TRAFEED

What the EU AI Act Actually Is — The First Thing Exporters to Europe Should Check

Published2026-08-01Updated2026-08-02Ryuta Hamamoto

A plain-language guide to the EU AI Act (Regulation (EU) 2024/1689) written for export-control professionals with no background in AI regulation. "If you export to Europe, you're in scope" is wrong — only the seven categories in Article 2 are covered. Covers the patterns where companies become a provider or product manufacturer without realising it, what actually starts on 2 August 2026, and how the Digital Omnibus (Regulation (EU) 2026/1744) pushed back the high-risk rules and moved machinery into a separate track.

What the EU AI Act Actually Is — The First Thing Exporters to Europe Should Check
シェア

This is Ryuta Hamamoto from TIMEWELL. The EU AI Act reached its general date of application on 2 August 2026, and this piece reflects the text and the Official Journal as of that date. Lately I have had a steady stream of export-control managers asking me the same thing: "We're caught by this too, right?"

Let me lead with the most important point. "If you export to Europe, you are in scope" is not accurate — not on the text of the Regulation.

I think this misconception spread with good intentions. The headline number — up to 7% of worldwide turnover — took on a life of its own, and companies with any EU business decided to brace for impact. That instinct is understandable. But burning internal hours on a regime that does not apply to you is just as expensive as missing a deadline that does.

This article has one goal: to get export-control practitioners to the point where they can determine, on their own, whether their company is in scope. No AI governance theory. No ISO/IEC 42001. Just the language of export compliance.

Every article number, date and figure below was checked word-for-word against the Official Journal text. Anything I could not verify is not in this article.

What you will learn

  • How the AI Act is structured (it clicks faster if you compare it to classification under export control)
  • The seven categories in Article 2, and why goods that contain no AI fall outside them
  • The patterns where a company becomes a provider or product manufacturer without noticing
  • What genuinely starts on 2 August 2026 — and what does not
  • How the Digital Omnibus (Regulation (EU) 2026/1744) delayed the high-risk rules and moved machinery into a sectoral track
  • How AI Act scope relates to export-control classification (different regimes, both can apply)

What the EU AI Act actually is

The formal citation is Regulation (EU) 2024/1689. It sets harmonised rules for AI in the EU and entered into force on 1 August 2024.1

In character, it is product safety legislation. It is not an export-control statute. The logic is: if you are putting this AI onto the EU market, here are the steps you must take, scaled to how risky the use is.

Translated into export-control terms

For anyone who has spent years doing classification work, this comparison is the fastest way in.

How export control thinks How the AI Act thinks
Is the item or technology on a control list? (classification) Is the AI prohibited, high-risk, or subject to transparency duties?
If listed, apply for a licence If caught, run conformity assessment, technical documentation, CE marking
The subject of the assessment is the exporter The subject is the provider, or the deployer using it professionally
The trigger is export — goods crossing a border The trigger is placing on the market / putting into service in the EU
You document negative determinations too You must document a "not high-risk" determination too (more below)

Row four is the one that matters. Export control catches goods and technology crossing a border. The AI Act catches placing AI on the EU market, and — as we will see — output being used in the EU.

So the question is not "do we export to the EU?" It is "do we place AI on the EU market, or is the output of our AI used in the EU?" Get this wrong and every downstream determination is wrong with it.

One caveat on the familiar "four risk tiers" framing. That is a practitioner's shorthand, not a structure you will find as chapter headings in the Regulation. "Minimal risk" has no definition at all — it is simply the residue left over once prohibited, high-risk and Article 50 are excluded. When you build internal materials, track things by article number rather than tier name. It saves arguments later.

Why "everyone exporting to Europe is caught" is wrong

Scope is set by Article 2. Paragraph 1 is, in effect, the list of who is covered.1

Point Who is covered In plain terms
(a) Providers placing AI systems on the market or putting them into service, or placing GPAI models on the market, in the Union — whether established in the EU or in a third country Anyone putting AI into the EU. A Japanese entity counts
(b) Deployers established or located in the Union Entities using AI professionally inside the EU (an EU subsidiary, say)
(c) Providers and deployers in a third country where the output produced by the AI system is used in the Union No EU entity needed — output reaching the EU is enough
(d) Importers and distributors of AI systems Whoever stands on the EU side of the transaction
(e) Product manufacturers placing an AI system on the market together with their product, under their own name or trademark Manufacturers shipping own-brand products with AI inside
(f) Authorised representatives of providers not established in the Union The appointed representative itself
(g) Affected persons located in the Union Not an operator duty — this maps to individuals' rights to complain and to an explanation

Read that table top to bottom and notice one thing: the object of every single point is an AI system or a GPAI model.

Which means:

  • If you export fasteners, steel, chemicals or industrial components — goods with no AI in them — the EU AI Act does not apply to you.
  • Having EU revenue is, by itself, irrelevant to the determination.
  • Conversely, you may never have "exported" anything to the EU and still be caught under (c), because your output reaches the EU over a network.

Point (g) is different in kind. It does not impose duties on businesses; it corresponds to the rights of individuals in the EU to lodge complaints and request explanations. You can skip it in a scope assessment.

My view: the first thing to do internally is to write down the conclusion "the AI Act does not apply to us" with the article citations that support it. Same discipline as a negative classification determination in export control — record the facts and the reasoning. It is by far the cheapest option available.

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

So who is caught? A determination sequence

Work down the list. A single "yes" means you should keep reading.

# Question Basis
1 Does anything you supply into the EU contain a machine-learning model or inference capability? (If no, you are done) Art.2(1) chapeau
2 Do you place that AI on the EU market under your own name or trademark — standalone or embedded in a product? Art.2(1)(a), (e)
3 You place nothing in the EU, but is the output of your AI used there? Art.2(1)(c)
4 Does a group company sit on the EU side as importer or distributor? Art.2(1)(d)
5 Does an EU entity use the AI in the course of its business? Art.2(1)(b)
6 Have you badged, substantially modified, or repurposed AI already on the market? Art.25(1)

The patterns where companies get caught without realising

These are the four that reliably produce a "wait, that counts?" reaction. Note that none of them involve an AI vendor.

Pattern 1: production equipment with AI visual inspection, exported to the EU

You ship inspection machinery with a learned model inside to a plant in Europe, under your own brand. The internal self-image is "we make machines, we are not an AI company" — but this lands squarely in Article 2(1)(e). And Article 25(3) goes further: where a high-risk AI system is a safety component of a product covered by Annex I Section A and is placed on the market under the product manufacturer's name or trademark, the product manufacturer is considered the provider.1 It makes no difference that you bought the AI from someone else.

One qualification: if the equipment is machinery, machinery moved out of Annex I Section A in the 2026 amendment (covered below), so Article 25(3) is no longer the operative route for it. Article 2(1)(e) still puts you in scope either way. Which harmonisation legislation covers the product decides this, so check it product by product.

Pattern 2: predictive-maintenance AI delivered to EU customers as SaaS

Servers in Japan, no EU entity, machines already installed with no new shipments. If you are ingesting operating data and returning failure predictions, the output is being used in the EU and Article 2(1)(c) applies. Export-control instinct says "nothing physical is moving, so nothing applies." This is where that instinct fails most often.

Pattern 3: an EU subsidiary reselling under its own brand

The Japanese parent builds the AI-enabled product; the EU subsidiary sells it under a local brand name. Article 25(1)(a) treats anyone who puts their name or trademark on a high-risk AI system already on the market as a provider. And the point carries a specific qualifier: "without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated."1

This is, I think, the single most important sentence in the Regulation for export practitioners. You can allocate cost and workload by contract; you cannot contract your way out of regulatory status. Who pays and who does the work is negotiable. Who the authority regards as the provider is fixed by the text. If your company believes a distribution agreement has this covered, sit down with legal and read that clause together.

Pattern 4: repurposing a bought-in general-purpose model

Article 25(1)(c) treats a party that changes the intended purpose of an AI system — including a general-purpose AI system — such that it becomes high-risk as the provider. In other words, ordinary product development using a commercial model off the shelf can move you into provider status.

What starts on 2 August 2026 — and what does not

This is the most widely misunderstood part of the whole regime, so I will be precise.

First: the Digital Omnibus is already law

The AI-related Digital Omnibus was adopted on 8 July 2026 as Regulation (EU) 2026/1744, published in OJ L 2026/1744 on 24 July 2026, and entered into force on 27 July 2026.2 Plenty of briefing material still describes it as a proposal awaiting adoption over the summer. That is out of date. If your internal materials say the same, fix that first.

The amendments matter a great deal to exporters.

Where we are in the phase-in

The right-hand column says whether the date is a start of application or a compliance deadline.

Date What applies Nature of the date
2024-08-01 Entry into force; no obligations yet Entry into force
2025-02-02 Chapter I (general provisions, definitions, AI literacy) and Chapter II (Art.5 prohibited practices) Start of application (applicable)
2025-08-02 Chapter V (GPAI models), Chapter VII (governance), Chapter XII (penalties), Art.78 and others — Art.101 excepted Start of application (applicable)
2026-07-27 Omnibus enters into force; AI Act Arts.102–110 apply Start of application (applicable)
2026-08-02 General date of application: Chapter IV (Art.50 transparency), Chapter III Section 5 (standards, conformity assessment, CE marking, registration), Art.101 (Commission power to fine GPAI providers) Start of application
2026-12-02 Two newly added prohibited practices begin; deadline for existing synthetic-content systems under Art.50(2) Start of application / deadline
2027-08-02 Compliance deadline for GPAI models placed on the market before 2025-08-02 Deadline
2027-12-02 Chapter III Sections 1–3 apply to Annex III (standalone) high-risk Start of application
2028-08-02 Same, for Annex I (embedded) high-risk Start of application
2030-08-02 Final compliance date for high-risk AI intended for public authorities Deadline

The high-risk rules do not land on 2 August 2026

Under the original Article 113, the high-risk provisions were also set for 2 August 2026. That is why so much existing commentary says "high-risk AI applies in full on 2 August 2026." Regulation (EU) 2026/1744 rewrote it.

As amended, Article 113 third paragraph point (c) sets application of Chapter III Sections 1, 2 and 3 at 2 December 2027 for systems classified as high-risk under Article 6(2) and Annex III, and 2 August 2028 for those under Article 6(1) and Annex I.2

That means the provisions exporters worry about most — appointing an authorised representative (Art.22), value-chain responsibility (Art.25), deployer obligations (Art.26) — hang off those later dates too. Nothing about high-risk compliance becomes mandatory on 2 August 2026.

One qualification. Chapter III Section 5 — Articles 40 to 49 on harmonised standards, conformity assessment, CE marking and EU database registration — has applied since 2 August 2026. That is not an inference from the wording. What the amending act actually moved is Chapter III Sections 1, 2 and 3 (excluding Article 6(5)), and Section 5 appears in none of the exceptions. The recital says the same thing in terms: the deferral covers "the obligations related to high-risk AI systems laid down in Sections 1, 2 and 3 of Chapter III"2.

That said, Section 1 — which decides what counts as high-risk — does not move until 2 December 2027, so there is nothing yet to put through the Section 5 machinery. Plan against the high-risk dates. The framework is running; what goes into it has not arrived.

I would not read the delay as breathing room, though. Conformity assessment preparation does not compress into a few months, and the two things covered next sit outside the delay entirely.

Meanwhile, some obligations have been live since 2025

The prohibitions in Article 5 have applied since 2 February 2025, and they carry the highest penalty band: up to EUR 35,000,000 or 7% of total worldwide annual turnover, whichever is higher (Art.99(3)).1 The penalty chapter itself (Chapter XII) has applied since 2 August 2025.

The prohibition that catches exporters most often is Article 5(1)(f): inferring emotions in the workplace and in education institutions. The text carves out use "for medical or safety reasons," but everything else is flatly prohibited. A fatigue- or attention-monitoring system framed around worker safety has an exception to argue; the moment it is repositioned toward productivity scoring or attendance management, that argument is gone. And this is a prohibition, not a high-risk classification — there is no conformity assessment that makes it permissible.

What genuinely begins on 2 August 2026: transparency

The substantive obligation landing on that date which most affects exporters is Article 50.

  • 50(1) AI intended to interact directly with people must be designed so that the person is informed they are dealing with an AI (unless that is obvious to a reasonably observant person)
  • 50(2) Providers of AI generating synthetic audio, image, video or text must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated
  • 50(3) Deployers must inform people exposed to emotion-recognition or biometric categorisation systems
  • 50(4) Deployers must disclose deep fakes

If your product ships with a chatbot-style interface or a document-generation feature, 50(1) and 50(2) are your problem. For systems already on the market before 2 August 2026, the new Article 111(4) inserted by Regulation (EU) 2026/1744 gives until 2 December 2026 to comply with Article 50(2).2

You may also see claims that the transparency obligations were "moved up to 2 December 2026." That is not right. Chapter IV appears in none of the exceptions in the amended Article 113, so it applies from the general date — 2 August 2026. What happens on 2 December 2026 is two things only: the new prohibitions begin, and the transitional deadline for existing systems expires.

What to check, tier by tier

Prohibited practices (Article 5)

Applicable since 2 February 2025; 7% of turnover. For exporters the check is simple: does any AI in your product infer people's emotions or mental states in a labour-management, access-control or training context? Clear that one first.

From 2 December 2026 the list expands to cover non-consensual sexual deep fakes (Art.5(1)(ba)) and generation of child sexual abuse material (Art.5(1)(bb)). The new Article 5(1a) limits this: placing on the market or putting into service is prohibited only where such generation is the intended purpose, or where it is a reasonably foreseeable and reproducible result — without significant technical modification — of the system's design, training, architecture, capabilities or interface, and reasonable and appropriate technical safeguards are absent.2 For a product carrying general image-generation capability, whether you implemented safeguards is the deciding factor.

High-risk, Annex I type (embedded in products) — manufacturers start here

This is the heaviest part for exporters. Article 6(1) classifies AI as high-risk where both of the following hold:1

  • (a) the AI is intended to be used as a safety component of a product covered by the Union harmonisation legislation listed in Annex I, or is itself such a product; and
  • (b) that product is required to undergo a third-party conformity assessment under that Annex I legislation

Condition (b) does the work. If self-declaration of conformity suffices for your product, adding AI does not make it Annex I high-risk. For companies already running CE marking processes, this is not new work — it folds into the conformity route you already maintain.

Annex I Section A, as amended, covers toy safety 2009/48/EC, recreational craft 2013/53/EU, lifts 2014/33/EU, ATEX 2014/34/EU, the Radio Equipment Directive 2014/53/EU, pressure equipment 2014/68/EU, cableways 2016/424, PPE 2016/425, gas appliances 2016/426, the Medical Devices Regulation 2017/745 and the IVDR 2017/746. Section B covers aviation security, two- and three-wheel vehicles, agricultural and forestry vehicles, marine equipment, rail interoperability, motor vehicle type-approval, general vehicle safety, and civil aviation / unmanned aircraft.1

Machinery moved to Section B — the headline change for manufacturers

Regulation (EU) 2026/1744 removed the reference to Machinery Directive 2006/42/EC from Annex I Section A and added Machinery Regulation (EU) 2023/1230 to Section B.2

The effect runs through the amended Article 2(2): for high-risk AI systems related to products covered by the legislation listed in Annex I Section B, only Article 6(1), Article 60a and Articles 102 to 112 of the AI Act apply. So for AI embedded in machinery, the Chapter III high-risk requirements — risk management, data governance, technical documentation, CE marking, EU database registration — no longer bite directly through the AI Act.

The recital explains the reasoning: given the specific nature of machinery and the machinery sector, and the need to simplify the regulatory framework for AI-enabled machinery, a sectoral approach is appropriate.2

But this is not an exemption. The same instrument provides for delegated acts amending Annex III to Machinery Regulation 2023/1230 so that the AI-related requirements are carried across as essential health and safety requirements on the machinery side — and those delegated acts are to apply by 2 August 2028.2

For Japanese industrial machinery, machine tool and robotics makers, the accurate reading is not "the AI Act obligation disappeared" but "the obligation moved to the Machinery Regulation." The statute you read and the internal owner change; the work does not evaporate. Some briefing material is already presenting this optimistically, so treat it carefully.

New rules that limit accidental high-risk status

The same amendment inserted three paragraphs into Article 6, all of which cut in exporters' favour:2

  • 6(1a) AI used solely for non-safety aspects of user assistance, performance optimisation, service efficiency, automation, convenience or quality control does not qualify as a safety component
  • 6(1b) But AI whose failure or malfunction would endanger health and safety does qualify
  • 6(1c) A product required to undergo third-party conformity assessment solely because of risks other than health and safety — in particular radio spectrum distribution or electromagnetic interference not affecting health and safety — does not satisfy Article 6(1)(b)

6(1c) looks technical but is commercially significant: it largely resolves the worry that equipment assessed by a third party only because of the Radio Equipment Directive would be pulled into high-risk simply for containing AI. And 6(1a)'s reference to quality control matters when you are positioning visual-inspection AI. That said, if an inspection failure feeds directly into the safety of the finished product, 6(1b) pulls it back. Assess use by use — that principle has not changed.

High-risk, Annex III type (standalone)

For AI not embedded in a regulated product, Annex III lists eight areas. Application: 2 December 2027. The ones exporters ask about:

Area Coverage (extract)
1 Biometrics Remote biometric identification; categorisation by sensitive attributes; emotion recognition (verification only is excluded)
2 Critical infrastructure Safety components in critical digital infrastructure, road traffic, and the supply of water, gas, heating and electricity
3 Education and vocational training Admission and placement, learning-outcome evaluation, proctoring
4 Employment and worker management Recruitment screening, CV filtering, promotion and termination decisions, monitoring and evaluation of performance and behaviour
5 Essential private and public services Eligibility for public benefits; creditworthiness and credit scoring (fraud detection excluded); life and health insurance risk assessment and pricing; emergency call triage
6–8 Law enforcement; migration, asylum and border control; administration of justice and democratic processes

Article 6(3) provides a derogation. An Annex III system is not high-risk where it does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision-making. The conditions are: a narrow procedural task; improving the result of a previously completed human activity; detecting decision-making patterns or deviations without intending to replace or influence the prior human assessment absent proper human review; or a preparatory task to an Annex III assessment.1

Then the text adds a hard stop: "an AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons." Profiling individuals means high-risk regardless of the derogation. Write that exception-to-the-exception into your internal guidance.

One more, and it is the provision I would highlight to any export team. Article 6(4) requires a provider who concludes that an Annex III system is not high-risk to document that assessment before placing it on the market, to provide the documentation on request from national competent authorities, and to comply with the registration obligation in Article 49(2).1

That structure should look familiar. A negative determination still requires a record. If your organisation already produces non-applicability determinations for export control, you can reuse the format almost as-is. What you cannot do is respond to an authority with "it didn't apply, so we didn't do anything."

Transparency and minimal risk

Article 50 applies from 2 August 2026, as covered above. "Minimal risk" has no defining provision — AI that is neither prohibited nor high-risk nor within Article 50 simply carries no substantive AI Act obligation. Article 95 provides for voluntary codes of conduct.

GPAI models are a separate axis (and irrelevant to most exporters)

Running alongside the tiers, Chapter V imposes obligations on providers of general-purpose AI models: technical documentation, information for downstream providers, a policy to comply with EU copyright law, and publication of a sufficiently detailed summary of training content.

The thing to grasp is that these are obligations for the party that trains and releases a foundation model. If you procure a commercial model and embed it, you are a downstream AI system provider, not a GPAI model provider. If you are not training large models yourself, you can skip this chapter.

One correction worth making: the widely repeated line that "GPAI means training compute above 10^23 FLOPs" is not what the law says. The definition in Article 3(63) contains no compute threshold at all.1 The 10^23 FLOP figure is an indicative criterion in the Commission's guidelines, and it is paired with a modality condition — that the model can generate language (text or audio), text-to-image, or text-to-video.3 Stating it as a statutory threshold in internal documents will be wrong. For the detail, see GPAI provider fine exposure and how to manage it.

Penalty levels

Type of breach Cap Basis Applies from
Prohibited practices (Art.5) EUR 35,000,000 or 7% of worldwide annual turnover, whichever is higher Art.99(3) 2025-08-02
Obligations of providers (16), authorised representatives (22), importers (23), distributors (24), deployers (26), notified bodies, transparency (50) EUR 15,000,000 or 3%, whichever is higher Art.99(4) 2025-08-02
Incorrect, incomplete or misleading information to authorities or notified bodies EUR 7,500,000 or 1%, whichever is higher Art.99(5) 2025-08-02
GPAI model providers (imposed directly by the Commission) 3% or EUR 15,000,000, whichever is higher Art.101(1) 2026-08-02
SMEs and start-ups The lower of the percentage and the amount above Art.99(6) 2025-08-02

More useful than the headline numbers is Article 99(7). Among the factors authorities must consider when setting a fine are the degree of cooperation with the authorities, the degree of responsibility taking into account the technical and organisational measures implemented, and the manner in which the infringement became known to the authority — in particular whether, and to what extent, the operator notified it.1

Keep records of your determinations; if you find a problem, self-report. The discipline export teams already practise maps directly onto how the fine is calculated.

How this relates to export-control classification

Export control (FEFTA, EAR, EU Dual-Use) EU AI Act
Conduct captured Export and technology transfer across a border Placing on the EU market; output used in the EU
What is assessed Item specifications, end user, end use The AI's intended purpose and risk tier
Consequence if caught Licence application Conformity assessment, technical documentation, CE marking, registration
Who assesses The exporter Provider / product manufacturer / deployer

There is one point to internalise. You can classify to an ECCN, complete a FEFTA determination, and obtain an export licence — none of that extinguishes an AI Act obligation. The reverse holds too: passing conformity assessment under the AI Act does not remove the need for a re-export licence out of the EU.

Assume two separate nets, and decide internal ownership before the question arises. For how the two overlap — the relationship between Annex III high-risk areas and cyber-surveillance items, and the intersection with EU Dual-Use Regulation 2021/821 — see Where the EU AI Act meets export control.

Three traps in the exclusions

When someone tells me "we're excluded," these are the three things I check.

The military exclusion says "exclusively." Article 2(3) second subparagraph excludes AI placed on the market, put into service or used exclusively for military, defence or national security purposes.1 Which means dual-use AI also marketed for civil applications is not excluded. Treating a product sold into both defence and commercial channels as "out of scope because it's a defence item" is a mistake.

There are two R&D exclusions, and real-world testing is not one of them. Article 2(6) excludes AI developed and put into service for the sole purpose of scientific research and development; Article 2(8) excludes research, testing and development activity prior to placing on the market. But 2(8) carries an explicit sentence: "Testing in real world conditions shall not be covered by that exclusion."1 Running a trial at an EU customer's site falls outside. In manufacturing, this comes up constantly.

The open-source exclusion does not survive high-risk. Article 2(12) excludes AI systems released under free and open-source licences — unless they are placed on the market or put into service as high-risk AI systems, or as an AI system falling under Article 5 or 50.1

Exporter's checklist

At a level of detail you can circulate internally.

Step 1: inventory the AI (if there is none, stop here)

  • List every product and service supplied into the EU that contains a machine-learning model or inference capability
  • Distinguish AI you developed from procured models you embedded
  • If the list is empty, document that conclusion and its basis — that the object of Article 2(1) is an AI system or GPAI model — and close it out

Step 2: fix your own status

  • Are you supplying under your own brand? (Art.2(1)(e), Art.25(3))
  • Nothing placed in the EU, but is output used there? (Art.2(1)(c))
  • Is your EU entity an importer, distributor or deployer? (Art.2(1)(b), (d))
  • Do distribution or OEM agreements purport to allocate AI Act responsibility? Allocation does not move regulatory status (Art.25(1)(a))

Step 3: clear the prohibitions first — they are already live

  • Any function inferring emotions in the workplace or an education setting? (Art.5(1)(f))
  • Does the medical-or-safety exception genuinely cover it, at the level of the documented intended purpose?

Step 4: run high-risk classification through your existing CE route

  • Which Annex I harmonisation legislation covers the product?
  • Does that legislation require third-party conformity assessment? If not, it is not Annex I high-risk (Art.6(1)(b))
  • For machinery, assign someone to track the delegated acts on the Machinery Regulation 2023/1230 side
  • Is the AI limited to quality control and convenience, or would its malfunction endanger health and safety? (Art.6(1a), (1b))
  • Any standalone AI in the eight Annex III areas? If so, does it profile individuals?
  • Document every "not high-risk" determination before placing on the market (Art.6(4))

Step 5: check the transparency duties landing 2 August 2026

  • Any interface interacting directly with people? (Art.50(1))
  • Any synthetic audio, image, video or text generation? Where does machine-readable marking stand? (Art.50(2))
  • Anything already on the market before 2 August 2026 has until 2 December 2026 (Art.111(4))

Step 6: work backwards from the deadlines and name an owner

  • Annex III high-risk: 2 December 2027
  • Annex I high-risk: 2 August 2028
  • Third-country providers must appoint an EU authorised representative by written mandate prior to making high-risk AI available on the Union market (Art.22(1)). That is not a task you complete the day before — schedule it backwards from the dates above

How TRAFEED fits

If your reaction is "so this lands on top of export-control classification," TRAFEED (formerly ZEROCK ExCHECK) may be worth a look. It is an export-control AI agent that checks counterparties and end users against restricted-party lists, screens item classification, and flags end-use concerns.

It does not perform your EU AI Act compliance. What it does is compress the hours you spend on export-control checks, which frees capacity for the AI inventory work described above. Final legal interpretation stays with people — your compliance team, counsel, or customs specialist — by design.

Details on the TRAFEED product page; to talk it through, use contact.

Summary

  • The EU AI Act (Regulation (EU) 2024/1689) is product safety legislation. It captures placing AI on the EU market and output being used in the EU — not "exporting"
  • "Everyone exporting to Europe is caught" is wrong. The object of every point in Article 2(1) is an AI system or GPAI model, so goods containing no AI are outside scope
  • The real risk is being caught without knowing. Manufacturers shipping own-brand products with AI inside are product manufacturers in scope (Art.2(1)(e), Art.25(3)). You can also be caught with nothing placed in the EU at all, if output is used there (Art.2(1)(c))
  • Allocating obligations by contract does not move regulatory status (Art.25(1)(a))
  • The Digital Omnibus (Regulation (EU) 2026/1744, in force 27 July 2026) delayed the high-risk rules: Annex III to 2 December 2027, Annex I to 2 August 2028
  • Meanwhile the prohibitions have applied since 2 February 2025 at up to 7% of turnover. Workplace emotion inference is the first thing to check
  • The substantive obligation starting 2 August 2026 is Article 50 transparency; existing systems have until 2 December 2026
  • Machinery moved to Annex I Section B, so AI Act high-risk requirements no longer apply directly — but this is a transfer to Machinery Regulation 2023/1230, not an exemption (delegated acts to apply by 2 August 2028)
  • A "not high-risk" determination carries its own documentation duty (Art.6(4)). Run it like a negative classification determination

Start by putting the in-scope / out-of-scope conclusion on a single page with article citations. If you are out of scope, that page answers every future question. If you are in scope, work backwards from 2 December 2027 and 2 August 2028. I hope this gives you the raw material for that first page.

References

Article numbers, dates and figures in this article were checked word-for-word against the following Official Journal texts.

Footnotes

  1. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal, ELI: https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng 2 3 4 5 6 7 8 9 10 11 12 13 14

  2. Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI). OJ L 2026/1744, 24.7.2026. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng 2 3 4 5 6 7 8 9

  3. European Commission, "Guidelines on the scope of the obligations for providers of general-purpose AI models under the AI Act" (18 July 2025). https://digital-strategy.ec.europa.eu/en/library/guidelines-scope-obligations-providers-general-purpose-ai-models-under-ai-act

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Share this article if you found it useful

シェア

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

無料診断ツール

輸出管理のリスク、見えていますか?

まず5問(約2分・メール不要)のライト診断。必要なら10問本編で詳細レポートまで。

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Related Articles