Showing Posts From

High risk ai

EU AI Act Enforcement: What European Companies Must Already Comply With Right Now

EU AI Act Enforcement: What European Companies Must Already Comply With Right Now

Something changed on 2 February 2025 that most European executives missed entirely. A category of AI practices became prohibited and enforceable under the EU AI Act. Not in the future. Not subject to a transitional period. Enforceable on that date. Organisations running AI systems that fell into the prohibited category were non-compliant from that point forward — not approaching non-compliance, not at risk of future non-compliance, but in breach of an enforceable prohibition. Most European executives I work with treat the AI Act as a 2026 problem. Some treat it as a 2027 problem, given that the Digital Omnibus agreement of May 2026 deferred the full obligations for certain high-risk system categories to December 2027. The confusion is understandable — the regulation has a staggered enforcement schedule, and media coverage has focused primarily on the August 2026 milestone for high-risk systems. But the staggered schedule doesn't mean nothing is in force. It means different obligations apply at different points in time. And the first milestone passed eighteen months ago. The enforcement timeline — what is live, what is coming The AI Act entered into force on 1 August 2024. From that date, the regulation exists and creates obligations. The question is which obligations are enforceable when. 2 February 2025: Prohibited AI practices became enforceable. Organisations using AI systems in the prohibited categories have been in breach since this date. 2 August 2025: Rules governing General Purpose AI (GPAI) models became enforceable. This applies primarily to providers of foundation models — the companies building the underlying AI infrastructure. For most European enterprises that are deployers rather than builders, this milestone creates indirect obligations through the requirement to use GPAI providers who themselves comply. 2 August 2026: Full high-risk AI system obligations apply for most categories under the Act. 2 December 2027: Annex III high-risk systems, deferred under the Digital Omnibus agreement of May 2026. This is the deferred deadline that has led some organisations to extend their compliance timelines across the board — which is a misreading of the agreement. The deferral applies to Annex III systems specifically, not to the full regulation. For European enterprises that are AI deployers — using third-party AI systems rather than building foundation models — the immediate exposure is the prohibited practices that have been enforceable since February 2025, and the high-risk system obligations that arrive in full in August 2026. The prohibited practices — enforceable now The banned categories under the AI Act cover AI applications that the European legislature determined are fundamentally incompatible with European values and fundamental rights, regardless of the purpose they serve. Understanding them is important because enforcement has been live for over a year, and because some of these systems appear in enterprise AI programmes under different names. Social scoring systems are prohibited: AI that evaluates individuals based on their social behaviour or personal characteristics and applies consequences to them in contexts unrelated to where the data was collected. Enterprise "employee engagement scoring" or "social collaboration analytics" tools that rate individuals and feed those ratings into decisions about career progression, training access, or benefit eligibility need to be assessed against this definition. Systems that exploit psychological vulnerabilities to manipulate behaviour are prohibited. This includes AI that exploits age, disability, or specific psychological susceptibilities to influence individuals in ways that harm them. Marketing AI that targets individuals based on inferred vulnerability profiles sits in this category. Emotion recognition in the workplace is prohibited. AI systems that infer the emotional state of employees from facial expressions, voice tone, physiological signals, or other biometric data — for any employment-related purpose — are banned. This includes tools marketed as "engagement measurement," "meeting analytics," "performance monitoring," or "wellbeing tracking" if they incorporate emotional inference. Any European company currently running such systems has been operating a prohibited AI practice since February 2025. Real-time biometric identification in public spaces by law enforcement is prohibited, with narrow exceptions. This has limited direct application for most enterprises but is relevant for companies operating public-facing AI surveillance systems. The assessment question for any European enterprise is not "does this tool do what the label says?" It is "what does this tool actually do with the data, and does that function fall within a prohibited category?" The label is marketing. The function is what the Act governs. The high-risk obligations arriving in August 2026 High-risk AI categories under the Act include HR and recruitment AI, credit scoring and financial risk assessment, critical infrastructure management, educational AI that determines access or progression, and law enforcement tools. For a typical European enterprise, the most immediately relevant categories are HR AI and credit or risk scoring. A high-risk designation is not a prohibition. It is a full set of technical and governance obligations that must be in place before and during deployment: Technical documentation of the system must exist before deployment — a complete description of the system's purpose, design, training data, performance characteristics, limitations, and risk mitigation measures. A conformity assessment — either a self-assessment or, for certain categories, a third-party assessment — must be completed before the system goes into production. Human oversight mechanisms must be built into the system's operation. Automated decisions in high-risk categories cannot be final without a meaningful opportunity for human review. Meaningful means a human who has been given sufficient information to actually evaluate the decision — not a checkbox that routes through a queue. Post-market monitoring must be ongoing. The deployer must track how the system performs in real use, log outcomes, identify drift or unexpected behaviour, and have a process for reporting serious incidents. For European companies that have been deploying HR AI — tools that screen CVs, rank candidates, recommend candidates for rejection or progression, or support performance review — without this framework in place, the August 2026 deadline is not far off. Building the technical documentation, redesigning oversight mechanisms, and implementing post-market monitoring are not quick projects. They require architectural decisions made in advance. The four risk tiers and how to map an enterprise AI programme The Act organises AI systems into four tiers. Understanding which tier an AI tool sits in determines what obligations apply. Unacceptable risk (prohibited): Banned outright. Enforceable since February 2025. If any tool in your programme sits here, it needs to stop, not be redesigned. High risk: Full documentation, conformity assessment, human oversight, and post-market monitoring required. Most HR AI, credit scoring AI, and similar tools sit in this tier if they produce decisions with significant effects on individuals. Limited risk: Transparency obligations apply. Users must be informed when they are interacting with an AI system. Chatbots, customer service AI, and AI-generated content tools typically sit here. The obligation is disclosure, not redesign. Minimal risk: No specific obligations beyond general GDPR. Most AI tools — recommendation systems, spam filters, productivity tools that don't make decisions about individuals — sit here. A well-run mapping exercise across a European enterprise's AI programme will typically find: a large number of tools in the minimal or limited risk tier; some tools in or approaching the high-risk tier, particularly in HR, compliance, and finance functions; and — in organisations that have deployed AI broadly without systematic oversight — a reasonable chance of finding a tool that functions in ways that fall within or near the prohibited category. The mapping is not a one-time document. AI systems change. Vendors update their models. A tool that was minimal risk in 2024 may be operating differently in 2026. The mapping needs to be a living assessment. What to take from thisAudit your AI programme against the prohibited practices list immediately. If any system involves emotion recognition in the workplace, social scoring, or exploiting psychological vulnerabilities to influence behaviour, it has been operating in breach since February 2025. Stop first, then assess. Map every AI tool against the four risk tiers. This is a one-time exercise that becomes a living document. Do it across the full programme — not just the tools the CIO knows about, but the tools individual functions have procured and deployed without central oversight. For high-risk systems — particularly HR AI and any credit or risk scoring tools — start the documentation and oversight architecture now, not in 2026. Technical documentation, conformity assessment, and human oversight mechanisms require architectural decisions made before deployment, not added retrospectively. Put AI Act penalty exposure in the board-level risk register with realistic probability weightings. The €35 million or 7% ceiling for prohibited practices is enforceable today. Complaint-driven enforcement from affected individuals is the most likely trigger. Confirm that deployer obligations under Article 26 are addressed in your vendor contracts. Using a third-party model provider doesn't remove the deploying company's compliance obligations. The vendor's compliance doesn't substitute for the deployer's. Review the Digital Omnibus deferral carefully. The deferral to December 2027 applies to Annex III systems specifically. It does not apply to prohibited practices (enforceable since February 2025), GPAI rules (enforceable since August 2025), or the majority of high-risk system obligations that arrive in August 2026.The AI Act is a regulation with a staggered enforcement schedule, and that staggering has created the conditions for a comfortable deferral of the compliance conversation. The problem is that staggering means different things apply at different times — not that nothing applies yet. The organisations currently treating the AI Act as a future problem have already missed the February 2025 milestone. The question is how many will realise that before a complaint does.

Read full article