The European Commission recently released its full series of draft Guidelines on classifying high-risk AI systems under the AI Act:
They tell you what to classify, but they are silent on how. And the marking pen is now in the regulated organisation's hand, with Article 99 penalties attached.
The Guidelines walk providers through both routes: Article 6(1) and Annex I (safety components and regulated products), and Article 6(2) and Annex III (the eight standalone high-risk use cases). They explain the autonomous safety-component definition under Article 3(14), the third-party conformity assessment requirement, the Article 6(3) filter conditions, and the profiling exclusion. As reference documents go, they are clear, careful, and useful.
What they do not do, because it is not their job, is tell providers how to actually conduct the classification in a way that survives a market surveillance review under Article 80. That work falls to the practitioners.
In our experience across hundreds of conversations with risk teams in financial services, healthcare, the public sector, and increasingly across mid-market deployers, most providers do not yet have:
→ A defensible Article 6 assessment workflow for both routes
→ A named individual accountable for the classification decision
→ A coherent intended-purpose statement that aligns across instructions, technical documentation, and marketing materials
→ Lifecycle monitoring to catch intended-purpose drift after deployment
→ The trained capability to defend the decision when challenged
The European Commission has done the work of telling us what to classify.
The work of how to classify it sits with us.
We have written a full briefing and our interpretation on what this means for risk professionals, and how the EW-AiRM™ framework addresses exactly this gap, through a standalone assessment tool, CPD training pathways, and implementation consultancy. You can access the full article here: https://www.linkedin.com/pulse/eus-high-risk-classification-guidelines-xvroe/
#AIGovernance #EUAIAct #EWAiRM #HAiPECR #AnnexI #AnnexIII #AIRiskManagement #Article6
