{"meta":{"dataset_id":"praxikon:sys:registry:dataset:ai-act-implementation-graph","dataset_version":"2.1.0","schema_version":"1.4.0","lang":"en","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","count":38,"filters":{"id":null,"type":"guidance","role":null,"duty_holder":null,"topic":null},"identifiers":{"canonical_namespace":"praxikon","canonical_form":"praxikon:<jurisdiction>:<regulation>:<type>:<slug>","legacy_namespace":"raip","legacy_resolution":"permanent","resolved":{"id":null,"role":null,"duty_holder":null}}},"data":[{"id":"praxikon:eu:ai-act:guidance:guidance-article-4-no-mandatory-course-or-certificate","legacy_id":"raip:guidance:guidance-article-4-no-mandatory-course-or-certificate","type":"guidance","slug":"guidance-article-4-no-mandatory-course-or-certificate","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"8e07dd9efd3545029344dab517fe03c043b41d3bb1e72327c553bd9f48dc126b","label":"No mandatory course format, no certificate, no exam and no AI officer","summary":"Article 4 prescribes no form. The Commission confirms that no certificate is required, no obligation to measure knowledge exists, no training is mandatory and no governance structure is prescribed.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"guidance-article-4-no-mandatory-course-or-certificate-scope","operator":"all","description":"Applies to providers and deployers of AI systems, who take measures to support AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf."}],"exceptions":[{"id":"guidance-article-4-no-mandatory-course-or-certificate-exception","operator":"not","description":"For deployers of high-risk AI systems, a separate obligation under Article 26 will apply in addition, requiring them to ensure that staff working with the system are sufficiently trained to handle it and ensure human oversight. That duty goes beyond Article 4, but it does not apply yet: it becomes applicable on 2 December 2027 for standalone high-risk systems under Annex III and on 2 August 2028 for high-risk systems embedded in products under Annex I."}],"statements":[{"kind":"official_fact","text":"The Commission Q&A on AI literacy states that there is no one size fits all when it comes to AI literacy and that no strict requirements or mandatory trainings are imposed. On certification, the Q&A states literally that there is no need for a certificate and that organisations can keep an internal record of trainings or other guiding initiatives. On assessment, it states that Article 4 of the AI Act does not entail an obligation to measure the AI knowledge of employees. On governance, it states that no specific governance structure is mandated to comply with Article 4, so that unlike the data protection officer under the GDPR, no AI officer needs to be appointed. On the level, the Q&A states that following the Digital Omnibus amendment AI literacy remains an obligation for providers and deployers of AI systems, but that no specific or sufficient level is mandated and that the Regulation does not require guaranteeing any specific level of AI literacy of any individual. Against that, the Q&A states that simply relying on the AI systems' instructions for use or asking staff to read them might be ineffective, and that organisations should take into account general AI understanding within the organisation, whether they are a provider or a deployer, the risks associated with the systems deployed, staff knowledge gaps considering technical knowledge, experience, education and training, and contextual factors such as sector, purpose and affected populations. The Q&A further states that organisations may implement different levels of training or learning approaches depending on knowledge, experience, education and role, and that staff with a degree or experience in AI development are normally considered AI literate, while the organisation must still verify that those persons understand the specific AI systems of the organisation, know how to deal with them and are aware of all risks.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","source_locator":"Commission Q&A on AI literacy, sections on required level, training formats, certificates, assessment of knowledge and governance structures (consulted 9 August 2026)","source_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This guidance cuts both ways and both are abused. The supply side of the market sells certificates and exams as a legal requirement: that is demonstrably wrong, because the Commission states literally that no certificate is needed and that there is no obligation to measure knowledge. The other side is the organisation that concludes from the same answer that nothing is required. That is equally wrong. In the same Q&A the Commission says that merely forwarding the instructions for use might be ineffective, and it expects a reasoned choice based on your role, your risks and your people's knowledge gaps. The correct reading is therefore: no prescribed format, but a demonstrable measure. That makes the internal record named in the Q&A the practical heart of your file. And note the nuance about technical staff: a data scientist is not automatically done, because the organisation must still verify that this person knows its own systems and the associated risks.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","source_locator":"Commission Q&A on AI literacy, sections on required level, training formats, certificates, assessment of knowledge and governance structures (consulted 9 August 2026)","source_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Stop steering on certificates and steer on a demonstrable, reasoned measure. Record what you did, for which groups, why that format fits their role and the risks of the systems they use, and keep a simple internal record as the Q&A suggests. Differentiate by role rather than giving everyone the same module, and include your technical staff with a specific component on your own systems and risks. Replace the mere forwarding of instructions for use with something that is demonstrably read and understood.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","source_locator":"Commission Q&A on AI literacy, sections on required level, training formats, certificates, assessment of knowledge and governance structures (consulted 9 August 2026)","source_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 4 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-article-4-scope-and-enforcement","legacy_id":"raip:guidance:guidance-article-4-scope-and-enforcement","type":"guidance","slug":"guidance-article-4-scope-and-enforcement","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"254d354a849f9911e88468cf6c6729b1306cfe0a77bcec4a4cf765a8628cc132","label":"Article 4 reaches beyond your own staff, and the national supervisor enforces it","summary":"The duty to take measures also covers contractors, service providers and sometimes clients. Supervision lies not with the AI Office but with national market surveillance authorities, enforcing since 2 August 2026.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"guidance-article-4-scope-and-enforcement-scope","operator":"all","description":"Applies regardless of place of establishment, as long as the AI system is placed on the Union market, used in the Union, or its use has an impact on people located in the Union."}],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission Q&A on AI literacy states that Article 4 applies to providers and deployers of AI systems and in addition to other persons dealing with the operation and use of AI systems on their behalf, covering persons broadly within the organisational remit, with a contractor, a service provider and a client given as examples. On clients, the Q&A states that they may need AI literacy depending on the specific risk, reasoning that affected persons should understand how decisions taken with the assistance of AI will have an impact on them. On geographic scope, the Q&A states that the AI Act's legal framework applies to both public and private actors inside and outside the EU as long as the AI system is placed on the Union market, used in the Union, or its use has an impact on people located in the EU. On supervision, the Q&A states that the supervision and enforcement of Article 4 is not with the AI Office but under the remit of national market surveillance authorities, and that supervision and enforcement began on 2 August 2026, while Article 4 itself entered into application on 2 February 2025. On sanctions, the Q&A states that national market surveillance authorities could impose penalties and other enforcement measures for infringements of Article 4, that this will be based on national laws that Member States were due to adopt by 2 August 2025, that any sanction must be proportionate and based on the individual case taking into account factors such as the nature and gravity of the infringement and its intentional or negligent character, and that sanctions are more likely if there is proof of an incident due to a lack of appropriate training and guidance. Article 4 is not listed in the enumeration in Article 99(4) of the AI Act, which covers only Articles 16, 22, 23, 24, 26, 31, 33(1), (3) and (4), 34 and 50, so the level of any penalty for Article 4 follows from national law rather than from the Regulation's own ceilings. The Q&A further states that Article 4 reinforces the transparency provisions of Article 13 and the human oversight provisions of Article 14 and indirectly contributes to the protection of affected persons, and that for deployers of high-risk systems the Article 26 obligation to ensure staff are trained to ensure human oversight is a distinct requirement; that requirement becomes applicable on 2 December 2027 for standalone Annex III systems and on 2 August 2028 for Annex I systems.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","source_locator":"Commission Q&A on AI literacy, sections on target groups, geographic scope, supervision and enforcement, and sanctions (consulted 9 August 2026)","source_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Two things are consistently underestimated here. The first is the circle of people. Many organisations translate Article 4 into a staff programme and forget the seconded workers, the call centre, the implementation agency and the freelancers who use the same systems daily. The Q&A expressly widens that circle to everyone within the organisational remit, and even leaves the door open to clients where the risk calls for it. The second is who will come knocking. Because the AI Office gets all the attention, organisations assume Article 4 is a Brussels file. It is not: this runs through the national market surveillance authority. The most useful sentence for your own prioritisation is that a sanction is more likely where there is proof of an incident caused by a lack of appropriate training and guidance. Enforcement will therefore rarely start with a spot check on your training plan, and far more often with an incident after which the question becomes whether the person involved was prepared. That makes the file reactively useful, and therefore worth having in order now.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","source_locator":"Commission Q&A on AI literacy, sections on target groups, geographic scope, supervision and enforcement, and sanctions (consulted 9 August 2026)","source_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Extend your target list from permanent staff to everyone working with your AI systems under your direction, including contingent workers, contractors and implementation partners, and write that expectation into your procurement and hiring terms. Assess per system whether clients or affected persons also need an explanation of how AI-assisted decisions affect them. Structure your records so that after an incident you can show within a day which measures the person involved had received and when. Finally, establish which national market surveillance authority is competent for you, because that is your counterpart, not the AI Office.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","source_locator":"Commission Q&A on AI literacy, sections on target groups, geographic scope, supervision and enforcement, and sanctions (consulted 9 August 2026)","source_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 4 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-article-50-ai-agent-self-disclosure","legacy_id":"raip:guidance:guidance-article-50-ai-agent-self-disclosure","type":"guidance","slug":"guidance-article-50-ai-agent-self-disclosure","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1169f3717da19ed6a14a80d5af186da930548a1825b628884c181c5f30a28762","label":"AI agents must disclose both their AI nature and on whose behalf they act","summary":"An AI agent that makes bookings, handles correspondence or concludes contracts must identify itself as AI and state on whose behalf it is acting, including towards the person instructing it.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"guidance-article-50-ai-agent-self-disclosure-scope","operator":"all","description":"Applies as soon as the agent is capable of interacting with the person instructing it or with other natural persons in the execution of the task."}],"exceptions":[{"id":"guidance-article-50-ai-agent-self-disclosure-exception","operator":"not","description":"Purely machine-to-machine communication between agents whose outputs are not intended to reach a natural person falls outside the disclosure duty of Article 50(1), and intermediate reasoning steps and non-perceptible actions fall outside the marking duty of Article 50(2)."}],"statements":[{"kind":"official_fact","text":"Point (31) of the guidelines of 20 July 2026 states that AI agents are covered by Article 50(1) if they are capable of interacting with the persons instructing them or with other natural persons in the execution of their tasks, citing as examples making bookings, managing correspondence, negotiating or concluding contracts and executing purchases. That same point requires AI agents to be designed and developed so that they disclose both their artificial nature and the person on whose behalf they are acting, given the need for transparency of the origin and of the delegation of authority and accountability for the consequences of their actions. This also applies in complex multi-agent architectures in which other agents interact directly with natural persons. Where the provider cannot reliably determine before placing on the market or putting into service whether the agent will directly interact with a natural person, the agent should be designed at the architecture level and instructed to disclose itself in every situation where it is reasonably likely to interact with a natural person, including where that person represents a legal entity. Agents should also disclose themselves to the persons instructing them at key steps such as authorisation, reporting and validation, including where the agent receives, processes or relies upon outputs generated by other AI systems rather than by a natural person, and at every new interaction. Point (63) adds that Article 50(2) may apply to AI agents where the agent takes an action whose output is AI-generated or manipulated content perceptible by natural persons, while intermediate processing steps such as reasoning and chain of thought and non-perceptible actions such as a web request or browser action fall outside that scope.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 3.1.1 point (31) and Section 4.1.2 point (63)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Here the guidelines go further than most organisations expect. The obligation is twofold: not only 'I am AI', but also 'I act on behalf of this party'. That turns agentic email, procurement and negotiation into a design question rather than a line in a footer. Two things are systematically missed. First, the disclosure duty also runs towards your own instructing party, at key steps such as authorisation and validation, and particularly where the agent builds on outputs from other AI systems rather than on human input. Second, the provider's uncertainty resolves nothing: if the provider cannot determine in advance whether the agent will reach a human, the answer is not 'then it does not apply' but 'then you build the disclosure into the architecture by default'. An agent that stays quiet until it is certain a human is reading is not what is intended.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 3.1.1 point (31) and Section 4.1.2 point (63)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Treat your agent's disclosure as an architecture requirement, not a prompt instruction that can be overridden per task. Ensure every outbound channel of the agent, meaning email, chat, telephony and forms, carries both the AI origin and the instructing organisation by default. Also build confirmation moments towards your own user at authorisation, reporting and validation, and flag explicitly there when the agent is building on output from another AI system. Finally, mark the perceptible content the agent produces in line with Article 50(2), but not the internal reasoning steps.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 3.1.1 point (31) and Section 4.1.2 point (63)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 50 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-article-50-artistic-attenuated-disclosure","legacy_id":"raip:guidance:guidance-article-50-artistic-attenuated-disclosure","type":"guidance","slug":"guidance-article-50-artistic-attenuated-disclosure","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2a6556bdda279577904e1a80ab7717e80a0a64056312645e38596a105deabf05","label":"Artistic or satirical work is not exempt but attenuated, and the informative character always prevails","summary":"For deep fakes in evidently artistic, creative, satirical or fictional work, the disclosure must not hamper the work, but it remains mandatory. Where the content mixes in an informative or commercial character, the standard label applies.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"guidance-article-50-artistic-attenuated-disclosure-scope","operator":"all","description":"The deep fake must evidently form part of an artistic, creative, satirical, fictional or analogous work or programme, assessed case by case by the deployer."}],"exceptions":[{"id":"guidance-article-50-artistic-attenuated-disclosure-exception","operator":"not","description":"Where content combines multiple characters, the informative character always prevails and the standard labelling requirements apply; content that is exclusively informative or commercial and recognisable as such, such as news reporting, falls outside the lighter regime."}],"statements":[{"kind":"official_fact","text":"Point (119) of the guidelines of 20 July 2026 describes an attenuated transparency obligation for deep fakes forming part of evidently artistic, creative, satirical, fictional or analogous works or programmes, where the obligation is limited to disclosure in an appropriate manner that does not hamper the display or enjoyment of the work. Point (120) describes the categories: artistic works are created for the purpose of art, including music, cinematographic works and visual arts; creative works involve creative choices, while works mainly motivated by functional or technical considerations cannot be regarded as creative; satirical works are intended to criticise society, politics, business or public figures through humoristic techniques; fictional works involve persons, objects, places, entities or events in an imaginary but verisimilitude setting; analogous works share core traits with those categories without fitting neatly into one. Point (122) states that it must be evident to the natural persons exposed to it that the content falls within one of those categories, that the categories must therefore be interpreted strictly given the lighter disclosure regime and the interests of freedom of expression and freedom of the arts and sciences, and that content whose nature is potentially unclear or ambiguous to the audience falls outside this lighter regime. Relevant factors, per that same point, are whether the content displays formats or styles characteristic of the category, the context in which it is presented, and audience expectations. That same point excludes content whose nature is exclusively informative or commercial and recognisable as such, citing news reporting, notes that advertisements or documentaries may be regarded as evidently creative or fictional in certain specific situations but not in others because the assessment is case-specific, and states that where the deep fake combines multiple characters, for example informative and creative, the informative character should always prevail and the standard labelling requirements apply. Point (123) stresses that these deep fakes are not excluded from the obligation: the deployer must still disclose the AI origin or manipulation, but may do so in an appropriate manner, and must in any case comply with Article 50(5). Point (124) states that reliance on the attenuated obligation cannot justify failing to respect the fundamental rights of individuals or the rights of rightsholders under Union intellectual property or data protection law. As examples within the categories the document cites movies featuring AI de-aged existing actors or digital replicas of deceased actors, AI-generated music in the style of existing artists, and an AI-manipulated image of an existing politician in a scene clearly meant as humorous criticism. Outside the categories the document places among others an AI-manipulated video in the style of a teleshopping channel, AI-generated images of celebrities implying involvement in activities that never happened, and an AI-manipulated video featuring a realistic synthetic influencer focused solely on displaying a sponsored product's functionalities.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 6.1.3, points (119) to (124) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Two misconceptions dominate here. The first is that 'creative work' is an exemption. It is not: you must still disclose, only in a way that does not ruin the work, for example in the credits, in an accompanying notice, or at the start of the video rather than as a permanent block across the image. The second misconception is more serious and hits marketing directly. Advertising is not automatically creative work. The guidelines cite teleshopping-style videos and synthetic influencers demonstrating a product precisely as examples falling outside the category, and further state that where characters mix, the informative one always prevails. So anyone making a funny, clearly stylised campaign that also carries a product claim falls back on the standard label. Finally, note the evidence requirement: if the audience could doubt whether it is seeing satire or real news, it is by definition not evident and the lighter regime does not apply.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 6.1.3, points (119) to (124) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Assess per production whether the work is unmistakably artistic, satirical or fictional for your audience, and briefly record that assessment against the three factors in point (122): stylistic features, publication context and audience expectation. For campaigns and commercial video, default to the standard label and rely on the lighter regime only in rare cases. For evidently creative work, choose a disclosure that leaves the work intact, for example at the start or in the credits, bearing in mind that the information must be clear and distinguishable and that people joining later must also be able to perceive it.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 6.1.3, points (119) to (124) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 50 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-article-50-code-of-practice-effect","legacy_id":"raip:guidance:guidance-article-50-code-of-practice-effect","type":"guidance","slug":"guidance-article-50-code-of-practice-effect","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f7e48914cd44ef9874aef29ccdbd4580232937021d6c4a85de660ca6ae24ce8d","label":"Signing the code of practice is voluntary, but not signing means proving it yourself","summary":"Signing the code of practice on transparency of AI-generated content is voluntary and not signing is not in itself non-compliance. Those who do not sign must demonstrate compliance by other means, including a gap analysis against the code.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"guidance-article-50-code-of-practice-effect-scope","operator":"all","description":"Applies to providers and deployers of generative AI systems within the scope of Article 50(2) and (4)."}],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission Q&A on signing the Code of Practice on Transparency of AI-generated Content states that signing is voluntary and that not signing does not constitute non-compliance with the AI Act. That same Q&A states that the code has two sections, one for providers on marking AI-generated or manipulated content in machine-readable formats and the related detection mechanisms, and one for deployers on the disclosure and labelling of deep fakes and of certain AI-generated or manipulated text on matters of public interest. It further states that signatories may, subject to a positive assessment by the Commission and the AI Board, rely on the code to demonstrate compliance with their obligations under Article 50 regardless of their place of establishment, and that the deadline for inclusion in the initial list of signatories was 27 July 2026 at 18:00 CEST, with later signature remaining possible but not appearing on that initial list. The Commission guidelines of 20 July 2026 state in point (146) that providers and deployers within the scope of Article 50(2) and (4) may demonstrate compliance by adhering to a code of practice assessed as adequate under Article 50(7), and that such a code does not replace the Regulation or the guidelines but complements them as the only Union-wide recognised practical framework for that purpose. Point (147) states that compliance may also be demonstrated through other adequate means, that for signatories supervisory activities will focus on whether they have adhered to the code and implemented the measures it contains, and that opting out of sections results in losing the benefit of facilitated demonstration of compliance for that part. Point (148) states that non-signatories are expected to demonstrate through other adequate means how they comply with Article 50(2), (4) and (5) and to explain how their measures ensure compliance, for instance by carrying out a gap analysis comparing their measures with those set out in a code assessed as adequate, and that they will likely face more requests for information and for access. Point (149) states that competent authorities may take commitments implemented in line with a code assessed as adequate into account as a mitigating factor when setting the amount of fines. Point (150) states that if a code is not deemed adequate, the Commission may adopt an implementing act specifying common rules for the implementation of Article 50(2), (4) and (5).","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 8.1, points (146) to (150); Commission Q&A on signing the Code of Practice on Transparency of AI-generated Content (consulted 9 August 2026)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The voluntariness is real, but it is not free. The guidelines shift the burden of proof: signatories are assessed on whether they do what the code says, non-signatories must explain why their own approach suffices. That difference translates into work. Point (148) expects non-signatories to run a gap analysis against the code, which means you have to read the code and benchmark your measures against it either way. Not signing therefore saves you the signature, not the substance. On the other side, point (149) explicitly names adherence in line with the code as a mitigating factor for fines, which makes the code commercially interesting for parties producing large volumes of generated content. Finally, note the opt-out rule: partial signature is possible, but for the sections you skip you fall back into the heavier evidential position. For anyone who missed the initial list, signature remains open; only the listing on that first list has passed.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 8.1, points (146) to (150); Commission Q&A on signing the Code of Practice on Transparency of AI-generated Content (consulted 9 August 2026)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Decide deliberately whether to sign and record the reasoning. If you do not sign, still carry out the gap analysis named in point (148) and keep it as the core of your file, together with a description of how your own measures cover Article 50(2), (4) and (5). Account for the fact that as a non-signatory you may receive more information and access requests, and structure your documentation accordingly. If you sign but opt out of sections, treat those sections as a non-signatory would and document them separately.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 8.1, points (146) to (150); Commission Q&A on signing the Code of Practice on Transparency of AI-generated Content (consulted 9 August 2026)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 50 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-article-50-deployer-perceivable-labelling","legacy_id":"raip:guidance:guidance-article-50-deployer-perceivable-labelling","type":"guidance","slug":"guidance-article-50-deployer-perceivable-labelling","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"85008088c20a5e3f90ddaa51118c0e8e86353a579c51168dd58a2f274d497f9e","label":"The deployer cannot rely on the provider's machine-readable marking","summary":"Whoever publishes a deepfake must apply a label perceivable by humans. The watermark or metadata supplied by the provider does not discharge that duty.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"guidance-article-50-deployer-perceivable-labelling-scope","operator":"all","description":"Applies to deployers of AI systems that generate or manipulate deep fakes in the form of image, audio or video content."}],"exceptions":[{"id":"guidance-article-50-deployer-perceivable-labelling-exception","operator":"not","description":"An attenuated form of disclosure applies to deep fakes forming part of evidently artistic, creative, satirical, fictional or analogous works, and an exception applies to use authorised by law to detect, prevent, investigate or prosecute criminal offences."}],"statements":[{"kind":"official_fact","text":"Point (117) of the guidelines of 20 July 2026 states that deployers of AI systems generating or manipulating deep fake content must clearly and distinguishably disclose that the content has been artificially created or manipulated, by labelling the output accordingly and disclosing its artificial origin. According to that same point, the labelling or disclosure methods used must be understandable and perceivable by natural persons, for example with visible or audible labels, without those persons needing to rely on any specific technical tools or performing dedicated actions. The point closes expressly by stating that deployers cannot rely on the machine-readable marking embedded in the content by the provider under Article 50(2), since those markings are not immediately clear and distinguishable for the natural persons exposed to the deep fake content. Point (12) adds that deployers involved in complex content production and distribution value chains must take proportionate measures to ensure that the labelling they have implemented under Article 50(4) is actually displayed in a clear and distinguishable manner to the targeted and foreseeable audience at the point of first exposure, for example via contractual conditions with distributing partners and via user experience settings and interfaces. Point (14) states that a legal person remains the deployer even where it involves third parties such as contractors or freelancers in the operation of the system on its behalf and under its authority, and that individual employees acting under its instructions and control are not considered separate deployers.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, Section 6.1.2 point (117) and Section 2.3 points (12) and (14)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the sharpest role confusion in the whole transparency chain. Provider and deployer carry two different duties aimed at two different audiences: the provider marks machine-readably for systems and supervisors, the deployer labels perceptibly for humans. The common error is that a marketing department or agency assumes the generated image is 'already marked' by the tool and that nothing further is needed at publication. That is wrong. Equally important is how the duty travels down the chain: it does not end with applying the label, but with whether the audience actually sees the label at first exposure. If your label disappears because a platform re-encodes, crops or auto-plays the video without the opening title, the label formally exists but functionally does not. That is why the guidelines expressly name contractual arrangements with distribution partners as a means. And note the last sentence of point (14): you do not pass the deployer role on to the agency or freelancer producing the content for you.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, Section 6.1.2 point (117) and Section 2.3 points (12) and (14)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Add a separate step to your publication process in which a label visible or audible to humans is applied to deep fake content, independent of whatever the generation tool writes into the files. Verify per distribution channel that the label is still visible at first contact after uploading, re-encoding and auto-play. Write the labelling requirement into your terms with agencies, production partners and distribution platforms, and do not assume that engaging an external agency moves the deployer role.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, Section 6.1.2 point (117) and Section 2.3 points (12) and (14)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 50 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-article-50-disclosure-timing","legacy_id":"raip:guidance:guidance-article-50-disclosure-timing","type":"guidance","slug":"guidance-article-50-disclosure-timing","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1d84d58420f8a24a1d13d7b31bea51d92ef06ea18d81146ab84a1a1964afde98","label":"Disclosure at the latest at first interaction, and again for every new person","summary":"The notice that a person is dealing with an AI system must be given at the latest at the time of the first interaction. That moment applies per natural person, not once per system.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"guidance-article-50-disclosure-timing-scope","operator":"all","description":"Applies to providers of AI systems intended to interact directly with natural persons, and through the horizontal requirements of Article 50(5) to all notices under Article 50(1) to (4)."}],"exceptions":[{"id":"guidance-article-50-disclosure-timing-exception","operator":"not","description":"The information obligation falls away if the interaction is obvious to a reasonably well-informed, observant and circumspect person, or if the system is authorised by law to detect, prevent, investigate or prosecute criminal offences, unless the system is available to the public to report a criminal offence."}],"statements":[{"kind":"official_fact","text":"The final Commission guidelines of 20 July 2026 (C(2026) 5054 final) state in point (33) that the notification mechanism must be embedded in the design of the system and that the notice must be provided during operation of the system and at the latest at the time of the first interaction with the natural person, as required by Article 50(5). Point (143) clarifies that 'first interaction or exposure' refers not only to the first person who encounters the system, but also to any subsequent first interaction with or exposure to the system by any other natural person. For an interactive system, the information must be provided at least once at the start of an interactive session. For content under Article 50(2) and (4), the information obligation applies to each output with respect to any natural person exposed to it. Point (40) adds that a single prominent notification before the first interaction is likely to suffice in most instances, but that in riskier contexts periodic reminders and context-aware disclosures are likely to be necessary, in particular for vulnerable persons, sustained or immersive interactions, financial, insurance, legal or health advice and complaints handling, and AI companions. That same point requires the system to be designed so that it always discloses where it is asked about its nature or the origin of the interaction, or where it can reasonably be assumed from the exchange that the person is likely to be misled or confused about the AI origin.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, Section 3.1.2 points (33) and (40), and Section 7.2 point (143)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The trap is the word 'first'. Many organisations read it as a one-off announcement when the chatbot launches, or as a line in a welcome email that every visitor is assumed to have seen. The guidelines read it as an obligation that arises anew for each natural person who encounters the system or its output for the first time. A second common error is assuming that a notice at the start of the session covers the whole customer journey. If the role of the system changes mid-session, or the interaction is long and concerns money, health or law, the Commission expects repetition. The third trap is letting the system dodge the question when a user directly asks whether they are speaking to a human. That is not permitted: the question must always be answered honestly, whatever notice was given earlier.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, Section 3.1.2 points (33) and (40), and Section 7.2 point (143)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Document for each customer contact channel at what moment the notice appears, and test it with a fresh session from a new device so you see what a first-time visitor sees rather than what a logged-in employee sees. Also build a hard rule into the system prompt or conversation logic that forces the system to confirm its AI origin as soon as it is asked or as soon as the user addresses it as a human. Finally, decide for your higher-risk channels, such as financial advice, claims handling, care and complaints, whether a single opening notice suffices or whether you need a persistent label or periodic reminders, and record that assessment in writing.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, Section 3.1.2 points (33) and (40), and Section 7.2 point (143)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 50 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-article-50-editorial-control-exception","legacy_id":"raip:guidance:guidance-article-50-editorial-control-exception","type":"guidance","slug":"guidance-article-50-editorial-control-exception","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a7748691ed1b2ac94d7c41e397695219b2575d4d9c2404df7917bc6a98623657","label":"The editorial exception: substantive review plus an identifiable responsible person","summary":"No label is needed where the AI text has been substantively reviewed by a human and someone holds editorial responsibility. A spellcheck or a written editorial policy is not enough, and any AI intervention after sign-off voids the exception.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"guidance-article-50-editorial-control-exception-scope","operator":"all","description":"Both conditions must be met together: substantive human review or editorial control, and an identifiable natural or legal person holding editorial responsibility for the publication."}],"exceptions":[],"statements":[{"kind":"official_fact","text":"Point (133) of the guidelines of 20 July 2026 sets two cumulative conditions: the AI-generated or manipulated text must have undergone human review or editorial control, and a natural or legal person must hold editorial responsibility for the publication. Point (134) describes human review as the deliberate examination of the substance of the content by one or more natural persons possessing relevant knowledge and professional judgement on the subject matter, citing academic peer review and professional validation chains as examples, and states that fact-checking the accuracy of the content is a minimum requirement that must form part of that review. Editorial control is described in that same point as the control exercised in practice by a responsible editorial entity, for example an editor-in-chief, with the authority to approve, alter or reject the substance of the text on substantive grounds, including fact-checking and ensuring the trustworthiness of sources. Point (135) states that superficial, solely formal or procedural checks such as spell-checking or grammatical correction, the mere existence of an editorial policy, automated review processes, and cursory editorial approval without substantive engagement by the human reviewer or the editorial entity cannot fulfil the conditions. Point (136) states that where AI systems are used to modify, supplement or reformulate content following editorial sign-off, the resulting content must be treated as AI-generated or manipulated, and that any substantive AI intervention occurring after the human review or editorial control will cause the exception to become void. Point (138) states that the person holding editorial responsibility must hold the ultimate responsibility over the publication, including the human review or editorial control, and that the identity and contact details of that legal person, natural person or function should be made publicly available in an easily findable location, online for example through a website's terms and conditions or other user-facing legal information, offline for example in a colophon. As examples meeting the conditions the document cites among others an AI-manipulated newspaper article or AI-generated summary subject to the editorial control of the editor-in-chief, an AI-manipulated academic blog that has undergone internal peer review, AI-generated public safety warnings approved by a public official, and AI-generated sustainability reports reviewed by professionals in relevant functions. As examples failing the conditions the document cites a website where AI-generated articles on Union policy are posted without any deliberate human review, and AI-generated articles reviewed and edited by another AI system where a human editor performs a mere superficial grammatical check before publication.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 6.2.3, points (133) to (138) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This exception is why most newsrooms and communications departments do not have to label, but it is narrower than it looks. Three pitfalls. First, sequence: many organisations have the text approved and then let an AI tool 'polish it a bit' for SEO, length or tone. Point (136) states literally that any substantive AI intervention after sign-off voids the exception. The AI step must therefore come before the human review, not after it. Second, depth: it must be deliberate examination of the substance with fact-checking as a minimum. An editor who only reads for flow does not qualify, and an AI reviewing another AI certainly does not. Third, visibility: it must be publicly findable who holds editorial responsibility. A colophon or a clear statement in the site's legal information is not a formality but a condition of the exception. Notably, the guidelines expressly place this exception outside the media as well, citing sustainability reports and government warnings. Your compliance or communications function can therefore act as the reviewer, provided the review is genuinely substantive.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 6.2.3, points (133) to (138) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Always place your AI step before human approval in the workflow, and technically block any AI edit running after sign-off, including automatic SEO optimisation or shortening. Record per publication stream who performs the substantive review, that fact-checking forms part of it, and who holds editorial responsibility. Publish that responsible function or person with contact details in an easily findable location, for example in the colophon or with the site's legal information. Keep a short record per publication of who reviewed the substance and when, so you can substantiate reliance on the exception.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 6.2.3, points (133) to (138) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 50 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-article-50-insufficient-disclosure-methods","legacy_id":"raip:guidance:guidance-article-50-insufficient-disclosure-methods","type":"guidance","slug":"guidance-article-50-insufficient-disclosure-methods","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a61216744fea363ea209be6924027e8a4cc59cac559a7cc92505d51bc300c12c","label":"What does not suffice on its own as an AI disclosure","summary":"A line in the terms and conditions, a hidden metadata mark or a vague word like 'assistant' will not do. The guidelines name five methods that are insufficient when used alone.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"guidance-article-50-insufficient-disclosure-methods-scope","operator":"all","description":"Applies to every disclosure under Article 50, because Article 50(5) requires information to be provided in a clear and distinguishable manner and to conform to applicable accessibility requirements."}],"exceptions":[],"statements":[{"kind":"official_fact","text":"Point (38) of the guidelines of 20 July 2026 lists techniques that are not necessary and that, when used alone, are insufficient to satisfy Article 50(1) and (5). These are: disclosures contained only in terms and conditions, URLs or documentation, with the document adding that such disclosures may complement but not replace in-context disclosure; machine-readable markings such as metadata or watermarks that are not perceivable by users at the point of interaction, which does not affect their appropriateness for Article 50(2); unclear or ambiguous signals, with the document expressly naming a generic reference to 'assistant', and human-like representations that may mislead users; generalised disclosures that are not sufficiently specific to the system's outputs and interactions, with the document citing as inadequate a statement on a platform offering a variety of services that 'Services on this website use AI'; and technical or capability-based descriptions referring solely to the underlying technology, such as 'this system uses LLMs', without explaining the function or the implications for the user and the artificial origin. Point (142) adds that information is not clear and distinguishable where it can be easily overlooked or missed under normal exposure or interaction conditions, for example where it is included only in a manual, hidden under layers of menu options in an online interface, or part of terms of use that users often do not read.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 3.1.2 point (38) and Section 7.1 point (142)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the list that topples most existing implementations. Three patterns occur structurally and all three fail. First, the legal cover: a line in the terms and conditions or privacy statement saying the organisation uses AI. Second, the technical cover: the argument that the output carries a C2PA mark or watermark and that the user is therefore informed. The guidelines keep those two tracks strictly separate, because a machine-readable mark counts for Article 50(2) but not as a disclosure to the human. Third, the brand-driven cover: giving the chatbot a friendly name and calling it 'your digital assistant'. That precise formulation is named as an example of an ambiguous signal. The popular generic site-wide banner stating that the site uses AI is likewise explicitly labelled insufficient, because it is not specific enough to the actual output.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 3.1.2 point (38) and Section 7.1 point (142)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Inventory where your current AI disclosure sits. If it lives only in the terms and conditions, the privacy statement, a cookie banner or a help page, it does not comply and must move into the interaction itself, close to the input and output field. Replace phrasings such as 'digital assistant' or 'virtual colleague' with an explicit statement that this is an AI system. Keep the machine-readable marking in place for Article 50(2), but do not count it towards the disclosure to the user.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 3.1.2 point (38) and Section 7.1 point (142)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 50 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-article-50-legacy-content-and-transition","legacy_id":"raip:guidance:guidance-article-50-legacy-content-and-transition","type":"guidance","slug":"guidance-article-50-legacy-content-and-transition","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"146b27c7c1ab9d757ed27e3a5f541df95650dc136ed86e5a6a564606636b6b15","label":"Existing systems and legacy content: what does and does not apply retroactively","summary":"Only the machine-readable marking under Article 50(2) has a transitional period for systems already on the market. Legacy content need not be labelled retroactively, but legacy text you publish now must be.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"guidance-article-50-legacy-content-and-transition-scope","operator":"all","description":"The transitional period to 2 December 2026 applies only to the marking and detection obligation of Article 50(2) and only to generative systems placed on the market or put into service before 2 August 2026."}],"exceptions":[{"id":"guidance-article-50-legacy-content-and-transition-exception","operator":"not","description":"Content generated or manipulated before 2 August 2026, and text on matters of public interest generated and published before that date, need not be marked or labelled retroactively."}],"statements":[{"kind":"official_fact","text":"Point (153) of the guidelines of 20 July 2026 states that under Article 113, Article 50 applies from 2 August 2026 and that all in-scope AI systems placed on the market or put into service in the Union must comply on that date, regardless of their date of placing on the market or putting into service. That same point describes that the regulation amending the AI Act provides a targeted transitional rule concerning only the marking and detection obligations under Article 50(2) for generative AI systems placed on the market or put into service before 2 August 2026, giving providers of those existing systems a transitional period to bring them into conformity by 2 December 2026. Point (153) states expressly that systems that are partly interactive and partly generative may benefit from that transitional period only with regard to the marking obligation under Article 50(2), while compliance with the disclosure obligation for AI systems directly interacting with natural persons must be ensured as of 2 August 2026. Point (154) states that AI-generated or manipulated outputs within the scope of Article 50(2) and deep fakes within the scope of Article 50(4), first subparagraph, generated or manipulated before 2 August 2026 do not need to be marked or labelled retroactively, and that the same applies to texts on matters of public interest that were AI-generated or manipulated and published before that date. That same point states conversely that texts generated or manipulated before 2 August 2026 but published on or after that date must be labelled. Point (154) adds that deployers and other actors in possession of or disseminating pre-existing unlabelled deep fakes are nonetheless encouraged to label them, without being expected to engage in disproportionate efforts such as auditing pre-existing content databases or modifying already printed product packaging. A footnote to point (153) clarifies that the special grandfathering rule of Article 111(2) for high-risk AI systems does not extend to Article 50, because the high-risk obligations and the transparency obligations apply cumulatively.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 8.4, points (153) and (154)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Two things get conflated here. The first is the assumption that the transitional period to 2 December 2026 is a general postponement of Article 50. It is not: it covers only the machine-readable marking and detection of Article 50(2). If your system also runs a chat interface, the disclosure to the user had to be in place on 2 August 2026, even though marking of the output may wait until December. The second is the assumption that legacy content is safe. That holds for already published content, but not for your stock. If you had a batch of AI texts produced last year and are only publishing them now, the labelling duty does apply. The same goes for a campaign visual that has been sitting on the shelf for months. Practically, the distinction is not old versus new, but the moment of publication. The encouragement to label pre-existing deep fakes is not a duty, but it is where a supervisor can look at the reasonableness of your choices.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 8.4, points (153) and (154)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Split your inventory into three: systems interacting directly with people, which have had to disclose since 2 August 2026; generative systems relying on the transitional period to 2 December 2026 for machine-readable marking; and systems doing both, which therefore carry a different date per obligation. Also walk through your content stock: anything still to be published that was AI-generated or substantially edited gets a label at publication, regardless of when it was generated. Record why you are not retroactively labelling already published legacy content, so you can explain that choice.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 8.4, points (153) and (154)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 50 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-article-50-obvious-ai-exception","legacy_id":"raip:guidance:guidance-article-50-obvious-ai-exception","type":"guidance","slug":"guidance-article-50-obvious-ai-exception","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a34d3634aef745e469063ab8eeb951a82a032352c34867233c8af9df969b3583","label":"When is AI obvious? The exception applies only where almost no doubt remains","summary":"The exception for obvious AI interaction must be interpreted restrictively. It applies only where almost no doubt remains for an average member of the intended and reasonably foreseeable audience.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"guidance-article-50-obvious-ai-exception-scope","operator":"all","description":"Assessment per system and per context of use, to be carried out and documented by the provider."}],"exceptions":[{"id":"guidance-article-50-obvious-ai-exception-exception","operator":"not","description":"This exception does not release you from the information obligations under EU consumer protection law: the guidelines state that those obligations apply irrespective of whether the interaction is considered obvious under Article 50(1)."}],"statements":[{"kind":"official_fact","text":"The Commission guidelines of 20 July 2026 place on the provider, in point (42), the burden of assessing and demonstrating the obvious artificial nature of the interaction to a person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use. Point (43) anchors that standard in the notion of the 'average consumer' in EU consumer protection law. Point (44) prescribes a two-step assessment: first the provider considers the audience with whom the system is intended and reasonably likely to interact, then how well-informed, observant and circumspect an average member of that audience is. That same point states that the exposed audience does not always equal the target audience, that expected levels are lower where persons with disabilities, elderly people or minors are likely to be part of the audience, and that levels may be higher for an exclusively professional or specialised audience. Point (45) states that the exception should be interpreted restrictively because it deprives natural persons of the right to clear and distinguishable disclosure, that general awareness that AI systems exist does not imply that people recognise them in interactions, and that the exception should be limited to cases where there is almost no doubt left about the nature of the interaction. As examples where the exception does apply, the document lists among others code assistance chatbots available only to professional developers, an internal employee-facing assistant for properly trained and AI-literate staff, systems used only by properly trained health professionals, ambient AI embedded in home appliances, and non-playable characters in a single-player video game. As examples where the exception does not apply, the document lists a robotic companion pet closely resembling its natural equivalent, AI in immersive environments using realistic avatars or voices, and chatbots on online platforms or helpdesks whose outputs users may perceive as human-generated.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 3.2.1, points (42) to (45) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the most frequently over-claimed exception. The reasoning 'everyone knows this is a chatbot' is explicitly rejected by the guidelines: general awareness that AI exists is not the same as recognition in the actual conversation. What matters is not what your average customer knows, but who could reasonably end up at your system. As soon as your system is publicly accessible, the broader audience of elderly people, children and people with lower digital literacy is by definition included, and the exception falls away. The mirror image matters just as much and is often missed: for a strictly internal assistant used by trained staff, the Commission does expressly recognise the exception. Note the condition embedded in that example, namely that the staff are actually trained and AI-literate. That ties this exception directly to your Article 4 measures: without demonstrably AI-literate staff, the foundation for relying on the exception falls away.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 3.2.1, points (42) to (45) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Rely on this exception only for systems with a closed, professional user base, and record the two-step assessment in writing: who is the target audience, who else could reach it, and why almost no doubt remains for an average member of that audience. For anything publicly accessible, assume you must disclose. Link any internal reliance on the exception to your Article 4 file, so you can show that the staff concerned were genuinely prepared for the use of that system.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 3.2.1, points (42) to (45) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 50 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-article-50-standard-editing-exception","legacy_id":"raip:guidance:guidance-article-50-standard-editing-exception","type":"guidance","slug":"guidance-article-50-standard-editing-exception","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f1546b07eee9af5d0cecc75dfbe5f14aa1e16230be04bb1bc71fc1df8bfbd590","label":"Standard editing versus semantic change under the marking obligation","summary":"Spellchecking, formatting and minor image corrections fall outside the marking obligation. An AI summary, rewrite or face replacement falls inside it.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"guidance-article-50-standard-editing-exception-scope","operator":"all","description":"Applies to providers of AI systems generating or manipulating synthetic audio, image, video or text content, in the context of the machine-readable marking and detection obligation of Article 50(2)."}],"exceptions":[{"id":"guidance-article-50-standard-editing-exception-exception","operator":"not","description":"Alongside standard editing and non-substantial alteration, a third exception applies to generative systems authorised by law to generate or manipulate synthetic content to detect, prevent, investigate or prosecute criminal offences."}],"statements":[{"kind":"official_fact","text":"Point (90) of the guidelines of 20 July 2026 describes standard editing as the process of preparing existing content for publication or distribution, such as small edits to improve readability, grammar, quality and format, without generating new content. According to that same point, editing goes beyond standard editing where the content is changed in a material way through substantive or structural modifications that affect its meaning, style or intent. Point (91) addresses the second exception, for systems that do not substantially alter the input data provided by the deployer or the semantics thereof, and states that an alteration is substantial where the input data or its semantics have been manipulated significantly during output generation, to be assessed against factors including format, media content type, style and changes affecting meaning, style or intent. Point (92) provides that where a system can be used both for generation or manipulation and for minor non-substantial alterations, the obligation does not apply to the content altered in a minor non-substantial manner. As examples falling under the exception the document lists among others grammar correction and spellchecking, minor stylistic polishing that does not change substance or messaging, AI-generated translations, formatting and format conversion, noise reduction, minor cropping and colour corrections, removal of dust spots and red-eye, blurring of faces, rescaling of video clips and transcriptions of conversations. As examples of semantic changes that do require marking the document lists among others AI-generated summaries of text, paraphrasing or rewriting that changes style, structure and meaning, removal, replacement or insertion of objects or persons, face replacement, synthesis of realistic speech in a specific person's voice and the creation of composite images.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 4.3, points (90) to (92) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The dividing line is meaning, not effort and not whether a human was involved. That produces two outcomes that surprise many organisations. The first: an AI-generated summary sits explicitly on the marking side. Summarising feels like editing, but the guidelines classify it as semantic change. Anyone auto-generating summaries of articles, reports or case files is therefore inside the marking obligation. The second, mirror-image: an AI-generated translation sits on the exempt side, as does transcription. That is the opposite of what many editorial teams assume. Finally, note point (92): the question is not what your tool can do, but what actually happened to the content in the specific case. The same tool can fall outside the obligation in one use and inside it in another.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 4.3, points (90) to (92) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Sort your AI applications into two buckets: editing without semantic change, and producing or changing meaning. Put summarising, rewriting, image editing where persons or objects disappear or appear, and voice cloning explicitly into the second bucket, and spellchecking, formatting, translation and transcription into the first. Record the classification per application with a short justification, because the guidelines require a case-by-case assessment rather than a per-tool one.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 4.3, points (90) to (92) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 50 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-article-50-text-public-interest-scope","legacy_id":"raip:guidance:guidance-article-50-text-public-interest-scope","type":"guidance","slug":"guidance-article-50-text-public-interest-scope","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9fb49d781c2baa1dd229fae39e2ad59138943aa93e275bc0c92e554a4ffbca83","label":"Which AI text needs a label: published, informing the public, on a matter of public interest","summary":"The labelling duty for AI text applies only where three elements coincide: the text is published, is intended to inform the public, and concerns a matter of public interest.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"guidance-article-50-text-public-interest-scope-scope","operator":"all","description":"The three elements are cumulative: only where the text is published, seeks to inform the public and concerns a matter of public interest does the disclosure duty arise."}],"exceptions":[{"id":"guidance-article-50-text-public-interest-scope-exception","operator":"not","description":"The duty falls away where the AI-generated or manipulated text has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication, and where use is authorised by law to detect, prevent, investigate or prosecute criminal offences."}],"statements":[{"kind":"official_fact","text":"Point (131) of the guidelines of 20 July 2026 splits the scope of Article 50(4), second subparagraph, into three elements. Published text means the text is accessible by an indeterminate, fairly large number of unrelated potential readers simultaneously or successively, whether or not against payment such as a subscription. Text is not considered published where access is restricted to specific individuals within a closed, private group, for example a small closed group on an instant messaging app or a group that is too small or insignificant; the document cites as examples of unpublished text private interpersonal correspondence for professional purposes and organisation-internal texts or communications such as publications on internal corporate networks. Informing the public means the text intends to communicate knowledge, opinions or facts; short texts that do not materially communicate knowledge, opinions or facts cannot be deemed to inform the public. Matters of public interest are, according to that same point, generally those relevant to society at large, at local, national, Union or international level, and meriting public debate or scrutiny; the document includes texts on politics and democratic processes, public administration and services, the administration of justice and law enforcement, the protection of fundamental rights, public security, public health, environmental protection, consumer safety, and any economic, financial, political, scientific or cultural development that may be a relevant subject of public debate, noting that what counts as public interest can evolve over time and across contexts. As examples within scope the document cites an AI-generated summary of a human-authored article on a newspaper's website discussing a recent town council decision, AI-manipulated parts of a lifestyle-website article comparing the effects of various diets on a particular disease, AI-manipulated corporate reports containing investor information published on a listed company's website, and an AI-generated message on a meteorological institute's social media profile warning citizens about stormy weather and precautionary measures. Outside scope the document places among others AI-generated fantasy novels, AI-manipulated text that is part of a company's advertisement or product descriptions without claims relating to for example health, consumer safety or sustainability, a news summary generated by a chatbot that is only available to the user who prompted it, and AI-manipulated text by a consultant advising a client on measures for regulatory compliance.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 6.2.1 point (131) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The reflex is to read this as a media rule that only concerns newsrooms. The examples show otherwise. A listed company with AI-edited investor information on its own website is inside. A meteorological institute posting a storm warning on social media is inside. A lifestyle site with health claims is inside. What binds those cases is not that they are journalism, but that a broad audience draws information from them about something that affects society. The second nuance sits on the other side: an advertisement or product description falls outside, but only as long as it carries no claims about health, consumer safety or sustainability. Sustainability claims in commercial copy therefore move into scope. The third nuance is the split between internal and published: your intranet and your one-to-one correspondence fall outside, even where the content is socially relevant. And note: the presence of the AI-generated summary of a human-authored article in the example list means the automatic summary feature under a news article can by itself trigger the labelling duty.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 6.2.1 point (131) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Walk through your publication channels and flag where AI generates or substantially edits text: news items, knowledge articles, annual reports and investor information, public information and citizen warnings, and sustainability or health claims. Assess per channel whether the text is published in the sense of the guidelines, meaning accessible to an indeterminate and fairly large audience. Treat automatic summary features on articles as a separate, standalone assessment rather than as part of the underlying article.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 6.2.1 point (131) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 50 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-gpai-downstream-modifier-becomes-provider","legacy_id":"raip:guidance:guidance-gpai-downstream-modifier-becomes-provider","type":"guidance","slug":"guidance-gpai-downstream-modifier-becomes-provider","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0ed9f3418998c47b4bff2f13773c624f63b3fbf0f6fd82dcb2624899df6d5188","label":"When a downstream party that fine-tunes becomes a GPAI provider itself","summary":"Not every modification makes you a provider. The indicative threshold is a modification using more than a third of the original model's training compute, and your obligations are then limited to the modification.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"guidance-gpai-downstream-modifier-becomes-provider-scope","operator":"all","description":"Applies to downstream actors distinct from the original provider and not acting on its behalf, who modify or fine-tune a general-purpose AI model, with or without integrating it into an AI system."}],"exceptions":[{"id":"guidance-gpai-downstream-modifier-becomes-provider-exception","operator":"not","description":"If you become the provider of the modified model, obligations remain limited to the modification itself: the technical documentation covers the change, and the copyright policy and training-content summary cover only the data used in the modification."}],"statements":[{"kind":"official_fact","text":"The Commission guidelines of 18 July 2025 (C(2025) 5045 final) on the scope of the obligations for providers of general-purpose AI models state in point (61) that it is not necessary for every modification of such a model to lead to the downstream modifier being considered the provider of the modified model, in line with the Blue Guide, which states that a product subject to important changes or overhauls aiming to modify its original performance, purpose or type may be considered a new product. Point (62) states that the Commission considers a downstream modifier to become the provider of the modified model only if the modification leads to a significant change in the model's generality, capabilities or systemic risk. Point (63) sets the indicative criterion: a downstream modifier is considered to be the provider where the training compute used for the modification is greater than a third of the training compute of the original model. Point (64) states that where the downstream modifier cannot be expected to know that value, for example because it has not been communicated by the provider of the original model, and cannot estimate it, the threshold is replaced by a third of 10 to the power of 25 FLOP where the original model is a model with systemic risk, and otherwise by a third of 10 to the power of 23 FLOP. Point (65) explains that a modification of that size is expected to display a significant change justifying the transparency obligations of Article 53(1)(a) and (b), that such a modification can be expected to have used a significant amount of data relevant to the copyright policy and the public summary of training content under Article 53(1)(c) and (d), and that where the original model has systemic risk the modified model can be expected to present significantly different systemic risk. Point (67) notes that currently few modifications meet this criterion, that the number of downstream modifiers becoming providers may increase over time, and that the criterion is thus primarily forward-looking. Point (68) states that in the case of a modification the obligations are limited to that modification: the documentation under Article 53(1)(a) and (b) is limited to information on the modification, and the copyright policy under point (c) and the summary of training content under point (d) are limited to the data used as part of the modification. Point (69) states that a downstream modifier who becomes a provider must also comply with Article 54, which means appointing an authorised representative established in the Union to the extent that the modifier is itself established outside the Union. Point (70) states that where a downstream actor modifies a model classified as having systemic risk in such a way that they become the provider of the modified model, the resulting model is presumed to have high-impact capabilities and is therefore considered a model with systemic risk, and point (71) states that the modifier must then comply with the obligations for providers of models with systemic risk and notify the Commission in line with Article 52(1).","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, Section 3.2 points (60) to (67) and Sections 3.2.1 and 3.2.2, points (68) to (71)","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The practical message is more reassuring than most organisations expect, with one catch. Ordinary fine-tuning on your own documents, RAG, prompt engineering or a LoRA adapter comes nowhere near a third of the training compute of a large base model. The Commission itself says that few modifications currently meet the criterion. Anyone adapting a model for their own use therefore generally does not become a GPAI provider. The catch sits in point (64): if you do not know the original model's training compute and cannot estimate it, you fall back on an absolute threshold of a third of 10 to the power of 23 FLOP. That is a considerably lower bar than a third of a large model, and with closed models whose compute is not published, that is exactly the scenario you are in. The second trap is the systemic-risk chain: if you modify a model already designated as having systemic risk and thereby become a provider, you inherit that label and the duty to notify the Commission. On the positive side, obligations in that case remain limited to your own modification: you do not have to reproduce the original model's documentation or training-content summary.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, Section 3.2 points (60) to (67) and Sections 3.2.1 and 3.2.2, points (68) to (71)","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record per modified model which base model you use, which modification method you apply and how much compute that modification consumed, so you can test the criterion rather than speculate about it. Ask the base model's provider for the training compute and document the answer, because if you cannot know that value you fall back on the considerably lower absolute threshold. Also check whether the base model is designated as having systemic risk, because that changes both the threshold and the consequences of crossing it. Reassess this judgement at every substantial retraining, since the Commission itself indicates that the number of downstream modifiers becoming providers is expected to grow.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, Section 3.2 points (60) to (67) and Sections 3.2.1 and 3.2.2, points (68) to (71)","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 53 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-annex-i-lists-legislation-not-products","legacy_id":"raip:guidance:guidance-high-risk-annex-i-lists-legislation-not-products","type":"guidance","slug":"guidance-high-risk-annex-i-lists-legislation-not-products","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"3fd1da47cb4c99a33d5e7595a433bec0d9a5c1686b866fc247c7b1bb499b6864","label":"Annex I lists legislation, not products","summary":"Annex I contains no list of high-risk products but an exhaustive list of harmonisation legislation. The AI Act does not extend the scope of that product legislation and does not change a product's risk profile.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The draft guidelines of 19 May 2026, published for consultation and expressly non-binding, clarify that Annex I AI Act does not list individual products to be classified as high-risk, but Union harmonisation legislation regulating the safety aspects of certain products. Whether an AI system falls within the scope of Annex I therefore depends on whether the system, or the product of which it is a safety component, falls within the material scope of one of the listed legislative acts. According to the draft guidelines the list in Annex I is exhaustive; products can only be added or removed by amending the scope of the harmonisation legislation itself or by adding new harmonisation legislation to Annex I. The draft guidelines also state that through Article 6(1) the AI Act does not itself extend the scope of harmonisation legislation to new or additional products, and that the AI Act does not determine or change the risk profile of a product but builds on the sectoral risk classification. Products mentioned include machinery, toys, lifts, equipment and protective systems for potentially explosive atmospheres, radio equipment, pressure equipment, recreational craft, cableway installations, appliances burning gaseous fuels, medical devices, in vitro diagnostic medical devices, and products in the automotive and aviation sectors.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (23) to (26)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Your starting point is therefore not the AI Act but your existing product file. The question is not whether your product appears on an AI list, because no such list exists. The question is whether your product already fell under one of the listed regulations or directives before AI was added to it. If not, this route does not bring you into the high-risk regime, however advanced the AI system is. The draft guidelines do note that for this classification the concept of safety component may be read as excluding public interests in the sectoral legislation that go beyond health, safety and fundamental rights, such as risks relating to radio spectrum use or electromagnetic compatibility. Those interests therefore do not contribute to the qualification.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (23) to (26)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Start your classification with an inventory of the product legislation that already applies to your portfolio today, and record per product line which regulation or directive covers you. That overview is reusable and prevents you from redoing the entire analysis for each AI feature.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (23) to (26)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-annex-i-section-a-versus-section-b","legacy_id":"raip:guidance:guidance-high-risk-annex-i-section-a-versus-section-b","type":"guidance","slug":"guidance-high-risk-annex-i-section-a-versus-section-b","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"3f1e607c8b0c4c04678119a5b3c69fe5a732c7c91393a9ddd0947ec82fbbd277","label":"Section A and Section B of Annex I trigger different requirement sets","summary":"For products under Section A of Annex I the full set of high-risk requirements applies. For Section B only Article 6(1), Articles 102 to 109 and Article 112 apply.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026, which are non-binding as long as the final version has not been adopted, draw a distinction that is often missed in practice. AI systems classified as high-risk under Article 6(1) in respect of products covered by the harmonisation legislation in Section A of Annex I are subject to the requirements for high-risk systems in Section 2 of Chapter III AI Act. By contrast, for AI systems classified as high-risk under Article 6(1) in respect of products covered by the harmonisation legislation in Section B of Annex I, only Article 6(1), Articles 102 to 109 and Article 112 AI Act apply. The draft guidelines refer to Article 2(2) AI Act for this. Section A contains harmonisation legislation based on the New Legislative Framework, Section B the other Union harmonisation legislation.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, point (60), referring to Article 2(2) AI Act","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This distinction determines the size of your project. Two organisations can both correctly conclude they have a high-risk AI system and still face a completely different work package. If you are in Section A, the full set applies: risk management system, data quality, technical documentation, logging, transparency towards deployers, human oversight, accuracy and robustness. If you are in Section B, the requirement set is materially narrower. So check first which section your legislation sits in, before you set budget and planning.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, point (60), referring to Article 2(2) AI Act","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"In your classification note, record not only that you fall under Annex I but also under which section. Attach the corresponding requirement set immediately, so that your project plan is correctly sized from the outset.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, point (60), referring to Article 2(2) AI Act","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-annex-i-two-cumulative-conditions","legacy_id":"raip:guidance:guidance-high-risk-annex-i-two-cumulative-conditions","type":"guidance","slug":"guidance-high-risk-annex-i-two-cumulative-conditions","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"da0604d8c4d9bc6e309a1ff0bd7cf963a65eac7ddb309e26d69a2ff6533f417e","label":"Two cumulative conditions for high-risk under Annex I","summary":"An AI system only becomes high-risk under Article 6(1) when two conditions are met at the same time: the system is itself a regulated product or a safety component of one, and that product must undergo third-party conformity assessment.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The European Commission draft guidelines of 19 May 2026, which are expressly non-binding and not final, read Article 6(1) as two cumulative conditions. First, the AI system must be intended to be used as a safety component of a product, or the AI system must itself be a product, covered by the Union harmonisation legislation listed in Annex I. Second, that product, or the AI system itself where it is the product, must be required to undergo a third-party conformity assessment. The draft guidelines state explicitly that not all AI systems that are components of regulated products are high-risk, but only the subset that satisfies both criteria.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (27) and (21)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is a filter with two screens, and both must be passed. In practice organisations stop at the first screen and conclude their product is high-risk simply because sectoral product legislation applies to it. That is premature. The second screen, mandatory third-party involvement, removes a substantial share. The reverse also holds: anyone who looks only at the CE route and skips the safety component question will miss systems that only enter through the failure route. You must therefore ask both questions separately and record both answers.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (27) and (21)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For every AI system in a regulated product, record a two-part classification note: first whether the system is a product or a safety component, then whether a third party must be involved for that product. Keep both answers with their reasoning in your technical documentation, so that during an audit you do not have to reconstruct after the fact why you reached your conclusion.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (27) and (21)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-article-6-3-filter-mechanism","legacy_id":"raip:guidance:guidance-high-risk-article-6-3-filter-mechanism","type":"guidance","slug":"guidance-high-risk-article-6-3-filter-mechanism","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"d6fc330373b2b9b704080d8d34c00f20be28c6ee7ba1357e09733209bdfd75ef","label":"The Article 6(3) filter: four exhaustive grounds, to be read narrowly","summary":"A system falling within Annex III can still stay outside high-risk if one of four grounds is met and the system does not perform profiling. The provider makes that call itself, must document the assessment before placing the system on the market, and must register the system in the EU database.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"According to the non-binding draft guidelines of 19 May 2026 on the classification of high-risk AI, Article 6(3) sets out four grounds on which a provider may exempt a system from high-risk classification: performing a narrow procedural task, improving the result of a previously completed human activity, detecting decision-making patterns or deviations from prior patterns without replacing or influencing the previously completed human assessment absent proper human review, and performing a preparatory task. Paragraph (88) of this draft states these grounds are exhaustive but alternative, that there is no separate independent risk test, and that they must be interpreted narrowly because Article 6(3) is an exception to rules that among other things protect fundamental rights. Paragraph (87) states the filter applies only to systems under Article 6(2) and not to systems under Article 6(1). Paragraph (89) states a system always remains high-risk where it performs profiling. Paragraph (90) adds that the filter does not apply where the system forms part of a complex system whose combined intended purpose or joint outputs materially influence an individual decision, including agentic AI. Paragraphs (113) to (116) of this draft describe that this is a self-assessment by the provider, that Article 6(4) requires documenting the assessment before placing on the market and registering in the Article 71 EU database, and that the assessment must contain at least the intended purpose, why the system falls under Article 6(2), which Article 6(3) condition applies and why, and why the system does not perform profiling. Paragraph (117) of these draft guidelines points to Articles 80 and 99 where an authority finds a system was misclassified as non high-risk to circumvent the rules.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), Annex III chapter, sections 2.7, 2.7.1, 2.7.3 and 2.7.4, paragraphs (84) to (90) and (113) to (117)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The filter is not a soft way out but a documented and visible decision. You leave the Chapter III high-risk obligations, but in exchange you appear in the public EU database and your reasoning must be available to the regulator at any time. For buyers that is a gift: the draft guidelines expressly encourage deployers to check that database to see whether a vendor relies on the exception.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), Annex III chapter, sections 2.7, 2.7.1, 2.7.3 and 2.7.4, paragraphs (84) to (90) and (113) to (117)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Write the filter file in four fixed blocks: intended purpose, why it falls under Annex III, which ground you invoke with reasoning, and why there is no profiling. Never rely on the filter because the risk feels low, since that free-standing test does not exist. When procuring, always check the EU database before believing a vendor who says its system is not high-risk.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), Annex III chapter, sections 2.7, 2.7.1, 2.7.3 and 2.7.4, paragraphs (84) to (90) and (113) to (117)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-article-6-two-routes","legacy_id":"raip:guidance:guidance-high-risk-article-6-two-routes","type":"guidance","slug":"guidance-high-risk-article-6-two-routes","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5b469bba143ed5b34c1afab440aee9ca78c70f2d513b65ee8c21990ecb393de7","label":"Article 6 has two separate routes to high-risk","summary":"An AI system can be high-risk in two ways. Either it is itself a product, or a safety component of a product, covered by the Annex I product legislation and that product must undergo third-party conformity assessment (Article 6(1)). Or it falls within one of the use cases listed in Annex III (Article 6(2)). The two routes have their own criteria and their own application dates.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The European Commission's draft guidelines on the classification of high-risk AI of 19 May 2026, which are expressly non-binding, state in paragraph (7) that an AI system is high-risk in two scenarios: first, where it is intended to be used as a safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in Annex I and required to undergo third-party conformity assessment; and second, where it falls within one of the use cases in the areas listed in Annex III. Paragraph (448) of those same draft guidelines notes that the Article 113 application dates have been postponed by the AI Omnibus to 2 December 2027 for the Article 6(2) route and 2 August 2028 for the Article 6(1) route.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II, paragraph (7); section V, paragraph (448)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The two routes are not interchangeable. The Annex I route turns on product legislation and on whether a third party must assess conformity, not on whether the system assesses people. The Annex III route turns on intended purpose and use case. A system can in theory touch both routes, but you must work through them separately. The exemption mechanism also differs: under the draft guidelines the Article 6(3) filter applies only to the Annex III route and not to the Annex I route.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II, paragraph (7); section V, paragraph (448)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each AI system, record in your register which route you assessed and with what outcome. Start with the Annex I question where hardware, machinery, medical devices or toys are involved, and with the Annex III question where the system touches people or access to services. Plan your programme against the earlier of the two dates that applies to you.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II, paragraph (7); section V, paragraph (448)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-broad-marketing-and-gpai-systems","legacy_id":"raip:guidance:guidance-high-risk-broad-marketing-and-gpai-systems","type":"guidance","slug":"guidance-high-risk-broad-marketing-and-gpai-systems","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"81fc87af44dd5631c6f242e98843aada30a807c4dcf29a9aafaa85879df1c01a","label":"Broadly positioned and general purpose AI systems: a disclaimer is not enough","summary":"If you market a system broadly without consistently limiting its application, high-risk use cases will be read into its intended purpose. Merely stating in the terms of service that high-risk uses are excluded is insufficient where the rest of your presentation in fact enables or promotes such uses.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"According to the non-binding draft guidelines of 19 May 2026 on the classification of high-risk AI, paragraph (12) provides that where the instructions for use, contractual arrangements, terms of service, usage policy, promotional and sales materials or technical documentation present the AI system as broadly applicable across a generality of contexts and functions, and do not consistently limit its application or exclude high-risk uses, the system's intended purpose will be deemed to also encompass high-risk use cases and therefore qualify as high-risk. Under these draft guidelines this applies in particular where such uses are feasible and reasonably foreseeable given the system's functionalities and capabilities. The same paragraph states that merely asserting, for example in the terms of service, that high-risk uses are excluded is insufficient where the provider's overall presentation, examples or product positioning effectively provides for or promotes such uses, and that any limitations of use must be described clearly, concretely and coherently across all materials.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraph (12)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This mainly affects providers of broad assistants, agents and platforms who say the product is not meant for HR, education or credit assessment, but show demos, templates or customer stories in exactly those contexts. The draft guidelines look at the whole of your communications, not at the strictest sentence in the small print. For buyers it means a vendor hiding behind a clause does not relieve you of your own assessment.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraph (12)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"If you genuinely want to exclude high-risk use, make that real in the product and not only on paper. Remove demos and examples in excluded domains, build technical or contractual blocks, and make sure sales, website and documentation draw the same line. If you cannot sustain that, assume high-risk and build your evidence file accordingly.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraph (12)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-classification-is-not-permission","legacy_id":"raip:guidance:guidance-high-risk-classification-is-not-permission","type":"guidance","slug":"guidance-high-risk-classification-is-not-permission","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"10104adb4730a287ecda1ce0947349ec478e5cc9d9d911bf13da50045befa6fb","label":"High-risk does not mean prohibited, and not high-risk does not mean permitted","summary":"Classification answers one question: which Chapter III obligations apply. It says nothing about whether the use itself is lawful. Prohibited practices, data protection, consumer law, product safety and national law continue to apply in full.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The draft guidelines of 19 May 2026 on the classification of high-risk AI, which are not binding, state in paragraph (3) that the fact an AI system is listed as an example in these guidelines does not mean its use should automatically be considered lawful, since such use would still need to comply with other applicable legislation, and in paragraph (4) that the scope of these guidelines is limited to whether an AI system is high-risk or not. In the Annex III chapter of this draft, paragraph (68) states that classifying systems as high-risk under Article 6(2) does not mean their use is prohibited, but that those systems are subject to appropriate requirements. Paragraphs (82) and (83) of this draft explain the wording in so far as their use is permitted under relevant Union or national law and state that falling within a use case does not necessarily mean the system may lawfully be used in those cases, that in addition to the prohibitions other provisions of Union or national law may restrict use, and that under Article 2(9) the AI Act applies without prejudice to rules on consumer protection, product safety and data protection.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, paragraphs (3) and (4); Annex III chapter, paragraph (68) and section 2.6, paragraphs (82) and (83)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This removes two errors of reasoning. The first is that a high-risk label equals a ban, which stops projects unnecessarily. The second, and the more dangerous one, is that an outcome of not high-risk means you have a free hand. A system can fall outside high-risk and at the same time be a prohibited practice, or fail on data protection or sector rules.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, paragraphs (3) and (4); Annex III chapter, paragraph (68) and section 2.6, paragraphs (82) and (83)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Run the classification test and the lawfulness test as two separate steps and record both outcomes separately. Always test first against the Article 5 prohibited practices, enforceable since 2 February 2025, and only then against Article 6. Finish with a short check on data protection and sector-specific law, even where the system turns out not to be high-risk.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, paragraphs (3) and (4); Annex III chapter, paragraph (68) and section 2.6, paragraphs (82) and (83)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-complex-and-agentic-systems","legacy_id":"raip:guidance:guidance-high-risk-complex-and-agentic-systems","type":"guidance","slug":"guidance-high-risk-complex-and-agentic-systems","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"e272b329ca696236a70acdbff8f97585e4b61e1b22565101e8694ca61a7f4a2c","label":"Split and agentic architectures are assessed as a whole","summary":"You cannot avoid classification by splitting a high-risk function into separate modules. The draft assesses the combined configuration.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The non-binding draft guidelines of 19 May 2026 provide in paragraphs 75, 76 and 90 that where several AI systems form part of a more complex whole and their combined intended purpose or joint outputs materially influence an individual decision, that configuration is treated as a single AI system for classification. The draft expressly states that split architectures are assessed as a whole to prevent circumvention by system design, that exemptions for individual modules do not apply where the overall configuration influences key aspects of the decision, and that this also extends to complex interconnected setups such as agentic AI systems whose linked actions jointly serve a high-risk purpose. Under the same draft, strictly procedural or preparatory functions do remain eligible for exemption where they are genuinely separable from the system and do not structure or feed outputs that materially influence the examination of an individual case.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.3, paragraphs 75 and 76, and section IV.2.7.1 paragraph 90","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This hits modern architecture head-on: a chain of agents, tools and model calls. Four subsystems that are each neatly preparatory on their own still form a high-risk system once the chain in practice drives the decision.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.3, paragraphs 75 and 76, and section IV.2.7.1 paragraph 90","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Assess at chain level, not component level. Record where separability genuinely lies, and show the exempted module can be put into service independently without contributing to the high-risk purpose.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.3, paragraphs 75 and 76, and section IV.2.7.1 paragraph 90","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-filter-documentation-and-registration","legacy_id":"raip:guidance:guidance-high-risk-filter-documentation-and-registration","type":"guidance","slug":"guidance-high-risk-filter-documentation-and-registration","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7234971feba6fc42df535faf220f4b3aadca4a744b6d41564a4441545e4ba01a","label":"Relying on the exception requires documentation and registration","summary":"The exception is a provider self-assessment, but not a free pass. The draft sets out four mandatory components of the assessment and links registration and supervision to it.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The draft guidelines of 19 May 2026 are not binding and describe in paragraphs 113 to 117 that applying the filter mechanism depends on a provider self-assessment, that the assessment must be documented before the system is placed on the market or put into service, and that the system must be registered in the EU database under Article 71 to ensure traceability of exempted systems. Under the draft, the assessment must contain four components: a description of the intended purpose, a description of why the system would qualify as high-risk under Article 6(2), a description of which condition or conditions of Article 6(3) are considered to apply and why, and a description of why the system does not perform profiling. The record must be available at any time on request of the market surveillance authority, and the draft encourages deployers to verify use of the exception in the Article 71 database as part of their due diligence. The draft further notes that market surveillance authorities may under Article 80 evaluate the classification, require the system to be brought into compliance and demand corrective action, and may impose penalties under Article 99 where a system was misclassified to circumvent the high-risk requirements.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Sections IV.2.7.3 and 2.7.4, paragraphs 113 to 117","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The exemption shifts the work, it does not remove it. You trade the full Chapter III regime for a documented and publicly traceable justification that a supervisor can request and challenge. For deployers, the database is conversely a procurement check.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Sections IV.2.7.3 and 2.7.4, paragraphs 113 to 117","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Build one fixed template covering the four mandatory components and date the assessment before market introduction. In procurement, always ask whether the supplier relies on Article 6(3) and whether that appears in the Article 71 database.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Sections IV.2.7.3 and 2.7.4, paragraphs 113 to 117","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-filter-four-conditions","legacy_id":"raip:guidance:guidance-high-risk-filter-four-conditions","type":"guidance","slug":"guidance-high-risk-filter-four-conditions","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5ebf775e247fe97fee67dba869fa855a95df9d16f8ec7a817fbf080597a1e753","label":"The Article 6(3) filter: four alternative conditions, to be read narrowly","summary":"A system that falls within an Annex III use case can still escape high-risk classification if it meets one of four conditions. The draft guidelines make clear this is not a broad escape route.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"According to the European Commission's draft guidelines of 19 May 2026, which are not binding and were published for stakeholder consultation, the following applies (paragraphs 84 to 90): the filter mechanism only works for systems that would be high-risk under Article 6(2) and Annex III, not for systems that are high-risk under Article 6(1) and Annex I; the four conditions (narrow procedural task, improving the result of a previously completed human activity, detecting decision-making patterns or deviations without replacing or influencing the previously completed human assessment without proper human review, and preparatory task) are exhaustive but alternative; there is no separate, independent risk test alongside those conditions; and because Article 6(3) is an exception to rules that also protect fundamental rights, the conditions must be interpreted narrowly and always read in light of the requirement that the system does not materially influence the outcome of decision-making.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Sections IV.2.7 and 2.7.1, paragraphs 84 to 90","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The practical question is not whether your system feels low risk, but whether it demonstrably fits one of the four described task types. The absence of a separate risk test cuts both ways: you do not need to make a general risk assessment, but you also cannot invoke one when none of the four conditions fits.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Sections IV.2.7 and 2.7.1, paragraphs 84 to 90","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each system, set out which of the four conditions you rely on and why, in the document's own vocabulary. If you rely on more than one, name each separately. If the reasoning feels strained, assume the narrow reading works against you and treat the system as high-risk.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Sections IV.2.7 and 2.7.1, paragraphs 84 to 90","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-human-involvement-does-not-declassify","legacy_id":"raip:guidance:guidance-high-risk-human-involvement-does-not-declassify","type":"guidance","slug":"guidance-high-risk-human-involvement-does-not-declassify","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"e0dab5a5fe2940b50bf147b06dee417a119fbe3888f65e39c8df060913aebfea","label":"A human in the loop does not make a system low-risk","summary":"Human involvement does not change the intended purpose and therefore has no effect on classification under Article 6(2). Human oversight is a compliance requirement for high-risk systems, not an escape from the classification.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The draft guidelines of 19 May 2026 on the classification of high-risk AI, which are not binding, state in paragraph (70) that the only relevant determinant for qualification under Article 6(2) is whether the intended purpose of the system includes one of the use cases listed in Annex III, that human involvement cannot change the purpose and area in which a system is intended to be used, and that human involvement therefore has no effect on classification. The same paragraph states that human oversight is instead a prerequisite for compliance with the rules for high-risk systems under Article 14. Paragraph (71) of this draft adds that the type and degree of human involvement may play a role for the Article 6(3) filter, but only to demonstrate that the tasks are narrow procedural or preparatory in nature or that the system only improves a previously completed human activity, and that a provider cannot categorise a system as low risk simply by adding a requirement of human involvement.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), Annex III chapter, section 2.1, paragraphs (70) and (71)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This defeats the most common defence in practice, namely that a human always looks at it anyway. That sentence changes nothing about the classification. Human involvement only becomes relevant when you can show that the system itself plays no more than a narrow procedural or preparatory role, and that is a far heavier test than an approval button.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), Annex III chapter, section 2.1, paragraphs (70) and (71)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Delete the sentence that a human is in the loop from your classification reasoning. Instead describe exactly what the system does in the decision process and at what moment. Use the degree of human involvement only as support within one of the four Article 6(3) grounds, and keep evidence that the review is genuinely substantive.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), Annex III chapter, section 2.1, paragraphs (70) and (71)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-human-oversight-no-declassification","legacy_id":"raip:guidance:guidance-high-risk-human-oversight-no-declassification","type":"guidance","slug":"guidance-high-risk-human-oversight-no-declassification","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9124b610886a642919da8ee9b2e63bae08e06271624198ce5721f6c5683b10fb","label":"A human in the loop does not make a system low-risk","summary":"Human oversight is a compliance requirement for high-risk systems, not a way to escape classification. Human involvement only counts when determining what task the system performs.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"In the non-binding draft guidelines of 19 May 2026, the Commission states in paragraphs 70 and 71 that classification under Article 6(2) depends solely on whether the system's intended purpose falls within an Annex III use case. Human involvement cannot change the purpose and area of intended use and therefore has no effect on that classification; human oversight is instead a condition for compliance under Article 14. Under the draft, the type and degree of human involvement can play a role in the filter mechanism, but only to demonstrate that the system's tasks are narrow procedural or preparatory in nature, or merely improve a previously completed human activity. The draft expressly adds that a provider cannot label a system as low-risk simply by adding a human involvement requirement to it.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.1, paragraphs 70 and 71","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The common reassurance that a human always reviews the output changes nothing about classification. In fact, the document's examples dismiss formal human review precisely where the output in practice weighs heavily on the outcome.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.1, paragraphs 70 and 71","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Base your classification on the intended purpose, not on your workflow. If you want to use human involvement in the argument, tie it to the system's task type and show the human assessment is substantive and complete, not a formality.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.1, paragraphs 70 and 71","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-improve-not-review","legacy_id":"raip:guidance:guidance-high-risk-improve-not-review","type":"guidance","slug":"guidance-high-risk-improve-not-review","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"656a4e99b759d1c8c8dd12d60ae912d80508379745a885f99fa72e1e825b230b","label":"Improving is deliberately different from reviewing","summary":"The second condition requires a completed human activity with a result that the system only refines. A materially different outcome does not qualify.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The draft guidelines of 19 May 2026 are a non-binding draft and state in paragraphs 94 to 96 that Article 6(3)(b) requires three cumulative elements: a human activity that has been completed, a result flowing from it, and improvement of that result by the AI system. The system may therefore not replace or autonomously perform the human activity. The draft notes the EU legislature deliberately chose the word improve rather than review, so the system must not be intended to provide a materially different result but to verify or refine the activity, and that any improvement must not change the rights, protection, legal or economic position of the persons affected. As an example that does not qualify, the draft cites a system that checks a human-made decision, plan or construction and provides a substantially different solution. As examples serving an auxiliary improvement function, the draft cites systems that flag errors or contradictions in finalised human work as quality assurance, systems that map conclusions to evidentiary records to strengthen traceability of a decision without substituting human judgment, and systems that convert human-validated content for interoperability or accessibility purposes.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.7.1(b), paragraphs 94 to 96","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This condition is narrower than it sounds. A writing assistant that sharpens the wording of a completed judgment fits; a second-opinion model that redoes the judgment does not, however useful it may be substantively.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.7.1(b), paragraphs 94 to 96","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Make the sequence in your process demonstrable: the human judgment is recorded first, only then does the system act. Record that scores, conclusions and outcomes are not altered by the system.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.7.1(b), paragraphs 94 to 96","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-intended-purpose-is-the-anchor","legacy_id":"raip:guidance:guidance-high-risk-intended-purpose-is-the-anchor","type":"guidance","slug":"guidance-high-risk-intended-purpose-is-the-anchor","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"8f7455feefe96374d1cb47b4dc57d2d947ef8ef83fd2cd04797cf00177b3eb33","label":"Intended purpose is the anchor of classification","summary":"Intended purpose determines whether a system is high-risk. That purpose is set not only by the technical documentation but also by the instructions for use, promotional materials, sales materials and statements by the provider. Reasonably foreseeable misuse falls by definition outside the intended purpose.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The draft guidelines of 19 May 2026 on the classification of high-risk AI, which are not binding, state in paragraph (10) that the intended purpose of an AI system plays an important role in its classification as high-risk, and that under Article 3(12) intended purpose is the use for which the provider intends the system, including the specific context and conditions of use, as specified in the instructions for use, promotional or sales materials, statements and technical documentation. Paragraph (11) of that draft adds that providers must clearly describe the envisaged use, including the system's functionalities, leaving no ambiguity as to scope and intended use. Paragraph (13) of these draft guidelines places the assessment with the provider, supervised by the competent market surveillance authorities.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraphs (10), (11) and (13)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Marketing is legal material here. What your website, sales deck or demo promises counts towards establishing the intended purpose, even if the technical documentation is more cautious. A gap between what the system does in practice and how its purpose is described will not protect you.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraphs (10), (11) and (13)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Have one owner for the intended-purpose description and review the instructions for use, technical documentation, website, sales material and demo scripts against each other annually. Also describe explicitly which contexts and applications are and are not intended, and keep that wording identical across all channels.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraphs (10), (11) and (13)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-must-first-be-an-ai-system","legacy_id":"raip:guidance:guidance-high-risk-must-first-be-an-ai-system","type":"guidance","slug":"guidance-high-risk-must-first-be-an-ai-system","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"eb62d3811c86970025c6b5235267569779e7a3149fe73059a242756c17a2368f","label":"First the definition question: is it an AI system at all?","summary":"Before classification comes into play, the system must meet the definition of an AI system in Article 3(1). Not every software application and not every automated decision-making system falls within the AI Act.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"According to the non-binding draft guidelines of 19 May 2026 on the classification of high-risk AI, before a system can be classified as high-risk it must first qualify as an AI system within the meaning of Article 3(1) of the AI Act (paragraph 8). Paragraph (9) of that draft states expressly that not every software application or automated decision-making system falls within the scope of the regulation, and refers for the interpretation of the definition to the separate guidelines on the definition of an AI system (C(2025) 5053).","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.1, paragraphs (8) and (9)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is a genuine preliminary question, not a formality. Classic rule-based software, fixed calculation rules and simple automation that does not infer from input how to generate output never reach the classification question. At the same time this is not an escape route: the definition guidelines are broad and in practice the burden of showing that something falls outside the definition rests on you.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.1, paragraphs (8) and (9)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Include an explicit definition-test field in your AI register, with the reasoning why a system is or is not an AI system. Run that test before you invest time in the Annex I or Annex III analysis, and record the result so you can show it during an inspection.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.1, paragraphs (8) and (9)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-natural-persons-scope","legacy_id":"raip:guidance:guidance-high-risk-natural-persons-scope","type":"guidance","slug":"guidance-high-risk-natural-persons-scope","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"4e7381817402e04bb3dd0998f913b3b24106a92090aad3a0fad3fffc67011457","label":"Only the assessment of natural persons falls within these use cases","summary":"Systems assessing only legal persons fall outside the relevant Annex III use cases. Self-employed people and sole traders do count as natural persons, however.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The draft guidelines of 19 May 2026, published as a non-binding draft, clarify in paragraphs 72 to 74 that a natural person is distinct from a legal person and that the notion is not limited to consumers: sole traders, independent professions and other self-employed persons also count as natural persons in relation to their commercial activity, including persons acting in a professional capacity such as consultants, designers and journalists. A system that assesses natural persons falls within the use case regardless of whether it also assesses legal persons; systems intended only to assess legal persons or companies fall outside it. The draft gives as an example that a system assessing the creditworthiness of companies based on company data, balance sheets and financial statements does not qualify as evaluating a natural person, and that an owner assessed to back a company loan also falls outside point 5(b) because the company, not the individual, is the primary beneficiary of the credit.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.2, paragraphs 72 to 74","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The boundary does not run along sector or sensitivity, but along who is being assessed. Watch the trap on the other side: as soon as your B2B system also assesses freelancers and sole traders, you are back inside the use case.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.2, paragraphs 72 to 74","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"State unambiguously in the intended purpose whether natural persons are part of the assessed population. Exclude that use contractually and technically if you want to stay outside the use case, because mixed use pulls the whole system in.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.2, paragraphs 72 to 74","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-preparatory-versus-decisive","legacy_id":"raip:guidance:guidance-high-risk-preparatory-versus-decisive","type":"guidance","slug":"guidance-high-risk-preparatory-versus-decisive","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5949170ab144d33aebcd0c63bafdfb84bcb158968ee437e2f0b691b532c4aada","label":"Preparatory or decisive: general input is allowed, a specific recommendation is not","summary":"The preparatory task under Article 6(3)(d) precedes the assessment. Once the system evaluates the specific case or makes a recommendation, the exception is gone.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"According to the non-binding draft guidelines of 19 May 2026, the notion of preparatory in Article 6(3)(d) refers to tasks occurring prior to the actual assessment process, which distinguishes it from the narrow procedural task in point (a) that may also occur during the assessment as long as it is clearly delimited (paragraphs 103 and 104). The draft cites as examples from Recital 53 indexing, searching, processing and linking: tasks that add structure to the input but do not themselves provide an assessment leading to an outcome (paragraph 106). Under paragraph 107, the decisive factor is the task's role in the decision-making process and its proximity to the final human decision. Paragraph 108 adds that output feeding a human operator's assessment can only be preparatory if it is a general input or supplementary information, and that a system producing a specific recommendation or evaluation of the case plays a decisive role and is therefore not preparatory.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.7.1(d), paragraphs 103 to 108","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The dividing line is workable in practice: laying out information is allowed, interpreting the case is not. A system that surfaces legal provisions, jurisdiction and internal guidance stays preparatory; the same system drawing a conclusion for this file no longer is.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.7.1(d), paragraphs 103 to 108","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Test your system on one question: does the output produce anything specific to this case that points towards an outcome? If so, assume high-risk. Where possible, build a hard separation between information retrieval and assessment logic.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.7.1(d), paragraphs 103 to 108","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-profiling-blocks-filter","legacy_id":"raip:guidance:guidance-high-risk-profiling-blocks-filter","type":"guidance","slug":"guidance-high-risk-profiling-blocks-filter","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"de66ad718cdb5bc2e7ffd33ce48de1951647c3988431407e26b500ef41a92521","label":"Profiling always blocks the exception, even when a condition would otherwise fit","summary":"As soon as the system profiles, the Article 6(3) exemption is ruled out. The draft guidelines give three cumulative elements against which you test this.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The draft guidelines of 19 May 2026, which are a non-binding draft document, explain in paragraphs 89 and 109 to 112 that a system listed in Annex III always remains high-risk where it performs profiling within the meaning of Article 4(4) GDPR, Article 3(4) of Directive (EU) 2016/680 or Article 3(5) of Regulation (EU) 2018/1725. Under the draft, profiling consists of three cumulative elements: automated processing, carried out on personal data, with the objective of evaluating personal aspects relating to a natural person. The draft states the first element is always satisfied for AI systems, so the provider must mainly establish whether personal data form the input and whether personal aspects are being evaluated. The draft adds that a simple classification on characteristics such as age, sex or height does not automatically amount to profiling, because a form of prediction, assessment or inference must be present.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.7.1 paragraph 89 and section IV.2.7.2, paragraphs 109 to 112","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The profiling bar is the sharpest brake on the filter mechanism. Many systems that at first sight perform a tidy preparatory or procedural task still fail here because along the way they predict or judge something about a person. Note that this may be a person other than the subject of the decision, for example the assessor themselves.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.7.1 paragraph 89 and section IV.2.7.2, paragraphs 109 to 112","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"State explicitly in your file which data the system ingests, whether those are personal data, and whether a prediction, score or inference about a person arises anywhere. Consider anonymisation or aggregation at source if you want to preserve the exception.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.7.1 paragraph 89 and section IV.2.7.2, paragraphs 109 to 112","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-safety-component-autonomous-definition","legacy_id":"raip:guidance:guidance-high-risk-safety-component-autonomous-definition","type":"guidance","slug":"guidance-high-risk-safety-component-autonomous-definition","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c929f0dcf3a5d6c5e0133edcbe649b200e7fa07453e03961c6a2e1a0255eae8a","label":"Safety component is an autonomous AI Act concept","summary":"For classification purposes only the definition of safety component in Article 3(14) AI Act counts. Definitions of the same term in sectoral product legislation are not relevant here.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"According to the draft guidelines of 19 May 2026, which are non-binding and may still change, the definition of safety component in Article 3(14) AI Act is an autonomous definition with its own meaning, independent of definitions of safety component in other Union harmonisation legislation. The draft guidelines state that this definition ensures uniform interpretation of the concept across all sectors covered by Annex I, and that in assessing whether an AI system is a safety component only Article 3(14) AI Act is relevant, not the definition in any legislation listed in Annex I. Article 3(14) describes a safety component as a component of a product or of an AI system which fulfils a safety function for that product or AI system, or the failure or malfunctioning of which endangers the health and safety of persons or property.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (32) and (33)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the most underestimated pitfall in the entire chapter. Many technical teams have worked for years with the notion of safety component as defined by their own sectoral standard, for instance in the machinery tradition or the medical devices world. That reflex produces the wrong outcome. The AI Act concept is broader than many sectoral definitions, precisely because it includes the failure route. A component that has never been designated a safety component in your sectoral file may well be one under the AI Act.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (32) and (33)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Run the safety component test again using only the text of Article 3(14), even if your product has had a sectoral safety file for years. Have a second reviewer who is not steeped in the sectoral tradition read along, because that person will more readily spot where the AI Act is broader than your habit.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (32) and (33)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-safety-function-versus-failure-route","legacy_id":"raip:guidance:guidance-high-risk-safety-function-versus-failure-route","type":"guidance","slug":"guidance-high-risk-safety-function-versus-failure-route","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"cef01d5437965eec1281d90fe2a0d784862f3905a04f90adbae923fe5b48fc33","label":"Two routes to safety component: intent or consequence","summary":"An AI system is a safety component via two alternative routes. Either it is intended to fulfil a safety function, or its failure or malfunctioning endangers health, safety or property.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The draft guidelines of 19 May 2026 are a draft document without binding force and read Article 3(14) as two alternative scenarios. In the first scenario the AI system fulfils a safety function, meaning that its intended purpose, as determined by the provider, is to prevent or mitigate risks to the health and safety of persons or property. The draft guidelines note that the mere fact that an AI system is integrated into or operates within a product subject to safety regulation does not in itself mean it fulfils a safety function. In the second scenario the system is a safety component because its failure or malfunctioning could endanger the health and safety of persons or property. The draft guidelines summarise this in a table: the safety function is intent-based and strongly provider-controlled, evidenced by instructions of use, technical documentation and promotional materials, while the failure route is consequence-based and risk-based with lower provider control, evidenced by system architecture, failure modes and effects.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (34) to (44), including table 1","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"You can steer the first route, not the second. That is the whole point. A provider determines the intended purpose and can therefore choose not to claim a safety function in the documentation. The draft guidelines close that exit with the failure route, which looks at what happens when things go wrong, regardless of what you wrote down. The guidelines list forms of failure including incorrect outputs such as false positives and false negatives, loss of function or availability, performance instability or drift, timing or latency errors, and misclassification leading to hazardous control decisions. Note the lower bound as well: the likelihood of failure must not be a merely theoretical possibility, and reputational harm, purely financial loss, minor service degradation or inconvenience without a safety hazard do not count.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (34) to (44), including table 1","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Document the two routes separately. For the safety function, record what you communicate as intended purpose in the instructions of use, technical documentation and sales materials, and keep those three consistent. For the failure route, produce a failure mode analysis noting for each failure form whether there is a path to injury or damage to property. That analysis is also your evidence towards a market surveillance authority.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (34) to (44), including table 1","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-single-compliance-framework-sectoral-integration","legacy_id":"raip:guidance:guidance-high-risk-single-compliance-framework-sectoral-integration","type":"guidance","slug":"guidance-high-risk-single-compliance-framework-sectoral-integration","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"bdbd9514e94771ae555ba26afdebf49ceca4dfb3dd3c1ee7db306c34c76532a2","label":"Integrating AI Act requirements into existing risk and quality systems","summary":"The AI Act allows you to add AI-specific risks to your existing risk management and quality management systems, so that you can work within a single compliance framework.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-9-risk-management"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"According to the draft guidelines of 19 May 2026, which are expressly published as a draft for stakeholder feedback and have no binding force, the AI Act provides mechanisms to reduce the compliance burden for economic operators. The draft guidelines cite Article 8(2) AI Act on the interplay with sectoral legislation, Article 9(10) AI Act on risk management and Article 17(3) AI Act on quality management, which allow economic operators to add, where necessary and appropriate, an assessment of AI-specific risks to already existing risk and quality management systems. Article 40 AI Act further requires that harmonised standards under the AI Act be consistent with standards developed under the Annex I harmonisation legislation. The draft guidelines state that these mechanisms enable economic operators to meet both the AI Act and the harmonisation legislation within a single compliance framework, thereby avoiding duplication of effort while maintaining a high level of protection of health, safety and fundamental rights.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (61) and (62)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the most reassuring point in the entire chapter, and at the same time the most underused. Manufacturers who already have a mature quality management system, for instance under a sectoral standard, do not need to set up a second system alongside it. You extend what is already there. That saves not only cost but above all the fragmentation in which your AI file becomes detached from your product file and the two start contradicting each other during an audit. The practical gain lies in a shared risk register in which AI risks are included as a category, not as a separate document.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (61) and (62)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Extend your existing risk register and quality manual with an AI chapter instead of building a parallel AI management system. Appoint an owner who manages both the sectoral file and the AI file, so that changes to the product automatically touch the AI assessment.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (61) and (62)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-standalone-software-updates-and-add-ons","legacy_id":"raip:guidance:guidance-high-risk-standalone-software-updates-and-add-ons","type":"guidance","slug":"guidance-high-risk-standalone-software-updates-and-add-ons","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"e6419b609560f8d6e6bbecfdb48762778743aca84f68ced7ce5dad5e6ef752fc","label":"Standalone software, updates and remote services can also be high-risk","summary":"Article 6(1) applies regardless of whether the AI system is embedded in the product or placed on the market independently. A software update, add-on or remote service can therefore be high-risk in its own right.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The draft guidelines of 19 May 2026 are non-binding and still under consultation, and clarify that Article 6(1) AI Act applies irrespective of whether the AI system is embedded within the product or placed on the market or put into service independently. An AI system supplied for example as a software update, an add-on or a remote service may therefore be classified as high-risk under Article 6(1), provided all conditions of that provision are met. The draft guidelines also distinguish the case where the AI system is the product itself: that is so where it is independently placed on the market, has its own intended purpose, and is directly regulated by the harmonisation legislation listed in Annex I. As an example the draft guidelines cite Regulation (EU) 2023/1230, the Machinery Regulation, whose definition of machinery-related products explicitly includes certain software, which may therefore itself be a regulated product and be classified as high-risk provided third-party conformity assessment is required. The draft guidelines further state that an AI system which is a safety component of a regulated product should be evaluated as part of that product's overall safety assessment, even where it is also placed on the market independently of that product.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (22), (30) and (31)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This affects a growing group of suppliers who believe they are outside the regime because they do not make a physical product. Anyone supplying an AI module that is later loaded into a machine, lift or vehicle may well be a provider of a high-risk AI system. The same holds for over-the-air updates that change or add an existing safety function. The flip side is that your assessment is not detached from the product: the draft guidelines require your component to be weighed in the overall safety assessment of the product it lands in. That requires coordination with the manufacturer and clear arrangements on information exchange.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (22), (30) and (31)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Map which regulated products your software ends up in and which safety-relevant functions your updates touch. Set out contractually what information you supply to the product manufacturer for their safety assessment, and treat an update that changes a safety function as a trigger to re-test the classification.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (22), (30) and (31)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-substantial-modification-article-25","legacy_id":"raip:guidance:guidance-high-risk-substantial-modification-article-25","type":"guidance","slug":"guidance-high-risk-substantial-modification-article-25","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"cf761dadbb93aa15f6b1773ef8ac6d7a5dec66037327356ff1634cabdd7ee54d","label":"When a customer or distributor itself becomes the provider","summary":"Distributors, importers, deployers and other third parties can take on provider obligations. That happens when you put your own name or trademark on a system, when you make a substantial modification to a high-risk system, and when you change the intended purpose of a non high-risk system so that it becomes high-risk.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The draft guidelines of 19 May 2026 on the classification of high-risk AI, which are not binding, note in paragraph (14) that distributors, importers, deployers or other third parties may become subject to provider obligations under Article 25(1) where they, first, put their name or trademark on a high-risk AI system already placed on the market or put into service; second, make a substantial modification to a high-risk AI system already placed on the market or put into service in such a way that it remains a high-risk AI system; or third, modify the intended purpose of an AI system, including a general-purpose AI system, which had not been classified as high-risk, in such a way that the system becomes a high-risk AI system under Article 6. A footnote to that paragraph announces that the Commission is preparing separate guidelines on responsibilities along the AI value chain under Article 25.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraph (14) and its footnote 6","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The third situation is the most underestimated. An organisation that buys a broadly deployable model or assistant and then aims it at recruitment, employee evaluation or access to services changes the intended purpose and can thereby become the provider of a high-risk system, with the full set of obligations. White labelling under your own brand is also enough, without changing a single line of code.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraph (14) and its footnote 6","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Introduce a standing check before you rebrand, modify or repurpose a procured AI system. Assess for each change whether you land in one of the three Article 25(1) situations and record that assessment. Make this part of your procurement and change process, not a one-off project check.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraph (14) and its footnote 6","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-third-party-conformity-assessment-module-choice","legacy_id":"raip:guidance:guidance-high-risk-third-party-conformity-assessment-module-choice","type":"guidance","slug":"guidance-high-risk-third-party-conformity-assessment-module-choice","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"81c96c1b43f6d6e80d5cbf98a9485b411e186e75b1d5e77f2efd6932c7dad7b4","label":"Module choice does not change the classification","summary":"The fact that a manufacturer may opt for internal control based on harmonised standards does not affect the high-risk classification. Classification follows the level of enhanced scrutiny required by the product legislation, not the procedure chosen.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The draft guidelines of 19 May 2026 have the status of a non-binding draft and clarify the second condition as follows. The AI Act does not itself determine the applicable conformity assessment procedures but relies on the choice of procedures established under the Annex I harmonisation legislation. Decision 768/2008/EC sets out eight main modules A to H. For all modules except module A the involvement of a notified body is required; module C does not require such involvement but is always combined with modules that do; for modules A1 and A2 a notified body or accredited in-house body is required only in the production phase. The draft guidelines then state explicitly that the fact that harmonisation legislation may allow a manufacturer to rely on internal control based on harmonised standards, as one procedural option, does not affect the classification of an AI system as high-risk under Article 6(1). The choice of module gives the manufacturer procedural flexibility to demonstrate compliance but confers no discretion to determine the risk classification under the AI Act. The decisive factor is that the product, under the Annex I legislation, is subject to enhanced regulatory scrutiny before it may lawfully be placed on the market, scrutiny ensured through the requirement of third-party conformity assessment or equivalent mechanisms, including internal control subject to mandatory application of harmonised standards published in the Official Journal. The draft guidelines point out that the Union legislature expressly confirmed this logic in recital 15 of Regulation (EU) 2025/2509 on the safety of toys.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (50) to (59)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Here the draft guidelines close the most obvious escape route. The reasoning many manufacturers hoped to use ran: we apply harmonised standards, therefore we use module A, therefore no third party is involved, therefore we are not high-risk. The Commission reverses that. What matters is not the chosen procedure but the level of protection the legislature considered necessary for that product type. Anyone who has built the module A route into their compliance planning must now revisit that assumption. The toys and machinery regulations are explicitly named as sectors where this plays out.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (50) to (59)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Test your classification not against the module you actually use, but against whether the legislature prescribed enhanced scrutiny for your product type. If your sectoral legislation permits internal control only subject to mandatory application of harmonised standards, assume you fall within the high-risk regime and plan your AI Act track accordingly.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (50) to (59)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}}],"included":{"sources":[{"id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","title":{"nl":"Vragen en antwoorden over AI-geletterdheid","en":"AI literacy questions and answers"},"publisher":{"nl":"Europese Commissie","en":"European Commission"},"canonical_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null,"source_version":"updated-2026-07-27","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"a07599c1c5af5cb25fbe1a72caecc7f0093326202cea7949a43d7a89c6c7f038","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:commission-ai-literacy-qa"},{"id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","title":{"nl":"Richtsnoeren over Artikel 50","en":"Guidelines on Article 50"},"publisher":{"nl":"Europese Commissie","en":"European Commission"},"canonical_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null,"source_version":"final-2026-07-20","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"3c3d066f0294692b398f096861adb89198f3d6062939237a97b35fa9ced4d39d","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:commission-article-50-guidelines"},{"id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","title":{"nl":"Ontwerprichtsnoeren over de classificatie van hoog-risico AI-systemen","en":"Draft guidelines on the classification of high-risk AI systems"},"publisher":{"nl":"Europese Commissie (AI Office)","en":"European Commission (AI Office)"},"canonical_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null,"source_version":"draft-for-consultation-2026-05-19","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"1560a59f57f0d9c0c6fe9d1a370772d43e93c21c6686db6ab198f44712dcb8d3","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:commission-draft-high-risk-classification-guidelines"},{"id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","title":{"nl":"Richtsnoeren voor GPAI-modelaanbieders","en":"Guidelines for GPAI model providers"},"publisher":{"nl":"Europese Commissie","en":"European Commission"},"canonical_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null,"source_version":"checked-2026-08-08","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"b3691c417d2ea106c7767e1b78bf30f045b0172a4292cb44ba76ff45109de497","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:commission-gpai-guidelines"}]},"links":{"self":"https://www.praxikon.com/api/v1/entities?lang=en&type=guidance","alternate":"https://www.praxikon.com/api/v1/entities?lang=en&type=guidance&format=jsonld","licence":"https://www.praxikon.com/nl/legal/terms"}}