The EU AI Act: which obligations are already in force, and which are still ahead
The Act did not arrive all at once. Its duties switch on in stages, and by August 2026 several are already live. A plain reading of the timetable, and what each stage requires of whom.
ひとことで言うと
Which parts of the EU AI Act are in force now?
The EU AI Act entered into force on 1 August 2024 and applies in stages. The bans on prohibited practices and the AI-literacy duty applied from February 2025; obligations for general-purpose AI models from August 2025; and the main high-risk regime from August 2026, with product-embedded high-risk systems following in 2027.
要点
- The Act is staged: prohibitions first, general-purpose model duties second, the high-risk regime last.
- Obligations attach to roles — provider, deployer, importer, distributor — not to companies, and one organisation can hold several roles at once.
- It applies extraterritorially: if the output is used in the EU, the Act can reach a provider established anywhere.
- Transparency duties for chatbots and synthetic media hit far more ordinary products than the high-risk category does.
Most coverage of the EU AI Act treats it as a single event. It is not. The Regulation entered into force on 1 August 2024 and then switched its duties on in tranches, each aimed at a different group. Reading the timetable is the fastest way to work out whether it currently affects you.
The staged timetable
| From | What applies |
|---|---|
| 1 Aug 2024 | The Regulation enters into force. Nothing yet obligatory. |
| 2 Feb 2025 | Prohibited practices banned. AI-literacy duty on providers and deployers. |
| 2 Aug 2025 | Obligations for general-purpose AI (GPAI) models; governance bodies operational; penalty regime largely applicable. |
| 2 Aug 2026 | The general application date, including the Annex III high-risk regime and the Article 50 transparency duties. |
| 2 Aug 2027 | High-risk AI embedded in products already covered by EU product-safety law. |
Two caveats before you plan against this. First, transitional provisions treat systems already on the market differently from new ones. Second, the timetable has been the subject of active political debate about simplification and delay; the Regulation's own dates are the baseline, but implementing acts, harmonised standards and guidance continue to arrive. Check the Commission's implementation page rather than trusting a summary — including this one — that may have aged.
The four risk tiers
Unacceptable risk — banned. Social scoring by public authorities, manipulative techniques that materially distort behaviour and cause harm, untargeted scraping of facial images to build recognition databases, emotion inference in workplaces and schools, and — with narrow, authorised exceptions — real-time remote biometric identification in public spaces for law enforcement.
High risk — permitted, heavily conditioned. Two routes in: AI listed in Annex III (biometrics, critical infrastructure, education, employment, essential public and private services, law enforcement, migration, administration of justice), or AI acting as a safety component of a product already regulated under EU law. High-risk systems require a risk management system, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity measures, a conformity assessment, and registration.
Limited risk — transparency. People must be told they are interacting with an AI system unless it is obvious. Synthetic image, audio and video content must be marked in a machine-readable way, and deepfakes disclosed. This tier catches far more everyday products than the high-risk tier does, and it is the one most consumer-facing teams underestimate.
Minimal risk. Everything else. No obligations.
General-purpose models sit in their own track
GPAI providers face a separate set of duties: technical documentation, information for downstream providers who build on the model, a policy for complying with EU copyright law, and a sufficiently detailed public summary of training content. Models judged to present systemic risk carry additional duties — model evaluation, adversarial testing, incident reporting and cybersecurity protection.
The Commission's General-Purpose AI Code of Practice is the intended route to demonstrating compliance for this tier. It is voluntary in form; signing it is meant to reduce administrative burden relative to proving compliance some other way.
Anyone building on top of a general-purpose model should note the downstream effect: if the base model provider does not hand you the documentation you need, your own compliance story has a hole in it. That is a procurement question to raise before signing, not after.
Roles, not companies
The Act allocates duties by role, and a single organisation frequently holds more than one:
- Provider — develops a system, or has one developed, and places it on the market under its own name or trademark.
- Deployer — uses a system under its own authority in a professional context.
- Importer and distributor — place a third-party system on the EU market or make it available.
The provision that catches people: a deployer who puts their own name on a high-risk system, or substantially modifies it, or changes its intended purpose, becomes a provider for the purposes of the Regulation, with the full high-risk obligation set attached. Fine-tuning a model and shipping it as your own feature is exactly the kind of act that can trigger this.
What to do in the next quarter
For most organisations the honest first step is an inventory — what AI is in use, who supplied it, what it decides, and which role you hold for each system. Very few teams can answer that today, and none of the rest of the compliance work can start without it.
After that, in rough priority order: check nothing you operate falls in the prohibited list; satisfy the AI-literacy duty for staff who work with these systems; determine whether any use case lands in Annex III; implement the transparency markings for chatbots and generated media; and, if you build on a general-purpose model, obtain the provider's documentation in writing.
The Act rewards organisations that know what they are running. That is unglamorous, and it is where the work is.
よくある質問
- Does the EU AI Act apply to companies outside the EU?
- Yes, where the AI system is placed on the EU market or its output is used in the Union. Non-EU providers are also expected to designate an authorised representative in the EU.
- Is my chatbot a high-risk AI system?
- Usually not. High risk is defined by listed use cases — biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice — plus AI embedded in regulated products. A general customer-support assistant typically falls under transparency duties instead.
- What are the penalties?
- The Regulation sets tiered administrative fines, with the highest band — up to 7% of global annual turnover or €35 million, whichever is higher — reserved for engaging in prohibited practices.
- What is the difference between a provider and a deployer?
- A provider develops an AI system or has it developed and places it on the market under its own name. A deployer uses one under its authority in a professional capacity. Rebranding a third-party system, or substantially modifying it, can turn a deployer into a provider.
出典
- Regulation (EU) 2024/1689 — the AI Act, full text — EUR-Lex
- AI Act — official overview and implementation timeline — European Commission
- European AI Office — European Commission