Back to Publications
Regulatory Brief · AI Act

Audit Your AI Systems Against Draft High-Risk Guidelines: What Deployers Must Check Now

30 May 2026By NexCyber Editorial AI Act

The European Commission’s **draft guidelines on high-risk AI classification** (published May 2026) are not just another consultation document—they are the closest thing to final rules deployers will get before the **EU AI Act’s high-risk obligations apply on 2 August 2026**. For CTOs, AI leads, and compliance teams, this is the moment to conduct an internal audit, identify systems that may fall under high-risk scope, and begin compiling compliance evidence. Waiting for the final guidelines is no

The European Commission’s draft guidelines on high-risk AI classification (published May 2026) are not just another consultation document—they are the closest thing to final rules deployers will get before the EU AI Act’s high-risk obligations apply on 2 August 2026. For CTOs, AI leads, and compliance teams, this is the moment to conduct an internal audit, identify systems that may fall under high-risk scope, and begin compiling compliance evidence. Waiting for the final guidelines is not an option: the clock is ticking, and misclassification now could mean costly remediation later.

---

Why the May 2026 Draft Guidelines Matter More Than You Think

The Legal Weight of Draft Guidelines

The AI Act (Regulation 2024/1689) empowers the Commission to issue binding guidelines on high-risk classification under Article 6(3). While the May 2026 draft is not yet final, it reflects the Commission’s current interpretation of Annex III—the list of high-risk AI systems. Courts and national authorities will likely defer to these guidelines when assessing compliance, even if minor revisions occur before adoption.

The "Safe Harbour" Effect

Deployers who align with the draft guidelines now can argue they acted in good faith if enforcement actions arise later. Conversely, ignoring the draft increases the risk of retroactive reclassification, forcing last-minute compliance scrambles. The draft is not a suggestion—it is a preview of how regulators will assess high-risk status.

The Cost of Misclassification

Under the AI Act, high-risk systems face strict obligations, including:

  • Risk management (Article 9)
  • Data governance (Article 10)
  • Technical documentation (Article 11)
  • Human oversight (Article 14)
  • Accuracy, robustness, and cybersecurity (Article 15)

Non-compliance carries fines of up to €15 million or 3% of global turnover—whichever is higher. For an EU mid-cap deploying AI in hiring or credit scoring, misclassification could mean millions in retroactive costs to meet these requirements.

---

The Three-Step Internal Audit Checklist for Deployers

Step 1: Map Your AI Systems Against Annex III

The AI Act’s Annex III lists eight domains where AI systems are presumed high-risk unless they meet narrow exceptions. Deployers must audit every AI system against these categories:

  1. 1Biometric identification and categorisation (Annex III, Point 1) - Includes real-time remote biometric ID (e.g., facial recognition in public spaces) and biometric categorisation (e.g., emotion recognition in workplaces). - Exception: Systems used for narrow biometric verification (e.g., unlocking a smartphone) are not high-risk.
  1. 1Critical infrastructure management (Annex III, Point 2) - AI used in road traffic, water, gas, heating, or electricity supply is high-risk. - Exception: Systems with negligible impact on safety (e.g., predictive maintenance for non-critical components).
  1. 1Education and vocational training (Annex III, Point 3) - AI determining access to education (e.g., university admissions) or assessing students (e.g., automated grading) is high-risk. - Exception: AI used for general administrative tasks (e.g., scheduling) is not high-risk.
  1. 1Employment, workers management, and access to self-employment (Annex III, Point 4) - AI in hiring, promotions, or performance monitoring is high-risk. - Exception: AI used for general HR analytics (e.g., workforce planning) may not qualify.
  1. 1Access to essential private and public services (Annex III, Point 5) - AI determining credit scores, insurance premiums, or social benefits is high-risk. - Exception: Systems with limited impact (e.g., chatbots for customer service) are not high-risk.
  1. 1Law enforcement (Annex III, Point 6) - AI used for predictive policing, crime risk assessment, or evidence evaluation is high-risk. - Exception: Systems used for administrative tasks (e.g., case file management) are not high-risk.
  1. 1Migration, asylum, and border control (Annex III, Point 7) - AI assessing visa applications, asylum claims, or border security is high-risk. - Exception: Systems used for general administrative support (e.g., document translation) are not high-risk.
  1. 1Administration of justice and democratic processes (Annex III, Point 8) - AI used in legal research, sentencing support, or election monitoring is high-risk. - Exception: Systems used for general legal databases (e.g., case law search) are not high-risk.

Action: Create a register of AI systems and tag each against Annex III. If a system falls under any category, proceed to Step 2.

Step 2: Apply the "Material Risk" Test

Not all Annex III systems are automatically high-risk. The AI Act allows deployers to argue that a system does not pose a "material risk" to health, safety, or fundamental rights (Article 6(3)). The May 2026 draft guidelines provide a two-part test for this assessment:

  1. 1Severity of Harm - Does the AI system directly influence decisions with significant consequences (e.g., denial of a loan, rejection of a job application)? - Example: An AI tool that ranks job candidates but does not make final hiring decisions may still be high-risk if it disproportionately excludes protected groups.
  1. 1Probability of Harm - Is there a realistic likelihood of harm occurring? Factors include: - Bias in training data (e.g., historical hiring data favouring one gender). - Lack of human oversight (e.g., fully automated loan approvals). - Opacity of decision-making (e.g., black-box models in healthcare diagnostics).

Action: For each Annex III system, document whether it meets the material risk threshold. If unsure, assume high-risk status—erring on the side of caution is safer than under-classification.

Step 3: Check for "Limited Risk" Exemptions

The draft guidelines clarify that some Annex III systems may qualify as limited-risk if they meet all of the following criteria:

  • The system is not used for profiling (e.g., a chatbot providing general advice).
  • The system does not make final decisions (e.g., a tool that flags potential fraud but requires human review).
  • The system does not process sensitive data (e.g., biometric or health data).

Action: If a system meets these criteria, document the justification. However, do not assume exemption—consult legal or compliance teams before ruling out high-risk status.

---

Common Misclassification Traps: Where Deployers Get It Wrong

Trap 1: Assuming "Support Tools" Are Low-Risk

Many deployers assume that AI systems used for support (e.g., resume screening, loan pre-approvals) are not high-risk because they do not make final decisions. This is incorrect. The AI Act focuses on potential harm, not the finality of the decision. A resume-screening tool that systematically excludes older applicants is high-risk, even if a human makes the final call.

Trap 2: Ignoring "Fundamental Rights" Risks

The AI Act’s definition of high-risk includes systems that adversely affect fundamental rights (e.g., non-discrimination, privacy). Deployers often overlook this when assessing systems like:

  • Workplace monitoring AI (e.g., keystroke tracking, productivity scoring).
  • Customer behaviour analysis (e.g., AI that infers sensitive attributes like sexual orientation or political views).

Example: An EU retailer using AI to personalise pricing based on browsing history may inadvertently discriminate against lower-income groups, triggering high-risk obligations.

Trap 3: Overlooking "Indirect" High-Risk Use Cases

Some deployers focus only on direct applications of AI (e.g., a chatbot for customer service) and miss indirect high-risk uses. For example:

  • A supply chain optimisation AI may indirectly affect critical infrastructure (e.g., energy grid management).
  • A marketing AI that segments customers may inadvertently profile vulnerable groups (e.g., elderly consumers).

Action: Audit all AI systems, not just those with obvious high-risk applications.

Trap 4: Relying on Vendor Assurances

Many deployers assume that if a vendor labels an AI system as "low-risk", it is compliant. This is dangerous. The AI Act places primary liability on deployers, not vendors. A vendor’s classification is not binding—deployers must conduct their own assessment.

---

Documentation and Evidence You Need to Gather Now

1. System Inventory and Classification Records

  • A register of all AI systems, including: - Purpose and use case. - Data inputs and outputs. - Annex III category (if applicable). - Justification for high-risk or non-high-risk classification.

2. Risk Assessment Reports

  • For each high-risk system, document: - Potential harms (e.g., bias, safety risks). - Mitigation measures (e.g., bias testing, human oversight). - Evidence of compliance with AI Act requirements (e.g., data governance logs, accuracy metrics).

3. Data Governance Documentation

  • Training data sources (e.g., public datasets, proprietary data).
  • Bias and fairness assessments (e.g., disparate impact analysis).
  • **Data minimisation measures