EU AI Act High-Risk AI Regulations Kick Into Full Gear — Compliance Deadlines and Penalty Risks Become Reality for 45 Japanese Companies
機械翻訳 / Machine-translated
機械翻訳 / Machine-translated
The high-risk AI system provisions of the EU's AI Act entered full enforcement on August 2, 2026. Businesses using AI in areas such as medical diagnostic support, recruitment screening, and credit scoring are now required to maintain logs, implement human oversight, and document risk assessments in order to continue operating within the EU. At least 45 Japanese companies with EU-facing operations are believed to fall directly under the law's scope, marking an inflection point at which AI adoption shifts from being a "technology issue" to a "governance issue."
The AI Act, passed by the European Parliament in March 2024, has been phased in gradually. The provisions banning certain AI systems (such as emotion recognition and social scoring) came into effect in February 2026, and the "high-risk AI systems" category entered full enforcement on August 2.
The main use cases classified as high-risk are as follows:
"Our legal department is scrambling to determine whether our AI recruitment tool is deployed for EU markets. Compliance costs look like they'll run twice what we expected, and we're overhauling our roadmap entirely." (Representative of a major Japanese staffing company, via post on X)
Penalties are capped at whichever is higher: 1–3% of global annual turnover or €7.5 million–€15 million, depending on the severity of the violation.
The concept behind the AI Act dates back to 2021. It took roughly five years to move from proposal to phased enforcement, but this marks the first time that implementation obligations have become a concrete reality for businesses.
Japan has taken a "soft law" approach to AI regulation that differs from the EU's. The Ministry of Economy, Trade and Industry's "AI Business Guidelines," formulated in 2025, carry no legal binding force — but Japanese companies operating in EU markets are directly subject to EU law under the principle of extraterritorial application. For services that scale across borders, like SaaS, claiming "we weren't targeting the EU market" is simply not a viable defense.
Gartner projected as of February 2026 that "by the end of 2026, more than 40% of AI products aimed at the EU market will be recording some form of compliance cost," and the first half of that prediction is now materializing.
Averaging the estimates from three European consulting firms, compliance costs for the AI Act's high-risk category come to approximately €850,000 (around ¥120 million) for mid-sized companies (those with 500–5,000 EU-based employees). The breakdown is roughly 45% for technical implementation (logging and monitoring systems), 30% for legal and documentation work, and 25% for internal training. When outsourced, scope creep poses a significant risk of costs running over.
High-risk systems must incorporate "meaningful human oversight." The prevailing interpretation is increasingly that having a human simply provide after-the-fact approval of AI-generated hiring or credit decisions is insufficient — human intervention must be built into the decision-making process from the design stage. This requirement is fundamentally at odds with AI agent-type systems designed on the premise of full automation.
The "Brussels Effect," whereby EU standards become de facto global norms, is beginning to be observed in the AI domain as well. The Ministry of Economy, Trade and Industry and the Digital Agency are reportedly examining alignment with EU standards, with an eye toward submitting a draft "AI Basic Law" to the Diet in autumn 2026. Even for AI products designed for the domestic market, specifications that conform to EU standards may effectively become the baseline going forward.
What this full enforcement changes structurally is the yardstick by which AI investment is evaluated. The question is no longer just "how accurate is the model?" — the ability to explain, record, and audit a system's decisions is now being added as a procurement and adoption requirement. This hits not only vendors but also the internal design of companies embedding AI into their operations.
An easy point for Japanese companies to overlook is that the regulation can apply even without a European presence. Services that are accessible to EU-resident users are, as a general rule, within scope. B2C and B2B SaaS products with global reach are now at a stage where an immediate legal review is warranted.
At the same time, a paradoxical dynamic is emerging in which regulatory compliance — ostensibly a cost factor — is turning into a new business opportunity. The market for AI compliance-focused legaltech and AI audit tools is projected to grow more than twofold compared to 2025 (MarketsandMarkets, May 2026 estimate), and demand for compliance consulting and certification services is expanding rapidly.
The full enforcement of the EU AI Act's high-risk provisions signals a shift to a stage where AI deployment is judged not by its "speed" but by its "explainability." How you design and document AI-driven decisions — not just how you wager on a model — is becoming part of your competitive edge.
Your company's AI products are now being asked, starting today, whether they can be used in the EU market. The next milestone to watch is the enforcement of additional obligations for general-purpose AI (GPAI) model providers, scheduled for February 2027.
This article was written by an AI writer (AI News) from the Mirai News editorial team.