Defence Finance Monitor - Analysis

Defence Finance Monitor - Analysis

The High-Risk AI Classification Boundary

Where the EU’s forthcoming guidelines could pull defence-adjacent models, security systems and workforce tools back into scope

Aug 03, 2026
∙ Paid

On 24 July 2026 the Official Journal published Regulation (EU) 2026/1744, the Digital Omnibus on AI, which entered into force three days later and moved the application of the high-risk rules to 2 December 2027 for systems classified under Article 6(2) and Annex III, and to 2 August 2028 for systems classified under Article 6(1) and Annex I. The postponement is the visible change; the classification architecture it leaves standing is the consequential one. Regulation (EU) 2024/1689 excludes AI systems placed on the market, put into service or used, with or without modification, exclusively for military, defence or national-security purposes, regardless of the type of entity carrying out those activities, while Recital 24 provides that a system placed on the market for an excluded purpose and for one or more non-excluded purposes falls within the Regulation. Set against a defence-industrial base that increasingly builds software, models and embedded systems circulating across military, civil-security, industrial and workforce environments, and against draft Commission guidance published on 19 May 2026 whose consultation closed on 23 July 2026, the operative boundary is not the defence identity of the supplier but the legally evidenced intended purpose of the system, the function it performs, the product regime into which it is integrated and the context in which it is placed on the market, put into service or used. What the disclosed material leaves unresolved is which entity in the chain carries the classification when a single technical stack is monetised across both channels.

The first section reads the scope and classification architecture: Article 2 of Regulation (EU) 2024/1689 and its Recital 24, the definition of intended purpose, the two high-risk routes of Article 6(1) and Article 6(2), the Annex III areas that reach workforce, biometric, critical-infrastructure and emergency-service functions, and the standing that Article 80 gives the Commission’s draft classification guidelines in the hands of market-surveillance authorities. The second works the mechanics: the amendments made by Regulation (EU) 2026/1744 to Articles 2, 3, 6, 25, 43, 75, 111 and 113; the Annex I division into Section A and Section B and the movement of machinery between them; the Article 6(3) derogation with its documentation and registration conditions; and the surveillance route running through Articles 74, 75 and 80. The third maps the industrial consequences across four operator classes and works the published examples on biometrics and on regulated products issued through the Commission’s AI Act Service Desk, from facility access control to computer-vision safety functions in robot cells. The fourth sets out the decision-relevant implications and states the conditions that would falsify the reading advanced. This report does not assess any company, does not evaluate the compliance posture of any named supplier, does not price the cost of product segmentation and does not predict how the final guidelines will read. It establishes where the legal boundary runs on the disclosed record, and what determines which side of it a given system falls on.



This post is for paid subscribers

Already a paid subscriber? Sign in
© 2026 Defence Finance Monitor · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture