The European Commission has released fresh guidance on the EU AI Act, and the news for businesses is sobering: regulators no longer care about your neural network's architecture if your marketing brochure or internal manual says too much. According to Article 6, an AI system's risk classification depends directly on its documented intended purpose. Your investor pitches and user manuals are no longer just text—they are now legal evidence capable of dragging your company into the grinding gears of strict compliance.
Key Takeaways from the New Guidance
A system's legal status is determined by the intended purpose stated in its documentation. Actual use of the system takes precedence over the developer's original intent. Errors in product positioning lead to an automatic "high-risk" classification.
Analysts at Airia estimate that many corporate systems already fall into the high-risk category de facto, even though top management remains blissfully unaware. Article 6 sets out two paths to this status: integrating AI into specific regulated products or using it in "sensitive" scenarios that impact health, safety, or fundamental rights. Crucially, how a system is actually operated trumps what the developer originally intended. This turns the self-assessment mechanism under Article 6(3) into a high-stakes lottery for organizations lacking established AI asset governance.
How you promote and implement a product is just as critical as its source code.
It is time for legal departments to head down to the server rooms and verify whether technical capabilities match the promises made by marketing. The European Commission has made it clear: the methods of promotion and implementation are as critical as the software itself. Any mention of "sensitive" use cases in documentation automatically triggers oversight. The era of vague phrasing and "smart assistants for everything" is officially over—now, every word in a product description can serve as a backdoor for fines and shutdowns.