Back to Publications
Regulatory Brief · AI Act

AI Act High-Risk Classification: Why Deployers Miss the May 2026 Guidelines Window

31 May 2026By NexCyber Editorial AI Act

The European Commission’s draft guidelines on high-risk AI classification close for public feedback in May 2026—yet most deployers have not begun mapping their AI systems to the emerging criteria. With enforcement of high-risk obligations set for August 2026, the gap between regulatory expectations and operational readiness is widening. For CTOs and CISOs in essential and important entities, this delay is not just a compliance risk but a strategic blind spot that could disrupt product roadmaps,

The European Commission’s draft guidelines on high-risk AI classification close for public feedback in May 2026—yet most deployers have not begun mapping their AI systems to the emerging criteria. With enforcement of high-risk obligations set for August 2026, the gap between regulatory expectations and operational readiness is widening. For CTOs and CISOs in essential and important entities, this delay is not just a compliance risk but a strategic blind spot that could disrupt product roadmaps, supply chains, and customer trust.

The AI Act’s risk-based framework hinges on accurate classification. Misclassification—whether over- or under-scoping—exposes organizations to fines of up to €15 million or 3% of global turnover, operational disruptions, and reputational damage. The May 2026 guidelines will crystallize how the Commission interprets ambiguous terms like “significant risk of harm” and “critical use cases.” Deployers who wait for finalization will find themselves scrambling to retrofit governance, documentation, and technical controls in a compressed timeline.

This article outlines why the guidelines matter, where deployers are falling short, and how to audit your AI inventory before enforcement begins.

---

Why the May 2026 Guidelines Matter More Than You Think

The Guidelines Are Not Just “Guidance”

The AI Act (Regulation 2024/1689) empowers the Commission to adopt implementing acts that specify technical criteria for high-risk classification. The draft guidelines under Article 6(3) are the first such act and will carry legal weight. While not binding in the same way as the regulation itself, they will shape how national authorities and courts interpret ambiguous provisions. For example, the guidelines will clarify:

  • Which biometric systems (e.g., emotion recognition, remote identification) qualify as high-risk under Annex III.
  • How to assess whether an AI system poses a “significant risk of harm” to health, safety, or fundamental rights (Article 6(1)).
  • The thresholds for “material impact” in employment, education, and access to essential services (Annex III, points 4–6).

Deployers who treat the guidelines as optional do so at their peril. National supervisory authorities will use them as a benchmark for enforcement, and deviations will require robust justification.

The Clock Starts Now, Not in August 2026

High-risk obligations under the AI Act apply from 2 August 2026, but the compliance journey begins with classification. The process involves:

  1. 1Inventory mapping: Identifying all AI systems in use or under development.
  2. 2Risk assessment: Evaluating each system against the criteria in Article 6 and Annex III.
  3. 3Gap analysis: Comparing current controls (e.g., data governance, bias mitigation) against AI Act requirements.
  4. 4Remediation: Implementing technical and organizational measures to close gaps.

For complex organizations—such as financial institutions under DORA or critical infrastructure providers under NIS2—this process can take 12–18 months. Waiting for final guidelines in May 2026 leaves no room for error.

---

The Deployer Readiness Gap: What the Consultation Reveals

Low Engagement from Non-Tech Sectors

The Commission’s public consultation on the draft guidelines has seen disproportionate participation from tech vendors and civil society, while deployers in healthcare, manufacturing, and public administration remain underrepresented. This imbalance risks guidelines that favor theoretical clarity over practical applicability. For example:

  • A hospital deploying AI for diagnostic support may struggle to interpret how “significant risk of harm” applies to clinical decision-making.
  • An automotive supplier using AI for quality control may misclassify its system if the guidelines do not address industrial use cases explicitly.

Deployers who do not engage in the consultation risk being blindsided by guidelines that do not reflect their operational realities.

Over-Reliance on Vendor Assurances

Many deployers assume that AI vendors will handle classification and compliance. This is a dangerous assumption. The AI Act places primary responsibility on deployers (Article 26), not providers. While vendors must provide documentation (e.g., technical specifications, risk assessments), deployers must:

  • Verify that the system meets high-risk criteria in their specific context.
  • Ensure that the system’s intended use aligns with the vendor’s documentation.
  • Conduct their own fundamental rights impact assessments (FRIAs) for high-risk systems.

An EU mid-cap manufacturer, for instance, may purchase an AI-powered predictive maintenance tool from a U.S. vendor. If the vendor classifies the tool as low-risk but the manufacturer deploys it in a safety-critical environment (e.g., monitoring pressure vessels), the deployer—not the vendor—will be liable for misclassification.

Lack of Internal Classification Frameworks

Most organizations lack structured processes for classifying AI systems. Common pitfalls include:

  • Ad-hoc assessments: Decisions are made by individual teams without centralized oversight.
  • Over-classification: Erroneously labeling systems as high-risk to “play it safe,” leading to unnecessary compliance burdens.
  • Under-classification: Failing to recognize that a system’s context of use (e.g., scale, user vulnerability) elevates its risk level.

For example, a retail bank using AI for credit scoring may assume the system is low-risk because it is not listed in Annex III. However, if the system disproportionately affects vulnerable groups (e.g., denying loans to minority applicants), it may qualify as high-risk under Article 6(1) due to its fundamental rights impact.

---

Three Critical Classification Scenarios Deployers Misread

Scenario 1: Biometric Systems in Public Spaces

Misconception: “Our facial recognition system is only used for access control, so it’s low-risk.” Reality: The AI Act’s Annex III lists biometric identification and categorization as high-risk by default. Exceptions are narrow and require:

  • Explicit consent (for non-law enforcement use).
  • Strict necessity (e.g., preventing a terrorist threat).
  • Proportionality (e.g., limited scope and duration).

Deployers must assess:

  • Is the system used for real-time or post-remote identification?
  • Does it categorize individuals based on sensitive attributes (e.g., race, emotion)?
  • Is it deployed in a publicly accessible space (e.g., shopping malls, airports)?

A logistics company using facial recognition to track warehouse workers, for instance, may assume the system is low-risk. However, if the system categorizes workers by perceived emotion or fatigue, it could qualify as high-risk under Annex III, point 1(a).

Scenario 2: AI in Employment and Workforce Management

Misconception: “Our HR AI tool is just for recruitment, so it’s not high-risk.” Reality: Annex III, point 4, explicitly classifies AI systems used for employment, workers management, and access to self-employment as high-risk. This includes:

  • Recruitment tools (e.g., CV screening, interview analysis).
  • Performance monitoring (e.g., productivity tracking, shift scheduling).
  • Termination decisions (e.g., AI-driven layoffs).

Deployers must evaluate:

  • Does the system influence hiring, promotion, or dismissal decisions?
  • Does it profile workers based on behavior or performance data?
  • Is it used at scale (e.g., across multiple locations or countries)?

A multinational retailer using AI to optimize shift schedules may not realize that the system’s impact on worker well-being (e.g., unpredictable hours, stress) could trigger high-risk classification.

Scenario 3: AI for Access to Essential Services

Misconception: “Our AI chatbot for customer service is just a convenience tool.” Reality: Annex III, point 6, covers AI systems that determine access to essential services, including:

  • Financial services (e.g., loan approvals, insurance underwriting).
  • Healthcare (e.g., triage, treatment recommendations).
  • Education (e.g., university admissions, scholarship allocations).

Deployers must assess:

  • Does the system deny or restrict access to a service?
  • Is the service essential (e.g., healthcare, housing, education)?
  • Does the system disproportionately affect vulnerable groups?

A fintech company using AI to automate loan approvals may assume the system is low-risk if it complies with GDPR. However, if the system systematically denies loans to certain demographics, it could qualify as high-risk under Article 6(1) due to its fundamental rights impact.

---

Building a High-Risk AI Audit Checklist for Your Inventory

Step 1: Inventory Your AI Systems

Create a centralized register of all AI systems in use or development. For each system, document:

  • Purpose: What problem does the system solve?
  • Data inputs: What data is used to train or operate the system?
  • Outputs: What decisions or recommendations does the system produce?
  • Users: Who interacts with the system (e.g., employees, customers, public authorities)?
  • Deployment context: Is the system used in a regulated sector (e.g., healthcare, finance)?

Step 2: Map Systems to Annex III Categories

For each system, assess whether it falls into one of the high-risk categories in Annex III:

  1. 1Biometric systems (e.g., identification, categorization).
  2. 2Critical infrastructure (e.g., energy, transport, water).
  3. 3Education and vocational training (e.g., admissions, grading).
  4. 4Employment and workforce management (e.g., recruitment, performance monitoring).
  5. 5Access to essential services (e.g., financial services, healthcare).
  6. 6Law enforcement (e.g., predictive policing, evidence analysis).
  7. 7Migration and border control (e.g., visa processing, asylum decisions).
  8. 8Administration of justice (e.g., sentencing, legal research).

If a system does not