EU AI Act tightens developer duties

- The European Commission began enforcing parts of the EU AI Act on August 2, 2026, while guidance clarified which systems count as high-risk. (digital-strategy.ec.europa.eu) - For developers, the central shift is documentary: high-risk systems need evidence on risk management, record-keeping, human oversight, transparency and conformity assessment. (digital-strategy.ec.europa.eu) - The next major deadline is December 2, 2027, when rules apply to listed high-risk areas such as employment and education. (digital-strategy.ec.europa.eu)

The European Union’s AI Act has moved from a future compliance project to a live enforcement regime. From August 2, 2026, the European Commission’s AI Office and national authorities began enforcing parts of the law, including new transparency rules for some AI systems. At the same time, Commission guidance set out how providers and deployers should assess whether a system is “high-risk,” a label that carries the heaviest obligations under the law. (digital-strategy.ec.europa.eu 1) (digital-strategy.ec.europa.eu 2) For developers, the immediate effect is not a blanket ban on building models or shipping features. It is a shift in what teams must be able to prove. The AI Act and Commission materials point to formal duties around technical documentation, record-keeping, human oversight, transparency, risk management and conformity assessment for high-risk systems. (digital-strategy.ec.europa.eu) ### Which AI teams are actually in scope for the toughest duties? The Commission says only a limited set of use cases are classified as high-risk, mainly where AI can affect health, safety or fundamental rights. Its guidance points to areas including biometrics, critical infrastructure, education, employment, migration, asylum and border control, while separate product-safety rules cover systems embedded in products such as robotics and industrial machinery. (digital-strategy.ec.europa.eu) The AI Act also reaches beyond EU-headquartered companies. The law applies to third-country providers and deployers when the output of the AI system is used in the EU, according to the Act summary and the Commission’s implementation materials. (eur-lex.europa.eu) ### Why are engineers suddenly talking about paperwork? The Commission’s standardisation page says the law’s requirements for high-risk systems must be met before placement on the market and monitored throughout the system’s lifecycle. It lists ten technical areas for standards work: risk management, governance, quality of datasets, record keeping, transparency, human oversight, accuracy, robustness, cybersecurity, quality management and conformity assessment. (digital-strategy.ec.europa.eu) That is why compliance work is landing with engineering teams, not only legal departments. In practice, companies are assembling technical documentation, data and system descriptions, logging and monitoring evidence, and materials that show how human oversight and risk controls work. (artificialintelligenceact.eu) The Act requires providers of high-risk systems to undergo the relevant conformity assessment, draw up an EU declaration of conformity and affix CE marking before placing the system on the market or putting it into service. ### Does running a model offline get a team out of scope? Mickai, a vendor that markets on-premise AI systems, says neither the EU AI Act nor the GDPR mandates a specific deployment model such as on-premise or cloud. Its explanation says the rules are outcome-based and technology-neutral, and that duties for high-risk systems focus on what an organisation can evidence rather than where compute sits. (digital-strategy.ec.europa.eu) That means offline deployment may change who controls the hardware, data paths and logs, but it does not remove the underlying obligations if the system is otherwise in scope. Mickai says ownership of infrastructure can keep decision records and data processing inside the organisation, which may change how evidence is gathered and who bears responsibility for it. (artificialintelligenceact.eu) ### Who enforces this, and what can they ask for? The Commission says enforcement is split among the AI Office, national competent authorities and the European Data Protection Supervisor for EU institutions. National authorities enforce the rules for most AI systems, while the AI Office has powers over general-purpose AI models, some related AI systems and systems integrated into very large online platforms and search engines. (mickai.co.uk) The AI Office can issue requests for information, require access for evaluations in some cases, interview people linked to investigations and inspect providers’ premises, according to the Commission’s enforcement framework. If it establishes an intentional or negligent breach, the Commission may impose penalties. (mickai.co.uk) ### What dates should developers actually track now? August 2, 2026 was the date when enforcement began for parts of the Act and new transparency rules started to apply, including disclosure duties for chatbots and labelling rules for deepfakes and other AI-generated or altered content. (digital-strategy.ec.europa.eu) December 2, 2027 is the next major date for many developers building in listed high-risk areas such as education, employment and migration, according to the Commission’s updated enforcement timeline. For AI systems integrated into products such as robotics and industrial machinery, the Commission says the rules apply from August 2, 2028. (digital-strategy.ec.europa.eu) (digital-strategy.ec.europa.eu) (digital-strategy.ec.europa.eu)

Get your own daily briefing

Scout delivers personalized news, insights, and conversations tailored to your role and industry.

Download on the App Store

Shared from Scout - Be the smartest in the room.