← LX AI 目录 博客首页

博客正文为机辅翻译,建议人工复审后再作正式引用依据。

【机辅译·待复审】发布于 2026-09-11 · A practical 2026 guide to 欧盟 AI 法案 合规 for US & UK teams: risk tiers, real deadlin · 更新于 2026-09-11

【机辅译·待复审】欧盟 AI 法案 合规 (2026): Deadlines, Tools & 清单

要点摘要

  • 【机辅译·待复审】The 欧盟 AI 法案 now applies in phases, and two major milestones have already passed: prohibitions (February 2025) and GPAI obligations (August 2025). Transparency duties under Article 50 became enforceable in August 2026.
  • 【机辅译·待复审】The Digital Omnibus regulation (Reg. (EU) 2026/1744) reshuffled several timelines: AI-content watermarking duties land in December 2026, most Annex III high-risk obligations in December 2027, and AI embedded in regulated products in August 2028.
  • 【机辅译·待复审】If you sell software into the EU from the US or UK, you are very likely in scope: the Act reaches providers and deployers whose systems'output【机辅译·待复审】is used in the EU, regardless of where you are incorporated.
  • 【机辅译·待复审】The core 合规 工作流 is the same for everyone: classify your use case → map obligations → document evidence → monitor change. Tooling exists at every step; picking one is about team size and audit posture, not ideology.
  • 【机辅译·待复审】This guide compares seven approaches — enterprise GRC suites (Holistic AI, Credo AI, IBM watsonx.治理, OneTrust, TrustArc, Vanta) and a focused classification-first tool, AIActRadar — so you can match spend to actual exposure.

【机辅译·待复审】Introduction: Why "合规 later" stopped being an option

【机辅译·待复审】For two years, the 欧盟 AI 法案 was something 法务 teams bookmarked and founders deferred. That window has closed. (2026) the Act is no longer a looming framework; it is an operating reality with enforcement powers, registration duties, and — critically for non-EU companies — extraterritorial reach.

【机辅译·待复审】If you are a US or UK SaaS team shipping anything with an AI feature — a support chatbot, a document classifier, an agent that drafts emails — the Act can apply to you even though you have never had an office in Europe. The trigger is not where your company sits. It is where your system's【机辅译·待复审】output is used in the EU.

【机辅译·待复审】This guide is written for exactly that audience: small-to-mid-size B2B teams that need to (1) understand what actually binds them (2026), (2) classify their exposure without hiring a Brussels law firm, and (3) choose tooling that matches their size. We will walk through the risk tiers, the deadlines that survived the Digital Omnibus reshuffle, a practical 合规 工作流, and a comparison of the main tool categories.

【机辅译·待复审】Suggested external link placement:【机辅译·待复审】link "Reg. (EU) 2026/1744" and "Article 50" to the relevant EUR-Lex pages on first mention, per GEO/SEO best practice for YMYL-adjacent 法务 content.

【机辅译·待复审】The 欧盟 AI 法案 in one page: scope, roles, and reach

【机辅译·待复审】Who counts as a provider, deployer, or both

【机辅译·待复审】The Act assigns duties based on your role. Aprovider【机辅译·待复审】develops an AI system and places it on the market under their own name. Adeployer【机辅译·待复审】uses an AI system in the course of their activities. Many SaaS companies are both: youprovide【机辅译·待复审】the AI feature to customers anddeploy【机辅译·待复审】AI internally (say, for support triage).

【机辅译·待复审】Why it matters: providers carry heavier documentation, registration, and conformity duties for high-risk systems; deployers carry usage-side duties like human oversight and informing affected persons. Misclassifying your role is one of the most common gaps we see in early self-assessments.

【机辅译·待复审】Extraterritorial reach — the clause that catches US and UK teams

【机辅译·待复审】Article 2 extends the Act to providers and deployers outside the EU when the output of their AI system is used in the Union. Practical translation: an American company whose AI writing assistant is used by a German customer is in scope for the obligations attached to that use. Penalties can reach the tens of millions of euros or a percentage of global 将over, whichever is higher — the same penal architecture that made GDPR a board-level topic.

【机辅译·待复审】What is explicitly banned (and already enforced)

【机辅译·待复审】Since February 2025, a short list of practices is prohibited outright: subliminal manipulation causing harm, exploitation of vulnerabilities of specific groups, social scoring by public authorities, untargeted facial-image scraping, emotion recognition in workplaces and schools (with narrow exceptions), biometric categorization of sensitive attributes, and real-time remote biometric identification in public spaces for law enforcement (with narrow exceptions). If any product feature touches these areas, the 合规 question is not "how" but "whether."

【机辅译·待复审】The 2026–2028 timeline (post–Digital Omnibus)

【机辅译·待复审】The original timeline was modified by the Digital Omnibus regulation, effective July 2026. Here is the schedule that matters as you plan roadmaps:

Milestone Date 【机辅译·待复审】What becomes binding
【机辅译·待复审】Prohibited practices (Art. 5) Feb 2025 【机辅译·待复审】Bans listed above; already enforceable
【机辅译·待复审】GPAI obligations Aug 2025 【机辅译·待复审】General-purpose AI model duties: technical documentation, copyright policy, training-data summaries
【机辅译·待复审】Art. 50 transparency + GPAI enforcement powers Aug 2026 【机辅译·待复审】Disclosure duties (AI interaction, deepfake labeling) become enforceable; AI Office gains enforcement authority
【机辅译·待复审】AI-content watermarking / NCIC-related bans Dec 2026 【机辅译·待复审】Machine-readable marking duties for synthetic content mature
【机辅译·待复审】Most high-risk Annex III obligations Dec 2027 【机辅译·待复审】Risk management, data 治理, technical documentation, logging, human oversight for Annex III use cases
【机辅译·待复审】AI as safety component in regulated products Aug 2028 【机辅译·待复审】Conformity assessment integration for AI embedded in machinery, medical devices, etc.

【机辅译·待复审】What this means for a typical SaaS roadmap

  • 【机辅译·待复审】Shipping (2026):【机辅译·待复审】your most likely exposure is Article 50 transparency — telling users they are interacting with AI, labeling synthetic media. This is cheap to implement and increasingly checked.
  • 【机辅译·待复审】Planning 2027–2028 launches:【机辅译·待复审】if your use case appears in Annex III (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration), start the risk-management file now; December 2027 arrives faster than it looks.
  • 【机辅译·待复审】构建ing on foundation models:【机辅译·待复审】the GPAI duties from August 2025 flow down through your model vendors' documentation. You inherit evidence obligations you cannot fabricate later — capture vendor attestations now.
【机辅译·待复审】Internal link suggestion:【机辅译·待复审】link "Article 50 transparency" to your own explainer post (e.g., /blog/ai-act-article-50-disclosure-清单) and the timeline table to the product page https://aiactradar.lxsaihub.com/.

【机辅译·待复审】Risk classification: the four tiers, applied to real products

【机辅译·待复审】The Act sorts AI systems into four tiers. The tier decides almost everything downstream, so it is worth getting right — and it is also where most self-assessments wobble.

【机辅译·待复审】Tier 1 — Unacceptable risk

【机辅译·待复审】Already banned (see above). There is no "合规 path" here; features must be removed or redesigned.

【机辅译·待复审】Tier 2 — High risk (Annex III)

【机辅译·待复审】High-risk status attaches to specificuse cases【机辅译·待复审】, not to AI in general. The Annex III families most relevant to B2B software:

  • 【机辅译·待复审】Employment and worker management【机辅译·待复审】— CV screening, promotion scoring, task allocation. If your HR-tech does any candidate filtering, you are here.
  • 【机辅译·待复审】Education and vocational training【机辅译·待复审】— admission scoring, exam proctoring.
  • 【机辅译·待复审】Essential private and public services【机辅译·待复审】— credit scoring, insurance pricing, benefits eligibility.
  • 【机辅译·待复审】Law enforcement, migration, border control【机辅译·待复审】— narrow but absolute.
  • Biometrics【机辅译·待复审】— identification, categorization, emotion recognition.
  • 【机辅译·待复审】Critical infrastructure【机辅译·待复审】— safety-relevant components.

【机辅译·待复审】A high-risk classification triggers the full stack: risk-management system, data 治理, technical documentation, logging, transparency to users, human oversight, accuracy/robustness/cyber安全 requirements, EU database registration, and conformity assessment.

【机辅译·待复审】Tier 3 — Limited risk / transparency duty

【机辅译·待复审】This is the tier most SaaS products actually live in. Chatbots must disclose they are AI; synthetic images, audio, and video must be labeled as artificially 生成d or manipulated. Since August 2026 this is enforceable — not aspirational.

【机辅译·待复审】Tier 4 — Minimal risk

【机辅译·待复审】Everything else: spam filters, recommendation ranking, autocomplete. No specific obligations, though voluntary codes are encouraged.

【机辅译·待复审】The classification trap

【机辅译·待复审】Systems are classified per use case, and one product can straddle tiers — a customer-service assistant is "limited risk," but if the same vendor sells a CV-screening module to an EU customer, that module is high-risk. Spreadsheets break down exactly here. This is the step where classification-first tooling earns its keep: a deterministic engine applied per use case beats an ad-hoc reading of Annex III.

【机辅译·待复审】The 合规 工作流 that actually fits a small team

【机辅译·待复审】Enterprise programs assume enterprise budgets. A five-person 合规-capable 工作流 (no, you do not need five people — fivesteps【机辅译·待复审】) looks like this:

  1. Inventory.【机辅译·待复审】List every AI feature you ship or use internally, including vendor models. One row per use case.
  2. Classify.【机辅译·待复审】Map each use case against Article 5 (prohibited), Annex III (high-risk), and Article 50 (transparency). Record reasoning — regulators ask for it.
  3. 【机辅译·待复审】Obligation mapping.【机辅译·待复审】For each classified use case, list the duties that attach: documentation, disclosure, oversight, registration, conformity.
  4. 【机辅译·待复审】Evidence collection.【机辅译·待复审】Gather what already exists (model cards, DPA summaries, vendor attestations, test reports) and mark what is missing. Regulators judge files, not intentions.
  5. Monitoring.【机辅译·待复审】The Act is a moving target; the Digital Omnibus proved it. Assign an owner and a cadence (quarterly is realistic) for re-classification and timeline drift.

【机辅译·待复审】This is the loopAIActRadar【机辅译·待复审】is built around — classify, map, document, monitor — which is why we will use it as the reference point when comparing 工具.

【机辅译·待复审】Suggested external links:【机辅译·待复审】"risk-management system" → Annex III text on EUR-Lex; "conformity assessment" → the Commission's AI Act overview page.

【机辅译·待复审】Tool landscape: seven ways to run the program

【机辅译·待复审】The market splits into two families:【机辅译·待复审】enterprise GRC suites【机辅译·待复审】(broad 治理 platforms that cover AI among many risk domains) and【机辅译·待复审】focused 合规 工具【机辅译·待复审】(narrow, 工作流-first products for the AI Act specifically). Neither family is wrong; the fit depends on your audit posture.

【机辅译·待复审】Comparison table

Tool Core focus 【机辅译·待复审】Indicative pricing* 【机辅译·待复审】Best-fit team size 【机辅译·待复审】Standout strength
AIActRadar 【机辅译·待复审】欧盟 AI 法案 classification-first 合规 (risk tiering, obligation maps, gap reports, roadmaps, Omnibus 追踪ing) 【机辅译·待复审】Free tier; Pro from ~$29/mo 1–50 people 【机辅译·待复审】Purpose-built for the Act; fast self-assessment without consultants
Holistic AI 【机辅译·待复审】Enterprise AI 治理 platform 【机辅译·待复审】Custom (enterprise) 500+ 【机辅译·待复审】Broad model lifecycle coverage; large-vendor references
Credo AI 【机辅译·待复审】AI 治理 & policy enforcement 【机辅译·待复审】Custom (enterprise) 500+ 【机辅译·待复审】Policy-to-evidence 工作流s; strong regulated-industry positioning
【机辅译·待复审】IBM watsonx.治理 【机辅译·待复审】Model 治理 inside the watsonx stack 【机辅译·待复审】Custom (enterprise) 1,000+ 【机辅译·待复审】Deep integration if you already run watsonx
OneTrust 【机辅译·待复审】Privacy + AI 治理 (TIA/algorithmic modules) 【机辅译·待复审】Custom (enterprise) 500+ 【机辅译·待复审】One vendor for privacy + AI; established GRC 工作流s
TrustArc 【机辅译·待复审】Privacy & responsible-AI assessments 【机辅译·待复审】Custom (enterprise) 300+ 【机辅译·待复审】Assessment-driven programs; mature methodology
Vanta 【机辅译·待复审】Trust management / 安全 合规, expanding into AI 【机辅译·待复审】From ~$21k/yr (indicative) 50–1,000 【机辅译·待复审】Bundling AI 治理 with SOC 2 / ISO 27001

【机辅译·待复审】* Indicative as of 2026; verify current pricing on each vendor's site. Enterprise tiers are quote-based.

【机辅译·待复审】AIActRadar — deep dive

功能概览.【机辅译·待复审】AIActRadar compresses the five-step 工作流 above into a guided product: describe your use case, get a risk-tier verdict mapped to Annex III, receive the obligation list for that tier, upload existing evidence for gap analysis, and 生成 a phased remediation roadmap. A change-追踪ing module follows Digital Omnibus-era timeline shifts so the December 2027 and August 2028 milestones do not sneak up on you.

Pros

  • 【机辅译·待复审】Classification-first: the hardest step is also the fastest one.
  • 【机辅译·待复审】Evidence-retention guidance built into the roadmap, so documentation accrues as you go rather than in a pre-audit scramble.
  • 【机辅译·待复审】Self-serve pricing that a bootstrapped or seed-stage team can actually approve.
  • 【机辅译·待复审】Timeline 追踪ing is maintained against the post-Omnibus schedule, not the original one.

Cons

  • 【机辅译·待复审】Not a full GRC suite: if you need SOC 2, ISO 42001, and vendor-risk management in one platform, you will pair it with (or eventually graduate to) a broader tool.
  • 【机辅译·待复审】English-first; multilingual outputs for EU-market filings are lighter than enterprise suites.

【机辅译·待复审】Real use case.【机辅译·待复审】A UK HR-tech startup preparing an EU pilot for its CV-screening module needed to know, before the sales call, whether the feature was high-risk and what that would cost them. Classification took an afternoon; the obligation map showed data-治理 and human-oversight duties they could partially satisfy with existing model documentation. The gap report went straight into the pilot's 法务 annex.

【机辅译·待复审】Real use case (second segment).【机辅译·待复审】A US agency-services firm uses AI 工具 for client deliverables. They ran their internal tool stack through classification to produce a one-page "AI Act exposure memo" for EU-bound clients — a cheap artifact that repeatedly unblocked procurement conversations.

【机辅译·待复审】When to choose an enterprise GRC suite instead

【机辅译·待复审】Pick Holistic AI, Credo AI, watsonx.治理, OneTrust, or TrustArc when you have: (a) an in-house 合规 function that will operate a platform daily; (b) multiple regulated regimes in scope simultaneously; (c) procurement processes that require SOC 2 reports and enterprise references from your 治理 vendor. At that point the suite's weight becomes an asset rather than overhead.

【机辅译·待复审】When Vanta-style bundling makes sense

【机辅译·待复审】If your near-term 合规 driver is SOC 2 or ISO 27001 — and AI Act work is secondary — Vanta's model of one subscription covering multiple frameworks can be economical. The trade-off is depth: AI-specific classification and Annex III mapping are newer and thinner than in dedicated 工具.

常见问题

【机辅译·待复审】Does the 欧盟 AI 法案 apply to a US company with no EU office?
【机辅译·待复审】Yes, if theoutput【机辅译·待复审】of your AI system is used in the EU. Article 2's extraterritorial clause reaches providers and deployers located in third countries whose system output is used in the Union. Enforcement runs through market surveillance authorities and can attach to your EU-facing customers' obligations too — which is why EU buyers increasingly demand AI Act evidence in procurement.
【机辅译·待复审】What are the actual deadlines after the Digital Omnibus?
【机辅译·待复审】Prohibitions: February 2025 (in force). GPAI: August 2025 (in force). Article 50 transparency duties and GPAI enforcement powers: August 2026 (in force). AI-content marking duties: December 2026. Most Annex III high-risk obligations: December 2027. AI embedded in regulated products: August 2028. Note these reflect Reg. (EU) 2026/1744; verify against EUR-Lex for filing-grade certainty.
【机辅译·待复审】How do I know if my product is "high-risk"?
【机辅译·待复审】Check your use case, not your technology, against Annex III: employment, education, essential services (credit, insurance), biometrics, critical infrastructure, law enforcement, migration. If you are in any of those families, assume high-risk until a documented assessment says otherwise. If you are a chatbot, writing assistant, or 分析 tool outside those families, your realistic tier is "limited risk" — the Article 50 disclosure duties.
【机辅译·待复审】What happens if we ignore it?
【机辅译·待复审】Penalty ceilings reach the tens of millions of euros or a percentage of worldwide annual 将over (the higher figure), scaled by violation type. Beyond fines, the practical cost shows up earlier: EU enterprise customers now ask for AI Act posture in 安全 questionnaires, and "we're assessing it" increasingly fails procurement.
【机辅译·待复审】Can a small team really do this without a law firm?
【机辅译·待复审】For classification and obligation mapping — yes, with the right tooling; the risk tiers are rule-based, and a deterministic engine plus a recorded rationale is a defensible starting position. For high-risk systems heading into conformity assessment, or for gray-zone use cases, bring in counselafter【机辅译·待复审】you have the classification file — it makes the engagement shorter and cheaper.
【机辅译·待复审】Is a "合规 report" from a tool enough for regulators?
【机辅译·待复审】No tool output is a 法务 safe harbor. What matters is a documented, current, and coherent program: classification with reasoning, mapped obligations, real evidence, and a monitoring cadence. Tools structure and accelerate exactly that; they do not replace accountability.
【机辅译·待复审】Does the UK AI policy landscape require the same work?
【机辅译·待复审】The UK has taken a principles-based, sector-regulator approach rather than a horizontal act — so no single "UK AI Act" 合规 file exists today. But if you serve EU users, the EU Act applies regardless of your UK base, and UK regulator guidance is converging on similar transparency expectations. ---

Sources

相关 工具

  • AIActRadar — Turn EU AI Act chaos into a clear compliance roadmap
  • AgentPolicy — Turn company policy into agent-enforced rules
  • AgentRedTeam — Break your AI agents before attackers do

Keep reading

新工具上线邮件通知

One short email when the LX factory ships a new micro-SaaS — no spam, unsubscribe anytime.