
EU AI Act: Could Your Existing AI Systems Already Be High-Risk Under Article 6?
Published by AINave Editorial • Reviewed by Ramit
The European Commission's draft guidelines on the EU AI Act high-risk AI classification make one thing clear: whether your AI system is high-risk depends on more than what it technically does. How you document, market, deploy, and use the system matters just as much. For AI governance teams, this means some existing systems may already be high-risk without you realizing it.
What happened
The European Commission released draft guidelines on classifying high-risk AI systems under Article 6 of the EU AI Act. The guidelines outline two pathways to high-risk classification: AI used in regulated products that require a third-party conformity assessment, and AI deployed in sensitive use cases that could significantly affect people's health, safety, or fundamental rights. Under Article 6, an AI system's intended purpose plays a central role in determining its risk level.
Why AI builders should care
For enterprises building or deploying AI, this guidance raises immediate questions. Which of your systems fall under Article 6? Does your current documentation accurately reflect how each system is actually used? Could the Article 6(3) exemption apply, and what evidence would you need? The answers affect compliance obligations, risk governance, and product roadmaps. The draft guidelines also clarify that AI systems listed under Annex III are always considered high-risk if they profile individuals.
Practical implications
AI governance teams should start by mapping their AI portfolio to Article 6's scope. Identify systems that are part of regulated products (e.g., medical devices, machinery) and those used in sensitive areas like credit scoring, recruitment, or education. Review and update documentation to reflect real-world usage, not just intended design. For systems that might qualify for the Article 6(3) exemption, gather evidence that the system does not pose a significant risk of harm to health, safety, or fundamental rights. The draft guidelines emphasize that self-assessment is limited and may not be sufficient in all cases.
Caveats
The draft guidelines are still subject to consultation and may change. The notified body ecosystem for the AI Act is not yet fully operational, which could affect enforcement timelines. The guidance is based on the European Commission's draft, and organizations should monitor final adoption. The source evidence on the EU AI Act and its draft guidelines is evolving; the above is based on the available draft and parent article summary.
FAQs
Sources
- Could Your AI Systems Already Be High-Risk Under the EU AI Act?
- AI Act | Shaping Europe's digital future - European Union
- Draft Commission guidelines on the classification of high-risk AI systems | Shaping Europe’s digital future
- High-level summary of the AI Act | EU Artificial Intelligence Act
- Article 6: Classification Rules for High-Risk AI Systems | EU Artificial Intelligence Act
- 7 steps to identify if your AI system is high-risk under the AI Act | Timelex
- EU Commission draft guidelines on classification of "high-risk" AI systems: Key points
- Inside the EU’s landmark AI regulation
- European Commission publishes long-awaited guidelines on high-risk AI systems
- The U.S. And China Agree On Almost Nothing Except AI’s Deadliest Risks
- Your AI risk register is not an incident response plan
- Is My AI System High-Risk Under the EU AI Act? | ComplyAgent
- Exactly What Are ‘Systemic’ AI Risks, Anyway? | NAVEX
- Your AI isn’t the risk, your lack of oversight is. | Grant Thornton
- Notified Bodies Under the EU AI Act: The Gatekeepers You...
- EU AI Act Chatbot Disclosure and Deepfake Labeling: July 22 Signatory Deadline






















