Skip to content
Spektor

Who decides whether a system is "high-risk" does not just look at the code

The European Commission has published draft guidelines on classifying high-risk AI systems. The most relevant point is not technical: it concerns how an organisation describes its systems, wherever it does so.

Raffaella Aghemo

On 19 May 2026 the European Commission published draft guidelines on classifying high-risk artificial intelligence systems, under Article 6 of Regulation (EU) 2024/1689, the AI Act. They are three documents, non-binding, open for stakeholder consultation until 23 June. Only the Court of Justice of the European Union can give them an authoritative reading. But it is the most detailed text published so far on how national market surveillance authorities will approach the assessment.

The draft sets out two paths. The first concerns systems that are safety components of products already regulated, such as machinery, toys, lifts: mandatory from 2 August 2028. The second concerns "standalone" systems used in specific areas listed in Annex III, such as biometrics, critical infrastructure, education, staff selection: mandatory from 2 December 2027. Transparency obligations, the ones requiring people to be informed when they interact with an AI system, are instead already active since August 2026, as set out in the general AI literacy obligation.

The most useful point in the draft, for those leading an organisation, is not technical. It is this: a system's "intended purpose", the criterion that decides whether it falls among those classed as high-risk, is assessed on how the system is described across every material, not only in technical documentation. Instructions for use, technical sheets, sales material, commercial communication: if an organisation presents a system as applicable across many contexts without explicitly excluding high-risk uses, the Commission still considers it high-risk, whenever that use is reasonably foreseeable.

This shifts the problem. Classifying a system is no longer only a question for those who develop it or those who acquire it for a technical use. It concerns whoever describes it, inside the organisation, in a commercial proposal or an internal slide. A sales team that promises a client "the system does everything" can, without realising it, move a product into the high-risk category.

The draft also addresses agentic systems, those made up of multiple AI components interacting with one another. When the combined outputs of these components materially influence a decision in a high-risk area, the Commission asks that they be assessed as a single system, not as separate pieces. This is a clarification that concerns directly anyone introducing AI agents into their workflows without a map of what those agents, together, actually decide.

It also confirms that emotion recognition systems, those that infer emotional states from voice, facial expressions or posture, are high-risk. This is not new in principle, but it is the first time the Commission has written it with this level of detail.

For an organisation, the practical conclusion is that classifying an AI system is not decided once, in a laboratory or a legal department. It is maintained, or lost, in every document that describes it. It is a matter of internal governance before it is one of engineering: who writes what, about an AI system, and who checks it before it leaves the organisation.