← LX AI 目录 博客首页

博客正文为机辅翻译,建议人工复审后再作正式引用依据。

【机辅译·待复审】发布于 2026-09-10 · A practical, dated 清单 for 小团队 deploying AI in the EU. · 更新于 2026-09-11

欧盟 AI 法案 合规 清单 for 小团队 (2026)

要点摘要

  • 【机辅译·待复审】Only a handful of 欧盟 AI 法案 dates actually bind small SaaS teams — know them before you 构建.
  • 【机辅译·待复审】A six-step 清单 walks from scoping and classification to documentation and monitoring.
  • 【机辅译·待复审】The five recurring mistakes are avoidable with one hour of structured review; tooling 帮助s with evidence, not judgment.

【机辅译·待复审】This is a practical engineering-and-operations 清单, not 法务 advice. Confirm anything material with counsel.

【机辅译·待复审】The 欧盟 AI 法案 does not switch on all at once, and that is exactly why 小团队 get it wrong. Your deadline depends on【机辅译·待复审】what your system does and 【机辅译·待复审】which role you play【机辅译·待复审】— provider or deployer — not on the date the regulation was signed. Most teams we talk to cannot answer the first question an auditor asks: which articles apply to this system, and by when? For the binding 法务 text, see Regulation (EU) 2024/1689 (【机辅译·待复审】eur-lex.europa.eu).

【机辅译·待复审】The 欧盟 AI 法案, defined

【机辅译·待复审】The 欧盟 AI 法案 (Regulation (EU) 2024/1689) is the world’s first comprehensive, risk-based law regulating artificial intelligence — it classifies systems by potential harm and attaches obligations that scale with that risk.【机辅译·待复审】For a small team, the practical question is never “is the Act in force?” but “which of my systems fall into which risk tier, and by when?”

【机辅译·待复审】“The AI Act is the world’s first comprehensive AI law, built on a risk-based structure that sorts systems from minimal to unacceptable risk.”
【机辅译·待复审】— European Commission, “AI Act” (digital-strategy.ec.europa.eu)
【机辅译·待复审】“The 欧盟 AI 法案 does not switch on all at once, and that is exactly why 小团队 get it wrong. Your deadline depends on what your system does and which role you play — provider or deployer.”
【机辅译·待复审】— LX AI (Xingliang Li), LX 微 SaaS Factory

【机辅译·待复审】The dates that actually bind you

【机辅译·待复审】The phasing below follows Regulation (EU) 2026/1744 (the “Digital Omnibus”,【机辅译·待复审】eur-lex.europa.eu【机辅译·待复审】), in force from 27 July 2026, which revised several application dates.

Obligation【机辅译·待复审】Applies fromWho it hits
【机辅译·待复审】Prohibited practices (Art. 5)2 Feb 2025Everyone
【机辅译·待复审】GPAI obligations2 Aug 2025【机辅译·待复审】Model providers
【机辅译·待复审】Art. 50 transparency + GPAI enforcement powers2 Aug 2026【机辅译·待复审】Providers & deployers
【机辅译·待复审】AI-生成d content marking / NCIC prohibitions2 Dec 2026【机辅译·待复审】Providers & deployers
【机辅译·待复审】High-risk Annex III2 Dec 2027【机辅译·待复审】Annex III use cases
【机辅译·待复审】Embedded in regulated products2 Aug 2028【机辅译·待复审】Product manufacturers

【机辅译·待复审】The six-step 清单

  1. 【机辅译·待复审】Inventory every AI system.【机辅译·待复审】Include the ones a contractor shipped, the model behind a support widget, and anything calling a third-party API. Teams routinely miss half their surface area.
  2. 【机辅译·待复审】Assign a role per system.【机辅译·待复审】Provider (you 构建/place it on the market) or deployer (you use it). The obligations differ sharply, and getting this wrong misroutes everything downstream.
  3. 【机辅译·待复审】Classify risk.【机辅译·待复审】Check Art. 5 prohibitions first, then Annex III high-risk categories, then Art. 50 transparency. A generic support chatbot is usually minimal-risk — it changes character if it screens CVs, scores credit, or does emotion inference.
  4. 【机辅译·待复审】Map obligations to dates.【机辅译·待复审】For each applicable article, write down the binding date from the table above. This converts a vague worry into a schedule.
  5. 【机辅译·待复审】Close the documentation gap.【机辅译·待复审】Even at minimal risk you need to be able to showwhy【机辅译·待复审】you classified it that way. A one-page rationale per system is usually enough and is what auditors ask for first.
  6. 【机辅译·待复审】Re-check on a cadence.【机辅译·待复审】The dates moved once already. Set a recurring review, and re-verify before each milestone in the table.

【机辅译·待复审】Five mistakes we see repeatedly

  • 【机辅译·待复审】Using the original dates.【机辅译·待复审】The Digital Omnibus pushed Annex III high-risk to 2 Dec 2027. Plans built on the pre-Omnibus 2026 date are planning against a deadline that no longer exists.
  • 【机辅译·待复审】Confusing “obligation applies” with “enforcement starts”.【机辅译·待复审】GPAI obligations applied from 2 Aug 2025, but enforcement powers only became exercisable from 2 Aug 2026. Both dates matter; they are not the same thing.
  • 【机辅译·待复审】Assuming “we are outside the EU” means out of scope.【机辅译·待复审】If your system's output is used in the EU, you are likely in scope regardless of where you are incorporated.
  • 【机辅译·待复审】Treating 合规 as a one-off.【机辅译·待复审】Adding a feature can move a system into a new risk tier. Re-classify on material change.
  • 【机辅译·待复审】Buying a “100% compliant” badge.【机辅译·待复审】No tool can certify that. Distrust any product that claims to.

【机辅译·待复审】Where tooling genuinely 帮助s

【机辅译·待复审】The tedious part is not understanding the regulation — it is repeating steps 1–4 across a dozen systems and keeping them current. That is the part worth automating.

  • AIActRadar【机辅译·待复审】classifies each system's risk tier and maps the applicable obligations to their phased deadlines with article citations, producing a risk register and a dated roadmap.
  • AgentPolicy【机辅译·待复审】converts your written policy into checks your agents actually enforce, which matters once you have autonomous systems acting on their own.
  • 【机辅译·待复审】AgentRedTeam【机辅译·待复审】simulates prompt injection, tool abuse and data exfiltration against those agents, since Art. 15 robustness expectations do not stop at documentation.

【机辅译·待复审】全部 three have a free tier, so you can 校验 the classification on one system before committing to anything.

常见问题

【机辅译·待复审】Does the 欧盟 AI 法案 apply to a small team outside the EU?
【机辅译·待复审】It can. The Act reaches providers placing AI systems on the EU market and deployers whose systems produce output used in the EU, regardless of where the team is incorporated. If your model's output is used by people in the EU, assume you are in scope and check your role.
【机辅译·待复审】When do high-risk Annex III obligations actually apply?
【机辅译·待复审】Under the Digital Omnibus (Regulation (EU) 2026/1744, in force 27 July 2026), high-risk Annex III obligations apply from 2 December 2027, later than the original 2026 date.
【机辅译·待复审】Is a generic support chatbot high-risk?
【机辅译·待复审】Usually not. A generic customer-support chatbot is typically minimal or limited-risk. It becomes higher-risk when it is used in Annex III contexts such as employment decisions, credit scoring, or essential services, or when it does biometric or emotion-related processing.
【机辅译·待复审】Do GPAI obligations apply now?
【机辅译·待复审】GPAI obligations have applied since 2 August 2025, but enforcement powers for GPAI only became exercisable from 2 August 2026. Transparency obligations under Article 50 also apply from 2 August 2026.
【机辅译·待复审】Do I need to watermark AI-生成d content?
【机辅译·待复审】Obligations covering marking and detection of AI-生成d content, including the prohibition on certain subliminal or deceptive techniques (NCIC), apply from 2 December 2026.

【机辅译·待复审】Sources & further reading

相关 工具

  • AIActRadar — maps your AI systems to their EU AI Act obligations automatically.
  • AgentPolicy — turns company policy into agent-enforced rules.
  • AgentRedTeam — red-teams your AI agents before attackers do.

Keep reading

新工具上线邮件通知

One short email when the LX factory ships a new micro-SaaS — no spam, unsubscribe anytime.