Sekėjai

Ieškoti šiame dienoraštyje

2026 m. rugpjūčio 7 d., penktadienis

High-Risk AI: What Businesses Should Know – Even Everyday Digital Tools Could Fall Under the New European Regulation


“The European Parliament and the Council recently agreed to extend the deadline for regulations concerning high-risk AI systems. Obligations for standalone high-risk AI systems are now set to apply starting December 2, 2027. If the systems are embedded in products, the regulations will not apply until August 2, 2028. Nevertheless, companies should not become complacent. The fundamental structure of the high-risk regime remains largely unchanged.

 

It is precisely the everyday digital tools that could soon be classified as high-risk AI—entailing extensive obligations.

 

The AI ​​Act aims to establish a uniform, high level of protection for fundamental rights while simultaneously fostering the use of AI in Europe.

 

At the core are systems whose decisions can significantly impact people's lives—ranging from algorithms used for personnel decisions to the assessment of consumer creditworthiness.

 

The obligations for "providers" are particularly far-reaching. This term encompasses more than just traditional AI developers; it also covers any company that puts an existing system into operation under its own name or further trains a model for a specific purpose and offers it as its own solution.

 

Consequently, numerous SMEs and start-ups could also become regulated AI providers. They would face comprehensive requirements regarding documentation, monitoring, and quality—some of which do not stem directly from the regulation itself but rather from a complex web of technical standards set by private standardization bodies. It remains to be seen whether the planned exemptions for SMEs will actually provide relief.

 

Many businesses currently lack a systematic inventory of their AI systems and have not yet assessed which applications will need to be classified as high-risk in the future.

 

Robust processes for risk management, data governance, and ongoing monitoring are also missing completely in many places—even though these elements form the core of the new compliance architecture.

 

If companies failed to utilize the original implementation deadline of August 2026, it is unlikely they will be able to build these structures from scratch by December 2027 either. The only remaining option is to build upon existing processes or to forgo the use of the relevant tools altogether.

 

In addition to the deadline extension, plans are now in place to exempt the mechanical engineering sector—a key pillar of the European economy—from AI regulations. Previously, many AI applications within machinery were classified as high-risk systems, particularly where AI performed safety functions or was closely linked to product quality assurance. Going forward, such systems are largely expected to fall outside the scope of the AI ​​Act, provided they are already covered by sector-specific regulations offering an equivalent level of safety—such as the Machinery Products Regulation. It remains to be seen whether these measures will provide any structural relief.

 

However, the regulatory environment can also create strategic opportunities. Many companies are currently deterred by the effort involved and are opting to avoid high-risk AI applications entirely. Those who consciously venture into this field now and implement the new requirements early on position themselves in a sparsely populated market segment, thereby gaining a competitive advantage.

 

Such companies can offer high-risk AI in a legally compliant manner, build trust with customers and regulators, and help shape standards rather than merely playing catch-up later.

 

The authors are lawyers at the law firm Noerr.” [1]

 

1. Hochrisiko-KI: Was Betriebe wissen sollten: Auch alltägliche digitale Werkzeuge könnten unter das neue europäische Reglement fallen. Frankfurter Allgemeine Zeitung; Frankfurt. 20 May 2026: 16. HENRIKE VON DEM BERGE, JOHANNES STUVE

 

 

Komentarų nėra: