Back to Publications
Regulatory Brief · AI Act

AI Act High-Risk Classification: Why You Need an Appeals Strategy Now

31 May 2026By NexCyber Editorial AI Act

The EU AI Act’s high-risk classification framework is now law, yet the draft guidelines on classification lack any formal appeals or reclassification procedure. For CTOs and CISOs, this omission creates a compliance blind spot: if a regulator deems your AI system high-risk, you have no clear pathway to challenge the decision—only the certainty of costly obligations. With enforcement of high-risk provisions beginning in August 2026, the time to prepare an appeals strategy is now.

The EU AI Act’s high-risk classification framework is now law, yet the draft guidelines on classification lack any formal appeals or reclassification procedure. For CTOs and CISOs, this omission creates a compliance blind spot: if a regulator deems your AI system high-risk, you have no clear pathway to challenge the decision—only the certainty of costly obligations. With enforcement of high-risk provisions beginning in August 2026, the time to prepare an appeals strategy is now.

The Silent Gap: Why Draft Guidelines Don’t Address Appeals

The AI Act’s classification rules for high-risk AI systems (Title III, Chapter 2) rely on two primary mechanisms: Annex III’s exhaustive list of use cases and Article 6’s criteria for systems that pose a "significant risk of harm." The European Commission’s draft *Guidelines on High-Risk AI Classification* (published 9 April 2025) clarify how to interpret these provisions but remain silent on what happens when a deployer disagrees with a regulator’s classification decision.

This gap is not accidental. The AI Act itself does not establish a harmonised appeals process for classification disputes. Article 77 grants Member States the power to "lay down rules on penalties and other enforcement measures," but stops short of mandating procedural safeguards for reclassification requests. The result: a patchwork of national approaches, with some regulators offering informal dialogue and others defaulting to enforcement actions.

For deployers, this means classification disputes will escalate quickly. Without a formal appeals mechanism, a regulator’s initial assessment could trigger immediate compliance obligations—even if the system was misclassified. The draft guidelines do not address how to contest such decisions, leaving deployers to navigate uncharted procedural terrain.

What Happens When Your AI System Gets Misclassified as High-Risk

A misclassification under the AI Act is not a theoretical risk. Consider an EU mid-cap manufacturer deploying an AI-driven predictive maintenance system for industrial machinery. The system monitors vibration patterns to predict equipment failures, but does not control safety-critical functions. Under Annex III, this use case falls outside the high-risk list. However, if a national regulator interprets the system as "directly influencing" safety outcomes (per Article 6(3)), it could be reclassified as high-risk—triggering obligations under Articles 9–15, including conformity assessments, technical documentation, and post-market monitoring.

The financial impact is immediate:

  • Conformity assessment costs: Mandatory third-party audits for high-risk systems (Article 43) can exceed €50,000 per system, depending on complexity.
  • Operational disruption: High-risk systems require continuous logging (Article 12), human oversight (Article 14), and cybersecurity measures (Article 15), increasing operational overhead by 20–30%.
  • Liability exposure: Misclassified systems may lack the required risk management frameworks (Article 9), exposing deployers to liability under the AI Liability Directive (proposed 2022).

Worse, the AI Act does not prescribe a timeline for resolving classification disputes. In the absence of a formal appeals process, deployers may face a choice: comply with high-risk obligations under protest or risk enforcement actions. The draft guidelines offer no guidance on how to escalate disagreements, leaving deployers to rely on ad-hoc negotiations with regulators.

Lessons from DSA Enforcement: Temu’s €200M Fine and Regulatory Escalation

The AI Act’s enforcement risks mirror those of the Digital Services Act (DSA), where procedural gaps have led to high-stakes disputes. In May 2025, the European Commission fined Temu €200 million for failing to comply with DSA transparency obligations. Temu contested the decision, arguing that its classification as a "very large online platform" (VLOP) was incorrect. However, the DSA’s lack of a formal appeals process for classification disputes forced Temu into a protracted legal battle, with compliance obligations taking effect immediately.

Key takeaways for AI Act deployers:

  1. 1Classification disputes escalate quickly: Temu’s fine was issued within six months of its VLOP designation, leaving little time to challenge the decision.
  2. 2Informal dialogue is not a substitute for appeals: While the Commission engaged in pre-enforcement discussions with Temu, these did not prevent the fine. Similarly, AI Act regulators may offer informal consultations, but these carry no legal weight.
  3. 3National courts may fill the gap: Temu’s appeal was heard by the General Court of the EU, not a dedicated DSA appeals body. AI Act deployers may need to pursue judicial review in national courts—a costly and uncertain process.

The DSA precedent underscores the urgency of preparing for classification disputes *before* enforcement begins. Deployers cannot assume that regulators will engage in good-faith negotiations; they must document their classification rationale proactively.

Building a Pre-Appeal Documentation Strategy for Your AI Systems

To challenge a high-risk classification, deployers must demonstrate that their system does not meet the criteria in Article 6 or Annex III. This requires a robust documentation strategy, aligned with the AI Act’s technical and risk management requirements. Key components include:

1. Classification Rationale Memo

  • Legal analysis: Cite the specific provisions of Annex III or Article 6 that exclude your system from high-risk classification. For example, if your system is used for "narrowly defined" purposes (Article 6(3)), document how its scope is limited.
  • Technical evidence: Provide data on the system’s intended use, input/output relationships, and decision-making logic. If the system does not "significantly influence" outcomes (per Article 6(3)), include impact assessments or third-party audits to support this claim.
  • Comparative benchmarks: Reference similar systems that have been classified as non-high-risk by regulators or industry bodies. While not binding, these benchmarks can strengthen your case.

2. Risk Assessment Reports

  • Harm quantification: The AI Act defines high-risk systems as those posing a "significant risk of harm" (Article 6(1)). Deployers should quantify potential harms using frameworks like ISO/IEC 23894 or ENISA’s AI risk management guidelines. If the risk of harm is below a defined threshold (e.g., <1% probability of severe impact), document this analysis.
  • Mitigation measures: Even if a system is borderline high-risk, demonstrate that existing safeguards (e.g., human oversight, bias testing) reduce risk to acceptable levels. The draft guidelines suggest that mitigations can influence classification, but do not specify how.

3. Regulatory Engagement Records

  • Pre-classification consultations: The AI Act encourages deployers to seek guidance from regulators (Article 60). Document all interactions, including written responses from regulators. If a regulator previously confirmed your system’s non-high-risk status, this can be used to challenge later reclassifications.
  • Industry standards compliance: Align your documentation with harmonised standards (once adopted under Article 40). Compliance with these standards creates a presumption of conformity, which can be leveraged in disputes.

Stakeholder Input Window Closes June 23: What to Demand in Your Submission

The European Commission’s draft guidelines are open for stakeholder feedback until 23 June 2025. Deployers have a critical opportunity to shape the final guidance—and push for clarity on appeals. Key demands to include in your submission:

1. Formal Appeals Process

  • Dedicated classification review board: Propose the creation of a pan-EU body to adjudicate classification disputes, modeled after the DSA’s Digital Services Coordinator network. This would provide a consistent forum for appeals.
  • Standardised timelines: Demand that regulators respond to reclassification requests within 60 days, with a clear escalation pathway for unresolved disputes.

2. Transparency in Classification Decisions

  • Public registry of decisions: Advocate for a public database of classification decisions, including the rationale for high-risk designations. This would allow deployers to benchmark their systems against precedents.
  • Written justifications: Require regulators to provide detailed written explanations for classification decisions, including references to specific provisions of the AI Act.

3. Safe Harbors for Low-Risk Systems

  • Presumption of non-high-risk: Propose that systems compliant with harmonised standards (Article 40) or certified under approved schemes (Article 42) be presumed non-high-risk unless a regulator demonstrates otherwise.
  • De minimis thresholds: Push for quantitative thresholds (e.g., harm probability, user impact) below which systems are automatically excluded from high-risk classification.

Submissions can be made via the Commission’s [Have Your Say portal](https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/13850-Artificial-intelligence-Act-guidelines-on-high-risk-classification_en). Deployers should coordinate with industry associations (e.g., DigitalEurope, CCIA) to amplify their demands.

Preparing for Reclassification Disputes Before Enforcement Begins

With high-risk provisions enforceable from August 2026, deployers must prepare for disputes now. Key steps:

1. Simulate Classification Challenges

  • Red-team your documentation: Conduct internal audits to identify weaknesses in your classification rationale. Engage external counsel to stress-test your arguments against hypothetical regulator objections.
  • Mock disputes: Simulate classification disputes with legal teams, focusing on how to present technical and legal evidence under time pressure.

2. Engage with National Regulators Early

  • Pre-classification consultations: Use Article 60 to seek informal guidance from regulators. Document all responses, even if non-binding.
  • Pilot programs: Participate in regulator-led sandboxes (Article 53) to test classification boundaries in a low-risk environment.

3. Build Alliances with Industry Peers

  • Joint submissions: Coordinate with industry groups to submit collective feedback on the draft guidelines. A unified voice is more likely to influence the final text.
  • Shared benchmarks: Collaborate with peers to develop industry-specific classification benchmarks, reducing the risk of inconsistent regulator interpretations.

Actionable Checklist: Appeals-Ready AI Governance by Q3 2026

To