AI Readiness Insights

AI Vibes

AI Adoption stories from Fusefy

The EU AI Act has been rolling out in phases and with each milestone, the clarity of the regulatory picture is enhancing, and the latest development could have a significant impact on how businesses determine their compliance path. On 19 May 2026, the Commission published its  long-awaited draft guidelines on the classification of high-risk AI systems under Article 6 of Regulation (EU) 2024/1689. The guidelines are now open for public consultation and offer the clearest indication yet of how the Commission intends to distinguish AI systems that fall under the high-risk regime from those outside its scope. 

For organizations building, deploying, or procuring AI systems that touch the EU market, this distinction matters. It could determine which requirements apply, what governance measures need to be in place, and how much compliance work lies ahead.

Why This Guidance Matters 

The EU AI Act adopts a risk-based framework and high-risk AI systems sit at the center of its most demanding obligations covering everything from data governance and technical documentation to human oversight and conformity assessment. Until now, providers have had to interpret Article 6’s classification criteria largely on their own with no authoritative Commission-level guidance to lean on.


EU AI Act Timeline

That gap had real consequences and the guidance on high-risk classification was originally expected by 2 February 2026, ahead of the Act’s initial high-risk compliance milestones. Its absence in addition to the delays in developing the harmonized technical standards that high-risk compliance depends on ,became a central concern in discussions about whether the AI Act’s implementation timeline was realistic at all!

What the Draft Guidelines Actually Cover 

The Commission has released three interconnected guidance papers, reflecting the two distinct routes into the high-risk category under Article 6 

  1. General principles –  the overarching interpretive framework for how the Commission reads Article 6 as a whole. 
  2. The Annex I route – high-risk classification for AI systems that are safety components of, or are themselves, products already regulated under EU harmonization legislation (e.g., machinery, medical devices, radio equipment, automotive, toys). 
  3. The Annex III route – high-risk classification based on specific use cases (e.g., recruitment, credit assessment, biometric categorization, and other sensitive domains). 

According to industry sources, this is the first time the Commission has set out, at this level of detail, how it reads what may be the single most consequential question in the entire Act: when a system falls inside the high-risk regime and when it stays outside. 

Importantly, the Commission has been explicit that these guidelines, even once finalized, will not be legally binding, only the Court of Justice of the EU can deliver an authoritative interpretation. Even so, the document is the strongest signal available of how the Commission, and by extension national market surveillance authorities, will approach enforcement in practice.

The Interpretive Shift 

Perhaps the most important takeaway for businesses is that the draft guidelines adopt an expansive interpretation of the high-risk conformity assessment test. Extensive analysis also suggests that, this means substantially more AI systems including those integrated into regulated products, or that are themselves regulated products under EU harmonization legislation may fall within the high-risk regime than a plain reading of the Act would suggest.

Businesses that previously assumed their AI was out of scope should revisit that assumption. Sector exposure is broader than expected. Any organization touching EU-regulated product-safety sectors viz., machinery, medical devices, radio equipment, automotive, toys or operating in Annex III use cases like recruitment, credit assessment, or biometric categorization should re-examine their classification with the new guidance in hand.

      The guidelines also clarify how the Commission will treat complex, multi-component systems. Notably, agentic AI systems composed of several interacting AI components must be assessed holistically rather than component-by-component implying, a system that looks low-risk in isolation may still be classified as high-risk once its combined output and behavior are considered  

      The guidance also draws careful lines around common carve-outs. For example, the Commission clarifies that AI systems used for risk assessment or pricing in life and health insurance cannot rely on a “fraud detection” exception to escape high-risk status. A fraud-detection capability only avoids high-risk classification if it functions as a genuinely standalone AI system which is  separate from the risk-assessment or pricing system itself. 

      The Consultation Process 

      The European Commission released the draft guidelines alongside a targeted stakeholder consultation involving providers, deployers, businesses, public authorities, academia, and citizens. The initial consultation closed on 23 June 2026, followed by a second targeted consultation that closed on 23 July 2026. As of this writing, the guidelines remain in draft form, with no formal adoption date announced. While feedback will inform the final version, businesses can treat the current draft as a reliable planning baseline but not yet a final rulebook.  

      The Timeline Has Moved 

      The Digital Omnibus on AI has reshaped the EU AI Act’s implementation timeline, particularly for high-risk AI. 


      EU AI Act Revised Timelines

      The Omnibus entered into force on 27 July 2026, giving organizations additional time to prepare for high-risk requirements. However, transparency obligations remain on schedule, making AI disclosure and content marking immediate priorities. 

      What This Means in Practice for Enterprises 

      The deferral of high-risk obligations gives enterprises more time but not a reason to pause AI governance. Organizations should use this window to understand their AI exposure, address immediate transparency requirements, and build a stronger compliance foundation.

      What Enterprises Should Do Now 


      What Enterprises Should Do

       The extra time is an opportunity to build AI governance right. 

      How Fusefy Helps You Get Ahead of the High-Risk Regime 

      Navigating a moving regulatory target that includes expansive classification criteria, deferred but still-approaching deadlines, and guidelines that are still being finalized would definitely be a challenge to handle. Fusefy, a unified AI assurance platform directly gets onto the three things this guidance demands of every enterprise operating with AI . 

      • AI Risk Assessment Fusefy evaluates your AI systems against the EU AI Act’s  classification criteria  including the expansive interpretation introduced in the draft guidelines to tell you, with evidence, whether a system is high-risk, and why. Instead of relying on a one-time legal opinion, you get a living risk score that updates as your models, use cases, or the guidelines themselves evolve. 
      • AI Governance & Compliance Fusefy operationalizes the obligations that follow a high-risk determination: technical documentation, data governance, human oversight design, EU database registration, and conformity-assessment readiness mapped simultaneously against the AI Act, NIST AI RMF, and ISO 42001. 
      • AI Testing & Evaluation Whether or not your systems ultimately fall inside the high-risk perimeter, Fusefy’s continuous testing framework validates models for bias, drift, robustness, and transparency , the same qualities regulators are scrutinizing under Annex III and Annex I , so that you’re audit-ready long before a market surveillance authority asks. 

      With the compliance runway now extended to December 2027 and August 2028, the organizations that come out ahead will be the ones using this window to build the risk, governance, and testing infrastructure now. That’s where Fusefy handholds enterprises.

      AUTHOR

      Sindhiya

      Sindhiya Selvaraj

      With over a decade of experience, Sindhiya Selvaraj is the Chief Architect at Fusefy, leading the design of secure, scalable AI systems grounded in governance, ethics, and regulatory compliance.