EU Publishes Enforcement Guidance for High-Risk AI Systems Under the AI Act
Brussels has clarified how the EU AI Act applies to high-risk systems used in hiring, credit scoring, and public services, with a concrete documentation checklist and a phased compliance window.
European regulators have released enforcement guidance clarifying how the EU AI Act applies in practice to AI systems classified as "high-risk", a category covering hiring tools, credit-scoring models, critical infrastructure, and certain law-enforcement applications.
The guidance narrows some of the ambiguity that had built up around the original text. A hiring-screening tool, for example, is now treated differently depending on whether its output is advisory or determinative in the final decision, a distinction regulators say will be assessed by deployment context, not by the underlying technology alone.
Organizations running high-risk systems will need to maintain a technical documentation file that covers, at minimum:
- Training data provenance and known limitations of the model.
- Testing results, including performance across demographic subgroups where relevant.
- An audit trail sufficient to reconstruct why the system produced a given output.
Penalties remain tied to global annual turnover, as in the Act's original text, and the guidance reconfirms it applies to any organization whose system is used by people in the EU regardless of where the company is headquartered. A phased compliance timeline gives organizations already running high-risk systems a defined window before enforcement begins in earnest.
If your organization touches hiring, lending, healthcare triage, or similarly high-stakes decisions and has EU users, a gap assessment against this documentation checklist is worth starting now, this is the most concrete basis yet for building a program that would survive a regulatory audit.
Source: European Commission: Draft Guidelines on Classification of High-Risk AI Systems