I'm Ryuta Hamamoto from TIMEWELL.
“EU AI Act? We don't have any EU operations, so it doesn't apply, right?” Up to around May 2026, when the first version of this article was written, 80-90% of Japanese executives I spoke to reacted this way.
That general application date has now arrived. Since August 2, 2026 (Article 113), the transparency obligations of Article 50 and the European Commission's fining powers over GPAI providers (Article 101) have been live. Fines top out at €35M or 7% of global revenue, whichever is higher. Reading the text carefully reveals three patterns under which Japanese-headquartered companies are caught extraterritorially.
One correction up front: the substantive high-risk regime did not start on that date. Under the amending act Regulation (EU) 2026/1744 (the “Digital Omnibus”; adopted July 8, 2026, published in OJ L 2026/1744 on July 24, 2026, in force July 27, 2026), Chapter III Sections 1, 2 and 3 (excluding Article 6(5)) apply to Annex III high-risk AI (Article 6(2)) from December 2, 2027 and to Annex I high-risk AI (Article 6(1), i.e. AI embedded in regulated products) from August 2, 2028. Note what that leaves alone: only those three sections moved. Chapter III Section 5 — harmonised standards, conformity assessment, CE marking and registration under Articles 40 to 49 — has been running since August 2.
“Doesn't apply to us” is a minority position. This article covers the application timeline, when Japanese companies are in scope, and a five-step roadmap to start now.
TL;DR
- EU AI Act applies in stages: prohibited AI and AI literacy obligations from February 2, 2025, GPAI models and the penalty provisions from August 2, 2025, and the general application date of August 2, 2026 (transparency obligations under Article 50, the Commission's GPAI fining powers under Article 101, and more)
- Substantive high-risk obligations start December 2, 2027 (Annex III) and August 2, 2028 (Annex I), per Regulation (EU) 2026/1744
- Japanese companies are caught extraterritorially in three patterns: (1) AI products/services placed on the EU market, (2) AI outputs used in the EU, (3) AI used by an EU subsidiary
- Fines reach €35M or 7% of global revenue, well above GDPR's €20M
- The pragmatic path forward is a five-step approach anchored to ISO/IEC 42001 with high-risk requirements layered on top
Get the EU AI Act timeline right
EU AI Act took effect on August 1, 2024, but obligations apply in waves (Article 113). The table below reflects the amendments made by Regulation (EU) 2026/1744.
| Date | What applies |
|---|---|
| Feb 2, 2025 | Chapter I (scope, definitions, Article 4 AI literacy) and Chapter II (Article 5 prohibited AI practices). Emotion inference at the workplace (Article 5(1)(f)) has been prohibited since this date |
| Aug 2, 2025 | Chapter III Section 4 (notifying authorities); Chapter V (GPAI models); Chapter VII (governance); Chapter XII (penalties, Articles 99 and 100); Article 78. Article 101 is excluded |
| Jul 27, 2026 | Regulation (EU) 2026/1744 enters into force; AI Act Articles 102-110 (amendments to other legislation) start to apply |
| Aug 2, 2026 (general application date) | Chapter IV (Article 50 transparency obligations); Chapter III Section 5 (Articles 40-49: harmonised standards, conformity assessment, CE marking, registration); Chapter VI; Chapters VIII-XI; Article 101 (the Commission's GPAI fining powers) |
| Dec 2, 2026 | New prohibited practices under Article 5(1)(ba) (non-consensual sexual deepfakes) and (bb) (CSAM generation), plus Article 5(1a) and (1b). Also new Article 111(4): providers of synthetic-content-generating AI placed on the market before August 2, 2026 must comply with Article 50(2) by this date |
| Aug 2, 2027 | Article 111(3): compliance deadline for GPAI models placed on the market before August 2, 2025 |
| Dec 2, 2027 | Annex III high-risk AI (Article 6(2)) becomes subject to Chapter III Sections 1, 2 and 3. Article 22 (authorised representatives), Article 25 (value chain), Article 26 (deployer obligations) and Article 27 (FRIA) also start here |
| Aug 2, 2028 | Annex I high-risk AI (Article 6(1), embedded in regulated products) becomes subject to the same requirements |
| Aug 2, 2030 / Dec 31, 2030 | Article 111(2) (use by public authorities) / Article 111(1) (Annex X large-scale IT systems) |
The prohibited AI, AI literacy, GPAI provider, and penalty provisions (Articles 99 and 100) are already live. What starts on August 2, 2026 is the transparency obligation (Article 50) and the Commission's GPAI fining powers (Article 101), among others—not the substantive high-risk obligations. Those arrive on December 2, 2027 (Annex III) and August 2, 2028 (Annex I).
AI Security training, taken seriously
A 2-day intensive course fully aligned with OWASP, NIST, ISO/IEC 42001, and METI. Take it as executives, practitioners, or both.
Penalty structure—heavier than GDPR
Article 99 sets tiered penalties:
| Violation | Maximum |
|---|---|
| Use of prohibited AI (social scoring, etc.) | €35M or 7% of global revenue (whichever is higher) |
| Major violations for high-risk AI systems | €15M or 3% of global revenue |
| Providing false information to authorities | €7.5M or 1% of global revenue |
GDPR maxed at €20M / 4% of global revenue. EU AI Act tops out at €35M / 7%. The EU is signaling—through the size of the fines—its intention to set the global rule for AI.
Three extraterritorial patterns that catch Japanese companies
Article 2 defines scope. The main patterns where Japan-headquartered companies are caught:
Pattern 1: AI products/services on the EU market
A Japanese company places AI systems or AI models into the EU market (sales, SaaS, API, free of charge—all count).
Examples:
- A cosmetics maker uses AI image recommendations on its EU e-commerce site
- An automotive parts maker embeds AI control in products sold to EU OEMs
- A SaaS company offers generative AI features to EU customers
Pattern 2: AI outputs used inside the EU
AI outputs (predictions, classifications, images) are used within the EU.
Examples:
- A recruitment AI run from Japan evaluates employees at EU subsidiaries
- A Japan-based credit scoring AI feeds transaction decisions at an EU subsidiary
- Marketing AI analyses run in Japan feed advertising targeting in the EU
Pattern 3: An EU subsidiary becomes a “deployer”
If an EU subsidiary uses an AI system in its operations, the subsidiary becomes a “deployer” with its own obligations—separate from headquarters' risk management.
Examples:
- EU subsidiary uses AI-based performance reviews
- EU subsidiary uses CRM-embedded generative AI features
- EU subsidiary uses AI agents for internal document summarization
Even if your company doesn't ship products to the EU, AI used daily at an EU subsidiary is often in scope.
Four risk categories and their obligations
EU AI Act classifies AI into four risk tiers:
| Tier | Includes | Obligation weight |
|---|---|---|
| Prohibited | Social scoring, subliminal manipulation, emotion recognition in workplace/school, etc. | Use forbidden (applies since Feb 2, 2025; the newly added practices apply from Dec 2, 2026) |
| High-risk | AI in recruitment / HR, credit scoring, medical diagnosis, education, critical infrastructure operation, law enforcement | Conformity assessment, technical documentation, logs, human oversight, data governance, etc. (Annex III from Dec 2, 2027; Annex I from Aug 2, 2028) |
| Limited risk | Chatbots, deepfakes, AI-generated content | Transparency obligation (disclosure) — Article 50, from Aug 2, 2026 |
| Minimal risk | AI spam filters, in-game AI, etc. | Voluntary (code of conduct encouraged) |
For most Japanese companies, the practical issues are high-risk and limited-risk. If you run customer-facing chatbots or AI-generated content, Article 50 transparency obligations apply from August 2, 2026. If you use recruitment / HR AI, credit scoring, or medical diagnosis aids, plan for compliance by December 2, 2027 (Annex III) or August 2, 2028 (Annex I, embedded in regulated products).
There is a transitional rule for synthetic-content-generating AI placed on the market before August 2, 2026: those providers must comply with Article 50(2) by December 2, 2026 (Article 111(4)).
A five-step implementation roadmap via ISO/IEC 42001
Reading the EU AI Act text alone is too abstract to act on. The pragmatic answer: use ISO/IEC 42001 (the AI Management System standard, published December 2023) as the scaffolding and layer EU AI Act high-risk requirements on top.
Step 1: AI system inventory (1-2 months)
Enumerate every AI system the company develops or uses.
- In-house, SaaS, embedded—all of it
- Purpose, business unit, data involved
- Tentative EU AI Act risk classification
Deliverable: AI system registry (Excel is fine).
Step 2: Identify high-risk and limited-risk systems (2-3 weeks)
Map each inventoried AI system against EU AI Act Annex III (high-risk use-case list).
Pay extra attention to:
- AI involved in hiring, promotion, firing → high-risk
- AI for education assessment or admissions → high-risk
- AI assisting medical diagnosis or treatment → high-risk
- AI for credit scoring or lending decisions → high-risk
Step 3: Build the ISO/IEC 42001 AIMS scaffold (3-6 months)
Implement core ISO 42001 requirements:
- Board-approved AI governance policy
- Documented AI risk assessment procedures
- Defined AI development and operations lifecycle
- Incident management process
- Education and literacy plan
Step 4: Fulfill high-risk-specific requirements (3-6 months)
Implement EU AI Act Chapter III, Section 2 obligations:
- Risk management system (Article 9)
- Data governance (Article 10)
- Technical documentation (Article 11, Annex IV)
- Logging (Article 12)
- Transparency and user information (Article 13)
- Human oversight (Article 14)
- Accuracy, robustness, security (Article 15)
Step 5: Conformity assessment and ongoing operations (continuous)
- Conformity assessment for each high-risk AI system (Article 43)
- CE marking where applicable
- Serious incident reporting to authorities (Article 73)
- Audit log retention and periodic review
Achieving ISO 42001 certification provides evidence of “appropriate AI management” in the EU AI Act sense. That is why PwC, EY, and Deloitte sell ISO 42001 certification support as a high-priced product.
Executive decisions required
EU AI Act compliance requires explicit executive decisions:
- Scope determination: enumerate all AI at the Japan headquarters that touches the EU
- Owner appointment: name a CAIO or an AI governance lead under the CISO
- Budget allocation: end-to-end ISO 42001 + EU AI Act compliance runs ¥30M-100M annually for a mid-sized company
- Timeline declaration: transparency obligations land on August 2, 2026; substantive high-risk obligations on December 2, 2027 (Annex III) and August 2, 2028 (Annex I). Decide which deadline you are building toward, with risk acceptance in hand
- Compliance vs. business: partial exit or reduction of EU-targeted services is a valid management decision
High-risk AI already on the market gets a transitional rule. As amended, Article 111(2) catches such systems only where significant changes in their designs are made on or after the date Chapter III applies. The reference date is not a fixed August 2, 2026—it tracks the Chapter III application dates (December 2, 2027 and August 2, 2028).
How WARP SECURITY treats this
TIMEWELL's WARP SECURITY Executives course runs participants through the EU AI Act timeline, fines, and the ISO 42001 relationship in an AI system inventory workshop.
Participants receive a Step-1 AI registry template and an ISO 42001 quick-check roadmap as course materials.
Where Regulation (EU) 2026/1744 leaves things (as of August 1, 2026)
What was discussed as the “Digital Omnibus” is now law: Regulation (EU) 2026/1744—adopted July 8, 2026, published in OJ L 2026/1744 on July 24, 2026, in force July 27, 2026. It sets the Chapter III Sections 1-3 application dates for high-risk AI at December 2, 2027 (Annex III) and August 2, 2028 (Annex I). The second paragraph of Article 113—“It shall apply from 2 August 2026”—was left unamended, so the general application date remains August 2, 2026.
From August 2, 2026, the European Commission's supervisory and enforcement powers over GPAI providers (Article 101) take effect, and GPAI-related infringements carry fines up to €15M or 3% of global annual turnover (read alongside the Article 99 structure above). Source: Regulatory framework on AI (European Commission).
Transparency obligations (Chapter IV / Article 50) are not listed in any of the exceptions in the third paragraph of Article 113, so Article 50 still applies from August 2, 2026. Regulation (EU) 2026/1744 amended only Article 50(7) (codes of practice); the substantive obligations in paragraphs (1) to (6) are unchanged. Two things happen on December 2, 2026: the new prohibited practices start, and the Article 111(4) transitional deadline for existing systems falls due.
Summary
- August 2, 2026 is the EU AI Act general application date: transparency obligations (Article 50) and the Commission's GPAI fining powers (Article 101), among others, start to apply
- Substantive high-risk obligations start December 2, 2027 (Annex III) and August 2, 2028 (Annex I) under Regulation (EU) 2026/1744. “High-risk goes fully live in August 2026” is incorrect
- Japanese companies are caught in three extraterritorial patterns—“not us” is a risky reading
- Fines reach €35M or 7% of global revenue—above GDPR
- Pragmatic path: a five-step approach via ISO/IEC 42001—inventory, classification, AIMS scaffold, high-risk requirements, conformity assessment
- None of it lands without explicit executive decisions
EU AI Act gets characterized as “overly aggressive,” but the U.S. Executive Order and Japan's AI Business Guidelines v1.2 are heading the same direction. The only choice is whether to do it now or later.






