惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

GbyAI
GbyAI
Y
Y Combinator Blog
F
Fortinet All Blogs
H
Hackread – Cybersecurity News, Data Breaches, AI and More
N
Netflix TechBlog - Medium
T
Tailwind CSS Blog
aimingoo的专栏
aimingoo的专栏
博客园 - Franky
T
The Blog of Author Tim Ferriss
D
DataBreaches.Net
量子位
博客园 - 三生石上(FineUI控件)
I
InfoQ
Engineering at Meta
Engineering at Meta
WordPress大学
WordPress大学
阮一峰的网络日志
阮一峰的网络日志
爱范儿
爱范儿
D
Docker
美团技术团队
雷峰网
雷峰网
U
Unit 42
Stack Overflow Blog
Stack Overflow Blog
Recent Announcements
Recent Announcements
人人都是产品经理
人人都是产品经理

Privacy & Cybersecurity Law Blog

EU Cyber Resilience Act Reporting Obligations Take Effect for Manufacturers Delaware Expands State Privacy Law Dutch DPA Fines Uber Over Automated Decisions Affecting Drivers European Commission Designates ChatGPT, Reddit, and Roblox Under the Digital Services Act China Issues New Rules on Cyberspace Security Inspection Court Approves Meta Settlement With 29 States Over Alleged Harms to Children and Teens FTC Proposes Enforcement Policy Statement on Personalized Pricing New Jersey Enacts the Kids Code Act with Privacy-by-Default and Safety-by-Design Obligations White House Memorandum Establishes Framework for Government-Directed Private-Sector Cyber Operations FTC, California and Utah Sue Telehealth Company Hims & Hers for Deceptive and Unlawful Privacy Practices CalPrivacy Settles with Two Data Brokers over Registration Failures and Privacy Violations New York Attorney General Releases Final Rules for SAFE for Kids Act EDPB Adopts Guidelines on Anonymous Data, Web Scraping, and Blockchain China Publishes Official Q&A on Administrative Policies for Cross-Border Data Transfers Hawaii Enacts AI Companion Disclosure and Safety Law EDPB Calls for Review of EU-U.S. Data Privacy Framework After U.S. Supreme Court Decision on FTC Independence CNIL Issues FAQs on Recommendation for Tracking Pixels in Emails European Commission Issues Guidance on the Cyber Resilience Act European Commission Issues EU AI Act Transparency Guidelines EU Digital Omnibus on AI Enters Into Force Connecticut AG Leads Multistate Settlement With 23andMe Over 2023 Data Breach CalPrivacy Targets Gig Economy Tech Platforms in First CCPA Compliance Audit New Jersey Adopts New Data Broker Registration Regime and Sensitive Data Sale and Licensing Restrictions CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026 Illinois Governor Signs Frontier AI Model Law New Hampshire Amends the NHDPA to Prohibit the Sale of Children’s Personal Data Canada’s Proposed Social Media Ban for Children and Chatbot Regulation: Bill C-34’s Impact on Platforms European Commission Unveils Cybersecurity and AI Action Plan European Commission Refers Four Member States to CJEU Over NIS2 Transposition Delays EDPB Opens Public Consultation on New Personal Data Breach Notification Template
European Commission Releases Draft Guidelines on High-Ris...
2026-05-20 · via Privacy & Cybersecurity Law Blog

European Commission Releases Draft Guidelines on High-Risk AI Under the EU AI Act

On May 19, 2026, the European Commission published draft guidelines on the classification of high-risk artificial intelligence (“AI”) systems under the EU Artificial Intelligence Act (the “EU AI Act”) and launched a public consultation open until June 23, 2026. The draft guidelines, which have been issued under Article 6(5) of the EU AI Act, are intended to assist providers, deployers and market surveillance authorities in determining whether an AI system falls within a high-risk category under Article 6 of the EU AI Act.

The EU AI Act, which entered into force on August 1, 2024, adopts a risk-based framework for AI systems used in the EU. Within that framework, high-risk AI systems are subject to a detailed set of requirements and obligations designed to address risks to health, safety and fundamental rights. The European Commission’s draft guidelines are aimed at supporting a more consistent interpretation of the high-risk classification rules and facilitating the application and enforcement of Article 6.

The draft guidelines are structured in three parts:

  • Section 1: This section sets out the general principles for determining whether an AI system should be classified as high-risk and introduces the two categories of high-risk AI systems under Article 6 of the EU AI Act.
  • Section 2: This section addresses classification under Article 6(1) and Annex I of the EU AI Act, covering AI systems that are safety components of products, or are themselves products, subject to specified EU product safety legislation.
  • Section 3: This section addresses classification under Article 6(2) and Annex III of the EU AI Act, covering certain stand-alone AI systems used in areas identified by the AI Act as presenting significant risk, including biometrics, education, employment, essential services and law enforcement.

The draft guidelines provide non-exhaustive examples of AI systems that may or may not be classified as high-risk, while making clear that inclusion of a use case does not by itself establish its lawfulness under applicable law.

The publication follows a delay from the European Commission’s original timetable. Guidance on high-risk classification had initially been expected by February 2, 2026, ahead of the EU AI Act’s original compliance milestones for high-risk systems. The absence of final guidance, together with delays in the development of standards and other implementation tools, became a central issue in broader discussions on the operational readiness of the EU AI Act. Those concerns contributed to the recent Digital Omnibus on AI, which revised the implementation schedule for certain high-risk AI obligations. Under the updated timetable, requirements for stand-alone high-risk AI systems are now due to apply from December 2, 2027, while obligations for high-risk AI systems embedded in products will apply from August 2, 2028. The revised deadlines were intended to provide additional time for the development of guidance, specifications and standards, and to give organizations greater legal certainty as they prepare for compliance.

The current draft guidelines will be subject to further consultation before the European Commission adopts a final version. The European Commission also emphasizes that the guidelines are not legally binding and that authoritative interpretation of the EU AI Act ultimately rests with the Court of Justice of the European Union.

Read the draft guidelines here.