August 2026 · 5 min read
EU AI Act High-Risk Rules Take Effect August 2
The Compliance Countdown Reaches Zero

Key Definitions
High-Risk AI System The EU AI Act classifies AI systems into four risk tiers: unacceptable, high, limited, and minimal. High-risk use cases include recruitment screening, credit scoring, insurance pricing, medical diagnostics, critical infrastructure management, law enforcement support, and immigration border control.
Conformity Assessment Enterprises must demonstrate compliance in data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness, and cybersecurity. This requires complete model documentation, training data provenance, risk management systems, and post-market monitoring mechanisms.
On August 2, the EU AI Act's high-risk AI system rules officially entered the enforcement phase. Enterprises must complete conformity assessments covering data governance, transparency, and human oversight — or face fines of up to €35 million or 7% of global turnover. This is not a warning. The countdown has reached zero.
Scope of High-Risk AI Systems Under Enforcement
The EU AI Act classifies AI systems into four risk tiers: unacceptable, high, limited, and minimal. The rules taking effect on August 2 target high-risk AI systems — and the scope is broader than many enterprises expect.
Affected High-Risk Use Cases
Includes recruitment screening, credit scoring, insurance pricing, medical diagnostics, critical infrastructure management, law enforcement support, and immigration border control. Any enterprise deploying AI in these domains must complete conformity assessments.
Core Compliance Requirements
Enterprises must demonstrate compliance in data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness, and cybersecurity. This means complete model documentation, training data provenance, risk management systems, and post-market monitoring mechanisms.
Fine Scale and Enforcement Mechanism
The consequences are severe. For compliance violations involving high-risk AI systems, fines can reach up to €35 million or 7% of global turnover, whichever is higher. For providing incorrect or misleading information, fines can reach €7.5 million or 1% of global turnover.
Enforcement is carried out by national competent authorities in each member state, coordinated by the EU AI Office. Enterprises should not expect regulatory leniency — the EU has made clear that enforcement begins on day one, with no additional transition period.
Enterprise Compliance Checklist
For enterprises that have not yet completed compliance preparation, the following actions are urgent:
1. Complete Your AI System Inventory
Catalog all AI systems currently in use or planned for deployment, classified according to the EU AI Act risk tiers. Without an inventory, you cannot determine which systems require conformity assessment.
2. Establish a Risk Management System
Build a documented risk management process for each high-risk AI system, covering identification, assessment, mitigation, and monitoring throughout the lifecycle. Risk management is not a one-time activity — it is a continuous process.
3. Ensure Human Oversight and Transparency
High-risk AI systems must allow for effective human oversight, including intervention capabilities, halt mechanisms, and result interpretability. Users must also be informed when interacting with an AI system.
4. Implement Post-Market Monitoring
Compliance is not a one-time certification. Enterprises must continuously monitor AI system performance, collect incident data, and report serious incidents to competent authorities.
The enforcement of the EU AI Act marks the transition of AI governance from voluntary principles to mandatory rules. Enterprises cannot treat compliance as an afterthought — governance must be embedded into the design, deployment, and operation of AI systems.
FAQ
How does the EU AI Act classify AI systems by risk, and which tier do the August 2 rules target?+
The EU AI Act classifies AI systems into four risk tiers: unacceptable, high, limited, and minimal. The rules taking effect on August 2 target high-risk AI systems — and the scope is broader than many enterprises expect.
Which use cases are classified as high-risk AI systems?+
Affected high-risk use cases include recruitment screening, credit scoring, insurance pricing, medical diagnostics, critical infrastructure management, law enforcement support, and immigration border control. Any enterprise deploying AI in these domains must complete conformity assessments.
What are the maximum fines for high-risk AI system compliance violations?+
For compliance violations involving high-risk AI systems, fines can reach up to €35 million or 7% of global turnover, whichever is higher. For providing incorrect or misleading information, fines can reach €7.5 million or 1% of global turnover. Enforcement is carried out by national competent authorities, coordinated by the EU AI Office.
How should enterprises build their AI system inventory and risk management system?+
Enterprises should catalog all AI systems currently in use or planned for deployment, classified according to the EU AI Act risk tiers. Without an inventory, you cannot determine which systems require conformity assessment. For each high-risk AI system, build a documented risk management process covering identification, assessment, mitigation, and monitoring throughout the lifecycle — risk management is a continuous process, not a one-time activity.
What are the human oversight and post-market monitoring requirements for high-risk AI systems?+
High-risk AI systems must allow for effective human oversight, including intervention capabilities, halt mechanisms, and result interpretability. Users must also be informed when interacting with an AI system. Compliance is not a one-time certification — enterprises must continuously monitor AI system performance, collect incident data, and report serious incidents to competent authorities.
相关文章
美国第一部 Agent 专项法案:可追溯性正在变成投标条件
9月3日两党议员提出 Stop Rogue AI Act:NIST 一年内制定 Agent 安全标准——机器可读清单、动作验证、防篡改日志;联邦承包商须达标。自愿标准+承包商强制=CMMC 式采购杠杆,可追溯正从最佳实践变成合同义务。
欧盟把 ChatGPT 定为『超大型搜索引擎』:AI 搜索的 DSA 合规倒计时
8月31日欧盟依 DSA 将 ChatGPT 指定为 VLOSE——159.1M 欧盟月活、2027年1月前须建成系统性风险评估+独立审计+算法透明度+公开广告库。触发门槛看能力而非品类,Gemini、Perplexity、Claude 都盯着同一个 45M 用户时钟。
你的 AI Agent 合规吗?— 2026 年美国 AI 监管四线并行全景
2026 年 7 月,美国 AI 监管四线并行:州法(Colorado 模式)、行业监管(FINRA)、联邦法案(AI AGENT Act)、联邦采购(GSA 供应链 flowdown)。企业面对的不是一部法规,而是四个层面同步推进的监管浪潮。
你的下一次 SOC 2 审计会包含 AI Agent:证据清单
SOC 2准则没变,但审计师已开始用它对自主Agent取证。三类标准证据——Agent清单(身份/所有者/风险级)、提示与完成日志、漂移证据——正在成为2026年审计的默认要求。
OOMeta AI
EU AI Act high-risk rules are now enforceable. OOMeta's AI governance platform helps enterprises rapidly build AI system inventories, risk assessment processes, and compliance documentation systems — ensuring readiness within the enforcement window.
Schedule a DiagnosticSources: EU AI Act, European Commission, EU AI Office