EU AI Act "High-Risk AI" Fully Enforced from August 2026 — No Grace Period for Companies Using AI in Healthcare, Hiring, or Finance
機械翻訳 / Machine-translated
The EU AI Act's core provision regulating "high-risk AI" entered full enforcement on August 2, 2026, as the transition period came to a close. Companies operating AI systems in the eight covered sectors — including medical diagnosis, recruitment screening, and credit assessment — are immediately required to maintain risk management documentation, establish human oversight mechanisms, and register with the EU AI database. Japanese companies are also subject to these rules if their AI systems affect end users within the EU, marking the effective start of the enforcement phase by national regulatory authorities.
The EU AI Act entered into force on August 1, 2024, with a phased enforcement schedule organized by risk category. Prohibited practices (such as emotion recognition and social scoring) were enforced starting February 2025. Obligations for general-purpose AI (GPAI) models took effect in August 2025. The August 2, 2026 deadline now represents the final enforcement milestone for high-risk AI systems.
The eight sectors subject to high-risk AI classification:
On X, a growing sense of urgency is being shared, particularly among legal and compliance professionals.
"The high-risk AI provisions are now in full effect. Registering with the AI register and documenting human oversight mechanisms became mandatory as of this week. After going through everything in-house, I was surprised by just how many of our systems fell under 'high-risk.'"
(Post on X by a compliance officer at a major domestic IT company)
The EU AI Act was first drafted by the European Commission in April 2021 and passed by the European Parliament in March 2024, making it the world's first comprehensive AI regulatory law. Its framework is built on a four-tiered system of obligations based on AI risk level, with the core obligations of the AI Act concentrated in the high-risk category.
High-risk AI systems are primarily required to comply with the following:
Penalties for violations reach up to €15 million or 3% of global annual turnover, whichever is higher. For violations of prohibited practices, the ceiling rises to €35 million or 7%.
The AI Act applies to companies that "provide" or "use" AI systems within the EU. Japanese companies are subject to the regulation if they have a business presence in the EU or provide services to EU residents. Japanese companies using recruitment AI, loan assessment AI, or medical support AI at their EU locations need to immediately verify their compliance obligations this month.
Systems classified as high-risk AI must be registered in the EU-operated public database known as the EU AI Register. Registration information includes the AI system's purpose, the types of training data used, and the human oversight mechanisms in place. Supervisory authorities are expected to use this database to identify targets for audits, meaning that failure to register may itself constitute a violation.
Obligations for general-purpose AI (GPAI) models such as GPT-5 Turbo and Claude took effect in August 2025 and operate on a separate track from the current enforcement. However, when these APIs are used to build systems for high-risk applications, the system provider incurs additional obligations as a high-risk AI operator. The fact that API users become the regulated party is an easy-to-overlook aspect of this structure.
What changes with this enforcement milestone is not the existence of the regulation, but the fact that enforcement has become a reality. Since 2024, many companies have developed AI ethics policies, but the high-risk obligations under the EU AI Act are qualitatively different from voluntary documentation. The structure has shifted in that legal coercive force — in the form of regulatory inspections, corrective orders, and financial penalties — is now in play.
Japan currently has no comprehensive domestic regulation equivalent to the EU AI Act, but major companies are accelerating efforts to align with the Ministry of Economy, Trade and Industry's "AI Business Guidelines (2nd Edition)" published in 2025, while using EU compliance as a precedent for establishing internal rules.
Another key concern is the risk of an "expansive interpretation" of the high-risk AI classification. The definitions in Annex III of the AI Act are written in relatively broad terms, leaving open the possibility that supervisory authorities may expand the scope of coverage based on actual operational circumstances. If the first penalty cases emerge within the next 12 months, those decisions are expected to become the de facto rules for the entire industry. Which sector and which country produce the first such case will be the critical first juncture.
The full enforcement of the EU AI Act's high-risk AI provisions marks the transition from "AI regulation is coming" as a warning to "AI regulation is now in operation" as a reality. For companies with EU locations or EU customers, registering with the AI register and documenting human oversight mechanisms have become items to confirm within this week. When the first penalty cases emerge — and in which sectors — will be the defining turning point over the next six to twelve months.
Does your organization use any AI systems that appear on the covered list?
This article was written by an AI writer (AI News) from the Mirai News Editorial Team.