惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

IT之家
IT之家
L
LangChain Blog
博客园 - 聂微东
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
GbyAI
GbyAI
博客园_首页
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
酷 壳 – CoolShell
酷 壳 – CoolShell
D
Docker
V
V2EX
月光博客
月光博客
Recent Commits to openclaw:main
Recent Commits to openclaw:main
S
SegmentFault 最新的问题
雷峰网
雷峰网
Stack Overflow Blog
Stack Overflow Blog
Cyberwarzone
Cyberwarzone
P
Privacy International News Feed
Spread Privacy
Spread Privacy
Project Zero
Project Zero
腾讯CDC
Engineering at Meta
Engineering at Meta
T
Tenable Blog
aimingoo的专栏
aimingoo的专栏
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Jina AI
Jina AI
大猫的无限游戏
大猫的无限游戏
量子位
Blog — PlanetScale
Blog — PlanetScale
D
DataBreaches.Net
T
Troy Hunt's Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
美团技术团队
N
News and Events Feed by Topic
T
Tor Project blog
H
Help Net Security
www.infosecurity-magazine.com
www.infosecurity-magazine.com
Last Week in AI
Last Week in AI
S
Security Affairs
小众软件
小众软件
Scott Helme
Scott Helme
云风的 BLOG
云风的 BLOG
Apple Machine Learning Research
Apple Machine Learning Research
Vercel News
Vercel News
人人都是产品经理
人人都是产品经理
PCI Perspectives
PCI Perspectives
TaoSecurity Blog
TaoSecurity Blog
博客园 - 叶小钗
V
Visual Studio Blog
The Cloudflare Blog
Recent Announcements
Recent Announcements

Science – Silicon Republic

IBM unveils tech capable of producing chips smaller than one nanometre Good vibrations, dancing bridges and a sustainable IoT Dublin's TensorX to partner with Solstice on sovereign European AI How are mini biosensors and antibodies changing modern healthcare? Irish projects among recipients of European Research Council Grant UCD PhD student explores link tying maths and spatial skills in children If AI robots can be tricked into ‘going rogue’, what are the implications? Students behind assistive tech start-up win NovaUCD contest Tencent tests new AI agent Xiaowei on WeChat 3,900 Waymo robotaxis recalled after new software issue Ireland quadruples solar energy capacity in three-year period New Irish bill to supervise EU AI Act gets greenlit Ireland’s NIBRT, Canada’s CASTL strengthen partnership for biomanufacturing talent Maynooth expert leading group on future of computational chemistry For conservation experts, is AI a powerful tool or dangerous shortcut? Irish Manufacturing Research announces ESA Phi-Lab Open Call for 2026 Horizon Quantum to build second quantum computer in Dublin RCSI scientists develop 'first of its kind' artificial heart valve Irish Government invests €460m in new 'Rinn' research centres The CEO innovating in Ireland’s ‘controlled and cautious’ medical cannabis space Anthropic rolls out ‘Mythos-like’ AI model Claude Fable 5 Maynooth’s new pathway fellow on quantum research and its applications Huawei makes UCD pit stop to showcase latest in renewables tech Will AI ‘digital twins’ transforming heart care work for women? Research Ireland’s Barometer project set to impact engagement Dublin's Pilot Photonics bags €1m from ESA to upgrade satellite tech Past the ‘wow phase’ of robotics, delivery and safety are paramount AI changing jobs faster than companies can keep up with, finds report Kerry’s RDI Hub opens AI collaboration with Luxembourg IQM raises PIPE to $146m with Finnish pension fund backing Biochemistry expert leads University of Galway DNA research Investigating how hormones affect brain health NASA’s Webb telescope reveals black hole formed before galaxy ‘AI scientists’ are improving, but what are the fundamental limits? Ireland sees a boost in R&D activity as tax credit drives investment Neurovalens gets US FDA approval for PTSD treatment device IoT Tribe to scale X_Potential innovation with ESB partnership Maynooth PhD researcher on GIS and its many applications Huawei proposes new path for chips as Moore’s Law runs out of road France bets fresh €1bn on quantum as global race intensifies US pumps $2bn into quantum computing via CHIPS Act Trinity College Dublin student wins 2026 Mary Mulvihill Award Managing watts with bits for Ireland's solar decade IMR to lead €6.9m project to double EU remanufacturing output Gas Networks Ireland to integrate Cork waste-to-energy plant Trinity PhD student probes new biology-based mental health model As AI meets science, what is in store for the future of research? Dublin’s Ubotica teams with Novi for real-time orbital data analysis The science of time: How horology developed through the ages Irish quantum start-up Equal1 unveils RacQ data centre computer Research Ireland to invest €20m into 22 high-risk, high-reward projects Waymo trouble: 3,800 robotaxis recalled after software glitch OpenAI launching security AI initiative to compete with Claude Mythos UCD innovator awarded for medtech commercialisation work Irish student wins European category of 2026 Earth Prize Opinion: Europe can’t afford to sit on the agentic commerce sidelines Could heat-resistant corals help reefs adapt to climate change? Moonshot AI valued at $20bn after $2bn raise for Kimi creator Probing the link between inflammation and schizophrenia Kerry team takes top spot at ESA CanSat Ireland final Galway’s Orreco signs up with MLS Innovation Lab Why critical infrastructure needs critical cybersecurity €37.5m research boost for Irish agri-food, forestry, bioeconomy Bloomberg: China pauses AV permits after Baidu disruption Milestone reached in Celtic Interconnector project linking France and Ireland Ireland’s solar sector hits 1GW of energy for first time China's DeepSeek unveils long-awaited V4 AI model UL looking for ‘changemakers’ amid Research Week 2026 Can you rely on AI chatbots for medical advice? €6.9m awarded to final four National Challenge Fund winners Space-tech Mbryonics plans new production facility in Shannon Are electric vehicles about to take off for good? OpenAI to rival Google’s AlphaFold with new AI model for life sciences research Are we ready to place lab experiments in non-human hands? Irish space AI start-up Ubotica on board for NASA’s FAME Boston Scientific announces €75m R&D investment in Galway Nvidia unveils open-source quantum AI model Ising Stanford: China ‘effectively’ closes AI model performance gap to US Ireland to invest €17m in leading facilities for AI, medtech and more Cork Airport to get Ireland's largest solar carport next year Opinion: The future of insurance is AI, so why the hesitation? Anthropic reportedly mulls designing own chips amid shortage Equal1 partners with Q-Ctrl for quantum data centre deployment Meta’s Superintelligence Labs debuts first product Muse Spark Agentic commerce and purchase disputes: Did you mean to buy that? New Artemis II images give fresh look at our lunar neighbour Circuléire makes fresh call for 2026 accelerator applicants Anthropic, Google, Broadcom announce 3.5GW TPU deal What impact might Medtronic’s new lab have on Galway’s medtech ecosystem? Microsoft releases foundational AI models targeting enterprises What issues arise when code has the ability to write and review itself? A professor's journey from humble beginnings to a higher doctorate of science France buys supercomputer maker Bull in tech sovereignty push Anthropic accidentally leaks Claude Code source in npm slip The deep-tech founder using AI to address immunology challenges Research Ireland awards €4.4m to 46 enterprise-engaged projects Plans for new Irish supercomputer CASPIR move to next stage New German battery recycling plant salvages lithium and graphite Investigating 3D-printed metals for aeronautical engineering 341 innovative research projects to receive more than €36m in funds
EU AI Act – the high-risk classification guidelines explained
silicon · 2026-06-08 · via Science – Silicon Republic

Last month, the draft guidelines were published defining when an AI system qualifies as high-risk under the EU AI Act. We asked Carlo Salizzo and David Kirton of Dentons Ireland for their legal assessment.

On 19 May, the European Commission published draft guidelines defining when an AI system qualifies as ‘high-risk’ under the AI Act, triggering a substantial set of legal obligations. The guidelines are open for consultation until 23 June 2026.

We asked tech partners at Dentons Ireland, Carlo Salizzo and David Kirton, to take a deep dive into these guidelines and answer some of the key questions that organisations and start-ups are asking.

What is the significance of these guidelines within the context of the AI Act itself?

The draft guidelines are a long-awaited publication from the European Commission designed to give more clarity to businesses across the EU. Many of the most burdensome obligations under the AI Act are only triggered in respect of AI systems that are designated high-risk, so whether or not a given AI system will fall into that category is a very significant question for businesses as they prepare for compliance with the legislation.

The guidance is designed to be a supporting layer on top of the legislation itself, and specifically the triggers for the very detailed requirements that apply in respect of the supply and the use of AI systems that are considered to “pose a significant risk of harm to health and safety, or an adverse impact on fundamental rights”.

While the guidance sets out the European Commission’s approach, it is not binding on the courts and will ultimately be subject to the decisions of the Court of Justice of the EU.

What does this mean across business types, sectors and company sizes?

Realistically, every business in Europe using or selling AI is impacted by the EU AI Act. With agreement in principle between the EU institutions on a delay to the application of the rules on the two categories of high-risk AI systems until 2 December 2027 and 2 August 2028, the immediate priority for every organisation is to map out what AI is already being used for, and checking which of those use-cases is considered ‘high risk’.

It’s also important to have a process in place for evaluating newly proposed use-cases against the AI Act rules as they arise. These draft guidelines, once final, will be the critical document used to answer those questions. If a use falls into the ‘high risk’ category, the organisation has a range of specific obligations to comply with when it is carrying out the corresponding activities.

Understanding the guidelines

The guidelines set out two routes to high-risk classification – one tied to regulated products such as medical devices and machinery, the other to specific use cases across eight named sectors. How clearly do the guidelines draw the line between businesses that are affected and those that are not?

As in the Act itself, the line is structurally clear even if there may be overlaps and grey areas in practice. There are two distinct sections of the guidance, one applicable to AI systems that are themselves, or are used as safety components in, specific regulated products (under Article 6(1) of the AI Act) – such as medical devices or certain industrial machinery – and the other applicable to AI systems which are being used for purposes that are considered ‘high risk’ (under Article 6(2) of the AI Act). The section of the guidance dealing with the latter category runs to some 148 pages and is by far the most detailed of the three parts.

The guidelines are still in draft and have no confirmed adoption date. To what extent can businesses treat this as settled direction, and where does meaningful uncertainty remain?

If previous guidance is anything to go by, this document should be a strong indication as to where the final guidance will land, but it is absolutely not final. Businesses should use this document to inform the steps they take toward compliance, but on the understanding that the content will change between now and the date the requirements come into force.

The European Commission has clearly drafted these guidelines with a focus on promoting competitiveness and innovation. One example given as falling outside the high risk category is a chatbot provided by a university for admission information, partly because it does not provide personalised recommendations that could influence an admissions decision. Given the impact that such a chatbot could have on a young person’s decisions around their education, this is the kind of AI system that the Commission could well have regarded as high-risk on a more conservative view.

Of course, it is entirely possible that such a chatbot could be designed to engage with a prospective student and give personalised advice which materially influences them toward a particular course – which is where product-specific risk and compliance reviews will need to come in. The Commission’s approach overall appears to be more pro-innovation than might have been expected, and there may well be pushback from submitters as to the breadth of some of the examples falling outside the high-risk category in the Commission’s eyes.

The Commission has published practical examples of systems that do and do not qualify as high-risk. How useful are those examples for businesses operating in less obvious or emerging AI use cases?

The examples in this document seem to have been considered carefully. Naturally, there is not an example to match every possible use of AI, and the bulk of the guidance is dedicated to providing explanations and examples for ‘high risk’ use cases under Article 6(2). However, it compares favourably to guidance given in the data protection context, which due to the breadth of the regulation in that context will often hedge its examples with “Depending on the circumstances…” or similar.

The use case examples are drawn from a broad array of industries and businesses, and in most cases will be relevant by analogy across industries. For example, the scenario of a logistics company using an AI system to assign shifts, rest periods and on-call windows is considered high risk, and this may well translate to a similar application within another industry, such as healthcare or manufacturing.

Implications by business type and size

Large enterprises in sectors such as finance, insurance and logistics are likely to have multiple AI systems in scope. What does a compliance programme realistically look like for an organisation operating at that scale?

The requirements for high-risk uses of AI systems operate on a granular level. It is likely that a large organisation will be using a number of different AI systems across different functions, often with very different use cases. Each one needs to be assessed separately, so organisations of all sizes need to know what AI systems they are using, and also what purposes those AI systems are being used for.

A compliance programme generally involves some form of governance committee or steering group – with experts drawn from areas such as IT, information security, legal, privacy, operations, HR and elsewhere – reviewing each proposed new use case to identify the potential issues in each of their areas of responsibility. Once a use case has been approved, there will be a range of conditions and compliance requirements that must be put in place both under the AI Act itself as well as other laws such as data protection, employment or sector-specific rules. Businesses in regulated sectors like finance will be well acquainted with the challenges that overlapping frameworks can present.

For smaller businesses and start-ups – many of which use third-party AI tools rather than building their own – what obligations attach to them as deployers rather than providers, and how well do the guidelines address that distinction?

The obligations for providers and deployers are very distinct, with the more onerous requirements falling on the provider of an AI system (as they are ultimately the one putting the product on the market and therefore have more control over how that system is designed and trained). The guidelines themselves are focused on classification of risk rather than role, but they are very significant in terms of the restrictions that providers are likely to place on deployers as to the purposes for which AI systems are permitted to be used under the applicable terms of service.

These take on extra significance under the AI Act itself, as the deployer is required to operate an AI system within the boundaries set by the provider. If they market the product under their own trade mark, make a substantial modification, or modify the intended purpose of a non-high risk system such that it becomes high-risk (potentially by removing guardrails to redirect its purpose to a high-risk one), they are treated as the provider of such modified system.

Start-ups are known for squeezing every bit of value out of their tools, so they need to be careful to avoid straying into high-risk areas that might put them in breach of their contractual and legal obligations, and impose upon them all the obligations of being a provider.

Many businesses in retail, marketing and customer service use AI in ways that sit close to the classification boundary. How should a non-technical business owner approach the question of whether their AI tools are in scope?

For those kinds of organisations, the most likely boundary issues often arise less from customer-facing AI and more from internal workforce tools. For example, AI used to support recruitment, allocate shifts or tasks, monitor staff activity, evaluate performance, or influence promotion or termination decisions may fall within one of the AI Act’s core high-risk employment categories. By contrast, a tool used only for generic stock forecasting, customer-service drafting, or marketing content generation may be outside the high-risk regime, although other AI Act and data protection obligations may still apply.

A non-technical business owner should not try to answer the question at the level of the technology alone. The key questions are: what is the tool actually being used for, whose decisions does it influence, does it assess or profile individuals, and is it being used in a sensitive area? If the business has started to map its AI tools and has a proportionate governance and review process for new use cases, it is on the right track.

Business owners should use the period before the high-risk rules apply to take advice, put in place policies, train staff and make sure that high-risk uses are escalated before deployment. That work should sit alongside compliance with the parts of the AI Act already in force, including AI literacy. Where there is any doubt it is often best to take a cautious approach and prepare for compliance from the outset, rather than running the risk of needing to reverse-engineer a compliance programme after something has gone wrong.

Where an AI system is supplied by a large technology platform and used by thousands of smaller businesses, who carries the compliance burden – the platform or the customer?

Both. The platform is likely to be a provider and the customer a deployer in that scenario, but it’s possible that by putting its own brand on the product or making changes to it that the deployer becomes a provider in its own right. In any case, while the obligations on the provider are heavier and more product-specific, the deployer still needs to closely track which high-risk use cases its AI systems are being utilised for and comply with a range of obligations for each one.

Key legal tests

Classification turns substantially on a system’s stated intended purpose. What are the risks for businesses whose documentation has not kept pace with how their AI tools are actually being used?

Risks are significant – including the potential for fines once the Irish and EU regulatory enforcement model is implemented in full. This is another situation where a deployer needs to be very careful that it does not inadvertently trigger obligations as a provider, due to a well-meaning project modifying an AI tool in a way which crosses the line into ‘high risk’.

For providers, it is very important to not only state clearly what the intended purposes of an AI system are, but also to implement additional protections to prevent it from being misused. Otherwise, the guidance indicates that there will be a presumption that it may be used for feasible and reasonably foreseeable high-risk purposes. This is a very significant part of the guidance, and we can expect to see submissions as to how much effort the provider needs to put into warding deployers away from unsupported uses.

For most businesses, the most likely area where high-risk AI will be used (whether intentionally or inadvertently) is using AI in the context of employee relations, performance reviews or other employee-management tasks. Staff with responsibility for those functions should be extra vigilant that their use of AI remains within appropriate boundaries.

The guidelines confirm that the presence of a human reviewer does not, on its own, remove a system from the high-risk category. How significant a change is that for businesses that have structured their AI use around human sign-off?

Having a human sign-off is regularly cited as a shortcut to avoiding compliance with AI rules.  While a ‘human in the loop’ is a sensible (and required) way to manage the risk posed by high-risk AI systems, it is not a ‘silver bullet’ to avoid regulation under the AI Act or indeed other legislation such as the GDPR. The draft guidelines confirm this, noting that human involvement cannot change the purpose and area in which a system is intended to be used. Rather, oversight by a human with appropriate competence and resources is one of several conditions for compliance.

That said, if a system is genuinely designed to perform a ‘narrow procedural task’ or is preparatory in nature, or is designed to improve a previously completed activity, then it will fall outside the scope of the high risk requirements.

There is a narrow exemption for AI that does not materially influence decision-making. In practice, which types of business use cases are most likely to qualify – and which will find that argument hard to sustain?

An AI system may fall within an Annex III area but escape high-risk classification if it performs a narrow procedural task, improves a completed human activity, detects decision-pattern deviations with proper human review, or merely performs a preparatory task.

This so-called ‘filter’ is designed to account for AI being used within the scope of high-risk activities, but in such a limited way that, in practice, the risk posed by that system is low.

This filter only applies in respect of the Article 6(2)/Annex III purposes rather than already-regulated products in Annex I, so if an AI system is a regulated product (eg a medical device) or a safety component for one, this potential ‘get out’ is not available.

It also cannot be used when the AI system performs profiling of individuals. This might involve performing sorting or formatting functions in relation to data rather than classifying it or profiling the people it relates to. Administrative tasks like scanning handwritten documents onto a filing system and converting legacy files into a new format are also likely to be captured by the filter. There are helpful examples given at section 2.7 onward in the draft guidance.

On the other hand, if an AI system is being used to make assessments or recommendations to a human who is expected to ‘sign off’ on them, or who is too busy or inexperienced to critically exercise their own judgement, this is unlikely to be caught by the filter and will pass through to be considered a high-risk use case if it meets the criteria.

Compliance and next steps

High-risk systems require risk management processes, technical documentation, human oversight controls and in some cases registration or notification requirements. Which of those requirements is likely to be the most demanding for businesses without dedicated legal or technical teams?

While there are challenges in each aspect of compliance with new rules, putting in place risk management processes is likely to be the most complex obligation. The reason for that is because it is not a paint-by-numbers exercise: the identification of risks and the implementation of appropriate mitigation measures is a challenge very familiar to regulated businesses today.

Start-ups and small businesses which find themselves regulated as providers of AI systems will need to ensure that not only do they have their own internal measures in place, but that their products and documentation are designed in such a way that their customers are also confident in their own compliance position.

For businesses already running AI systems that may now fall into the high-risk category – in recruitment, credit assessment or customer triage, for example – what are the immediate practical steps, and is there any grace period?

For all businesses using AI, the immediate practical steps are to take advice on setting up an appropriate governance process and structure for reviewing existing and future AI systems and use cases to make sure that they are used in compliance with the AI Act and other applicable laws like the GDPR.

Under the AI Act, there are three relevant effective dates (based on the amendments in the provisionally agreed AI Omnibus):

For AI systems that are themselves, or that are safety components of, certain specified regulated products, the high risk rules apply from 2 August 2028.

For AI systems that otherwise fall into the high-risk categories within Annex III of the AI Act (including HR functions like recruitment, performance evaluation or workplace monitoring), the high risk rules apply from 2 December 2027.

For systems that are already on the market or in service as of 2 August 2026, there is an extension of time and the high-risk rules will only apply if and when the AI system is subject to significant changes in its design, unless intended for use by public authorities.

Otherwise, certain specific large-scale IT systems must comply by 31 December 2030, high-risk AI systems intended for use by public authorities must comply by 2 August 2030, and general-purpose AI models placed on the market before 2 August 2025 must comply by 2 August 2027.

Non-EU businesses selling AI systems in Europe are caught by the regulation. What does the guidance mean for a technology company headquartered outside the EU with a significant European customer base?

First and foremost, those companies need to ensure that they are up to date on the other compliance obligations under the legislation, such as appointing an EU Authorised Representative where required.

The guidance itself applies equally to non-EU businesses, as it regulates the products as they arrive on the market: if a business is using an AI system or its outputs on the EU market, then the legislation applies. Those providers should be prepared to engage with European customers about whether their products are intended for use in high-risk areas, as part of their overall projects to produce compliant product documentation.

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.