GeoAI and the Law Newsletter
Tracking Developments in AI Laws and Regulations for Geospatial Professionals
GeoAI and the Law is not legal advice. The reader should consult with a trained lawyer on legal matters associated with GeoAI.
Deep Dive
When is Your GeoAI System “High-Risk”? The EU Commission Draws the Lines
In May, the European Commission published draft guidelines for stakeholder consultation on the classification of high-risk AI systems under Article 6 of the EU AI Act (Regulation (EU) 2024/1689). Issued pursuant to Article 6(5) of the Act, the package consists of a general-principles document and two annex-specific chapters addressing the two routes by which an AI system becomes “high-risk”: Article 6(1), covering AI that is itself a product, or a safety component of a product, regulated under the legislation listed in Annex I; and Article 6(2), covering the eight use-case areas listed in Annex III (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and border control, and the administration of justice).
The guidelines are not binding, and authoritative interpretation ultimately rests with the Court of Justice. But they are the clearest signal yet of how the Commission expects providers and deployers to self-assess classification. This timing matters as under the recently agreed Digital Omnibus, the high-risk obligations these guidelines interpret are now staggered, with Annex III duties applying from 2 December 2027 and Annex I duties from 2 August 2028. For geospatial organizations, the draft offers something the Act itself did not: concrete examples, several of which specifically reference satellite imagery, drones, thermal sensors, and spatial-analytics platforms.
Intended Purpose, Not the Sensor, Decides
The most important takeaway for geospatial professionals is classification turns on the intended purpose a provider assigns to a system, not on the technology used or where it is deployed. The Commission states plainly, in the migration and border-control context, that “the place of deployment and the sensor modality are not decisive.” The same satellite feed or thermal camera can be high-risk or out of scope depending entirely on what the provider says the system is for.
The guidelines illustrate this with examples that map directly onto geospatial practice:
A system that uses drone or satellite imagery to detect human presence in vast uninhabited areas to support search and rescue, relying on non-biometric cues, is not high-risk.
But “AI-combined satellite imagery services, surveillance towers or unmanned platforms that flag human presence” to cue a border-control response fall squarely within Annex III, point 7(d), and are high-risk. So does maritime surveillance that detects and tracks persons for border operations. Of note, the Commission is explicit that this holds “irrespective of whether the platform operates in territorial waters, the contiguous zone or on the high seas.”
While the sensing capability is the same, the uses differ. The line is the purpose the provider markets and documents.
This carries a sharp consequence for vendors of general-purpose or multi-use geospatial tools. The general-principles guidance warns that where a system is presented as “broadly applicable across a generality of contexts” and does not “consistently limit its application or exclude high-risk uses,” its intended purpose will be deemed to encompass high-risk use cases. Critically, a disclaimer is not enough: “merely asserting (for example in the terms of service) that high-risk uses are excluded is insufficient” where the provider’s overall presentation, examples, or product positioning effectively promotes such uses. Any limitation must be “clearly, concretely, and coherently described across all materials.”
Critical Infrastructure: Only “Safety Components” Count
Although GeoAI is woven into the management of roads, utilities, and networks, the guidelines confirm that not every such system is high-risk. Under Annex III, point 2, a system qualifies only if it is a safety component that directly protects the physical integrity of the infrastructure by preventing, controlling, or mitigating risks of physical harm. Systems that are “merely supportive, informational, organizational or optimization-oriented” do not qualify.
The Commission’s worked example is instructive: an AI-enabled traffic-flow optimization platform built on real-time data “provides insights but [does] not directly protect physical integrity,” and is therefore not high-risk, while a system that detects abnormal infrastructure behavior and triggers a protective response is. A second condition is easy to overlook: the system must actually be used by an entity formally identified as a critical entity, though, as the guidance notes, that status need not be disclosed to the provider, and many deployers will simply demand high-risk-grade compliance in procurement.
For Annex III systems, there is an escape hatch under Article 6(3) A system that performs only a narrow procedural task, improves a completed human activity, detects decision patterns, or performs a preparatory task may be exempted. Indexing, searching, format conversion, and de-duplication of imagery or case files may qualify under this exemption. But two limits matter for geospatial work. First, the exemption never applies to the Annex I (product-safety) route. Second, the filter is unavailable to any system that performs profiling, and the Commission’s definition expressly includes evaluating a person’s “location or movements” as profiling Much location-analytics work that infers patterns of life from spatial traces will therefore remain high-risk regardless of how narrow the task appears. Providers claiming the exemption must document the assessment and register the system in the EU database.
What Geospatial Professionals Should Do Now?
The runway created by the Digital Omnibus is time to prepare. Practitioners should:
Pin down intended purpose in writing. Audit your instructions for use, sales materials, and technical documentation to ensure any limitation on high-risk uses is concrete, consistent, and credible (i.e., not a buried disclaimer).
Classify by route. For each product, determine whether it travels the Annex I (safety-component) or Annex III (use-case) path as they carry different obligations (e.g., only the latter can use the 6(3) filter.)
Watch the surveillance line. Treat any system that detects, tracks, or identifies persons for border, migration, or law-enforcement response as high-risk. Conversely, clearly segregate genuine search-and-rescue or navigation-safety functions.
Test the filter carefully. Before relying on Article 6(3), confirm the system does not profile (including through inference of location or movement) and document the analysis.
Push the obligations into procurement. Deployers in critical-infrastructure and public-authority contexts should require high-risk-grade compliance contractually, regardless of vendor claims.
These draft guidelines remain open for feedback through June 23, 2026: geospatial organizations that are doing business in Europe should consider responding while the examples are still being written.
Edited by Kevin Pomfret
Partner at Pierson Ferdinand, Author of Geospatial Law, Policy and Ethics: Where Geospatial Technology is Taking the Law | LinkedIn


