Artificial Intelligence: Get the “high-risk AI” category right, or Europe will have to import the AI it could have built

The promise of the AI Act is to help artificial intelligence develop in Europe while ensuring a trusted and safe ecosystem. The AI Act’s risk-based approach keeps that promise alive by regulating only the riskiest uses. The Commission has drafted its Guidelines on Article 6 of the AI Act, defining which AI systems count as “high-risk”. No label in the AI Act carries more weight. The moment a system earns it, the heaviest obligations follow: conformity assessments, registration, data governance obligations and reams of documentation. So the line has to sit in the right place.

This is where Europe’s competitiveness turns concrete. An ordinary scheduling tool that needs months of legal analysis and compliance procedures before it can launch here in Europe is a tool that launches somewhere else. Draw the line by real risk, free low-risk AI uses from heavy obligations, and European companies will build and deploy at home with confidence. That is the line the legislator drew on purpose, and the final Guidelines should keep it bright. Trustworthy and competitive stop being a trade-off.

Judging people is high-risk. Running logistics is not.

AI that decides who gets hired, promoted, or dismissed belongs in the high-risk category. Most of what an on-demand platform runs on does not. A system that predicts how many food orders a neighbourhood will see on a rainy Friday forecasts demand; it does not rate couriers. A system that sends the nearest driver to a trip does logistics. The draft Guidelines already accept this for task allocation on neutral criteria. The Commission should finish the thought and keep dynamic pricing and objective fee calculations outside the category too.

The same clarity is needed for the metrics platforms rely on every day. No-shows, acceptance rates, and customer ratings record whether a task met normal objective standards. They are not behavioural evaluation, and they are certainly not social scoring. Nor should a short, precautionary account pause while a reported incident is investigated read as a decision to end someone’s work.

Everyday features are not high-risk either

Opening a laptop with your fingerprint has nothing in common with scanning a crowd. Unlocking your own device should stay outside the high-risk category, exactly where the AI Act put it. The same discipline applies to the AI Act’s own proportionality filter under Article 6(3), which should exempt genuinely preparatory tasks like transcribing an interview or translating an application, rather than pulling routine features into a stringent regime that was never intended for them. 

One point runs through all of this. High-risk AI never operates in a vacuum, so companies need the AI Act and the General Data Protection Regulation (GDPR) to speak to each other. Without a pragmatic reading of how these laws apply on the ground, European companies face more legal uncertainty and a harder job complying with both.

One classification, twenty-seven markets

A classification is only as good as the way it is enforced. A system counted as high-risk in one Member State cannot be waved through in the next. The Commission must ensure national authorities read the Guidelines the same way. Any future expansion of the high-risk list must also rest on evidence of real harm, rather than on caution.

Draw the line where it belongs

European tech companies urge the Commission to use the consultation input to sharpen the final Guidelines: genuinely risky AI uses inside the high-risk category, everyday AI-driven operational tools outside, and one reading of the line across the single market. 

Europe has the talent, the ecosystem, and the companies that compete worldwide from a European base. A high-risk category that means what it says, in alignment with the AI Act’s risk-based approach, enables Europe to protect its citizens and grow its own champions with one rulebook.