The European Commission’s newly released draft guidelines (May 2026) on high-risk AI systems mark a pivotal step in operationalizing the EU AI Act. While the Act itself established a risk-based regulatory framework back in 2024, these guidelines provide much-needed clarity on how to determine whether an AI system falls into the “high-risk” category—arguably the most consequential classification for organizations building or deploying AI in Europe. Ironically, this fits directly into one of the objectives for revision of ICH Q9 into R1, reducing subjectivity.

If you wish to catch up on the evolving AI landscape in pharma/biopharma, see Lachman’s three-part series on this issue at From Alignment to Action – Operationalizing AI Under CGMP (Part 3).

Two Clear Pathways to High-Risk Classification

Currently, the approved criteria for a high-risk AI system are detailed in Annex III with the date of implementation presently scheduled for August 2, 2026 (pending a delay proposed by the Digital Omnibus agreement). These drafts reinforce a central principle of the AI Act: there are two independent routes by which an AI system becomes “high risk.” In essence, these draft documents emphasize a commitment for continual investment in the refinement of the law.

1. Product Safety Route (Article 6(1))

AI systems are classified as high risk if they are embedded in, or constitute, products regulated under existing EU safety legislation (e.g., medical devices or machinery) and require third-party conformity assessments.

2. Use-Case Route (Article 6(2))

AI systems are also high risk if their intended purpose falls within specific sensitive domains listed in Annex III, such as biometrics, education, employment, critical infrastructure, and law enforcement.

Failure to start building capability and readiness now could significantly hinder a company’s AI maturity, especially when calibrated with the January 2026 release of the joint EMA-FDA ten “Guiding principles of good AI practice in drug development” (here).

Did Someone Say User Requirement Specification (URS) in a Different Way?

A key emphasis in the new draft guideline is the importance of an AI system’s “intended purpose” in determining classification. This points to a fundamental deliverable known as the User Requirement Specification (URS). Whatever the model used, V-Model, Agile with Use Cases, or CSA, the importance of documenting the intended use just received a big shout-out!

What is Your “System”?

A notable trend identified by Lachman is the inadequate system boundaries and the mistaken assignment of “inside the boundary” as a “black box.” This potential loophole is being directly challenged as the guidelines state that interconnected or modular AI systems must be assessed holistically if they collectively contribute to a high-risk outcome.

What is the Risk?

Ultimately, classifying an AI system as “high risk” triggers the application of controls and governance requirements. This shift may impact organizations that have historically applied a broad or liberal interpretation of what constitutes “high risk,” potentially requiring significant rework of projects already in progress. Misinterpretation is further reinforced by a consulting environment in which some advisors prioritize aligning with client expectations over providing objective guidance, leading to the implementation of inappropriate or misdirected mitigations.

The draft guidelines do reduce uncertainty. At the same time, they tighten the boundaries of what counts as high risk, signaling a stricter and more consistent enforcement approach across the EU and the global supply chain of the pharmaceutical and biotechnology ecosystem.

Lachman helps companies manage strategic risks and transform them into tangible advantages. Contact Lachman at LCS@LachmanConsultants.com today to see whether your company has blind spots in its digital GXP strategy.