The EU AI Act's High-Risk Rules Are Now in Force—Why Businesses Globally Just Entered the "Compliance Era"?
One-line takeaway: On August 2, 2026, the EU AI Act became fully applicable and the power to fine started the same day—the "grace period" for high-risk AI is officially over. Combined with a patchwork of US state laws, global companies are now facing a compliance era defined not by "whether to regulate" but by "how to regulate and how heavy the fines are."
On August 2, 2026, the long-anticipated EU AI Act became fully applicable across the European Union. From that day, businesses deploying high-risk AI systems in the EU market must complete conformity assessments, put human oversight in place, keep full audit trails, and disclose AI usage to affected people—with fines of up to 7% of global annual turnover or €35 million. The regulatory era is no longer coming; it has arrived.
Which Scenarios Count as "High-Risk"? A Map of Obligations Is Taking Shape
The EU AI Act classifies AI systems by risk: unacceptable-risk systems are banned outright, while high-risk systems carry the heaviest obligations. High-risk covers employment and hiring, credit scoring, education, law enforcement, medical devices, and critical infrastructure—banks must explain every algorithm-driven loan refusal, hospitals must log every diagnostic suggestion an AI offers, and using AI to screen résumés is no longer an "internal matter."
Notably, just six days before enforcement (July 27), the EU's Digital Omnibus Regulation (2026/1744) entered into force, deferring some Annex III high-risk obligations—covering hiring, credit scoring, and law enforcement—from August 2, 2026 to December 2, 2027. But this is not a reprieve: the Act itself applied on schedule, the power to fine began the same day, and transparency rules and model-provider duties went live untouched. As compliance watchers put it: deadlines can move; the regulatory direction cannot.
The US "Patchwork": No Federal AI Law, but States Are Legislating on Their Own
Unlike the EU's single code, the US federal level is pursuing an "AI Action Plan" approach with no unified federal AI law. Instead, states are legislating independently, creating a "one country, many rules" compliance puzzle:
- California SB 53: Requires frontier models to undergo safety testing before training and deployment, effective 2026—one of the few state laws anywhere that directly regulates "the model itself."
- Colorado AI Act: Focuses on algorithmic discrimination, regulating the use of AI in "consequential decisions" such as employment, insurance, and finance—in effect since June 2026.
- Combined with scattered legislation in other states, a multinational company may need to satisfy EU obligations, California testing requirements, and Colorado anti-discrimination rules simultaneously—one AI system, three compliance languages.
Ripple Effects: Compliance Costs vs. Innovation Flight
For businesses, compliance is not just "adding one document": conformity assessments, human oversight, audit logs, transparency disclosures, fundamental rights impact assessments, and post-market monitoring all cost money, people, and process. Financial, healthcare, and HR departments are on the front line, because they are exactly where high-risk scenarios cluster.
The bigger question is industrial: will strict regulation push AI innovation to "flee" to less-regulated regions? The EU's answer is to trade on single-market scale—making "legal in the EU" the global standard. Meanwhile, the diverging fines and obligations of US state laws are pushing companies to design products to the "lowest common denominator." August 2026 is the watershed: the AI conversation has formally shifted from "whether to regulate" to "how to regulate and how heavy the fines are."
FAQ
Q1: Which applications do the EU AI Act's high-risk provisions cover?Employment and hiring, credit scoring, education, law enforcement, medical devices, and critical infrastructure. Algorithmic loan refusals by banks, AI diagnostic suggestions in hospitals, and AI résumé screening in HR all fall in scope, requiring conformity assessment, human oversight, audit trails, and disclosure.
Q2: How do California SB 53 and the Colorado AI Act differ?California SB 53 directly regulates "frontier models" themselves, requiring safety testing before training and deployment. The Colorado Act targets algorithmic discrimination, governing fairness obligations when AI is used in consequential decisions like employment, insurance, and finance. One regulates the model; the other regulates its use.
Q3: How heavy are the fines?Up to 7% of global annual turnover or €35 million under the EU Act; transparency-related violations cost 3% or €15 million. For large multinationals, that is enough to elevate compliance from a legal matter to a boardroom matter.
Q4: Didn't the EU delay some deadlines right before August 2?Yes—the Digital Omnibus (2026/1744) deferred certain high-risk obligations in hiring, credit, and law enforcement to December 2, 2027. But the Act itself and the power to fine applied on August 2 as scheduled, and transparency plus model-provider duties were not deferred. Homework was postponed; the exam was not canceled.
Q5: What should companies do now?Inventory every high-risk AI system, build conformity assessments and audit trails, confirm human oversight, and disclose AI usage. Multinationals should also bake the differences between EU, California, and Colorado rules into product design—start from the lowest common denominator, prepare for the highest standard.
留言
張貼留言