Hello, this is Ryuta Hamamoto from TIMEWELL. The EU AI Act (Regulation (EU) 2024/1689) has expanded application step by step since its August 2024 entry into force, and the general application date set by Article 113 — 2 August 2026 — has now arrived.
Let me clear up the most common misreading first. High-risk AI did not come into full application on that date. What started is Chapter IV (Article 50 transparency duties), Chapter III Section 5 (Articles 40–49: harmonised standards, conformity assessment, CE marking, registration), Chapters VI and VIII–XI, and the Commission's power to fine GPAI providers (Article 101). The substantive high-risk obligations were rescheduled by the amending act Regulation (EU) 2026/1744 (adopted 8 July 2026; published as OJ L 2026/1744 on 24 July 2026; in force 27 July 2026), which moved Chapter III Sections 1, 2 and 3 (excluding Article 6(5)) to 2 December 2027 for Annex III type (Article 6(2)) and 2 August 2028 for Annex I type (Article 6(1), embedded in products). Only those three sections moved; Section 5 of the same chapter has been running since 2 August.
I keep hearing the same stuck question from owners: is the EU AI Act a product-safety regime or an export-control regime? Short answer: product safety. But the eight high-risk AI fields in Annex III largely overlap in practice with "cyber-surveillance items" as understood in export control. When high-risk AI is re-exported from the EU (especially to destinations that raise Dual-Use Article 5 end-use concerns), a separate export license under EU Dual-Use Regulation 2021/821 may also be required.
Japanese AI companies need to watch both conformity assessment for placing AI products on the EU internal market (AI Act) and export licensing for shipments from the EU to third countries (Dual-Use Reg). U.S. ECCN 4E091 / GP10 and Japan's Foreign Exchange and Foreign Trade Act catch-all revisions are moving in parallel. That is a four-layer stack.
Below I map the intersections so export-control practitioners can decide what to organize, and by when.
What you will learn
- The AI Act’s four risk tiers and what does — and does not — start on 2 August 2026
- The high-risk AI dates (Annex III type: 2 December 2027; Annex I type: 2 August 2028) and where Regulation (EU) 2026/1744 fits
- How Annex III high-risk AI fields overlap with Dual-Use Regulation “cyber-surveillance items”
- GPAI Model systemic-risk duties and the 10^25 FLOPs threshold
- How U.S. ECCN 4E091 / GP10 guidance maps to the EU (with comparison table)
- Three typical scenarios for Japanese companies and five practical steps
Three terms to understand first
Without shared vocabulary, AI Act × export-control discussions go off track quickly.
EU AI Act — product-safety regulation for AI systems
Formally Regulation (EU) 2024/1689. Entered into force August 1, 2024; applies by risk tier on a phased schedule. It is a product-safety regulation.
The key point: the AI Act regulates parties that place AI systems on the EU internal market. "Placing on the market" means first making available for sale or use in the EU. The AI Act does not itself stop exports. High-risk systems, however, substantially overlap export-control cyber-surveillance concepts, so they also catch on the export-control lane.
GPAI (General-Purpose AI Model)
Models trained with more than 10^23 FLOPs that can generate text, audio, image, video, and similar modalities. GPT, Claude, Gemini, Llama, Mistral, and peers almost certainly fall in this bucket.
GPAI duties applied from 2 August 2025 (copyright summary of training data, technical documentation, etc.). Models above 10^25 FLOPs carry heavier systemic-risk GPAI duties.
Systemic risk — the "heavy" compute-based tier
Under Article 51(2), GPAI models whose training compute exceeds 10^25 FLOPs are presumed to present systemic risk. Providers must notify the European Commission within two weeks of crossing the threshold; red-teaming, serious-incident reporting (within 72 hours), and cybersecurity of model weights are required.
The Commission does not publish a definitive count of in-scope models, so this article does not cite one. The point that matters: companies training large LLMs in-house cannot treat this threshold as someone else's problem.
Four risk tiers and fines
| Risk tier | Examples | Application date | Main duties |
|---|---|---|---|
| Unacceptable Risk (prohibited) | Social scoring; emotion inference in the workplace (Article 5(1)(f)); real-time remote biometric ID in public spaces | 2 February 2025 (Article 5) | Full ban |
| High Risk | Annex III eight fields (Article 6(2)) | 2 December 2027 | Conformity assessment / technical docs / risk management / human oversight / deployer duties and FRIA |
| High Risk | Annex I product safety components (Article 6(1)) | 2 August 2028 | Same |
| Limited Risk | Chatbots; deepfakes; generative AI outputs | 2 August 2026 (Article 50) | Transparency (disclose AI-generated content; machine-readable marking) |
| Minimal Risk | Spam filters; recommenders | Out of scope | Optional codes of conduct |
Phased application schedule (Article 113, as amended by 2026/1744)
The general application date itself did not move: the second paragraph of Article 113 ("It shall apply from 2 August 2026") was left unamended. What changed are the staged exceptions around it.
| Date | What starts applying |
|---|---|
| 2 February 2025 | Chapter I (scope, definitions, Article 4 AI literacy) and Chapter II (Article 5 prohibited practices) |
| 2 August 2025 | Chapter III Section 4 (notifying authorities), Chapter V (GPAI models), Chapter VII (governance), Chapter XII (penalties, Articles 99 and 100 — but not Article 101), Article 78 |
| 27 July 2026 | Regulation (EU) 2026/1744 enters into force; AI Act Articles 102–110 (amendments to other instruments) start applying |
| 2 August 2026 (general application date) | Chapter IV (Article 50 transparency duties), Chapter III Section 5 (Articles 40–49: harmonised standards, conformity assessment, CE marking, registration), Chapter VI, Chapters VIII–XI, and Article 101 (Commission's power to fine GPAI providers) |
| 2 December 2026 | New prohibitions: Article 5(1)(ba) (non-consensual sexual deepfakes), 5(1)(bb) (CSAM generation), and Article 5(1a)(1b). Also the new Article 111(4) deadline: providers of synthetic-content generating AI placed on the market before 2 August 2026 must comply with Article 50(2) by this date |
| 2 August 2027 | Article 111(3): compliance deadline for GPAI models placed on the market before 2 August 2025 |
| 2 December 2027 | Annex III high-risk AI (Article 6(2)) becomes subject to Chapter III Sections 1, 2 and 3. Article 22 (authorised representative), Article 25 (value chain), Article 26 (deployer duties) and Article 27 (FRIA) also start here |
| 2 August 2028 | Annex I high-risk AI (Article 6(1), embedded in products) becomes subject to the same Sections |
| 2 August 2030 / 31 December 2030 | Article 111(2) (use by public authorities) / Article 111(1) (Annex X large-scale IT systems) |
Two misreadings worth killing off:
- "High-risk AI applies in full on 2 August 2026" is wrong. The substantive high-risk obligations start on 2 December 2027 (Annex III type) and 2 August 2028 (Annex I type). What starts on 2 August 2026 is Article 50 transparency and the Commission's Article 101 GPAI fining power, among others.
- "Article 50 transparency was pulled forward to 2 December 2026 / the grace period was shortened" is also wrong. Chapter IV appears in none of the exceptions in the third paragraph of Article 113, so Article 50 still applies from 2 August 2026. Regulation 2026/1744 amended only Article 50(7) (codes of practice); the substantive duties in paragraphs (1)–(6) are unchanged. What happens on 2 December 2026 is the start of the new prohibitions and the Article 111(4) transitional deadline for existing systems.
Fines up to 7% of worldwide annual turnover
Article 99 sets ceilings heavier than GDPR in key cases:
- Prohibited AI: up to €35 million or 7% of worldwide annual turnover (whichever is higher)
- Other duty breaches: up to €15 million or 3%
- False information: up to €7.5 million or 1%
"7%" exceeds GDPR's 4%. For Japanese companies with EU revenue, this is not a soft obligation.
Annex III high-risk AI and the export-control intersection
This is the core of the article. The eight high-risk fields in Annex III to the AI Act conceptually overlap EU Dual-Use Regulation 2021/821 cyber-surveillance items.
Rough map:
- EU AI Act: conformity assessment and CE marking for high-risk AI sold or used inside the EU
- EU Dual-Use Reg: export licenses for cyber-surveillance-related items exported from the EU to third countries
The same AI system can hit the AI Act inside the EU and Dual-Use Reg on the way out. Highest-overlap fields:
| Annex III field | Export-control overlap | Related Dual-Use entries / articles |
|---|---|---|
| 1. Biometrics (ID, classification, emotion inference) | Face / iris / voice cyber-surveillance items | Annex I 5A001.f / 5D001; Article 5 catch-all |
| 2. Critical infrastructure (power, water, transport, digital) | SCADA / ICS control software | Annex I 4D / 5D cyber-related |
| 3. Education and vocational training | Limited | — |
| 4. Employment and worker management | Limited | — |
| 5. Essential services (credit, insurance, social benefits) | Limited | — |
| 6. Law enforcement (predictive policing, polygraphs, etc.) | Human-rights-sensitive cyber-surveillance | Article 5 catch-all |
| 7. Migration and border management | Same | Article 5 catch-all |
| 8. Administration of justice and democratic processes | Limited | — |
One practical takeaway: if you handle AI in biometrics, critical infrastructure, law enforcement, or migration/border management, watch both high-risk AI Act duties and Dual-Use Article 5 catch-all.
Article 5: cyber-surveillance catch-all
Article 5 of Dual-Use Regulation 2021/821 requires an export license for non-listed items when the exporter knows, or has reasonable grounds to suspect, use for human-rights abuses, internal repression, or serious IHL violations. AI alone is rarely listed, but systems combining AI with other cyber-surveillance technology can fall under catch-all.
On October 15, 2024 the Commission published due-diligence guidelines that effectively raise exporter investigation expectations.
Replace siloed classification work with AI.
METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.
GPAI duties and systemic risk (10^25 FLOPs)
Especially relevant for companies training large LLMs in-house.
Common GPAI duties (from 2 August 2025)
- Publish a copyright summary of training data
- Maintain technical documentation (architecture, training data, capability evaluations)
- Information duties toward downstream providers
- Cooperation with the EU AI Office
Additional systemic-risk GPAI duties
Models above 10^25 FLOPs are presumed systemic-risk and must also:
- Model evaluation: adversarial testing / red-teaming under standardized protocols
- Systemic-risk assessment and mitigation
- Serious-incident reporting to the AI Office within 72 hours
- Cybersecurity: protect model weights against exfiltration
- Energy-consumption disclosure
- Maintain and update a Safety and Security Framework
Model-weight protection is the closest link to export control. U.S. ECCN 4E091 regulates "AI model weights" as such. EU GPAI duties and U.S. EAR point in the same direction.
Timeline
| Date | Content |
|---|---|
| 2 August 2025 | GPAI duties (Chapter V) begin. Penalties under Articles 99 and 100 also start (Article 101 excluded) |
| 2 August 2026 | Article 101 starts applying: the Commission gains the power to fine GPAI providers |
| 2 August 2027 | Article 111(3): compliance deadline for GPAI models placed on the market before 2 August 2025 |
To be precise: the 2 August 2026 milestone here is about Commission supervision and enforcement over GPAI providers. It is a separate lane from the substantive high-risk obligations. Coverage that summarises this as "full application in August 2026" will mislead you if you read high-risk AI into it.
Dual-Use Regulation 2021/821 and AI-related entries
| EU Dual-Use Annex I | Content |
|---|---|
| 5A001.f | Communications interception / cyber-surveillance equipment |
| 5D001 | Software for the above |
| 4A005 / 4D004 | Intrusion software |
| 3A001.z / 4A090 | Advanced computing ICs (AI-training GPUs, etc.; 2025 update considerations) |
| 500 series (adopted September 8, 2025) | EU-autonomous emerging-tech entries (semiconductor equipment, quantum, etc.) |
Delegated Regulation 2025/2003 (adopted September 8, 2025) fully replaces Annex I and creates the EU-autonomous "500 series" for semiconductor equipment, quantum computing, cryogenics, and more. Some AI-training GPUs are regulated indirectly through this structure.
Details: Complete guide to the EU Dual-Use Regulation 2025 amendment (2025/2003). Read it together with AI Act planning.
Comparison with U.S. ECCN 4E091 / GP10
ECCN 4E091: model weights regulated directly
Created under the January 2025 AI Diffusion Rule, ECCN 4E091 treats model weights of advanced closed-weight AI models as controlled items. Among the first laws worldwide to treat AI models as physical export items.
The Trump administration later signaled withdrawal of the AI Diffusion Rule and is developing a successor. The "model weights equal controlled items" framing is still expected to persist as a baseline for other jurisdictions (see AI Diffusion Rule withdrawal and alternatives).
GP10: end-use / end-user catch-all
General Prohibition 10 under the EAR bars unlicensed exports when the exporter knows, or has reason to know, that end use or end user presents covered concerns. Japan is a lower-risk destination in principle, but third-country routing still requires care.
EU vs. U.S.
| Item | EU | U.S. |
|---|---|---|
| Direct model-weight control | No (indirect via GPAI duties) | Yes (ECCN 4E091) |
| Extraterritorial reach | Applies when outputs are used in the EU | EAR applies to re-exports of U.S. software |
| End-use diligence | Article 5 catch-all | GP10 across items |
| Penalties | Up to €35M / 7% worldwide turnover | Up to $1M per count + criminal |
| Regulatory philosophy | Product safety + human rights | National security |
EU is product safety and human rights; U.S. is national security. Understanding both "whys" reduces friction in internal reviews.
Three impacts on Japanese companies
Impact 1: Selling Japanese AI products into the EU
Example: a Japanese AI vendor supplies credit-scoring AI to a European bank. Credit scoring falls under Annex III “essential services” → high-risk AI.
| Required action | Application date |
|---|---|
| Appoint an EU authorised representative (Article 22) | 2 December 2027 |
| Conformity assessment (technical docs, risk management, testing vs. high-risk requirements; third-party or self-assessment) | Same (the framework itself — Chapter III Section 5, Articles 40–49 — applies from 2 August 2026) |
| CE marking and EU database registration | Same (again, the Articles 40–49 framework applies from 2 August 2026) |
| Technical documentation and risk-management system | 2 December 2027 |
| Human oversight and cybersecurity measures | Same |
| Deployer duties (Article 26) and fundamental rights impact assessment / FRIA (Article 27) | Same |
| Transparency duties for generative AI output (Article 50) | 2 August 2026 |
For Annex I type systems (embedded in products, Article 6(1)), the Chapter III Sections 1–3 date is 2 August 2028 instead.
Expect 6–12 months of preparation. With the Annex III date at 2 December 2027, build the internal schedule by working backwards from it.
Impact 2: Parallel response to Japan's catch-all reform
Japan's FEFTA catch-all reform of October 9, 2025 designated semiconductors and machine tools as "core items." On February 14, 2026 a bulk-license regime for defense-equipment maintenance parts was also introduced.
Example path: buy AI-training GPUs in the EU and ship to a Chinese customer via Singapore.
- EU: Dual-Use Annex I semiconductor entries, then EU export license
- U.S.: if U.S.-origin, EAR re-export (even EAR99 can engage GP10)
- Japan: FEFTA catch-all; Singapore routing can still be treated as China-bound if that is the substance
Three-layer checks run at once. The AI Act connects indirectly because GPAI weight-protection duties govern when and to whom weights are released (see How EAR, China, and EU export controls hit at once).
Impact 3: Ambiguous military-exclusion boundary under Article 2
AI Act Article 2(3) excludes AI for military, defense, and national-security purposes. In practice the boundary is fuzzy.
- Military-developed AI later used for civilian purposes: AI Act applies
- Civilian-market AI later used for military purposes: AI Act does not apply under Article 2(3)
- Dual-use items (civilian and military) are effectively under AI Act regulation when placed on the market
"Military-only, so irrelevant" is a risky call. Most AI systems are positioned as civilian at development time (see Dual-use technology and military conversion risk).
Five practical steps
If I had to pick one checklist item, it would be Step 1.
Step 1: Build a classification map of your AI
Inventory internal AI systems/products. Map which Annex III fields and which GPAI / systemic-risk GPAI tiers may apply. Leave gray zones explicit rather than forcing a clean label.
Step 2: Revisit EU market-access plans
For products with EU revenue or planned EU revenue, plan against two anchors: Article 50 transparency duties from 2 August 2026, and — where the product is high-risk — conformity assessment, CE marking and database registration from 2 December 2027 (Annex III type) or 2 August 2028 (Annex I type). If the timeline fails, reconsider launch dates or narrow use cases out of high-risk scope.
Step 3: Record training compute (FLOPs)
If you train large models, you need continuous total training FLOPs logging and reporting. When the 10^25 threshold is reasonably foreseeable, the two-week Commission notification duty activates.
Step 4: Define a simultaneous four-layer check procedure
Create an internal procedure that checks EU AI Act, EU Dual-Use Reg, U.S. EAR, and Japan FEFTA at once. Siloed departments leak risk; appoint one cross-functional owner.
Step 5: Institutionalize human-rights due diligence
Article 5 catch-all fires once "reasonable suspicion" arises. Standardize end-user purpose checks, initial human-rights screening, and record retention.
What TRAFEED can do
If four-layer daily checks feel unrealistic, consider TRAFEED (formerly ZEROCK ExCHECK), TIMEWELL's export-control AI agent:
- Whether counterparties and end users hit Entity List / MEU List / SDN List / Japan's Foreign User List
- Whether items hit EU Annex I / 500 series, U.S. ECCNs, or Japan's goods ordinances
- Probability that use cases map to Annex III high-risk fields or Article 5 catch-all
- Consistency with METI guidelines and notices
Final legal interpretation always stays with humans (internal owners, counsel, customs specialists). Value is in reducing missed signals, shortening review time, and leaving audit trails.
With AI Act compliance consuming headcount in 2026, cutting export-control friction has clear ROI.
Customer feedback
One trading company reported that four-layer checks (AI Act × Dual-Use × EAR × FEFTA) that averaged three days per deal fell to as little as two hours after TRAFEED. Teams with only one or two export-control owners can use it as infrastructure through the AI Act peak.
FAQ
Q1. Does a Japanese SaaS AI service used by EU customers fall under the AI Act?
A. Yes. Under Article 2's extraterritorial clause, if outputs are used in the EU, the provider is in scope. Transparency duties for generative AI and chatbots (Article 50) apply from 2 August 2026. Where the use is high-risk, conformity assessment and appointment of an EU authorised representative (Article 22) apply from 2 December 2027 (Annex III type) or 2 August 2028 (Annex I type).
Q2. We don't know if our in-house LLM exceeds 10^25 FLOPs. What should we do?
A. Calculate and log total training compute. Once the threshold is reasonably foreseeable, notify the Commission within two weeks (Article 52). Designate a single AI Office contact (often legal/compliance).
Q3. Are AI Act "high risk" and Dual-Use "cyber-surveillance" the same thing?
A. They overlap but are not identical. AI Act equals product safety for sale/use inside the EU. Dual-Use equals export licensing from the EU to third countries. An EU-market face-recognition system needs AI Act high-risk compliance (CE mark, etc.) and Dual-Use licensing on export to third countries.
Q4. Is military AI outside the AI Act?
A. Pure military systems are out of scope (Article 2(3)); dual-use systems placed on the market are in scope. The military-only boundary is fuzzy. Most AI systems should be treated as dual-use until proven otherwise.
Q5. What applies when re-exporting AI-related items from an EU subsidiary to a third country?
A. If the EU subsidiary is the exporter, Dual-Use Reg 2021/821 licensing sits with the subsidiary. Japan HQ still faces FEFTA service-transaction (technology) licensing and group-governance duties. Local EU counsel and Japan HQ export control must work together.
What Regulation (EU) 2026/1744 actually changed
The AI Act amendment carried by the Digital Omnibus is already law. Regulation (EU) 2026/1744 was adopted on 8 July 2026, published as OJ L 2026/1744 on 24 July 2026, and entered into force on 27 July 2026. Any description of it as "a provisional political agreement" or "awaiting formal adoption" is out of date.
Three practical points:
- The general application date did not move. The second paragraph of Article 113 ("It shall apply from 2 August 2026") is unamended.
- High-risk AI dates moved back. Annex III type (Article 6(2)) applies from 2 December 2027; Annex I type (Article 6(1)) from 2 August 2028. Articles 22, 25, 26 and 27 activate on the same dates.
- The transitional test for existing systems is now tied to the Chapter III dates. Under the amended Article 111(2), high-risk AI already placed on the market is caught only where there are "significant changes in their designs" after the Chapter III application date. The reference point is no longer a fixed 2 August 2026 but 2 December 2027 / 2 August 2028.
Separately, 2 December 2026 brings the new prohibitions (Article 5(1)(ba), 5(1)(bb), and Article 5(1a)(1b)) and is also the Article 111(4) deadline: providers of synthetic-content generating AI placed on the market before 2 August 2026 must comply with Article 50(2) by that date. That is not a change to the application date of Article 50 itself.
International frameworks moving in parallel
The multi-layer EU–U.S.–Japan structure described here continues to intensify as of July 2026. The 16th Japan–India Annual Summit on July 2, 2026 produced a joint economic-security declaration across semiconductors, critical minerals (rare earths), clean energy, ICT (subsea cables), and pharmaceuticals, with roughly ¥2 trillion in investment framed (Japan–India summit joint press conference (Prime Minister's Office, July 2026)). AI and advanced-semiconductor supply chains are being reorganized in a security frame, which makes "which partners, which items, which destinations" harder. The AI Act application dates are settled by Regulation (EU) 2026/1744 as set out above; on top of that, these international frameworks need tracking in parallel. Details: Japan–India Summit 2026 and economic security.
If you want to tighten export-control operations or cut classification cycle time, review the TRAFEED service catalog (PDF) or contact us.
Key takeaways
The AI Act and Dual-Use Regulation are separate instruments, but in practice they need the same operational lens:
- 2 August 2026 is the general application date. What starts then: Article 50 transparency duties, the Articles 40–49 conformity-assessment / CE-marking / registration framework, and Article 101 (the Commission's GPAI fining power)
- Substantive high-risk obligations apply from 2 December 2027 (Annex III type) and 2 August 2028 (Annex I type), as set by Regulation (EU) 2026/1744
- Fines for prohibited practices reach €35 million or 7% of worldwide annual turnover, whichever is higher
- Annex III high-risk fields largely overlap Dual-Use cyber-surveillance items in practice
- GPAI above 10^23 FLOPs; systemic-risk GPAI above 10^25 FLOPs
- U.S. ECCN 4E091 / GP10 and Japan FEFTA catch-all reform create a four-layer stack
- Typical Japanese scenarios: EU high-risk AI supply; third-country re-export; fuzzy military exclusion
- Practice path: inventory, market-access plan, FLOPs logging, four-layer procedure, human-rights DD
If you only do one thing, build a one-page map of your AI. The general application date is 2 August 2026; the substantive high-risk obligations land on 2 December 2027 (Annex III type) and 2 August 2028 (Annex I type). "We don't handle military items" or "we don't export AI" will increasingly fail.
Related articles
- Complete guide to the EU Dual-Use Regulation 2025 amendment (2025/2003)
- AI Diffusion Rule withdrawal and alternatives
- How EAR, China, and EU export controls hit at once
- Dual-use technology and military conversion risk
- Export-control changes in 2026
About TRAFEED
TRAFEED (formerly ZEROCK ExCHECK) is an AI agent that reduces missed signals for export-control teams. It checks counterparties, items, and use-case risk across the EU AI Act, EU Dual-Use Regulation, U.S. EAR, and Japan’s FEFTA. 2026 is a good year to cut export-control load while AI Act work peaks.
Three entry points:
- 30-minute online consultation: whether your AI products may hit Annex III fields or systemic-risk GPAI, plus TRAFEED fit
- AI Act quick relevance check: a one-page report mapping major products to Annex III, GPAI thresholds, and Article 5 catch-all
- Product demo: live UI for four-layer checks (AI Act, Dual-Use, EAR, FEFTA)
Details and booking: TRAFEED product page.
References
- Regulation (EU) 2024/1689 (AI Act text)
- Regulation (EU) 2026/1744 (amending act; adopted 8 July 2026, published as OJ L 2026/1744 on 24 July 2026, in force 27 July 2026)
- AI Act Service Desk — European Commission
- Annex III: High-Risk AI Systems
- Article 99: Penalties
- Regulation (EU) 2021/821 (Dual-Use Regulation)
- Guidelines on Cyber-Surveillance Items (October 2024)
- 2025 Update of EU Dual-Use Control List
- Guidelines for GPAI Providers (July 2025)
- Framework for Artificial Intelligence Diffusion — Federal Register
- METI — Trade Control
- CISTEC — Overview of Japanese Export Control Legal Framework
- Anderson Mori & Tomotsune — Major Changes to Catch-All Export Controls
- Akin — EU Updates Dual-Use Export Control List
- SIPRI — EU Catch-All Control on Cyber-Surveillance Exports
- WilmerHale — European Commission Issues Guidelines for GPAI Providers






