LaunchCode

The EU AI Act's high-risk obligations finally bite, and compliance teams are scrambling

The EU AI Act's high-risk obligations finally bite, and compliance teams are scrambling

The phased implementation timeline built into the European Union's AI Act has reached the stage that compliance officers across the bloc had been dreading since the regulation was first passed: the obligations governing high-risk AI systems - those used in employment decisions, credit scoring, law enforcement, critical infrastructure and a defined list of other sensitive categories - have moved from a future planning exercise into an active enforcement reality, with national market-surveillance authorities empowered to investigate and fine non-compliant deployments. The practical burden has fallen hardest on mid-sized enterprises that lack the dedicated AI-governance teams that the largest technology companies built years in advance of the deadline. Conformity-assessment requirements, mandatory risk-management documentation, human-oversight provisions and post-market monitoring obligations each demand a level of process rigor that many companies deploying third-party AI tools inside high-risk use cases were unprepared to produce on the compressed remaining timeline, and a cottage industry of AI-Act compliance consultancies has grown rapidly to meet the resulting demand. The extraterritorial reach of the Act has proven to be its most consequential feature for companies outside Europe. Any organisation offering an AI system that is used within the EU falls under the regulation's scope regardless of where the company is headquartered, which has forced American, Chinese and Indian technology companies with European customers to build EU-specific compliance workstreams even when their home markets impose no comparable requirements, creating a de facto global standard-setting effect similar to what GDPR achieved for data privacy. Indian IT services and SaaS companies selling into European enterprise and government customers have had to build AI Act compliance into their delivery contracts and product roadmaps, and several of the larger Indian technology firms have stood up dedicated European AI-governance practices explicitly to help their own clients navigate the same obligations - turning a regulatory burden into a services revenue line. What to watch: how aggressively national regulators pursue early enforcement actions to establish precedent, whether the European Commission grants any further phase-in extensions in response to industry lobbying, and whether other jurisdictions - including India, which has been drafting its own AI governance framework - adopt provisions modelled directly on the EU's risk-tiered approach.

Original source: Politico Europe