On August 2, 2026, the core obligations of high-risk AI systems under Regulation (EU) 2024/1689 officially entered the stage of full application. This means that companies that deploy or use high-risk AI systems in the EU market will now need to meet a complete set of compliance requirements, including technical documentation, risk management, data governance, and manual supervision.
From 'completion of legislation' to 'implementation of obligations'
The EU Artificial Intelligence Act officially came into effect on August 1, 2024, and is the world's first comprehensive law to comprehensively regulate AI. It adopts a "risk grading" approach: unacceptable risks (such as social ratings and manipulative AI) will be prohibited from February 2, 2026; The transparency obligation of the General Large Model (GPAI) has been applied since August 2, 2025; The full set of obligations for high-risk AI systems will be fully implemented on August 2, 2026, after two years of effectiveness.
What scenarios do high-risk AI systems cover? ━━
According to the annex of the bill, high-risk systems mainly fall into two categories: AI used as security components for regulated products such as medical devices, automobiles, and aviation; and AI systems in key areas explicitly listed in the bill, including biometric recognition, critical infrastructure, education, employment, basic public services, law enforcement, immigration and border management, judicial democracy, and other scenarios. Some high-risk use cases in Attachment 3 (such as some law enforcement scenarios) are entitled to an additional three-year transition period, which will be extended until August 2027.
What does the enterprise need to do? ━━
For enterprises operating in the European Union, the compliance checklist generally includes: establishing and maintaining a risk management system; Prepare high-quality training data and explain data governance practices; Write technical documents and keep operation logs; Ensure that the system has transparency and manual supervision mechanisms; Complete compliance assessment and register in the EU database before launching on the market. Violating core obligations may result in fines of up to 35 million euros or 7% of global annual revenue - the severity of the penalties is in line with GDPR, not just 'paper legislation'.
What does it mean for overseas enterprises? ━━
The bill has a clear 'extraterritorial effect': even if a company is located in China, as long as its AI system output is used within the EU, it may still fall under jurisdiction. It is recommended that overseas enterprises conduct an inventory of their product lines, assess risk levels, and complete gap analysis in accordance with the annex of the bill as soon as possible. Compliance costs should be included in product planning to avoid "going online and violating regulations".
[Reference source] Official text of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689, EUR Lex EU Legal Database)