06-reference/research

ai act article 6 classification guidelines

2026-08-26·research-brief·source: deep-research·by Ray Data Co (deep-research synthesis)
eu-ai-actarticle-6high-risk-classificationcommission-guidelinesai-workforce-positioning

Still Draft, Still Late, and the Draft Says Human-in-the-Loop Does Not Save You

Not legal advice. This is a source-status and text-reading pass by a non-lawyer agent. It reports what has and has not been published, and what a non-binding draft says, not what any of it means for a particular product.

The question

"Has the Commission issued its Article 6 classification guidelines, and what do they say about borderline high-risk classification, given Article 6(5) was carved OUT of the AI Act deferral and has applied since 2 August 2026?"

Derivative follow-up from [[2026-08-21-ai-act-article-113-operative-text-check]], raised again as the highest-value remaining item in [[2026-08-23-ai-act-annex-iii-employment-entries]] once that pass confirmed by literal diff that Annex III and the Article 6(3) filter are both frozen. With the statutory text unable to move, the guidelines are the only instrument left that can shift where the practical employment-context line falls.

Answer, up front.

Sub-question Answer Evidence tier
Have the Article 6(5) guidelines been issued? No. As of 26 August 2026 there is no final version. What exists is a draft published 19 May 2026 for consultation VERIFIED-FROM-PRIMARY (Commission page + PDF cover state)
Is the statutory deadline still 2 February 2026? Yes, unamended. Missed by roughly six and a half months and counting VERIFIED-FROM-PRIMARY (original text; no amendment point touches Article 6(5))
Did the Omnibus reset the deadline? No. It set a new guidelines deadline of 1 August 2027 for a different, Annex-I-side instrument, and left Article 6(5) alone VERIFIED-FROM-PRIMARY (Regulation (EU) 2026/1744, Article 1 point (36))
What does the draft say about borderline cases? Narrow construction of the filter, human involvement expressly insufficient, agentic multi-component systems assessed as a whole, employment personal scope stretched to freelancers and platform workers VERIFIED-FROM-PRIMARY as to what the draft says; the draft itself is non-binding and unadopted

What we already know (from the vault)

What the web says

Method and status of sources. European Union law text was retrieved from the Cellar content-negotiation endpoint at publications.europa.eu/resource/celex/<CELEX> with Accept: application/xhtml+xml, because the EUR-Lex web front end now returns an Amazon Web Services web-application-firewall challenge to curl (HTTP 202, JavaScript challenge page, zero content). Cellar is the same authoritative store EUR-Lex renders from and returned byte counts matching the prior run's documents. Three primary documents plus three Commission draft PDFs were read locally. No paywalls encountered.

What the draft says about borderline classification

Everything in this subsection is what a non-binding, unadopted draft says. It is the Commission's current interpretive direction, not law, and the draft itself notes that authoritative interpretation belongs to the Court of Justice.

Convergences and contradictions

Synthesis for RDCO

The status answer is a negative and it should be stated flatly: as of 26 August 2026 the Commission has not issued its Article 6 classification guidelines. It has issued a draft, on 19 May 2026, for a consultation that closed on 23 June 2026, and that draft has not moved since 23 July 2026. Anyone who says "the Commission's high-risk classification guidelines say X" is quoting an unadopted document. That is a small, checkable, date-stamped piece of expertise of exactly the kind the earlier briefs in this thread identified as cheap credibility, and it will stay true and stay uncommon for as long as the final version sits unpublished. The more interesting structural fact is the one the amending regulation reveals by contrast: in July 2026 the legislator wrote a brand-new guidelines deadline of 1 August 2027 into Article 96(1)(g) for the Annex I product side, and said nothing whatsoever about the Article 6(5) deadline it had already missed. That is not an oversight in drafting. It is a legislature declining to re-commit on a duty it is in breach of, and the practical consequence is that the classification guidelines now have no deadline at all - only the 2 December 2027 date when the obligations they explain start biting, which is roughly fifteen months out.

The substantive finding cuts against RDCO's current comfort, and it should be absorbed rather than argued with. The 2026-08-23 brief banked the Article 6(3) filter as a positioning asset on the reasoning that human-owner-decides is the architecture the derogation accommodates. The draft guidelines say the opposite twice, in plain words. Paragraph 71: a provider "cannot exempt and categorise an AI system as 'low risk' simply by adding to it a requirement for human involvement." Paragraph 258: a human who formally decides but "significantly relies on the output of the AI system" is inside point 4(b) anyway. The load-bearing question under this draft is not who signs but what the system does - whether the task is narrow, procedural, preparatory, or an improvement on completed human work, and whether the output carries a value judgement, a score, or a ranking. The moment an agent ranks candidates, scores performance, or produces a recommendation a manager leans on, the accountable-operator story is a governance story and a trust story, but it is not a classification story. That distinction is worth getting right before it appears in a deck, because the failure mode is discovering it in a client's procurement review rather than in a research brief.

The third finding is the one nobody would have gone looking for: the draft names agentic systems specifically. Paragraph 75 treats coordinated multi-component setups as a single system for classification purposes, refuses to honour module-level Article 6(3) exemptions where the ensemble influences key aspects of the decision, and explicitly extends the anti-circumvention principle to "complex, interconnected setups like agentic AI systems that coordinate and interact through linked actions." The RDCO shape - one durable generalist agent driving many linked skills - is a near-exact description of the thing that paragraph is aimed at. The escape in paragraph 76 is real but narrow: strictly procedural or preparatory components remain exempt where they are "genuinely separable" and do not structure or feed the outputs. Practically, that means the architectural boundary RDCO would need to be able to draw is a separability boundary, not a human sign-off boundary. If an EU-facing engagement ever touches worker-related decisions, the design question is which components can be shown to be genuinely detachable from the decision path, and that is a question better answered while building than while explaining.

Where this leaves the thread. Four passes in, the compliance surface is fully mapped and the answer has been consistently "RDCO is outside Annex III unless a specific client deployment puts it inside." That still holds - none of the above changes the scope conclusion in [[2026-08-02-agents-as-employees-regulatory-labor-framing]]. What changed is the quality of the escape hatch. The filter is narrower than the vault thought, the personal scope reaches freelancers and platform workers and not just employees, and the one architectural pattern the Commission chose to name is ours. That is not a reason to stop selling the accountability story. It is a reason to stop implying the accountability story is what keeps a system out of the high-risk bucket. The right claim, defensible against both the statute and the draft, is that the human owner is what makes the system governable and the task boundary is what makes it out of scope, and those are two different arguments that should stop being made as one.

Why this is in the vault

It converts the "have the guidelines issued" question from an open assumption into a date-stamped negative, and it corrects [[2026-08-23-ai-act-annex-iii-employment-entries]]'s read that the Article 6(3) derogation was written to accommodate a human-decides architecture - the Commission's draft says human involvement alone is expressly insufficient, and names coordinated agentic systems as the anti-circumvention target. Any RDCO positioning, deck, or European Union client conversation that leans on "our human owner keeps us out of high-risk" needs to be rewritten before it is used, and the worked examples in the draft supply the actual boundary language to rewrite it with.

Open follow-ups

Related

Sources

Primary - Commission draft guidelines (downloaded to disk, read locally, no truncation):

Primary - European Union law (retrieved via Cellar content negotiation, Accept: application/xhtml+xml):

Note on access: the EUR-Lex web front end (eur-lex.europa.eu/legal-content/...) returned an Amazon Web Services web-application-firewall JavaScript challenge (HTTP 202, 2 KB, zero content) to curl on this run, unlike the 2026-08-21 and 2026-08-23 runs. Cellar returned the full documents at matching byte counts. No paywalls encountered.

Vault: