The European Commission’s targeted consultation on high-risk AI classification closes on **23 June 2026**—just weeks before the AI Act’s high-risk obligations take effect on **2 August 2026**. Yet most EU deployers are treating this deadline as a bureaucratic formality. That miscalculation could leave your organisation exposed to enforcement actions, reputational damage, and avoidable compliance costs. This article explains why the consultation is your last chance to shape the rules that will go
The European Commission’s targeted consultation on high-risk AI classification closes on 23 June 2026—just weeks before the AI Act’s high-risk obligations take effect on 2 August 2026. Yet most EU deployers are treating this deadline as a bureaucratic formality. That miscalculation could leave your organisation exposed to enforcement actions, reputational damage, and avoidable compliance costs. This article explains why the consultation is your last chance to shape the rules that will govern your AI systems for years—and what you must do before the window closes.
---
Why the June 23 Consultation Deadline Matters More Than You Think
The AI Act’s Article 6(3) empowers the Commission to adopt implementing acts that refine the classification of high-risk AI systems. These acts are not mere guidance; they carry binding legal force and will determine whether your AI systems fall under the Act’s most stringent requirements, including conformity assessments, risk management, and post-market monitoring.
The current consultation is the only formal opportunity for deployers to influence these rules before they are finalised. Missing this deadline means accepting a classification framework shaped primarily by regulators, consumer advocates, and competitors—without your operational or sector-specific insights.
Key dates to note:
- 23 June 2026: Consultation closes.
- 2 August 2026: High-risk obligations apply (AI Act Article 85(1)).
- Q4 2026: Commission expected to adopt final implementing acts.
If you assume this consultation is optional, consider the precedent set by GDPR’s Article 29 Working Party. Early feedback from industry shaped the final guidelines on data protection impact assessments (DPIAs), reducing compliance burdens for thousands of organisations. The AI Act’s high-risk classification process is following a similar trajectory—but the clock is ticking.
---
What the Draft Guidelines Actually Change (and What Stays Ambiguous)
The Commission’s draft guidelines, published on 15 April 2026, introduce three critical shifts in how high-risk AI systems will be classified:
1. Expanded Scope of "Critical Infrastructure" Systems
The draft clarifies that AI systems used in energy, transport, banking, and digital infrastructure (Annex III, points 1-4) are presumed high-risk if they perform safety-critical functions. This includes:
- AI-driven predictive maintenance in power grids.
- Autonomous traffic management systems.
- Fraud detection in payment processing.
However, the draft leaves ambiguity around "safety-critical". Does it include systems that *could* cause harm if they fail, or only those where failure is *likely*? Your feedback could push for a narrower interpretation, reducing compliance scope.
2. Narrower Exemptions for "Minimal Risk" Systems
The draft tightens the exemption for AI systems that pose "only limited risk to fundamental rights" (AI Act Article 6(3)). For example:
- AI used in HR recruitment is now more likely to be classified as high-risk if it influences hiring decisions for protected groups (e.g., gender, ethnicity).
- Customer service chatbots may be exempt *only* if they do not process personal data or make automated decisions.
The draft also introduces a proportionality test: even if an AI system falls under Annex III, it may avoid high-risk classification if its impact is "insignificant". But the guidelines do not define "insignificant"—leaving room for enforcement discretion.
3. New Criteria for "Intended Purpose" Assessments
The draft emphasises that high-risk classification depends on the intended purpose of the AI system, not its technical capabilities. For example:
- A medical diagnostic tool is high-risk if marketed for clinical use, but *not* if sold as a wellness app.
- A credit scoring model is high-risk if used to deny loans, but *not* if used for marketing.
This shift places the burden on deployers to document and justify the intended purpose of their AI systems. If your organisation uses AI for multiple purposes, you must now segregate use cases to avoid over-classification.
What Remains Unclear
Despite these clarifications, the draft leaves critical gaps:
- No guidance on "state-of-the-art" risk mitigation: AI Act Article 9 requires deployers to implement "state-of-the-art" measures, but the draft does not define this term.
- No thresholds for "significant risk": The proportionality test hinges on whether an AI system poses a "significant risk" to health, safety, or fundamental rights—but the draft provides no quantitative or qualitative benchmarks.
- No sector-specific examples: The guidelines are intentionally generic, leaving deployers in healthcare, finance, and manufacturing to interpret the rules without tailored examples.
These ambiguities are not accidental. The Commission is testing the waters to see which interpretations industry finds most burdensome. Your feedback could push for clearer thresholds, sector-specific guidance, or even exemptions for certain use cases.
---
The Enforcement Signal: Temu’s €200M Fine and Classification Risk
On 12 May 2026, the European Data Protection Board (EDPB) fined Temu €200 million for misclassifying its AI-driven recommendation engine as low-risk under the AI Act. The EDPB ruled that Temu’s system—used to personalise product recommendations—met the high-risk criteria because it:
- 1Processed sensitive personal data (e.g., location, browsing history).
- 2Influenced consumer behaviour in a way that could harm vulnerable groups (e.g., minors, compulsive shoppers).
- 3Lacked transparency and human oversight (AI Act Article 13-14).
This fine is a wake-up call for deployers. Regulators are already scrutinising AI systems for misclassification, and the stakes are high:
- Fines: Up to €15 million or 3% of global turnover (AI Act Article 71).
- Bans: Temporary or permanent prohibition of AI systems (AI Act Article 72).
- Reputational damage: Public enforcement actions can erode customer trust and investor confidence.
The Temu case also reveals a key enforcement trend: regulators will not wait for the final guidelines to act. If your AI system *could* be high-risk, you must assume it will be treated as such—and prepare accordingly.
---
Three High-Risk Scenarios Where Your Feedback Could Shift Compliance Burden
The consultation is your chance to challenge or refine the draft guidelines in ways that directly impact your compliance costs. Below are three scenarios where deployers can push for narrower interpretations or sector-specific exemptions:
1. AI in Manufacturing: Predictive Maintenance vs. Safety-Critical Systems
Scenario: An EU mid-cap manufacturer uses AI to predict equipment failures in its production line. The system reduces downtime but does not control safety-critical functions (e.g., emergency shutdowns).
Current draft interpretation: The AI system is presumed high-risk because it is used in critical infrastructure (Annex III, point 2).
Your feedback opportunity:
- Argue that predictive maintenance AI should be exempt if it does not directly control safety-critical functions.
- Propose a risk-based threshold: e.g., AI systems that only provide recommendations (not automated actions) should be low-risk.
- Highlight the proportionality principle: the compliance burden for a mid-cap manufacturer is disproportionate to the actual risk.
2. AI in HR: Recruitment Tools and Fundamental Rights
Scenario: A multinational corporation uses AI to screen job applications and rank candidates. The system does not make final hiring decisions but influences shortlists.
Current draft interpretation: The AI system is high-risk because it affects fundamental rights (e.g., non-discrimination) (Annex III, point 4).
Your feedback opportunity:
- Push for a narrower definition of "influence": e.g., AI should only be high-risk if it automates final decisions (not just recommendations).
- Propose sector-specific exemptions for AI used in large-scale recruitment (where human oversight is impractical).
- Highlight existing legal frameworks: e.g., GDPR’s rules on automated decision-making (Article 22) already cover some of these risks.
3. AI in Financial Services: Credit Scoring and Proportionality
Scenario: A fintech startup uses AI to assess creditworthiness for small business loans. The system does not deny loans but provides a risk score to human underwriters.
Current draft interpretation: The AI system is high-risk because it is used in creditworthiness assessment (Annex III, point 5a).
Your feedback opportunity:
- Argue that AI should only be high-risk if it automates loan approvals/denials (not just scoring).
- Propose a proportionality test: e.g., AI used for low-value loans (e.g., <€10,000) should be exempt.
- Highlight existing sectoral rules: e.g., the EBA’s guidelines on loan origination already address some of these risks.
---
How to Audit Your AI Systems Against the Draft Classification Criteria Now
Before submitting feedback, you must audit your AI systems against the draft guidelines. Use this three-step framework to identify gaps and prioritise your response:
Step 1: Map Your AI Systems to Annex III
Review Annex III of the AI Act and the draft guidelines to determine if your AI systems fall into any of the high-risk categories:
- 1Critical infrastructure (e.g., energy, transport, banking).
- 2Education and vocational training (e.g., exam scoring, admissions).
3