tech, developers, and the code underneath

issue 199· news·

The AI Act's high-risk obligations take effect today

Two years after entry into force, the substantive requirements arrive. What changes, what was delayed, and what to do now.

The EU AI Act's obligations for high-risk AI systems apply from today. This has been scheduled since the Act entered into force in August 2024, and it is the point at which the most substantive requirements become enforceable.

what applies now#

For providers of high-risk systems — those used in employment, education access, credit, essential services, law enforcement, migration, justice, and as safety components in regulated products:

  • Risk management system, documented and maintained across the lifecycle.
  • Data governance, with documented training, validation, and test data and attention to bias.
  • Technical documentation sufficient for conformity assessment.
  • Automatic logging of the system's operation, retained.
  • Transparency to deployers about capabilities, limitations, and intended use.
  • Human oversight designed into the system.
  • Accuracy, robustness, and cybersecurity proportionate to the purpose.
  • Conformity assessment and CE marking before placing on the market.
  • Registration in the EU database.
  • Post-market monitoring and serious incident reporting.

Deployers — organizations using a high-risk system rather than supplying it — have a lighter but real set: use it according to instructions, ensure input data is relevant, monitor operation, retain logs, and assign competent human oversight.

the parts that moved#

The implementation timeline has been adjusted more than once during the run-up, which is normal for regulation of this scope and which made planning genuinely difficult for anyone trying to comply.

The important practical consequences:

Some obligations phase in later for systems already on the market, and for high-risk systems that are safety components of products covered by other EU legislation.

Harmonised standards are still being finalised. Conformity assessment is easier when you can demonstrate compliance against a standard; where standards are not yet available, providers must demonstrate compliance against the requirements directly, which is more work and more uncertain.

Enforcement capacity varies by member state. Market surveillance authorities are at different stages of readiness. That is not a reason to assume non-enforcement — it is a reason to expect inconsistency in the first period.

Check the current state before making decisions. The details have moved and may move again.

what to do if you are in scope#

If you have not classified your systems, do that today. It is the prerequisite for everything else and it is a legal question with technical inputs. A number of organizations discover they are in scope for one feature they had not considered — a CV screening tool, a proctoring feature, a creditworthiness proxy.

Documentation is the bulk of the work. Training data provenance, validation methodology, known failure modes, intended use and misuse. Most engineering teams do not have this written down and reconstructing it is slower than producing it as you go.

Logging is a technical requirement. Automatic recording of operation, retained, with enough detail to trace a decision. If your system does not do this, it is engineering work with a deadline that has passed.

Human oversight is a design constraint, not a checkbox. "A person reviews the output" is insufficient if the person cannot meaningfully understand, question, or override it. Surfacing confidence, explaining the inputs that drove a decision, and making override easy and recorded are interface requirements.

if you are not in scope#

Most software is not. The transparency obligations — disclose that users are interacting with an AI system, label synthetic media — apply much more broadly and are much lighter.

The thing worth doing regardless of scope: know which category you are in, and write down why. "We assessed this and concluded it is not high-risk because X" is a one-page document that saves an enormous amount of time when someone asks, and someone will ask.

the honest assessment#

The Act is the most comprehensive AI regulation any jurisdiction has attempted. It has real criticisms — compliance cost falls hardest on small companies, the risk categories map imperfectly onto how systems are actually built, and the standards process has lagged the deadlines.

It is also law, it has extraterritorial reach, and penalties scale with global turnover.

The organizations that started classification work a year ago are in reasonable shape today. The ones that waited for clarity are discovering that regulatory clarity tends to arrive after the deadline rather than before it, which is a lesson that generalizes well beyond this particular Act.

Dom, August 2, 2026

get README in your inbox

One dispatch, no noise. Tech and developer news, plus the occasional long piece on the craft.

subscribe →