Still Draft, Still Late, and the Draft Says Human-in-the-Loop Does Not Save You
Not legal advice. This is a source-status and text-reading pass by a non-lawyer agent. It reports what has and has not been published, and what a non-binding draft says, not what any of it means for a particular product.
The question
"Has the Commission issued its Article 6 classification guidelines, and what do they say about borderline high-risk classification, given Article 6(5) was carved OUT of the AI Act deferral and has applied since 2 August 2026?"
Derivative follow-up from [[2026-08-21-ai-act-article-113-operative-text-check]], raised again as the highest-value remaining item in [[2026-08-23-ai-act-annex-iii-employment-entries]] once that pass confirmed by literal diff that Annex III and the Article 6(3) filter are both frozen. With the statutory text unable to move, the guidelines are the only instrument left that can shift where the practical employment-context line falls.
Answer, up front.
| Sub-question | Answer | Evidence tier |
|---|---|---|
| Have the Article 6(5) guidelines been issued? | No. As of 26 August 2026 there is no final version. What exists is a draft published 19 May 2026 for consultation | VERIFIED-FROM-PRIMARY (Commission page + PDF cover state) |
| Is the statutory deadline still 2 February 2026? | Yes, unamended. Missed by roughly six and a half months and counting | VERIFIED-FROM-PRIMARY (original text; no amendment point touches Article 6(5)) |
| Did the Omnibus reset the deadline? | No. It set a new guidelines deadline of 1 August 2027 for a different, Annex-I-side instrument, and left Article 6(5) alone | VERIFIED-FROM-PRIMARY (Regulation (EU) 2026/1744, Article 1 point (36)) |
| What does the draft say about borderline cases? | Narrow construction of the filter, human involvement expressly insufficient, agentic multi-component systems assessed as a whole, employment personal scope stretched to freelancers and platform workers | VERIFIED-FROM-PRIMARY as to what the draft says; the draft itself is non-binding and unadopted |
What we already know (from the vault)
- The carve-out is real and enacting-text verified. [[2026-08-21-ai-act-article-113-operative-text-check]] read the words "with the exception of Article 6(5)" out of the authentic Official Journal text of amended Article 113, third paragraph, point (c). Article 6(5) is not deferred to 2 December 2027 and falls back to the general 2 August 2026 date.
- The statutory boundary is frozen. [[2026-08-23-ai-act-annex-iii-employment-entries]] confirmed by amendment-marker attribution and literal diff that Annex III point 4 and the whole of Article 6(2) to 6(8) are unamended original text. Nothing in the [[2026-08-15-eu-digital-omnibus-ai-official-journal-check]] touched the employment list or the four-condition filter.
- The vault's current read of the filter is favourable to RDCO, and this pass partly undercuts it. That same brief concluded that "the architecture RDCO already sells - human owner, agent recommends, human decides, decision logged - is the architecture the derogation was written to accommodate." The draft guidelines say something materially narrower. See Convergences below.
- The positioning that hangs on this is the accountability vocabulary. [[2026-08-02-agents-as-employees-regulatory-labor-framing]] recommended "AI workforce" as entry term only, with "one accountable operator" and "every action attributable" carrying the substance. [[2026-06-07-ai-workforce-positioning-map]] describes the RDCO shape as one durable accountable generalist agent rather than a fleet of narrow ones.
- The fetch route was already solved. Curl to disk and grep locally, established on the 2026-08-21 run. Reused here, with one adaptation noted in the method box.
What the web says
Method and status of sources. European Union law text was retrieved from the Cellar content-negotiation endpoint at publications.europa.eu/resource/celex/<CELEX> with Accept: application/xhtml+xml, because the EUR-Lex web front end now returns an Amazon Web Services web-application-firewall challenge to curl (HTTP 202, JavaScript challenge page, zero content). Cellar is the same authoritative store EUR-Lex renders from and returned byte counts matching the prior run's documents. Three primary documents plus three Commission draft PDFs were read locally. No paywalls encountered.
- No final Article 6(5) guidelines exist as of 26 August 2026. The Commission library entry is titled "Draft Commission guidelines on the classification of high-risk AI systems," publication date 19 May 2026, last update 23 July 2026, and it links to a targeted stakeholder consultation rather than an adopted act (digital-strategy.ec.europa.eu). The three downloadable documents carry the unadopted-document placeholder on their cover pages - "Brussels, XXX / … XXX draft" - and a running header reading "for stakeholder consultation." VERIFIED-FROM-PRIMARY.
- The Commission's own publication stream shows nothing since. The digital-strategy library listing, checked 26 August 2026, runs through 13 August 2026 with no adopted Article 6 classification guidelines. It does show a "Policy and legislation" item dated 20 July 2026: Guidelines on transparency obligations for providers and deployers of AI systems, the Article 50 instrument. The guidelines pipeline is moving; this particular instrument is not the one moving. VERIFIED-FROM-PRIMARY (Commission site listing).
- The three draft documents, for the record. General principles (6 pages), Annex I product-side classification (13 pages), and Annex III use-case classification (148 pages, 368 references to Annex III, 211 worked examples). The Annex III document is where all the borderline reasoning lives.
- The statutory duty and its deadline are verbatim and untouched. Article 6(5) of Regulation (EU) 2024/1689 reads: "The Commission shall, after consulting the European Artificial Intelligence Board (the 'Board'), and no later than 2 February 2026, provide guidelines specifying the practical implementation of this Article in line with Article 96 together with a comprehensive list of practical examples of use cases of AI systems that are high-risk and not high-risk." No amendment point in Regulation (EU) 2026/1744 touches Article 6(5). VERIFIED-FROM-PRIMARY.
- A new guidelines deadline was legislated in July 2026, and it is not this one. Article 1 point (36) of the Omnibus amends Article 96(1): it replaces point (a) to extend the compliance-guidance duty to Article 26 as well as Articles 8 to 15 and 25, adds a new point (g) covering "the practical implementation of Article 8(2), Article 9(10) and Article 17(3)" for Annex I operators with the clause "such guidelines shall be published by 1 August 2027," and replaces the second subparagraph to require that "the Commission shall involve the Board" when issuing guidelines. Recital text confirms point (g) is aimed at economic operators of Annex I high-risk systems. The legislator set a fresh 2027 deadline for the product-side guidance while leaving the already-blown Article 6(5) deadline without extension, replacement, or acknowledgement. VERIFIED-FROM-PRIMARY.
- Correction to a widely repeated secondary gloss. Search summaries and at least one law-firm-adjacent framing state that "by 1 August 2027 the Commission must publish guidelines on the classification of high-risk AI systems under Article 6." That is wrong on the text. The 1 August 2027 date attaches only to new Article 96(1)(g), which covers Articles 8(2), 9(10) and 17(3) complementarity for Annex I. There is no new deadline for Article 6 classification guidelines at all. VERIFIED-FROM-PRIMARY against both the enacting point and the recital.
- A textual oddity that predates the Omnibus. Original Article 113 applied the Regulation generally from 2 August 2026, with only Chapters I and II, a 2025 tranche, and Article 6(1) carved to other dates. Article 6(5) therefore applied from 2 August 2026 while carrying an internal deadline of 2 February 2026 - a duty whose deadline fell six months before the provision containing it became applicable. The Omnibus carve-out preserves that shape rather than creating it. VERIFIED-FROM-PRIMARY.
What the draft says about borderline classification
Everything in this subsection is what a non-binding, unadopted draft says. It is the Commission's current interpretive direction, not law, and the draft itself notes that authoritative interpretation belongs to the Court of Justice.
- The filter is to be read narrowly, and there is no residual risk test. Draft paragraph 88: the four Article 6(3) conditions are "exhaustive, but alternative," there is "no separate or independent assessment to determine whether the AI system poses a significant or any risk of harm besides those conditions," and "as Article 6(3) represents an exception from rules aimed at (among others) protecting fundamental rights, the conditions must be interpreted narrowly." This cuts both ways: no extra hurdle beyond the four gates, but each gate construed tightly and read in light of the "materially influence the outcome" chapeau.
- Human involvement does not change classification, and cannot be bolted on to escape it. Draft paragraph 70: for Article 6(2) "the only relevant determinant is whether the intended purpose of the system includes one of the use cases listed in Annex III," and human oversight is a compliance requirement under Article 14, not a classification input. Paragraph 71 is blunter: "The provider cannot exempt and categorise an AI system as 'low risk' simply by adding to it a requirement for human involvement." Human involvement is relevant only as evidence that the task the system performs is itself narrow, preparatory, or improvement-of-a-completed-human-activity.
- Agentic multi-component architectures are named and assessed as a whole. Draft paragraph 75: where several systems combine so that "their combined intended purpose or joint outputs materially influence an individual decision, the combined configuration is treated as a single AI system," split architectures are assessed as a whole "to avoid circumvention," module-level Article 6(3) exemptions "do not apply if the overall system's configuration and functioning influence key aspects of the decisions," and the principle "extends to complex, interconnected setups like agentic AI systems that coordinate and interact through linked actions as long as these linked actions or components serve in conjunction an intended high-risk purpose." Paragraph 90 repeats it as a filter override. Paragraph 76 preserves an exit: strictly procedural or preparatory functions stay exempt "where they are genuinely separable" and do not structure or feed the high-risk outputs.
- Narrow procedural task stops at the value judgement. Draft paragraphs 92 to 93: reformatting, restructuring, changing metadata, and predefined categorisation qualify; but systems that "perform a value judgement of data relevant for decision-making, for example categorisation of input data as 'useful' or 'less useful' for the human assessment, or attributing a score or ranking to input data" do not.
- "Decisions" in point 4(b) is functional, and reliance is enough. Draft paragraph 258: a decision is "any act or omission attributable to the employer that produces material effects on the worker's contractual position," and "intended to be used to make decisions" covers "both cases where the AI system takes the decision in an automated manner and cases where a human operator formally takes a decision, but significantly relies on the output of the AI system." Counterweight in paragraph 262: the decision must "reach a threshold of significance," and day-to-day operational calls that do not alter contractual rights - allocating office space, break timing inside an assigned shift - fall outside.
- The employment personal scope is stretched well past employees. Draft paragraphs 239 to 241: "work-related contractual relationships" is read past formal employment contracts, "workers' management" expressly covers recruitment, work allocation, monitoring, evaluation, promotion, remuneration and termination, and "freelancers, independent professionals, service providers, and platform workers regardless of contractual status fall within the personal scope of the use cases listed in point 4 of Annex III wherever AI systems mediate or condition their access to work opportunities."
- Profiling is narrowed slightly by a three-element test. Draft paragraphs 109 to 112: the Article 4(4) General Data Protection Regulation definition supplies three cumulative elements, automated processing is "always fulfilled" for an AI system, so the live questions are whether personal data is an input and whether the objective is evaluating personal aspects. Evaluation "must always include a form of prediction, assessment or judgement"; simple classification by age, sex or height "does not necessarily lead to profiling."
- The worked examples are the actually useful artefact. Out of scope for point 4(a): discriminatory-wording screeners for job ad copy, employer-brand advertising not tied to a vacancy, anonymised employer-reputation monitoring, post-hire onboarding question answering, and candidate-side tools (curriculum vitae tailoring, job matching) because their "use is initiated and managed by the candidate, outside of the potential employer's control." Filter-exempt but in scope: binary credential verification against official registries, curriculum vitae parsing into a searchable internal database, interview scheduling. Out of scope for point 4(b): parcel-route deviation detection where "the monitoring activity is incidental," voluntary training feedback that feeds nothing, desk booking, corporate travel optimisation, and non-binding demand-area suggestions to platform couriers provided there are "no penalties for declining recommendations, no specific registry of couriers that accepted or rejected the recommendation, and the system does not reduce their access to future tasks."
Convergences and contradictions
- Convergence on status, and it is a clean negative. The carve-out did what the parent brief said it did: Article 6(5) has been live since 2 August 2026. What the parent brief hypothesised - an interpretive layer arriving roughly sixteen months ahead of the enforcement layer - is only half true. The interpretive layer is in draft, is nearly seven months past its own statutory deadline, and has been sitting untouched on the Commission site since 23 July 2026. The asymmetry is real but it runs the other way from the optimistic reading: the duty is live and unperformed, and the remedy for non-performance is nothing.
- Direct tension with the vault's current filter read, and this is the finding that matters. [[2026-08-23-ai-act-annex-iii-employment-entries]] concluded that the human-owner-decides architecture "is the architecture the derogation was written to accommodate." Draft paragraph 71 says human involvement alone cannot exempt, and draft paragraph 258 says a human who formally decides but "significantly relies on the output" is still inside point 4(b). Both statements sit in a non-binding draft, so the vault claim is not wrong on the statute - the statute is silent and the statute is what binds. But the Commission's stated interpretive direction is narrower than the vault's read, and the vault's read should be softened from "the derogation was written to accommodate this" to "the derogation may accommodate this if the task itself is narrow, and the Commission's draft says the human is not what does the work."
- A second tension, on architecture rather than oversight. The RDCO shape described in [[2026-06-07-ai-workforce-positioning-map]] - one durable generalist agent coordinating many linked actions - is close to the exact configuration draft paragraph 75 names. The draft treats coordinated agentic components as a single system for classification and refuses module-level exemptions where the ensemble influences the decision. An architecture that is a positioning asset in the market is a classification liability under this draft, if and only if the ensemble is aimed at an Annex III purpose.
- Contradiction with secondary coverage, resolved against it. The "1 August 2027 for Article 6 classification guidelines" claim circulating in summaries is not in the text. Anyone planning against it is planning against a deadline that does not exist.
Synthesis for RDCO
The status answer is a negative and it should be stated flatly: as of 26 August 2026 the Commission has not issued its Article 6 classification guidelines. It has issued a draft, on 19 May 2026, for a consultation that closed on 23 June 2026, and that draft has not moved since 23 July 2026. Anyone who says "the Commission's high-risk classification guidelines say X" is quoting an unadopted document. That is a small, checkable, date-stamped piece of expertise of exactly the kind the earlier briefs in this thread identified as cheap credibility, and it will stay true and stay uncommon for as long as the final version sits unpublished. The more interesting structural fact is the one the amending regulation reveals by contrast: in July 2026 the legislator wrote a brand-new guidelines deadline of 1 August 2027 into Article 96(1)(g) for the Annex I product side, and said nothing whatsoever about the Article 6(5) deadline it had already missed. That is not an oversight in drafting. It is a legislature declining to re-commit on a duty it is in breach of, and the practical consequence is that the classification guidelines now have no deadline at all - only the 2 December 2027 date when the obligations they explain start biting, which is roughly fifteen months out.
The substantive finding cuts against RDCO's current comfort, and it should be absorbed rather than argued with. The 2026-08-23 brief banked the Article 6(3) filter as a positioning asset on the reasoning that human-owner-decides is the architecture the derogation accommodates. The draft guidelines say the opposite twice, in plain words. Paragraph 71: a provider "cannot exempt and categorise an AI system as 'low risk' simply by adding to it a requirement for human involvement." Paragraph 258: a human who formally decides but "significantly relies on the output of the AI system" is inside point 4(b) anyway. The load-bearing question under this draft is not who signs but what the system does - whether the task is narrow, procedural, preparatory, or an improvement on completed human work, and whether the output carries a value judgement, a score, or a ranking. The moment an agent ranks candidates, scores performance, or produces a recommendation a manager leans on, the accountable-operator story is a governance story and a trust story, but it is not a classification story. That distinction is worth getting right before it appears in a deck, because the failure mode is discovering it in a client's procurement review rather than in a research brief.
The third finding is the one nobody would have gone looking for: the draft names agentic systems specifically. Paragraph 75 treats coordinated multi-component setups as a single system for classification purposes, refuses to honour module-level Article 6(3) exemptions where the ensemble influences key aspects of the decision, and explicitly extends the anti-circumvention principle to "complex, interconnected setups like agentic AI systems that coordinate and interact through linked actions." The RDCO shape - one durable generalist agent driving many linked skills - is a near-exact description of the thing that paragraph is aimed at. The escape in paragraph 76 is real but narrow: strictly procedural or preparatory components remain exempt where they are "genuinely separable" and do not structure or feed the outputs. Practically, that means the architectural boundary RDCO would need to be able to draw is a separability boundary, not a human sign-off boundary. If an EU-facing engagement ever touches worker-related decisions, the design question is which components can be shown to be genuinely detachable from the decision path, and that is a question better answered while building than while explaining.
Where this leaves the thread. Four passes in, the compliance surface is fully mapped and the answer has been consistently "RDCO is outside Annex III unless a specific client deployment puts it inside." That still holds - none of the above changes the scope conclusion in [[2026-08-02-agents-as-employees-regulatory-labor-framing]]. What changed is the quality of the escape hatch. The filter is narrower than the vault thought, the personal scope reaches freelancers and platform workers and not just employees, and the one architectural pattern the Commission chose to name is ours. That is not a reason to stop selling the accountability story. It is a reason to stop implying the accountability story is what keeps a system out of the high-risk bucket. The right claim, defensible against both the statute and the draft, is that the human owner is what makes the system governable and the task boundary is what makes it out of scope, and those are two different arguments that should stop being made as one.
Why this is in the vault
It converts the "have the guidelines issued" question from an open assumption into a date-stamped negative, and it corrects [[2026-08-23-ai-act-annex-iii-employment-entries]]'s read that the Article 6(3) derogation was written to accommodate a human-decides architecture - the Commission's draft says human involvement alone is expressly insufficient, and names coordinated agentic systems as the anti-circumvention target. Any RDCO positioning, deck, or European Union client conversation that leans on "our human owner keeps us out of high-risk" needs to be rewritten before it is used, and the worked examples in the draft supply the actual boundary language to rewrite it with.
Open follow-ups
- When do the final Article 6(5) guidelines land, and does the final text keep paragraphs 71, 75 and 258? These three paragraphs carry the entire adverse finding. Consultation closed 23 June 2026 and industry pressure on exactly this point is predictable. Re-checking the Commission library at 60 and 120 days is cheap and tells us whether the adverse reading survived contact with stakeholders.
- Does a "genuinely separable component" boundary exist in RDCO's actual architecture, and could it be documented if asked? Draft paragraph 76 is the only escape hatch that survives paragraph 75, and it turns on separability rather than oversight. This is an engineering question about the skill and sub-agent topology, not a legal one, and it has never been asked of the real system.
- What does the Article 50 transparency guidelines document published 20 July 2026 actually require? It is adopted, it is final, it applies now, and it plausibly touches published RDCO output surfaces - Sanity Check, the sites, generated artefacts. The parent thread has flagged the Article 50(2) marking duty twice as an untested "assumed no." An adopted guidance document now exists to test it against.
- Is Cellar content-negotiation now the required route for European Union primary sources, and should the research skills encode it? EUR-Lex's front end returned an Amazon Web Services firewall challenge to curl on this run, which would have looked like an inconclusive result rather than a tool limit.
publications.europa.eu/resource/celex/<CELEX>with an explicitAcceptheader worked first try. This is the same class of finding as the WebFetch truncation lesson and deserves the same treatment. - How widely has the false "1 August 2027 Article 6 guidelines deadline" gloss propagated? It appeared in search-tier summaries on this run. If it is in law-firm client alerts as well, it is a second instance of the correction-lag phenomenon the thread has been tracking, and this time the error is a date rather than a characterisation.
Related
- [[2026-08-23-ai-act-annex-iii-employment-entries]]
- [[2026-08-21-ai-act-article-113-operative-text-check]]
- [[2026-08-15-eu-digital-omnibus-ai-official-journal-check]]
- [[2026-08-02-agents-as-employees-regulatory-labor-framing]]
- [[2026-06-07-ai-workforce-positioning-map]]
- [[2026-05-19-verification-as-independent-worker-pattern]]
Sources
Primary - Commission draft guidelines (downloaded to disk, read locally, no truncation):
- Draft Commission guidelines on the classification of high-risk AI systems under Article 6 of Regulation (EU) 2024/1689 (AI Act) for stakeholder consultation - General principles (6 pp), Annex I (13 pp), Annex III (148 pp) - https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems
- Commission "Shaping Europe's digital future" library listing, checked 26 August 2026 - https://digital-strategy.ec.europa.eu/en/library
Primary - European Union law (retrieved via Cellar content negotiation, Accept: application/xhtml+xml):
- Regulation (EU) 2024/1689, CELEX 32024R1689 - Article 6(5), Article 96, Article 113 - http://publications.europa.eu/resource/celex/32024R1689
- Regulation (EU) 2026/1744, CELEX 32026R1744 - Article 1 points (36), (37), (40) and associated recital - http://publications.europa.eu/resource/celex/32026R1744
Note on access: the EUR-Lex web front end (eur-lex.europa.eu/legal-content/...) returned an Amazon Web Services web-application-firewall JavaScript challenge (HTTP 202, 2 KB, zero content) to curl on this run, unlike the 2026-08-21 and 2026-08-23 runs. Cellar returned the full documents at matching byte counts. No paywalls encountered.
Vault:
- ~/rdco-vault/06-reference/research/2026-08-23-ai-act-annex-iii-employment-entries.md
- ~/rdco-vault/06-reference/research/2026-08-21-ai-act-article-113-operative-text-check.md
- ~/rdco-vault/06-reference/research/2026-08-02-agents-as-employees-regulatory-labor-framing.md
- ~/rdco-vault/06-reference/research/2026-06-07-ai-workforce-positioning-map.md