Re: Draft EU Commission guidelines on the classification of high-risk AI system

Dear Paola, and fellow participants,

Thank you for distilling the key terms from the draft guidelines. I want to put something concrete on the table, because it is directly relevant to how this group represents high-risk classification for agentic systems.

I maintain the Arsia Protocol, an open specification (Apache-2.0 / CC BY-SA 4.0) for AI agent identity, communication, and governance. It addresses a question the guidelines raise but do not resolve for agents: once a system is classified, how does that classification travel with the agent across service boundaries, and how is it enforced at the point of action?

To be clear on positioning: Arsia does not compete with agent protocols such as MCP or A2A. It sits on top of them, protocol agnostic.

This is not a paper proposal. The protocol is specified, implemented, and running in production. It has a published SDK, with multiple implementations built on it.

On the substance relevant to the key terms work:

1. Classification is a signed field. Every agent carries a signed identity record with an ai_system_classification value from a fixed vocabulary (minimal-risk, limited-risk, high-risk, unacceptable-risk), bound to its cryptographic identity, not asserted in prose. Provider and deployer are kept distinct, with jurisdiction encoded as ISO 3166.

2. Classification drives enforcement, not just disclosure. Unacceptable-risk agents are rejected at onboarding, high-risk agents must present a compliance profile before admission, and a runtime policy pipeline enforces human oversight (Article 14), tamper evident audit trails (Article 12), and capability level authorization.

3. Obligations travel as data, through machine readable compliance profiles including EU-AI-ACT-HIGH-RISK and EU-AI-ACT-LIMITED-RISK, alongside GDPR, DORA, MiFID II, and DSA.

So the group knows where this effort sits: Arsia Labs is part of NVIDIA Inception and the Cloudflare for Startups program, and Arsia Labs is a signatory to the EU AI Pact Pillar II voluntary pledges. We will be at Web Summit Lisbon demonstrating the protocol, and we are in discussions with cloud providers about implementing it natively, including early conversations with Microsoft.

The reason I raise this here is that, for agentic AI, a classification that cannot be represented, transported, and verified between independent parties is not enforceable in practice. That is a knowledge representation problem, and it is this group's remit. Arsia is one open implementation of this running in production.

If useful, the specification and the SDK are open to read, along with demos that implement the protocol end to end. Seeing how these terms behave in a system that actually runs in production may help the group make the abstract concrete. I am happy to point to the relevant parts or answer questions.

You can find more about Arsia Protocol at:


  *
https://arsiaprotocol.org<https://arsiaprotocol.org/#specification>
  *
https://github.com/arsialabs/arsia-protocol
  *
https://github.com/arsialabs/arsia-protocol-sdk

Best regards,
Kirk Patrick
arsiaprotocol.org

Sent from Outlook for Mac
From: Paola Di Maio <paola.dimaio@gmail.com>
Date: Wednesday, 1 July 2026 at 14:46
To: W3C AIKR CG <public-aikr@w3.org>; public-agentprotocol <public-agentprotocol@w3.org>
Subject: Draft EU Commission guidelines on the classification of high-risk AI system


Greetings AI KR CG Participants

Draft Commission guidelines on the classification of high-risk AI system
https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems
The Annexes in the page are faulty (as of July 1st both links download  the same document, which is a DRAFT  with blank placeholder slots)

Errors notwithstanding, here is a distilled  a draft of   key terms<https://docs.google.com/document/d/1g7qzRIFLY5jvAfPzT4aGsZ5QKY9F6EOnaeW7vAzVMFA/edit?usp=sharing> representing an important initiative here for  review and discussion

Please send  comments  and discussions if any to the public mailing list *this list  or to the Chair *me, or request edit access to the doc
so that inputs can be aggregated and included in the group's submission. *contributors will be acknowledged  unless they wish to remain anonymous

Thanking everyone in advance for the interest and participation in shaping representation for agentic AI


Paola Di Maio, PhD

Received on Thursday, 2 July 2026 22:48:53 UTC