classification test — the same test your team already applies internally when deciding whether a system is high-risk.
Second, because the guidelines are draft, they are non-binding. But the direction they set will shape how national market surveillance authorities read Article 6 from 2027 onwards.
The guidelines address the two paths into “high-risk”: systems intended as safety components of products covered by EU harmonisation legislation subject to third-party conformity assessment (Article 6(1)), and systems falling into the use cases listed under Annex III (Article 6(2)).
The Commission states the guidelines are intended to help providers and deployers of AI systems, as well as competent market surveillance authorities, in assessing whether an AI system should be classified as high-risk.
Which teams are affected.
If any of the following is true, this issue is directly relevant to your compliance plan: your organisation provides an AI system that could be a safety component under existing EU product law (medical devices, machinery, toys, radio equipment, in-vitro diagnostics); your organisation provides or deploys an AI system whose use case sits in one of Annex III’s eight domains (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and border, administration of justice); or your compliance argument depends on an Article 6(3) exception — where a system in an Annex III area does not pose a significant risk to health, safety, or fundamental rights.
For those teams, the draft guidelines are the closest thing to an official interpretive text the EC has yet produced.
What decisions to revisit.
Revisit each of these before you finalise your Article 6 position.
Your Annex III mapping. For every AI system in your inventory, confirm whether the Annex III area assignment matches the Commission’s reading in the draft. Verify against the primary text before making changes.
Your Article 6(3) exceptions. If you rely on the “does not pose significant risk” carve-out, the draft is where the Commission signals how strictly this will be read. Treat the exception as narrower than a plain reading of the Act suggests.
Your safety-component argument. If your position is that a system is not a safety component under Article 6(1) because it is auxiliary or informational rather than functional, verify that argument survives the Commission’s framing.
The evidence file behind your classification. Whatever decision you reach, an auditor will ask: who decided, on what date, on what evidence, and with what review cadence. If those four fields are empty, the classification decision is not yet audit-ready.
What to do this quarter.
Three concrete actions in priority order.
First, read the primary text yourself. The full draft guidelines are the reference. Legal-firm summaries are useful but not authoritative — the EC’s own text is what national authorities and courts will cite.
Second, log your classification decisions with the fields above. Even while the guidelines are draft, the classification decision itself is a live obligation. A dated log with a named owner and supporting evidence is what turns a claim into an audit artefact.
Third, decide whether to respond to the consultation. Anyone with an interest in AI system development, deployment, supervision, or use is invited to contribute via the online questionnaire on the EC consultation page. The Commission has committed to reflecting stakeholder feedback in the final version.
What remains uncertain.
The guidelines are draft. Nothing in them is binding until final adoption (targeted for end-2026). Any change to your compliance approach today should reflect that.
The draft contains practical examples, per the EC library page. Those examples are the concrete operational content, but they are subject to change based on consultation feedback.
National market surveillance authorities have not yet issued their own interpretive guidance. Divergence at member-state level remains possible.
The relationship between the draft guidelines and the Digital Omnibus deadline shifts (covered in Issue #2) is not addressed in the draft itself.
Dates that matter.
19 May 2026: draft guidelines published.
23 July 2026: consultation closing date, extended from 23 June by four weeks per stakeholder request.
End of 2026: target date for adoption of final guidelines.
2 August 2026: start of applicability for the Act’s high-risk obligations under the current schedule, subject to Digital Omnibus adjustments.
One decision framework for your team.
Before you close your calendar this week, apply this three-part test to any AI system your organisation provides or deploys.
Does it sit in Annex III, or is it a safety component under Article 6(1)?
If yes, do we have a dated classification decision, a named owner, supporting evidence, and a review cadence?
If we rely on an Article 6(3) exception, does the argument survive a strict reading?
Any “no” is a gap to close before 2 August 2026.
Sources.
European Commission Digital Strategy library — Draft Commission guidelines on the classification of high-risk AI systems: https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems
European Commission — Targeted consultation on the draft guidelines: https://digital-strategy.ec.europa.eu/en/consultations/targeted-consultation-draft-guidelines-classification-high-risk-artificial-intelligence-systems