What Is the EU AI Act
The EU AI Act, effective August 2024, is the world's first comprehensive AI regulation. Like GDPR, all companies providing AI systems within the EU are subject, so even Japan-headquartered firms must comply if they serve EU customers.
With phased enforcement: prohibitions from February 2025, GPAI (general-purpose AI) rules from August 2025 already applied. High-risk AI rules were initially planned for full operation from August 2026, but following industry pushback, the "Digital Omnibus on AI" package pushed back the main high-risk AI compliance deadlines to 2027-2028 (regulatory simplification aimed at easing SME burden). Deepfake/AI-generated-content labeling obligations take effect as planned in August 2026. "Nudification" apps remain clearly prohibited.
4 Risk Tiers
1. Unacceptable Risk (Prohibited)
- AI distorting behavior via subliminal manipulation
- AI exploiting vulnerabilities of children/disabled people
- Social scoring (overall scoring of citizens)
- Real-time biometric ID in public spaces (with exceptions)
Fully prohibited from February 2025. Violations: up to EUR 35M or 7% of global revenue in fines.
2. High Risk
AI used for hiring, credit evaluation, education evaluation, medical devices, critical infrastructure, judicial support. The following are obligations.
- Conformity assessment (CE-mark equivalent)
- Creating and retaining technical documentation
- Data governance (bias inspection, quality management)
- Transparency (explanation to users)
- Human oversight
- Accuracy/robustness/cybersecurity
- Registration in an EU database
3. Limited Risk (Transparency Obligation)
- Chatbots: clearly state the counterpart is AI
- Deepfakes: display as AI-generated
- Emotion-recognition/biometric-classification AI: notify users
4. Minimal Risk
Most others (spam filters, AI games, image classification). No regulation, voluntary-code based.
GPAI (General-Purpose AI Model) Obligations
Base-model providers like GPT, Claude, Gemini have separate obligations.
- Technical documentation (model architecture, training-data overview, energy consumption)
- Copyright-law compliance (a mechanism for rightsholders to opt out of training data)
- GPAI with systemic risk (compute over 10^25 FLOPs) additionally needs red-teaming, cyber measures, notification to the European Commission
What Japanese Firms Should Pin Down Now
- Applicability judgment: inventory whether you provide AI features to EU users
- Identify risk tier: confirm whether hiring, credit evaluation, medical, etc. fall under high-risk
- Prepare technical-doc templates: data sources, evaluation metrics, unexpected behavior and measures
- Review contracts: often joint liability with AI vendors. State Act compliance in the SLA
- Log retention: high-risk AI: audit logs at least 6 months; medical: 10 years, per-sector requirements
Alignment with Other Regulations
The EU AI Act overlaps with GDPR, the NIS2 Directive, and the Product Liability Directive (PLD). Especially GDPR's "protection from automated decision-making" (Art. 22) overlaps much with the AI Act's high-risk requirements, requiring implementation spanning both.
Summary
The EU AI Act's essence is "tiered regulation changing obligations by AI risk." Japanese firms also face extraterritorial application, so first inventory service applicability and, if high-risk, complete conformity assessment and documentation by August 2026.



