← Back to news
Archived · Published 7 August 2026
The EU AI Act Enters Its Difficult Phase as High-Risk Obligations Arrive
The EU AI Act's phased application was designed to give the market time, and the early phases were absorbed with comparatively little disruption. The prohibitions on unacceptable-risk practices affected a narrow set of applications most mainstream vendors were not building. The transparency obligations — disclosing AI interaction, labelling synthetic media — required product changes but not architectural ones. The general-purpose AI model obligations landed on a small number of well-resourced providers. The high-risk regime is a different proposition, because it applies to deployers as well as providers, and because what it demands is evidence.
The high-risk categories are defined by use rather than by technology, which is the part organizations most consistently misread. Employment and worker management, access to education, creditworthiness assessment, essential public and private services, law enforcement and migration functions, and safety components of regulated products are in scope regardless of how simple the underlying model is. A logistic regression that scores job applicants is high-risk; a large language model that summarizes internal meeting notes is not. Teams that scoped their compliance work by asking which of their systems use AI have generally produced the wrong inventory, because the statute asks what the system decides, not what technique it uses.
The obligations themselves are where the practical difficulty concentrates: a documented risk management process across the lifecycle, data governance covering training and validation data including examination for bias, technical documentation sufficient for a regulator to assess conformity, automatic logging, human oversight designed so the overseer can actually intervene, and demonstrated accuracy, robustness and cybersecurity. Individually none is exotic — they are recognizable from other regulated-industry quality regimes. Collectively they require a level of documentation about system behaviour that a substantial number of deployed models simply do not have, having been built by teams for whom "it performed well in evaluation" was the standard of evidence.
The deployer obligations are the ones most likely to surprise organizations that consider themselves buyers rather than builders. A company that purchases a high-risk AI system and puts it into use takes on duties of its own: using it in accordance with instructions, assigning competent human oversight, monitoring operation, retaining logs, and informing affected people in certain contexts. That responsibility cannot be contracted away to the vendor. For the large population of organizations whose AI exposure is entirely through purchased software, this is the provision that converts the AI Act from someone else's compliance problem into their own.
Defici Editorial · AI News
This article was generated by Defici's AI editorial system.