EU AI Act: Could Your Existing AI Systems Already Be High-Risk Under Article 6?
kdnuggets.com

EU AI Act: Could Your Existing AI Systems Already Be High-Risk Under Article 6?

Tech News
3 min read

Published by AINave Editorial • Reviewed by Ramit

TL;DRThe European Commission's draft guidelines clarify that an AI system's intended purpose and documentation, not just capabilities, determine high-risk classification under Article 6 of the EU AI Act.

The European Commission's draft guidelines on the EU AI Act high-risk AI classification make one thing clear: whether your AI system is high-risk depends on more than what it technically does. How you document, market, deploy, and use the system matters just as much. For AI governance teams, this means some existing systems may already be high-risk without you realizing it.

What happened

The European Commission released draft guidelines on classifying high-risk AI systems under Article 6 of the EU AI Act. The guidelines outline two pathways to high-risk classification: AI used in regulated products that require a third-party conformity assessment, and AI deployed in sensitive use cases that could significantly affect people's health, safety, or fundamental rights. Under Article 6, an AI system's intended purpose plays a central role in determining its risk level.

Why AI builders should care

For enterprises building or deploying AI, this guidance raises immediate questions. Which of your systems fall under Article 6? Does your current documentation accurately reflect how each system is actually used? Could the Article 6(3) exemption apply, and what evidence would you need? The answers affect compliance obligations, risk governance, and product roadmaps. The draft guidelines also clarify that AI systems listed under Annex III are always considered high-risk if they profile individuals.

Practical implications

AI governance teams should start by mapping their AI portfolio to Article 6's scope. Identify systems that are part of regulated products (e.g., medical devices, machinery) and those used in sensitive areas like credit scoring, recruitment, or education. Review and update documentation to reflect real-world usage, not just intended design. For systems that might qualify for the Article 6(3) exemption, gather evidence that the system does not pose a significant risk of harm to health, safety, or fundamental rights. The draft guidelines emphasize that self-assessment is limited and may not be sufficient in all cases.

Caveats

The draft guidelines are still subject to consultation and may change. The notified body ecosystem for the AI Act is not yet fully operational, which could affect enforcement timelines. The guidance is based on the European Commission's draft, and organizations should monitor final adoption. The source evidence on the EU AI Act and its draft guidelines is evolving; the above is based on the available draft and parent article summary.

FAQs

Under Article 6, an AI system is high-risk if it falls into one of two pathways: it is used in a regulated product that requires a third-party conformity assessment, or it is deployed in a sensitive use case that could significantly affect people's health, safety, or fundamental rights. The classification depends on the system's intended purpose, documentation, and actual deployment, not just its technical capabilities.

Sources

Latest Tech News