The context and structure of the Guidelines
Regulation (EU) 2024/1689 (“AI Act”) imposes significant obligations regarding governance, documentation, transparency, human oversight and monitoring on AI systems classified as “high-risk” under Article 6. In this context, the European Commission has recently published and launched a public consultation on draftGuidelines, adopted pursuant to Article 6(5) of the AI Act, with the aim of supporting providers, deployers and competent authorities in classifying the level of risk associated with AI systems.
Although not legally binding, the Guidelines represent the main interpretative reference currently available for carrying out this classification and provide numerous practical examples intended to guide the application of the provisions of the AI Act.
Article 6 distinguishes between two categories of high-risk systems. The first comprises AI systems intended for use as safety components of a product, or which themselves constitute a product covered by the EU harmonisation legislation listed in Annex I to the AI Act, provided that they are subject to third-party conformity assessment. The second, on the other hand, concerns systems that fall within one of the use cases listed in Annex III, which includes, amongst others, the areas of biometrics, employment, access to essential services (including credit scoring and insurance risk assessment), critical infrastructure, migration and the administration of justice.
Annex I: the concept of “safety component”
With regard to the systems covered by Annex I, one of the most significant clarifications provided by the Guidelines concerns the concept of “safety component” referred to in Article 3(14) of the AI Act,
which applies in two alternative scenarios.
The first scenario is fairly intuitive and concerns AI systems intended by the provider to perform a safety function, namely to prevent or mitigate risks to health, the safety of persons or property.
The second scenario is less obvious: an AI system may qualify as a safety component, irrespective of the provider’s intended purpose, if its failure or malfunction – including incorrect outputs, false negatives or misclassification – may endanger the health and safety of persons or property in the product context.
The Commission cites, by way of example, systems used in the operation of lift doors, lane assistance functions, or the optimisation of the functioning of household appliances, where a malfunction could result in physical harm to persons.
By contrast, functionalities aimed solely at operational efficiency, performance optimisation or service-quality improvement remain excluded where any error would not give rise to safety risks.
The “intended purpose” and liability along the AI supply chain
A key issue addressed by the Guidelines concerns the concept of “intended purpose”, defined in Article 3(12) of the AI Act as the use for which an AI system is intended by the provider, including the specific context and conditions of use, as specified in the relevant technical documentation, instructions for use and promotional or sales materials.
According to the Commission, the classification of a system does not depend solely on its technical characteristics, but also on the way in which the provider presents it on the market.
The Guidelines clarify that, where contractual documentation, instructions for use, promotional materials or technical documentation present the system as applicable across a generality of contexts, without clearly defining the permitted uses or specifically excluding high-risk uses, the intended purpose may also encompass such uses.
Of particular significance is the statement that a generic contractual clause asserting that high-risk uses of the system are excluded is in itself insufficient to prevent the system from being classified as “high-risk”, if the product positioning or the provider’s examples of use effectively provide for or promote such uses.
Annex III: use cases of greatest interest to businesses
Systems used in the employment sector
Among the cases covered by Annex III, those relating to the employment sector are of particular practical importance to businesses.
The Guidelines clarify that all systems which significantly influence the selection process are classified as high-risk, even if they do not directly determine the outcome.
Therefore, the high-risk category includes, for example, job-matching and candidate-ranking systems, tools that assign scores or classifications during the selection process, automated systems for searching for candidates on social networks or public databases, as well as targeted job advertising solutions that determine which users will see specific job vacancies.
A similar approach is adopted with regard to the management of work-related relationships. The Guidelines confirm that systems used to assign tasks, determine operational priorities, monitor performance, influence professional assessments or decisions relating to promotions, remuneration or termination of employment, particularly where such activities are based on the processing of behavioural indicators.
Furthermore, the Commission specifies that the scope of application of the cases in question is not limited to employees, but may also extend to self-employed individuals, professionals, contractors and platform workers.
Credit assessment systems
The Guidelines confirm an equally broad interpretation with regard to systems used for credit assessment.
According to the Commission, any AI system intended to be used to evaluate the creditworthiness of natural persons or to establish their credit score must be considered high-risk, even where the system serves only one of these purposes.
This category includes systems that process financial, asset-related or behavioural data to generate scores or assessments used in the decision-making process relating to the granting of credit. Excluded, however, are systems used exclusively for marketing, customer service or the monitoring of exposures following the granting of credit, as well as those intended solely for the purpose of detecting financial fraud, for which the AI Act provides a specific exemption.
The “filter” mechanism provided for in Article 6(3) of the AI Act
The Guidelines also devote considerable attention to the exclusion mechanism provided for in Article 6(3) of the AI Act, which allows excluding, subject to certain conditions, from the category of high-risk systems certain AI systems which, despite formally falling within one of the use cases listed in Annex III, do not materially influence the outcome of the decision-making process.
The Commission cites, by way of example, systems that perform purely preparatory, organisational or support tasks, such as document classification, the reorganisation of information or the provision of regulatory references, without making assessments of the specific case or affecting the content of the final decision.
The Guidelines specify, however, that the filter does not apply when the system carries out
profiling activities within the meaning of the GDPR, or when it operates within more complex architectures whose outputs contribute substantially to a significant decision. Furthermore, it is reiterated that the mere presence of human oversight (an essential requirement laid down by the AI Act itself) is not sufficient to preclude classification as a high-risk system.
Timeline and next steps
The Guidelines are currently open for public consultation, but already provide guidance of
considerable interest to organisations undertaking AI Act compliance programs. With regard to deadlines, the Guidelines note that the deadlines originally set out in Article 113 of the AI Act have been postponed by the proposed Digital Omnibus Regulation, on which the European institutions have reached a political agreement. In particular, the obligations for high-risk systems classified under Article 6(2) (Annex III) will apply from 2 December 2027, whilst those for systems classified under Article 6(1) (Annex I) will apply from2 August 2028. For systems already placed on the market or put into service before 2 August 2026, the AI Act will apply only in the event of significant design changes made after that date.
In this context, organisations should carefully review their inventory of AI systems in use, verify the intended purpose identified by providers – including through technical and commercial documentation – and adequately document the assessments carried out in cases of more complex classification.
Indeed, for many organisations, the main challenge will not be to identify systems that are clearly high-risk, but rather to demonstrate, through a structured and documented analysis, the reasons why a particular system should not be classified as such.