Skip to main content
Praxikon
Back to the explorer
GuidanceGuidancev1.0.0

Standalone software, updates and remote services can also be high-risk

Article 6(1) applies regardless of whether the AI system is embedded in the product or placed on the market independently. A software update, add-on or remote service can therefore be high-risk in its own right.

The official source remains authoritative. This is general information about obligations and not legal advice. See this object on the map

Address and citation

This object has an address of its own that is never renamed or reused. Store the identifier in your own file, not the title or the link.

Identifier
praxikon:eu:ai-act:guidance:guidance-high-risk-standalone-software-updates-and-add-ons
Payload hash (sha256)
e6419b609560f8d6e6bbecfdb48762778743aca84f68ced7ce5dad5e6ef752fc

Citation line

Praxikon, "Standalone software, updates and remote services can also be high-risk", praxikon:eu:ai-act:guidance:guidance-high-risk-standalone-software-updates-and-add-ons@1.0.0, dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0 (schema 1.4.0), effective_at 2026-08-08T00:00:00.000Z, known_at 2026-08-14T00:00:00.000Z, sha256 e6419b609560f8d6e6bbecfdb48762778743aca84f68ced7ce5dad5e6ef752fc
Version
1.0.0
Legal time (effective_at)
8 August 2026
Knowledge time (known_at)
8 August 2026
Closed on
Not closed
Topics
guidance

Review status: Placed against the official source (8 August 2026). Next check due by 4 February 2027. The check date is the knowledge date of this version; no later recheck has been recorded.

What this object links to

Every relation appears below as a path: from the source with its locator, through the conditions and exceptions of the object carrying the relation, to the consequence. A locator belongs to a statement in the data and not to a relation, so the source is the source anchor of the carrying object.

The obligation this hangs off

1 of 1 shown

The object belongs to this obligation. The source line it hangs off sits there.

  1. Source

    Official fact on this object, with its locator.

    • Draft guidelines on the classification of high-risk AI systems

      Locator: Draft guidelines Annex I, points (22), (30) and (31)

      praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines

      Open official source

    Via

    No condition or exception recorded on this object.

    Consequence

What this object is about

2 of 2 shown

The object is about this role. Undifferentiated: it does not follow that the duty rests on this role.

  1. Source

    Official fact on this object, with its locator.

    • Draft guidelines on the classification of high-risk AI systems

      Locator: Draft guidelines Annex I, points (22), (30) and (31)

      praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines

      Open official source

    Via

    No condition or exception recorded on this object.

    Consequence

What this object states

Official fact

Attributable to a named primary source, with a locator. Where they differ, the official source prevails.

  • The draft guidelines of 19 May 2026 are non-binding and still under consultation, and clarify that Article 6(1) AI Act applies irrespective of whether the AI system is embedded within the product or placed on the market or put into service independently. An AI system supplied for example as a software update, an add-on or a remote service may therefore be classified as high-risk under Article 6(1), provided all conditions of that provision are met. The draft guidelines also distinguish the case where the AI system is the product itself: that is so where it is independently placed on the market, has its own intended purpose, and is directly regulated by the harmonisation legislation listed in Annex I. As an example the draft guidelines cite Regulation (EU) 2023/1230, the Machinery Regulation, whose definition of machinery-related products explicitly includes certain software, which may therefore itself be a regulated product and be classified as high-risk provided third-party conformity assessment is required. The draft guidelines further state that an AI system which is a safety component of a regulated product should be evaluated as part of that product's overall safety assessment, even where it is also placed on the market independently of that product.

    • Locator: Draft guidelines Annex I, points (22), (30) and (31)praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelinesOpen official source

Our interpretation

Our own reading. It can change without the law changing, and it is not the position of a supervisory authority.

  • This affects a growing group of suppliers who believe they are outside the regime because they do not make a physical product. Anyone supplying an AI module that is later loaded into a machine, lift or vehicle may well be a provider of a high-risk AI system. The same holds for over-the-air updates that change or add an existing safety function. The flip side is that your assessment is not detached from the product: the draft guidelines require your component to be weighed in the overall safety assessment of the product it lands in. That requires coordination with the manufacturer and clear arrangements on information exchange.

    • Locator: Draft guidelines Annex I, points (22), (30) and (31)praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelinesOpen official source

Recommended step

A practical step we consider appropriate. Not an obligation following from the Regulation.

  • Map which regulated products your software ends up in and which safety-relevant functions your updates touch. Set out contractually what information you supply to the product manufacturer for their safety assessment, and treat an update that changes a safety function as a trigger to re-test the classification.

    • Locator: Draft guidelines Annex I, points (22), (30) and (31)praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelinesOpen official source

When this applies

No condition recorded on this object.

When this does not apply

No exception recorded on this object.

Referring to this object

Citation block

Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.

Reference

Praxikon, "Standalone software, updates and remote services can also be high-risk",
praxikon:eu:ai-act:guidance:guidance-high-risk-standalone-software-updates-and-add-ons@1.0.0,
dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0 (schema 1.4.0),
effective_at 2026-08-08T00:00:00.000Z, known_at 2026-08-08T00:00:00.000Z,
sha256 e6419b609560f8d6e6bbecfdb48762778743aca84f68ced7ce5dad5e6ef752fc,
https://www.praxikon.com/en/verkenner/guidance/guidance-high-risk-standalone-software-updates-and-add-ons
(https://www.praxikon.com/api/v1/entities?id=praxikon%3Aeu%3Aai-act%3Aguidance%3Aguidance-high-risk-standalone-software-updates-and-add-ons&effective_at=2026-08-08&known_at=2026-08-08&lang=en, accessed 2026-08-25)

Short form

praxikon:eu:ai-act:guidance:guidance-high-risk-standalone-software-updates-and-add-ons@1.0.0 (sha256 e6419b60)

BibTeX

@misc{praxikon-eu-ai-act-guidance-guidance-high-risk-standalone-software-updates-and-add-ons-1-0-0,
  author       = {{Praxikon}},
  title        = {Standalone software, updates and remote services can also be high-risk},
  year         = {2026},
  version      = {1.0.0},
  number       = {praxikon:eu:ai-act:guidance:guidance-high-risk-standalone-software-updates-and-add-ons},
  howpublished = {AI Act Change \& Evidence Graph, dataset 2.1.0, schema 1.4.0},
  note         = {effective_at 2026-08-08T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 e6419b609560f8d6e6bbecfdb48762778743aca84f68ced7ce5dad5e6ef752fc},
  url          = {https://www.praxikon.com/en/verkenner/guidance/guidance-high-risk-standalone-software-updates-and-add-ons},
  urldate      = {2026-08-25},
  language     = {en}
}

CSL JSON

[
  {
    "id": "praxikon:eu:ai-act:guidance:guidance-high-risk-standalone-software-updates-and-add-ons@1.0.0",
    "type": "dataset",
    "title": "Standalone software, updates and remote services can also be high-risk",
    "container-title": "AI Act Change & Evidence Graph",
    "publisher": "Praxikon",
    "version": "1.0.0",
    "number": "praxikon:eu:ai-act:guidance:guidance-high-risk-standalone-software-updates-and-add-ons",
    "URL": "https://www.praxikon.com/en/verkenner/guidance/guidance-high-risk-standalone-software-updates-and-add-ons",
    "language": "en",
    "issued": {
      "date-parts": [
        [
          2026,
          8,
          8
        ]
      ]
    },
    "accessed": {
      "date-parts": [
        [
          2026,
          8,
          25
        ]
      ]
    },
    "note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0; schema 1.4.0; effective_at 2026-08-08T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 e6419b609560f8d6e6bbecfdb48762778743aca84f68ced7ce5dad5e6ef752fc; retrieved_from https://www.praxikon.com/api/v1/entities?id=praxikon%3Aeu%3Aai-act%3Aguidance%3Aguidance-high-risk-standalone-software-updates-and-add-ons&effective_at=2026-08-08&known_at=2026-08-08&lang=en; licence https://www.praxikon.com/nl/legal/terms"
  }
]

How to verify a reference later is set out in the methodology. Terms

For agents and integrations

This page and the machine output come from the same object and the same two time axes.