AI generated content
The European Commission was supposed to have published guidelines on the classification of high-risk AI systems by February 2, 2026. This is based on Article 6 of the EU AI Act, which defines which AI applications are considered particularly high-risk and are therefore subject to strict requirements.
The guidelines have not yet been published. Instead, the Commission is continuing to work on a draft, which will first be subject to consultation and is expected to be finalized in the spring of 2026.
At first glance, this may seem like a mere procedural delay. In practice, however, it creates a period of heightened uncertainty. While companies know that the full requirements for high-risk systems will take effect on August 2, 2026, they do not yet have complete clarity on how specific use cases will be classified.
ACT NOW!
Appoint AI Officer
A high-risk AI system is subject to significantly stricter requirements than other applications. These include, among other things:
comprehensive risk management processes
technical documentation
Conformity Assessments
Transparency Requirements
Ongoing Monitoring and Reporting Requirements
Sectors such as healthcare, critical infrastructure, lending, HR automation, and security-related components are particularly affected.
The text of the law describes the criteria in abstract terms. However, companies need concrete guidance for practical application:
When is a system considered high-risk?
How should a hybrid use case be classified?
What are the specific documentation requirements?
How is reliable evidence provided to the authorities?
Without guidelines, there is room for interpretation. And it is precisely this room for interpretation that can later become a liability risk.
AI generated content
The regulatory reality remains unchanged: The full requirements will take effect in August 2026. The lack of guidelines does not delay this deadline.
Right now, it’s becoming clear which organizations view governance as a strategic discipline. Those who wait for a final document are wasting valuable time. Those who instead prepare systematically gain the confidence to act.
The key question, therefore, is not when the guidelines will be published. The key question is whether your company is already capable of systematically identifying and managing high-risk AI.
AI generated content
Especially during periods of regulatory transition, structure is key to security.
We help companies
to make a reliable high-risk classification
Establishing governance models that are viable even without final guidelines
Designing efficient documentation and verification processes
Provide clear and transparent justifications for risk classifications
to clearly define internal responsibilities
Our approach combines legal analysis with practical implementation. The goal is not to wait for regulatory clarity, but to establish it internally.
After all, regulatory pressure will continue starting in the summer of 2026.
The only question is whether your company is prepared
We are ISO certified
We are delighted to announce that K11 is now officially certified to ISO 27001. This international standard for information security management
Would you also like to have your organization certified? We will guide you through the process—professionally, efficiently, and cost-effectively. From the initial gap analysis to successful audit preparation, we offer you a clear, structured path to certification readiness.
K11 Highlights
Book Publication: *
: AI Regulation Made Easy* / Deicke, Heynike, Deuerling
, Duncker & Humblot / ISBN 978-3-87440-408-2