EU AI Act High-Risk Enforcement Is Live: What Product Teams Must Do Now
TL;DR
August 2, 2026 was not a deadline to prepare for. It was the day enforcement of the EU AI Act high-risk provisions started. Articles 9 through 17 (provider requirements) and Article 26 (deployer requirements) are now active law. Fines run up to 15 million euros or 3% of global annual revenue. If your product touches biometrics, credit decisions, hiring, education, healthcare, critical infrastructure, or law enforcement, the compliance obligations are not optional and the grace period is over. This article covers exactly what changed, what you must do next, and what a 90-day action plan looks like.
The AI PM Minute
One tactic to make you a sharper AI PM, twice a week. 60 seconds to read. Free.
No fluff. Unsubscribe anytime.
What Actually Changed on August 2, 2026
The EU AI Act has been phasing in since it entered force in August 2024. The February 2025 wave banned unacceptable-risk AI systems outright. The August 2025 wave activated governance and GPAI model obligations. August 2, 2026 is the biggest wave yet: it activates the full compliance framework for high-risk AI systems, covering both providers (companies that build and place AI on the market) and deployers (companies that put AI into use in an EU context).
Articles 9 to 15: Provider technical requirements
Risk management systems, data governance, technical documentation, transparency obligations, human oversight measures, accuracy and robustness standards. These are not process checklists. They require documented evidence, built into the product, before it ships.
Article 16: Provider administrative obligations
Registration in the EU AI database, CE marking, declaration of conformity, cooperation with market surveillance authorities. High-risk AI systems must be registered before they are placed on the EU market.
Article 17: Quality management system
A documented QMS covering design, testing, post-market monitoring, incident reporting, corrective action, and staff accountability. The QMS must be continuously maintained, not a one-time document.
Article 26: Deployer obligations
Deployers must designate human oversight responsibility, provide appropriate training to operators, retain automated decision logs for at least six months, and conduct Fundamental Rights Impact Assessments (FRIAs) in specific contexts.
The enforcement is not automatic. National market surveillance authorities in EU member states investigate complaints, conduct audits, and issue penalties. But the investigation clock starts the moment an infringement occurs, and the law makes clear that placing a non-compliant high-risk system on the market after August 2 is an infringement.
Which Products Are Actually High-Risk
The Annex III list is the definitive source. If your product falls into one of these categories and is used in an EU context, you are a provider of a high-risk AI system. "Used in an EU context" means accessed by EU users, deployed by EU deployers, or integrated into EU products, even if your company is headquartered outside the EU.
Biometric identification and categorization
Remote biometric ID, emotion recognition, facial recognition in CCTV, biometric-based profiling
Critical infrastructure management
AI managing water, gas, electricity, transport, or digital infrastructure networks with safety implications
Education and vocational training
AI that determines access to educational institutions, evaluates students, or controls curriculum progression
Employment and worker management
Hiring screening, promotion decisions, performance monitoring, task allocation systems for gig workers
Access to essential private and public services
Credit scoring, insurance risk, social benefits eligibility, emergency services routing
Law enforcement
Predicting crime likelihood, profiling, evidence evaluation, polygraph-adjacent emotion detection
Migration, asylum, and border control
Visa risk assessment, document authentication, irregular migration prediction
Administration of justice
Legal research AI used by courts, dispute resolution systems, sentence recommendation tools
Important edge cases: General purpose AI systems like ChatGPT or Claude are not inherently high-risk, but using them to build a credit scoring product or a hiring screen makes the resulting product high-risk. The risk classification attaches to the use case, not the underlying model. If your product wraps an LLM for one of the eight categories above, the high-risk obligations fall on you.
Provider Requirements: What You Must Build and Document
If your company is the provider (you built the AI system and are placing it on the market or into service), your obligations span design, testing, documentation, monitoring, and governance. These are ongoing requirements, not one-time audits.
Risk management system (Article 9)
Requirement: A continuous, documented process for identifying, analyzing, and mitigating risks across the full lifecycle. Must be updated when new risks emerge post-deployment.
PM action: Own the risk register. Document known failure modes, edge cases, and bias risks in your incident tracker. Schedule quarterly risk reviews tied to your model update cadence.
Data and data governance (Article 10)
Requirement: Training, validation, and test datasets must meet quality standards for accuracy, coverage, and freedom from errors and biases relevant to the intended purpose.
PM action: Add data provenance documentation to your model card. Record who labeled the data, what quality checks ran, and what known dataset limitations exist. This becomes part of your technical documentation.
Technical documentation (Article 11 + Annex IV)
Requirement: Comprehensive documentation covering system architecture, design choices, training data, testing methodology, performance metrics, and known limitations. Must be kept up to date.
PM action: Create a living Technical Documentation artifact. Treat it like a PRD that never closes. Every model update, prompt change, or fine-tune needs a documentation update.
Transparency and user information (Article 13)
Requirement: Users must be able to understand the system's intended purpose, accuracy levels, and limitations. High-risk systems must come with instructions for use.
PM action: Ship an Instructions for Use document alongside your product. State what the system can and cannot do, its accuracy range, and the conditions under which it should not be used.
Human oversight by design (Article 14)
Requirement: The system must be designed so that a human can monitor its operation, intervene when needed, and override outputs. Not just a checkbox: the design must make this physically possible.
PM action: Audit your product for override paths. Can an operator stop an AI decision before it executes? Can they reverse it after? Log every override so you have an audit trail.
Post-market monitoring (Article 72)
Requirement: A post-market monitoring plan must be in place before the system launches. Providers must actively collect and analyze data on performance after deployment.
PM action: Set up model drift detection and performance degradation alerts before launch. Track real-world accuracy against your documented performance claims, and report material deviations.
Lead Your Team on AI Compliance
The AI PM Masterclass covers EU AI Act obligations, risk classification, and how to build compliant AI products from the start, taught live by a Salesforce Sr. Director PM.
Deployer Requirements: If You Deploy But Did Not Build
Deployers are companies that put a high-risk AI system into use within the scope of their professional activities. If you bought or licensed a high-risk AI system from a provider and are using it, Article 26 applies to you directly.
Designate human oversight responsibility
Assign a specific person or role accountable for monitoring the AI system during operation. This cannot be delegated to the AI itself. Document who owns this responsibility.
Train your operators
Staff who operate or are supervised by the AI must receive adequate training. You must keep records of that training. The AI provider should supply Instructions for Use; your job is ensuring operators have read and understood them.
Retain logs for at least 6 months
Automated decision logs generated by the AI system must be kept for a minimum of 6 months where you have control over those logs. These may be required during regulatory audits.
Conduct Fundamental Rights Impact Assessments (FRIAs)
For public bodies and some private entities in regulated contexts, a FRIA is mandatory before deployment. It assesses which fundamental rights the system could affect and what mitigations are in place.
Report serious incidents
If the AI system causes or contributes to a serious incident (death, injury, significant rights violation), deployers must report it to the provider and to the relevant national authority.
Stop using non-compliant systems
If the provider does not fix a compliance issue you have raised, you are responsible for suspending use. Deploying a known non-compliant system transfers liability to you.
Penalties: What Non-Compliance Actually Costs
The fines are structured in tiers. The absolute maximums apply to the most serious violations and to large enterprises. SMEs and startups are subject to the lower caps in each tier (whichever is lower, the fixed cap or the percentage of global turnover). National authorities have discretion on the exact penalty based on severity, negligence, and remediation actions.
Tier 1: Prohibited AI practices
Up to 35 million euros or 7% of global annual turnoverPlacing on market or using an AI system listed as unacceptable risk (social scoring, real-time biometric surveillance, manipulation of vulnerable people). The February 2025 wave already activated these.
Tier 2: High-risk system non-compliance
Up to 15 million euros or 3% of global annual turnoverNon-compliance with any obligation in Articles 9 to 17 or Article 26. This is what the August 2 enforcement wave added. Failing to register, failing to maintain a QMS, deploying without a conformity assessment.
Tier 3: False or misleading information
Up to 7.5 million euros or 1.5% of global annual turnoverProviding incorrect information to notified bodies or national authorities during conformity assessments or market surveillance investigations.
The 3% cap sounds manageable for a startup with 2 million euros in revenue (60,000 euro maximum). For a company with 500 million euros in global revenue, the cap is 15 million. For any company in the Fortune 500, the maximum is the flat 15 million euro ceiling, not the percentage. GDPR enforcement history suggests that regulators will use high-profile cases to establish precedent in the first two years, then broaden enforcement as capacity grows.
The 90-Day Action Plan for Product Teams
If your product is or might be high-risk, the window for remediation is now. Authorities will investigate complaints before they conduct proactive audits, which gives product teams a narrow window to get compliant before an incident surfaces a gap. Here is the order of operations.
Days 1 to 14: Classify and scope
- Map every AI feature against Annex III. Do not rely on product names or marketing descriptions, map against what the feature actually does.
- Document the geographic distribution of your users. Any meaningful EU user base triggers the regulation.
- Identify whether you are a provider, a deployer, or both for each feature.
- Engage EU-qualified legal counsel. Internal assessment alone is not sufficient for formal compliance decisions.
Days 15 to 45: Documentation and controls
- Create or update Technical Documentation per Annex IV. Pull existing model cards, PRDs, and test reports into the required structure.
- Audit your human oversight paths. Can an operator override every automated output? Build what is missing.
- Establish automated log retention. Ensure logs are held for at least 6 months and are exportable for audits.
- Draft your Instructions for Use document. Make it readable, not legal boilerplate.
Days 46 to 75: Conformity assessment and registration
- Determine whether your product requires third-party conformity assessment or self-assessment. Most Article 6(2) use cases allow self-assessment; some (biometrics, law enforcement) require third-party review.
- Complete the conformity assessment. For self-assessment, this means running through Annex VII and documenting results.
- Register your system in the EU AI database at the European Commission portal.
- Prepare your Declaration of Conformity and CE marking documentation.
Days 76 to 90: Monitoring and governance
- Stand up your post-market monitoring plan. Define what you measure, at what frequency, and what thresholds trigger review.
- Assign a QMS owner internally. Document who is accountable for each of the Articles 9 to 17 obligations.
- Establish your incident reporting process. Know who to notify, at what severity threshold, and within what timeframe.
- Brief your leadership on the compliance posture and the ongoing maintenance obligations. Compliance is not a project that closes.
The most common compliance failure in the first wave of GDPR enforcement was not malicious intent: it was documentation gaps in products that had done the right thing technically but had not recorded it. The EU AI Act enforcement will follow the same pattern. If you have built human oversight, a risk management process, and a QMS, document it properly so you can demonstrate compliance when asked.
Build AI Products That Are Ready for What Comes Next
The AI PM Masterclass prepares you to lead in a regulated AI environment. Learn compliance strategy, risk management, and how to ship AI responsibly.
Related Articles
Before you go: get the AI PM Minute
One tactic to make you a sharper AI PM, twice a week. 60 seconds to read. Free.
No fluff. Unsubscribe anytime.