Direct answer
Do we need a quality management system?
This falls under Article 17: quality management system. That obligation applies from 2 December 2027. There is one exception you have to assess yourself.
This could go the other way
- Providers already under sectoral quality regimes may integrate the AI elements into that existing system; SMEs may implement elements in simplified form.
First step: Set up an AI quality management system.
You describe: You are the provider of a high-risk AI system and want to know whether you must set up a documented quality system, and what belongs in it. Likely role: provider (you place the system on the market).
This applies now
- For this situation, the preparation phase matters most right now.
Coming up
- Article 17: quality management systemfrom 2 December 2027
- Article 11: technical documentationfrom 2 December 2027
- Articles 43-49: conformity assessment, CE and registrationfrom 2 December 2027
The quality management system is the organisational side of conformity: it describes how you structurally assure design, testing, change and oversight, and it is what a conformity assessment examines. An existing ISO quality system can be the basis but does not automatically cover the AI Act requirements.
Your first actions
- Set up an AI quality management system. Describe strategies, procedures and responsibilities for compliance, from design and data to post-market monitoring.
- Build the technical file per Annex IV. Document system description, development process, data, oversight measures, performance and risk management before market placement.
- Complete the conformity route before market placement. Select the correct assessment procedure, draw up the EU declaration of conformity, affix the CE marking and register in the EU database.
Record this
- QMS documentation
- Technical file (Annex IV)
- Conformity file
agriculture and food
Agriculture: AI system targeting land areas for chemical spraying
An AI system determines which areas of agricultural land are sprayed with chemicals. The intended purpose given to it by the provider is optimising the use of chemicals.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether AI as a safety component falls under the Annex I product legislation. The document is a consultation version: non-binding and not yet final.
Do not limit your failure analysis to the product itself but include the environment in which it operates, because people nearby help determine whether a malfunction creates danger.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation
agriculture and food
Agriculture: AI for yield forecasting and irrigation optimisation
An AI system is integrated into a drone or robot and used for agronomic purposes such as yield forecasting or irrigation optimisation.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether AI as a safety component falls under the Annex I product legislation. The document is a consultation version: non-binding and not yet final.
Record per application why a malfunction in your setup creates no danger, because the same agronomic function can become a safety component in a different product design.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation
ATEX: AI system monitoring gas concentrations and commanding shutdown
Equipment for potentially explosive atmospheres contains an AI system intended to monitor gas concentrations and command shutdown when thresholds are exceeded.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether AI as a safety component falls under the Annex I product legislation. The document is a consultation version: non-binding and not yet final.
Once you offer a system that monitors a dangerous value and itself commands an intervention, the safety function follows from your stated intended purpose, not from how reliably the system performs.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation
Gas appliances: AI optimising combustion efficiency
An AI system optimises combustion efficiency in a household gas appliance. The intended purpose is energy efficiency.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether AI as a safety component falls under the Annex I product legislation. The document is a consultation version: non-binding and not yet final.
Whether an efficiency system is a safety component depends on the product design: if a malfunction can cause fire, explosion or carbon monoxide it counts, if it only raises the energy bill it does not.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation
Annex I lists legislation, not products
The draft guidelines of 19 May 2026, published for consultation and expressly non-binding, clarify that Annex I AI Act does not list individual products to be classified as high-risk, but Union harmonisation legislation regulating the safety aspects of certain products. Whether an AI system falls within the scope of Annex I therefore depends on whether the system, or the product of which it is a safety component, falls within the material scope of one of the listed legislative acts. According to the draft guidelines the list in Annex I is exhaustive; products can only be added or removed by amending the scope of the harmonisation legislation itself or by adding new harmonisation legislation to Annex I. The draft guidelines also state that through Article 6(1) the AI Act does not itself extend the scope of harmonisation legislation to new or additional products, and that the AI Act does not determine or change the risk profile of a product but builds on the sectoral risk classification. Products mentioned include machinery, toys, lifts, equipment and protective systems for potentially explosive atmospheres, radio equipment, pressure equipment, recreational craft, cableway installations, appliances burning gaseous fuels, medical devices, in vitro diagnostic medical devices, and products in the automotive and aviation sectors.
Draft guidelines Annex I, points (23) to (26)
Section A and Section B of Annex I trigger different requirement sets
The Commission draft guidelines of 19 May 2026, which are non-binding as long as the final version has not been adopted, draw a distinction that is often missed in practice. AI systems classified as high-risk under Article 6(1) in respect of products covered by the harmonisation legislation in Section A of Annex I are subject to the requirements for high-risk systems in Section 2 of Chapter III AI Act. By contrast, for AI systems classified as high-risk under Article 6(1) in respect of products covered by the harmonisation legislation in Section B of Annex I, only Article 6(1), Articles 102 to 109 and Article 112 AI Act apply. The draft guidelines refer to Article 2(2) AI Act for this. Section A contains harmonisation legislation based on the New Legislative Framework, Section B the other Union harmonisation legislation.
Draft guidelines Annex I, point (60), referring to Article 2(2) AI Act
Two cumulative conditions for high-risk under Annex I
The European Commission draft guidelines of 19 May 2026, which are expressly non-binding and not final, read Article 6(1) as two cumulative conditions. First, the AI system must be intended to be used as a safety component of a product, or the AI system must itself be a product, covered by the Union harmonisation legislation listed in Annex I. Second, that product, or the AI system itself where it is the product, must be required to undergo a third-party conformity assessment. The draft guidelines state explicitly that not all AI systems that are components of regulated products are high-risk, but only the subset that satisfies both criteria.
Draft guidelines Annex I, points (27) and (21)
The Article 6(3) filter: four exhaustive grounds, to be read narrowly
According to the non-binding draft guidelines of 19 May 2026 on the classification of high-risk AI, Article 6(3) sets out four grounds on which a provider may exempt a system from high-risk classification: performing a narrow procedural task, improving the result of a previously completed human activity, detecting decision-making patterns or deviations from prior patterns without replacing or influencing the previously completed human assessment absent proper human review, and performing a preparatory task. Paragraph (88) of this draft states these grounds are exhaustive but alternative, that there is no separate independent risk test, and that they must be interpreted narrowly because Article 6(3) is an exception to rules that among other things protect fundamental rights. Paragraph (87) states the filter applies only to systems under Article 6(2) and not to systems under Article 6(1). Paragraph (89) states a system always remains high-risk where it performs profiling. Paragraph (90) adds that the filter does not apply where the system forms part of a complex system whose combined intended purpose or joint outputs materially influence an individual decision, including agentic AI. Paragraphs (113) to (116) of this draft describe that this is a self-assessment by the provider, that Article 6(4) requires documenting the assessment before placing on the market and registering in the Article 71 EU database, and that the assessment must contain at least the intended purpose, why the system falls under Article 6(2), which Article 6(3) condition applies and why, and why the system does not perform profiling. Paragraph (117) of these draft guidelines points to Articles 80 and 99 where an authority finds a system was misclassified as non high-risk to circumvent the rules.
Draft guidelines on high-risk AI classification (19 May 2026), Annex III chapter, sections 2.7, 2.7.1, 2.7.3 and 2.7.4, paragraphs (84) to (90) and (113) to (117)
EN 18286:2026: quality management system for EU AI Act regulatory purposes
EN 18286:2026 (Artificial intelligence: Quality management system for EU AI Act regulatory purposes) was drafted by CEN/CLC/JTC 21 under standardisation request M/613 and approved by CEN-CENELEC on 12 July 2026. It is the first JTC 21 deliverable to reach publication. According to a published coverage statement accompanying the standard, not yet confirmed by a second independent source, it addresses Article 17(1) points (a) to (m) and Article 11(1) first sentence, and expressly not Article 17(2) to (4) or Article 72. The standard is NOT currently cited in the Official Journal. The Article 40 presumption of conformity only attaches after that citation.
EN ISO/IEC 42001: artificial intelligence management system
ISO/IEC 42001:2023 is the first certifiable international standard for an AI management system, published on 18 December 2023 and structured on the plan-do-check-act cycle. The text was adopted unchanged as EN ISO/IEC 42001:2026, approved by CEN on 13 March 2026, with national implementation by the member standards bodies. This adoption is not a deliverable under standardisation request M/613: the standard is not cited in the Official Journal and therefore confers no presumption of conformity under Article 40. For Article 17, the designated deliverable under M/613 is EN 18286:2026; that standard is likewise not cited in the Official Journal.
prEN 18285: conformity assessment framework for AI systems
prEN 18285 (Conformity assessment framework) is the JTC 21 deliverable under M/613 covering the conformity assessment of high-risk AI systems under Article 43 and Annex VII of the AI Act. As at June 2026 the deliverable was at the drafting stage. It has not yet been published as an EN and is not cited in the Official Journal. Standardisation request M/613 was amended by Implementing Decision C(2025)3871 of 23 June 2025 and expires on 28 February 2027.
General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.
Full map for your situationExecution
From obligation to arranged and demonstrable
Knowing where you stand is step one. Embed AI translates this obligation into a concrete approach for your organisation: scope, ownership, register and evidence.
See the Embed AI approach