Breaking News 7 min read

February 2026: Commission Publishes Article 6 Implementation Guidelines

The long-awaited guidelines on high-risk AI classification are here. Practical examples, the filter exception, and what your risk assessment must now include.

By Elena Rossi, Legal Tech Analyst · Published

Clarity at Last

February 2, 2026 brought a milestone for AI Act implementation: the European Commission published detailed guidelines specifying the practical implementation of Article 6—the rules for classifying AI systems as high-risk.

What Article 6 Covers

Article 6 is the classification gateway. It determines whether your AI system falls under the heavy compliance burden of high-risk rules or escapes with lighter obligations. The new guidelines provide detailed flowcharts for classification decisions, over 50 practical examples of high-risk vs. non-high-risk systems, sector-specific guidance for healthcare, finance, HR, and education, and clarification of the "filter exception" under Article 6(3).

The Filter Exception Explained

One of the most significant clarifications concerns Article 6(3)—when an AI system listed in Annex III is not actually high-risk. The guidelines confirm three scenarios:

  1. Narrow Procedural Task: The AI performs a single, limited procedural step that doesn't independently determine outcomes
  2. Improvement, Not Decision: The AI improves a previously completed human activity without replacing human judgment
  3. Pattern Detection: The AI detects decision patterns without substituting for or influencing actual decision-making

Warning: Using this exception requires documented assessment. The burden of proof is on you.

Key Examples from the Guidelines

Use CaseClassificationReasoning
AI scheduling job interviewsNot High-RiskNarrow procedural task only
AI ranking job candidatesHigh-RiskMaterially influences hiring decisions
Spell-checker in educationNot High-RiskDoes not evaluate students
AI grading student essaysHigh-RiskDetermines educational outcomes
Fraud detection flagging for reviewContext-dependentDepends on human oversight design

Post-Market Monitoring Plans

The guidelines also specify requirements for post-market monitoring plans: continuous performance monitoring against documented metrics, feedback collection mechanisms from deployers, incident detection and reporting procedures, regular risk reassessment schedules, and update and correction protocols.

Action Items

Review your AI inventory against the new guidelines immediately. Many organizations will find their classification assumptions need updating.