EU AI Act "High-Risk" Provisions Now Fully in Force — €35M Penalties Become Reality, Reshaping AI Procurement Design
機械翻訳 / Machine-translated
The high-risk AI system provisions (Articles 6–7) of the EU AI Act came into full force on August 2, 2026, and during the first week of September the EU AI Office announced it had sent formal Requests for Information to multiple companies. With maximum penalties of up to €35M (approximately ¥5.7 billion) or 7% of global annual turnover now a genuine threat, the development, procurement, and legal frameworks of companies integrating AI into their operations are being fundamentally re-examined.
The EU AI Act, which entered into force in August 2024, has followed a phased implementation schedule. Prohibited AI practices (social scoring, emotion recognition, etc.) took effect in February 2025, and transparency obligations for general-purpose AI (GPAI) models were activated in August 2025.
The current phase constitutes the "third phase." AI systems across 43 categories — including recruitment screening, credit scoring, medical devices, biometric authentication, infrastructure control, and judicial support — are now collectively subject to the following requirements:
Voices from practitioners have been appearing in rapid succession on X:
"The EU AI Act — all our recruitment screening AI might be out of compliance. I've been in meetings with legal three times a week. Where do you even start with a Conformity Assessment?"
(Engineer at a major domestic systems integrator)
On September 3, the EU AI Office officially announced that it had sent Requests for Information to multiple companies providing GPAI models. This constitutes a preliminary step before formal penalty proceedings.
While the high-risk provisions were designed to apply to a defined set of 43 categories, the scope for interpretation is broad. HR management tools, loan assessment AI, and medical diagnostic support are the primary targets, but systems that embed general-purpose LLMs into any of these use cases may also fall within scope — a point that has been troubling corporate legal teams.
OpenAI, Google, Anthropic, and Microsoft have all been strengthening their European governance frameworks since the second half of 2025. However, according to industry association estimates, approximately 38% of companies commercially deploying AI in Europe had not yet completed their Conformity Assessments as of a July 2026 survey. Mid-sized SaaS companies and industrial startups are structurally the furthest behind.
For Japanese companies, this is not irrelevant simply because they lack a European presence. Any company providing products or services to the EU market falls within scope, making businesses in manufacturing, finance, and healthcare particularly important to watch.
A maximum of €35M (approximately ¥5.7 billion) or 7% of global revenue is a higher standard than GDPR (maximum €20M or 4%). The first wave of investigations is expected to focus on GPAI model providers, while the prevailing view is that full-scale investigations into companies operating high-risk systems will begin from Q4 2026 onward.
Companies adopting high-risk AI are obligated to verify vendors' Conformity Assessment documentation. This is establishing "AI procurement due diligence" as a formal business function, and a structure is emerging in which vendors holding ISO/IEC 42001 (AI Management Systems) certification gain an advantage in competitive bids.
When a general-purpose LLM is embedded into a high-risk use case, there is an urgent need to codify in contracts how risk is allocated among the three parties: the model provider, the systems integrator, and the end-user company. Industry-wide efforts to establish standard contractual clauses are expected to accelerate.
The Ministry of Economy, Trade and Industry plans to revise its AI Business Guidelines during fiscal year 2026. A direction has been indicated toward adopting the EU AI Act as a reference standard, and the pressure to converge on "EU compliance = global standard" is likely to intensify, particularly among export-oriented industries.
The fact that many companies are only now realizing "our tools might be subject to this" reflects how slowly the issue has been recognized — not as a regulatory matter, but as a business risk.
This is a mechanism that compels an engineering culture in which "explainability," "human oversight," and "data quality" are built in from the design stage. We are entering a phase where the habit of discussing governance before product speed translates into competitive advantage even outside the EU.
The asymmetry is worth noting. Major model providers moved proactively, while the companies that use AI have not kept pace with their preparation. A structure is taking hold in which the buyers of tools bear the regulatory risk.
From within Japan, "EU regulation feels like a distant concern" — but for manufacturers, financial institutions, and healthcare companies with European operations, the impact becomes real starting this month. Underestimating the cost of compliance is the most dangerous bet of all.
With the full enforcement of the EU AI Act's high-risk obligations, we have entered a phase where global standards for AI development and procurement are changing. The momentum will likely accelerate toward "whether or not you hold a Conformity Assessment" becoming a business trust indicator ahead of any actual penalties.
Is the AI tool your company uses involved in hiring, lending, or healthcare? — It is worth taking the time to check.
This article was written by an AI writer (AI News) of the Mirai News editorial team.