High Risk: Turning Fifteen Months into Proof of Compliance

Partager

As of September 1, 2026, the institutional sources consulted still refer to the classification guidelines as a draft. A final publication on August 31 could not be verified. The fifteen months leading up to December 2, 2027, are intended to establish the evidence.

The Essentials in 30 Seconds

  • Article 6(1): Annex I.
  • Article 6(2): Annex III.
  • Profiling: still high risk.
  • Annex III: December 2, 2027.

What Happened

The Commission’s consultation announced final adoption by the end of 2026, and the AI Act platform describes the available documents as “draft Guidelines.” They serve as practical guidance, not a binding standard: the regulation remains mandatory. The version consulted, its date, and the reasoning used must be retained in the file.

The draft guidelines address a practical challenge: translating the categories in the regulation into reproducible decisions. They help organize the reasoning but do not replace either Article 6 or the annexes. An organization must therefore cite the applicable text before relying on an administrative explanation.

The targeted consultation was intended to gather comments on this interpretation. Its extension until July 23 indicates that the document was still in the discussion phase. As of September 1, a prudent team must therefore specify the version consulted rather than presenting the draft as definitive guidance.

The fifteen months available do not constitute a period of inactivity. They provide a timeframe for compiling a dossier capable of explaining a classification and then demonstrating that the chosen measures correspond to the system actually in operation. This work is more robust when it begins before the guidelines are finalized.

The Analysis

Article 6 provides two pathways: security products or components listed in Annex I subject to a third-party assessment, with a deadline of August 2, 2028, and systems listed in Annex III. An exception under Annex III requires the absence of significant risk and material impact; narrow or preparatory procedural tasks are listed. The profiling of natural persons remains a high-risk activity.

The Annex I pathway depends on both the product in question and the security function assigned to the system. The Annex III pathway is assessed based on the domain and purpose of use. The two approaches are not interchangeable. The documentation must clearly indicate which approach was followed.

The exception provided for certain cases under Annex III requires a positive justification. It is not sufficient to state that the system supports a decision. It must be explained why its result does not create a significant risk or materially influence the outcome for the individual concerned.

Profiling constitutes a specific threshold. When it is applied to individuals within the relevant scope, the possibility of invoking the exception is ruled out. This rule must be brought to the attention of business teams, who may use this term in a broader sense than the regulation intends.

Operational Impact

For each system, the decision must be linked to a specific purpose, an identifiable version, a legal role, the individuals likely to be affected, and the deployment context. An up-to-date inventory, controlled user instructions, and a clear assignment of responsibilities are the prerequisites for demonstrable compliance. Management must be able to distinguish between directly applicable obligations, deferred deadlines, and tasks that remain relevant in all cases. This discipline facilitates responses to regulatory authorities, contract management, and coordination with business teams.

A compelling record links the system to its environment. It specifies the version used, relevant data or inputs, the person who acts on the result, and the decision that was influenced. Without this link, a high-risk analysis risks remaining theoretical and failing to reflect actual usage.

Governance must include a trigger for review. A new feature, expansion to a new audience, or a change to the supported decision may alter the classification. The person in charge should not have to rely on an informal alert to reopen the case.

The timeline should be broken down into short milestones: creating the registry, gathering evidence, legal review, testing measures, and management approval. This phased approach makes discrepancies visible early enough to correct them. It prevents evidence from being concentrated as the deadline approaches.

What to Do Now

  • Map — identify the system, version, purpose, and legal role.
  • Document — preserve the reasoning and evidence.
  • Plan — assign a lead person, deadline, and review.
  • Verify — reconcile contracts, instructions, and technical measures.

Create a qualification sheet for each system. It must distinguish between observed facts, assumptions, and conclusions. This separation helps reviewers understand what needs to be updated when a supplier or use case changes.

Schedule a cross-check review for systems that fall close to a category in Annex III. A person familiar with the business process and a person responsible for the regulatory framework can jointly test the reasoning. Any disagreement must be documented, along with the decision ultimately adopted.

Use the draft guidelines as a reference tool, without citing them as a mandatory rule. Comparing the internal file against the classification questions helps identify missing information. The conclusion, however, must remain grounded in the regulations.

Measure progress by the quality of the files, not solely by the number of systems identified. A system that is well described but awaiting analysis may be a priority. This approach helps management allocate resources where the classification decision remains uncertain. Monthly follow-ups ensure that the required evidence is actually collected and reviewed.

Sources


Lire la suite