High-Risk AI Systems: New AI Act Deadlines and Draft Guidelines
At the end of May, the European Commission published draft guidelines on the classification of high-risk AI systems. The document, which is currently open for public consultation, is intended to help providers and deployers assess whether their systems fall within the high-risk requirements.
At the same time, the Digital Omnibus has delayed the date of application of the obligations related to such systems: those obligations will apply from 2 December 2027 for standalone high-risk AI systems and from 2 August 2028 for high-risk AI systems embedded in certain products.
The obligations must be fulfilled primarily by providers and deployers, but importers, product manufacturers integrating AI systems into their products, and distributors should also ensure compliance before the date of application.

The AI Act divides systems according to their risk into:
- prohibited practices;
- high-risk systems;
- systems subject to transparency obligations for providers/deployers and
- minimal-risk systems, for which the AI Act does not impose restrictive rules.
When does an AI system become a high-risk system? Two key scenarios
Scenario 1: AI systems covered by Union harmonisation legislation
The first scenario concerns AI systems that are either products in their own right or safety components of products covered by the Union harmonisation legislation listed in Annex I to the AI Act, for example medical devices or aviation products, where the classification requires a third-party conformity assessment before the product is placed on the market or put into service.
Some clarifications will still have to wait for AI systems that are simultaneously subject to other EU regulations. The Commission has announced forthcoming guidance, including:
- guidelines on the interaction between the AI Act and other EU rules, for example joint guidance from the Commission and the European Data Protection Board,
- as well as guidance on the application of the AI Act in preclinical research and the development of medicinal products and medical devices.
Compliance with the AI Act for these systems must be ensured by 2 August 2028.
Scenario 2: AI systems in specific use areas
The second scenario covers AI systems intended for the specific standalone uses listed in Annex III to the AI Act.
Use cases include:
- Biometrics: remote biometric identification systems, biometric categorisation based on sensitive data, and emotion recognition.
- Critical infrastructure: AI systems intended to be used as safety components in critical digital infrastructure and in the supply of road traffic, water, gas, heating and electricity.
- Education and vocational training: AI systems intended to be used to determine access or admission, to evaluate learning outcomes, to assess the appropriate level of education, and to monitor and detect prohibited behaviour of students during tests.
- Employment, workers management and access to self-employment: AI systems intended to be used for recruitment or selection of natural persons, and to manage work-related relationships, such as assigning tasks based on behavioural analysis or evaluating performance.
- Access to and enjoyment of essential private services and essential public services and benefits: AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, to carry out risk assessment and pricing in the case of life and health insurance, and to evaluate the eligibility of a natural person for essential public assistance benefits and services.
- Law enforcement, migration, asylum and border control management, and administration of justice and democratic processes: AI systems intended to be used to assess the risk of a natural person becoming the victim of a criminal offence, to evaluate the reliability of evidence, and to assist in the examination of asylum, visa and residence permit applications.
Compliance with the AI Act for these systems must be ensured by 2 December 2027.
When can an AI system be removed from the high-risk category?
The draft guidelines also describe the so-called filter mechanism. It allows providers to exempt a system from the high-risk classification, even if its intended purpose falls within Annex III, provided that it does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of the decision-making process.

If the system meets that description, it must also satisfy one of the following conditions in order to be excluded from high-risk classification:
- it performs only a narrow procedural task;
- it improves the result of a previously completed human activity;
- it detects decision-making patterns or deviations from prior patterns, but is not intended to replace or influence a previously completed human assessment without appropriate human review
- it performs only preparatory tasks in the context of an assessment relevant to the Annex III use case.
What already applies?
- Prohibitions on certain practices have already applied since 2 February 2025, but the Digital Omnibus introduces an exception for the newly added prohibition concerning non-consensual sexually explicit or intimate synthetic content and child sexual abuse material (CSAM), which will apply from 2 December 2026.
- Rules relevant for national notified bodies, such as the notification procedure, already apply.
- As a general rule, the provisions of Chapter V of the AI Act governing general-purpose AI models (GPAI) entered into force and became fully applicable on 2 August 2025. From that date, new models placed on the market must comply with obligations concerning, among other things, training transparency and copyright respect.
Exemptions and deadlines for bringing existing AI systems into line with the AI Act
- General-purpose AI models placed on the market before 2 August 2025 have until 2 August 2027 to comply with the rules.
- For high-risk AI systems, systems placed on the market before the entry into application of the relevant requirements must comply only if they undergo a significant change in their design, except for systems used by the public sector, which have an absolute deadline of 2 August 2030 to comply.
Get ready for AI transparency obligations from 2 August 2026.
From 2 August 2026, new requirements regarding the labelling of AI-generated content have been in force. If your system was placed on the market before this date, it is worth checking whether it is eligible for the extended compliance deadline of 2 December 2026. Contact our team to assess the scope of your obligations and prepare your system for compliance, and subscribe to our newsletter to receive updates on the most important legal and regulatory changes in Poland.