The European Commission’s draft *Guidelines on High-Risk AI Classification* land in May 2026—just three months before enforcement of the AI Act’s high-risk obligations begins. For CTOs, CISOs, and compliance leads, this timing is not a grace period. It is a warning: regulators will not wait for your audit to conclude before assessing whether your systems meet the law’s standards. The enforcement-compliance lag is real, and the gap is widening. Understanding how market surveillance authorities wi
The European Commission’s draft *Guidelines on High-Risk AI Classification* land in May 2026—just three months before enforcement of the AI Act’s high-risk obligations begins. For CTOs, CISOs, and compliance leads, this timing is not a grace period. It is a warning: regulators will not wait for your audit to conclude before assessing whether your systems meet the law’s standards. The enforcement-compliance lag is real, and the gap is widening. Understanding how market surveillance authorities will interpret classification rules—before the guidelines are final—is now a strategic imperative.
---
The Enforcement-Compliance Paradox: Why May 2026 Guidelines Don’t Mean May 2026 Compliance
The AI Act’s high-risk obligations become enforceable on 2 August 2026. The Commission’s draft guidelines, expected in May 2026, are intended to clarify how to classify AI systems under Annex III of the AI Act. However, this timeline creates a dangerous misconception: that compliance can wait until the guidelines are published.
In reality, enforcement begins on day one. Market surveillance authorities (MSAs) in each Member State are already preparing to assess AI systems against the AI Act Article 6 criteria, which define high-risk systems based on their intended purpose and potential impact on health, safety, or fundamental rights. The guidelines are not legally binding—they are interpretative tools. MSAs are not obligated to wait for them before initiating investigations.
Moreover, the AI Act’s Article 93 empowers MSAs to request documentation, conduct inspections, and issue corrective measures *immediately* after the enforcement date. If your classification process is still in draft form when regulators come knocking, you will be defending a position, not demonstrating compliance.
---
What the Draft Guidelines Actually Clarify (And What They Leave Ambiguous)
The draft guidelines are expected to address three critical areas of Annex III:
1. **Intended Purpose and Context of Use**
The guidelines will likely expand on AI Act Article 6(2), which states that a system is high-risk if it is *intended to be used* in one of the areas listed in Annex III. The Commission may provide examples of how "intended purpose" is determined, such as:
- The system’s marketing materials, user manuals, or training data.
- The economic sector in which it is deployed (e.g., healthcare, employment, law enforcement).
- The foreseeable downstream uses, even if not explicitly stated by the provider.
However, ambiguity will remain around dual-use systems—AI tools that can be deployed in both high-risk and low-risk contexts. For example, a resume-screening tool may be used for general hiring (low-risk) or for hiring in critical infrastructure sectors (high-risk under Annex III, point 4). The guidelines may not resolve whether the *provider* or the *deployer* bears the burden of classification in such cases.
2. **Significant Risk to Health, Safety, or Fundamental Rights**
Annex III lists eight areas where AI systems are presumed high-risk, but AI Act Article 6(3) allows providers to rebut this presumption if they can demonstrate that their system does *not* pose a significant risk. The guidelines may clarify how to conduct this risk assessment, including:
- The use of ISO/IEC 23894 (AI risk management) or NIST AI RMF as reference frameworks.
- The role of fundamental rights impact assessments (FRIAs) in determining significance.
- The weight given to third-party certifications (e.g., CE marking under the CRA for AI-enabled products).
Yet, the guidelines are unlikely to define "significant risk" with quantitative thresholds. MSAs will retain discretion, meaning providers must build a *defensible narrative* rather than rely on a checklist.
3. **Exclusions and Edge Cases**
The guidelines may address exclusions under AI Act Article 6(4), such as:
- AI systems used for research, development, or prototyping before market placement.
- Systems that perform narrow, auxiliary functions (e.g., spam filters in email clients used by law enforcement).
- General-purpose AI (GPAI) models that are *not* integrated into high-risk use cases (though this overlaps with the AI Act’s GPAI provisions).
However, the guidelines will not resolve all edge cases. For instance, AI-enabled medical devices are already regulated under the Medical Devices Regulation (MDR), but the AI Act’s interaction with sectoral laws remains unclear. Providers will need to reconcile overlapping regimes, particularly where the AI Act imposes stricter requirements (e.g., Article 10 on data governance).
---
How Market Surveillance Authorities Will Interpret Classification Before Your Audit Is Done
MSAs are not passive observers. They are already preparing for enforcement, and their approach to classification will be shaped by three factors:
1. **Precedent from Other Digital Regulations**
MSAs will draw on their experience enforcing the Digital Services Act (DSA) and GDPR. Under the DSA, regulators have shown a willingness to interpret "illegal content" broadly, even in the absence of clear guidelines. Similarly, under the AI Act, MSAs may adopt an expansive view of high-risk systems to err on the side of caution.
For example, if an AI system is used in a sector listed in Annex III (e.g., education or vocational training, point 3), MSAs may presume it is high-risk unless the provider can demonstrate otherwise. This shifts the burden of proof onto providers, who must proactively document their classification decisions.
2. **Coordination Through the European AI Office**
The European AI Office, established under AI Act Article 64, will play a central role in harmonizing enforcement. While the Office’s guidelines are non-binding, MSAs are likely to align with its interpretations to avoid fragmentation. The Office’s first priority will be consistency in classification, meaning providers should monitor its publications closely—even before May 2026.
3. **Use of Soft Law and Sectoral Guidance**
MSAs may rely on soft law instruments, such as:
- ENISA’s AI threat landscape reports (e.g., on adversarial attacks in high-risk systems).
- EDPB’s guidelines on AI and data protection (e.g., on automated decision-making under GDPR Article 22).
- Sector-specific guidance from bodies like the European Medicines Agency (EMA) or European Banking Authority (EBA).
Providers should not wait for the Commission’s guidelines to engage with these resources. MSAs will use them to inform their assessments, and providers who ignore them risk being caught off guard.
---
The Temu Precedent: DSA Enforcement Signals AI Act Enforcement Velocity
The Digital Services Act (DSA) offers a preview of how quickly enforcement can escalate under the AI Act. In April 2024, the European Commission opened formal proceedings against Temu (a global e-commerce platform) for alleged DSA violations, including transparency failures and risk management gaps. The investigation was launched just four months after the DSA’s enforcement deadline for large platforms.
Key takeaways for AI Act compliance:
- 1Speed of Enforcement: Regulators will not wait for providers to "get it right." If your classification is unclear, MSAs may initiate proceedings immediately.
- 2Documentation as a Shield: Temu’s case hinged on its inability to provide adequate evidence of compliance. Under the AI Act, Article 11 requires providers to maintain technical documentation *before* placing a system on the market. If you cannot produce this documentation on demand, you will be vulnerable.
- 3Reputational Risk: The Temu case attracted global media attention, demonstrating that enforcement actions are not just legal risks—they are brand risks. For AI providers, misclassification could lead to customer churn, investor scrutiny, and loss of market access.
The AI Act’s enforcement machinery is designed to move just as quickly. Providers must assume that MSAs will act decisively—and that the first wave of enforcement will target low-hanging fruit: systems with ambiguous classifications or inadequate documentation.
---
Three High-Risk Scenarios Where Classification Ambiguity Becomes Enforcement Risk
Not all AI systems are equally likely to draw regulatory scrutiny. However, three scenarios are particularly vulnerable to enforcement action due to classification ambiguity:
1. **AI in Employment and Worker Management**
Annex III, point 4 lists AI systems used for recruitment, promotion, or termination as high-risk. However, ambiguity arises in:
- Internal vs. external use: Is an AI tool used *only* for internal HR processes (e.g., shift scheduling) high-risk, or only when used for hiring/firing?
- Hybrid decision-making: If an AI system *assists* human recruiters but does not make final decisions, does it still qualify as high-risk?
- Third-party providers: If a SaaS provider offers an AI-powered hiring tool to multiple clients, who is responsible for classification—the provider or the deployer?
Enforcement risk: MSAs may adopt a precautionary approach, presuming that any AI system used in employment is high-risk unless proven otherwise. Providers should document their risk assessments *now*, even if the guidelines are not yet final.
2. **AI-Enabled Medical Devices**
Annex III, point 1 includes AI systems used for medical diagnosis, prognosis, or treatment. However, the interaction with the Medical Devices Regulation (MDR) creates confusion:
- Standalone AI tools: If an AI system is not embedded in a medical device (e.g., a diagnostic app), does it fall under the AI Act, the MDR, or both?
- Software as a Medical Device (SaMD): The MDR’s definition of SaMD is broader than the AI Act’s high-risk category. Providers must reconcile the two regimes, particularly around Article 10 (data governance) and Article 13 (transparency).
Enforcement risk: MSAs may defer to **national