The Full Scope of the EU AI Act and Its Impact on Japanese Companies
Definition and Overview of the EU AI Act
The EU AI Act is the world's first comprehensive AI regulation, which entered into force on August 1, 2024. Similar to the GDPR, it is based on extraterritorial application, meaning that even if an entity does not have a base within the EU, it is subject to regulation if it provides AI to the EU market or if AI output is used in the EU.
Entities subject to regulation include:
Provider: Businesses that develop and place AI on the market
Deployer: Businesses that use AI
Importer: Businesses that distribute third-country AI into the EU market
Distributor: Intermediary businesses that distribute within the EU
This extends across the entire supply chain. Japanese companies are no exception; they are subject to the regulation if their products have AI embedded in them or if they operate generative AI services used by EU residents.
Risk-Based Classification of the AI Act
The AI Act defines four categories based on risk.
Unacceptable risk (Prohibited AI, Art. 5)
Includes social scoring and unauthorized facial recognition databases. Fines for violations are up to 7% of annual turnover or 35 million euros.High-risk (Art. 9–15)
Includes AI related to education, employment, medical devices, and critical infrastructure. Requirements include risk management, data governance, technical documentation, log retention, human oversight, and cybersecurity. EU database registration and conformity assessment are required.Limited risk (transparency obligations) (Art. 50)
Includes emotion recognition, deepfake generation, etc. Obligations are imposed for notification that it is AI, labeling, and disclosure of synthetic content..Minimal risk
General use. There are almost no obligations, and compliance with a Code of Practice is recommended..
General-Purpose AI (GPAI) and Systemic Risk
General-purpose AI models (GPAI), such as generative AI, are treated specially.
Obligations: Creation of technical documentation, provision of information to downstream operators, compliance with EU copyright law, and publication of summaries of training data.
Systemic risk models: Models exceeding a certain threshold in computational power or user count. Mandatory risk assessment, adversarial testing, reporting of serious incidents, and strengthening of cybersecurity.. Notification to the EU Commission must be made within two weeks.
This means that not only providers of foundation models such as OpenAI and Google, but also Japanese companies incorporating GPAI must comply with transparency obligations and information disclosure requirements.
Future Timeline
Key Schedule:
2025/02/02: Start of application of prohibited AI provisions
2025/08/02: Start of application of GPAI regulations
2026/08/02: Full application including high-risk requirements and transparency obligations
2027/08/02: Grace period deadline for certain high-risk AI (embedded in existing systems)
2030/12/31: Final grace period deadline for specific large-scale IT system components
Maximum Penalties:
Violation of prohibited AI: 35 million euros or 7% of turnover
Violation of high-risk requirements/transparency: 15 million euros or 3% of turnover
Providing misleading information: 7.5 million euros or 1% of turnover
Roadmap for Japanese Companies' Compliance
Scope Confirmation: Inventory your company's AI use cases and identify the applicable risk categories.
Risk Classification: Prioritize the evaluation of AI for high-risk applications (recruitment, education, healthcare, etc.).
GPAI Compliance: Prepare technical documentation, copyright policies, and training data summaries.
High-Risk Requirement Implementation: Integrate risk management, data governance, and cybersecurity into your QMS.
Transparency Obligation Compliance: Incorporate labeling for synthetic content and user notifications into the UI.
Transition Plan: Based on the application schedule from 2025 to 2027, execute the PDCA cycle of gap analysis → countermeasures → internal audits.
It is important for Japanese companies not to stop at mere "regulatory compliance," but to make the strengthening of AI governance an element of competitive advantage.
Summary
The EU AI Act is extraterritorial and risk-based, and Japanese companies are no exception.
GPAI has additional obligations (technical documentation, copyright compliance, training data summaries, and systemic risk assessment).
Fines of up to 7% for violations. You should prepare now, focusing on the dates of 2025/02/02, 2025/08/02, and 2026/08/02.
いいなと思ったら応援しよう!
よろしければサポートお願いします! いただいたサポートはクリエイターとしての活動費に使わせていただきます!