February 2026: Commission Publishes Article 6 Implementation Guidelines
The long-awaited guidelines on high-risk AI classification are here. Practical examples, the filter exception, and what your risk assessment must now include.
Clarity at Last
February 2, 2026 brought a milestone for AI Act implementation: the European Commission published detailed guidelines specifying the practical implementation of Article 6—the rules for classifying AI systems as high-risk.
What Article 6 Covers
Article 6 is the classification gateway. It determines whether your AI system falls under the heavy compliance burden of high-risk rules or escapes with lighter obligations. The new guidelines provide detailed flowcharts for classification decisions, over 50 practical examples of high-risk vs. non-high-risk systems, sector-specific guidance for healthcare, finance, HR, and education, and clarification of the "filter exception" under Article 6(3).
The Filter Exception Explained
One of the most significant clarifications concerns Article 6(3)—when an AI system listed in Annex III is not actually high-risk. The guidelines confirm three scenarios:
- Narrow Procedural Task: The AI performs a single, limited procedural step that doesn't independently determine outcomes
- Improvement, Not Decision: The AI improves a previously completed human activity without replacing human judgment
- Pattern Detection: The AI detects decision patterns without substituting for or influencing actual decision-making
Warning: Using this exception requires documented assessment. The burden of proof is on you.
Key Examples from the Guidelines
| Use Case | Classification | Reasoning |
|---|---|---|
| AI scheduling job interviews | Not High-Risk | Narrow procedural task only |
| AI ranking job candidates | High-Risk | Materially influences hiring decisions |
| Spell-checker in education | Not High-Risk | Does not evaluate students |
| AI grading student essays | High-Risk | Determines educational outcomes |
| Fraud detection flagging for review | Context-dependent | Depends on human oversight design |
Post-Market Monitoring Plans
The guidelines also specify requirements for post-market monitoring plans: continuous performance monitoring against documented metrics, feedback collection mechanisms from deployers, incident detection and reporting procedures, regular risk reassessment schedules, and update and correction protocols.
Action Items
Review your AI inventory against the new guidelines immediately. Many organizations will find their classification assumptions need updating.