What are the draft guidelines and how binding are they?
The guidelines, also referred to as the High-Risk AI Guidelines, are a draft without binding effect, but they are currently the most informative benchmark for administrative practice. A binding interpretation of the AI Act can only be provided by the Court of Justice of the European Union.
The Commission presented the draft on 19 May 2026 — with some delay, as the classification guidance had originally been expected by 2 February 2026. Providers and deployers had therefore been eagerly awaiting it. The draft consists of three documents: one part on the general principles, Annex I on product safety and Annex III on use cases. Stakeholders can submit comments until 23 June 2026.
There is no formal timetable for adoption.
Even once finalised, the guidelines will remain non-binding. Nevertheless, providers and deployers should take them seriously: the Commission and the national market surveillance authorities are very likely to align their assessment with these documents. Those who follow them reduce the risk of a divergent classification by the authorities.
Legally, the draft does not bind anyone; in practice, it is the best available compass for the administrative practice to come. Before looking at individual areas, it is worth considering the overarching principles.
Which general principles apply to classification?
The documents set out five principles that, in some cases, significantly broaden the scope of the high-risk rules. Each follows the same pattern: a clarification by the Commission and a specific consequence for practice.
1. GPAI systems can be high-risk
- Affected: general-purpose AI, such as large language models
- Benchmark: instructions for use, technical documentation, advertising and marketing material
- Trigger: high-risk use cases are not consistently excluded
- Consequence: the intended purpose is deemed high-risk, which considerably expands the obligations
2. “Human in the loop” is not enough
- Human oversight alone does not remove a system from the classification.
- Reason: it changes neither the purpose nor the area of use.
- An exemption under Article 6(3) is possible, but only without profiling and subject to further conditions.
3. Documentation determines the exemption
- Requirement: a documented self-assessment before placing on the market or putting into service
- The guidelines specify what this assessment must contain.
- Without documentation, there can be no reliance on the exemption.
4. Several components can constitute one system
- When: where interacting AI components together materially influence a decision
- Assessment: the configuration as a whole
- Purpose: to prevent providers from splitting up their system in order to exclude components
- Scope: purely preparatory or procedural functions may potentially be excluded
5. Annex III is dynamic; Annex I is not
- Annex III: annual review under Article 112(1); use cases may be changed by delegated act
- Annex I: exhaustive; amendments only through the underlying sectoral legislation
- Consequence: compliance programmes must remain flexible
The principles shift the burden of proof towards providers: anyone seeking to rely on an exemption must document it.
When is AI considered a “safety component”?
The second part of the document deals with the product safety route under Article 6(1). The decisive term here is “safety component”, which is defined autonomously in the AI Act.
The definition in Article 3 No. 14 AI Act applies autonomously, i.e. independently of definitions of the same term in other EU harmonisation legislation. According to the Commission, there are two alternative routes to qualifying as a safety component:
- Purpose-based route, safety function: the intended purpose of the system is to prevent or mitigate risks to health, safety or property.
- Consequence-based route, failure or malfunction: the system was not intended as a safety function, but its failure or malfunction would endanger health, safety or property.
This distinction is practically relevant because the second route also captures systems that, at first glance, have nothing to do with safety. The mere consequences of a malfunction can make a system a safety component not only its stated purpose.
Which high-risk areas are listed in Annex III?
When is AI considered a “safety component”?
The second part of the document deals with the product safety route under Article 6(1). The decisive term here is “safety component”, which is defined autonomously in the AI Act.
The definition in Article 3 No. 14 AI Act applies autonomously, i.e. independently of definitions of the same term in other EU harmonisation legislation. According to the Commission, there are two alternative routes to qualifying as a safety component:
Purpose-based route, safety function: the intended purpose of the system is to prevent or mitigate risks to health, safety or property.
Consequence-based route, failure or malfunction: the system was not intended as a safety function, but its failure or malfunction would endanger health, safety or property.
This distinction is practically relevant because the second route also captures systems that, at first glance, have nothing to do with safety. The mere consequences of a malfunction can make a system a safety component not only its stated purpose.
Which high-risk areas are listed in Annex III?
Annex III defines eight high-risk areas. The guidelines examine five of them in more detail: biometrics, critical infrastructure, education, employment, and creditworthiness and credit scoring.
In each area, the precise distinction determines whether a system qualifies as high-risk at all. The following overview shows, for each area, which AI systems qualify as high-risk and which do not:
| Area | Falls within the high-risk area | Does not fall within it |
|---|---|---|
| Biometrics | Remote identification without active participation, e.g. keystroke biometrics for identification; categorisation based on ethnic origin, genetic or health data; emotion recognition | Identification with conscious participation, e.g. a sensor at the door; age or gender classification for advertising; purely physical states such as pain or fatigue |
| Critical infrastructure | AI as a safety component in the operation of digital infrastructure, road traffic, water, gas, heating or electricity supply | Systems without a safety-component function or outside the listed sectors |
| Education | Systems that, on the basis of a summative assessment, contribute to a final decision on a person’s educational pathway; proctoring; real-time behavioural analysis during examinations | Purely formative assessment to support learning without a final decision |
| Employment | Recruitment, targeted job advertising, CV filtering, promotion and dismissal decisions, performance monitoring — including in relation to freelancers and platform work | Systems used solely to fulfil statutory obligations or for safety purposes, provided they are not also used for assessment |
| Creditworthiness | Assessment of creditworthiness or credit scoring, including as a ranking or label, not only numerically | Systems whose main purpose is financial fraud detection, based on pattern and anomaly detection rather than creditworthiness assessment |
Two clarifications deserve particular attention. In the area of emotion recognition, the Commission expressly warns of the lack of scientific basis for such systems. The term must not be interpreted narrowly: describing emotions as “attitudes” does not circumvent the AI Act. If a system detects, on the basis of biometric data, for example an “angry attitude”, it falls within the high-risk use case.
In education, the distinction between summative and formative assessment is decisive. Only systems based on a summative assessment that contribute to a final decision affecting a person’s educational pathway are considered high-risk.
Whether a system is high-risk almost always depends on a fine distinction. Blanket assessments are misleading.
What do the guidelines mean for your compliance practice?
Providers and deployers should review three things: their public documentation, their self-assessment for potential exemptions and the flexibility of their compliance programme.
Review documentation and marketing. Because unclear or overly broad descriptions can draw a GPAI system into the high-risk area, it is worth taking a critical look at instructions for use, technical documents and advertising material. Anyone who does not wish to exclude high-risk use cases must expect the corresponding obligations.
Document the self-assessment. The exemption under Article 6(3) is available only to those who can demonstrate a documented self-assessment before placing the system on the market. This assessment should comply with the requirements set out in the guidelines.
Remain flexible. Annex III is designed to evolve. Compliance programmes that are rigidly aligned with the current state of play can quickly become outdated as a result of delegated acts. Plan regular reviews.
The guidelines reward forward-looking documentation and penalise carelessness in describing the intended purpose.
Conclusion: High-Risk AI under the AI Act: documentation determines classification
The draft guidelines are legally non-binding, but highly relevant in practice. They significantly broaden the high-risk area by capturing unclear product descriptions, interacting components and consequence-based safety components. Human oversight alone does not protect against classification.
For providers and deployers, this means that the intended purpose and its documentation determine classification, not the technology alone. Those who document properly at an early stage and keep their compliance programme flexible will be well prepared for the administrative practice to come.
Frequently Asked Questions (FAQ):
#1 Are the European Commission’s guidelines legally binding?
No, the guidelines are not legally binding. A binding interpretation of the AI Act can only be provided by the Court of Justice of the European Union. Nevertheless, they are the clearest indication of how the Commission and market surveillance authorities will handle classification in practice.
#2 What is the difference between Annex I and Annex III in the AI Act?
Annex I covers AI in products that fall under EU harmonisation legislation, the product safety route, while Annex III lists eight standalone high-risk use cases. The key difference lies in their flexibility: the Commission can amend Annex III by delegated act, whereas Annex I can only be amended through the underlying sectoral legislation.
#3 Does human oversight automatically make an AI system non-high-risk?
No. “Human in the loop” alone does not remove a system from high-risk classification because it changes neither the purpose nor the area of use. An exemption under Article 6(3) is possible only subject to further conditions and without profiling.
#4 Can a GPAI system such as a large language model fall under the high-risk rules?
Yes, that is possible. General-purpose AI systems fall within the high-risk area if their public documentation does not consistently exclude high-risk use cases. Providers should therefore draft instructions for use and marketing material carefully.
#5 Until when can comments on the guidelines be submitted?
The consultation period runs until 23 June 2026. Until then, stakeholders can submit comments on the draft. There is currently no formal timetable for final adoption.
Schedule your initial consultation
Describe your situation to us in a no-obligation phone call, and our lawyers will work with you to find the best solution.