SYSTEM NOTICE

Auto translation by AI. Be sure, accuracy, nuances and authorial intent may not be fully reflected.
見出し画像

The Full Scope of the EU AI Act and Its Impact on Japanese Companies


Definition and Overview of the EU AI Act

The EU AI Act is the world's first comprehensive AI regulation, which entered into force on August 1, 2024. Similar to the GDPR, it is based on extraterritorial application, meaning that even if an entity does not have a base within the EU, it is subject to regulation if it provides AI to the EU market or if AI output is used in the EU.

Entities subject to regulation include:

  • Provider: Businesses that develop and place AI on the market

  • Deployer: Businesses that use AI

  • Importer: Businesses that distribute third-country AI into the EU market

  • Distributor: Intermediary businesses that distribute within the EU

This extends across the entire supply chain. Japanese companies are no exception; they are subject to the regulation if their products have AI embedded in them or if they operate generative AI services used by EU residents.


Risk-Based Classification of the AI Act

The AI Act defines four categories based on risk.

  1. Unacceptable risk (Prohibited AI, Art. 5)
    Includes social scoring and unauthorized facial recognition databases. Fines for violations are up to 7% of annual turnover or 35 million euros.

  2. High-risk (Art. 9–15)
    Includes AI related to education, employment, medical devices, and critical infrastructure. Requirements include risk management, data governance, technical documentation, log retention, human oversight, and cybersecurity. EU database registration and conformity assessment are required.

  3. Limited risk (transparency obligations) (Art. 50)
    Includes emotion recognition, deepfake generation, etc. Obligations are imposed for notification that it is AI, labeling, and disclosure of synthetic content..

  4. Minimal risk
    General use. There are almost no obligations, and compliance with a Code of Practice is recommended..


General-Purpose AI (GPAI) and Systemic Risk

General-purpose AI models (GPAI), such as generative AI, are treated specially.

  • Obligations: Creation of technical documentation, provision of information to downstream operators, compliance with EU copyright law, and publication of summaries of training data.

  • Systemic risk models: Models exceeding a certain threshold in computational power or user count. Mandatory risk assessment, adversarial testing, reporting of serious incidents, and strengthening of cybersecurity.. Notification to the EU Commission must be made within two weeks.

This means that not only providers of foundation models such as OpenAI and Google, but also Japanese companies incorporating GPAI must comply with transparency obligations and information disclosure requirements.


Future Timeline

Key Schedule:

  • 2025/02/02: Start of application of prohibited AI provisions

  • 2025/08/02: Start of application of GPAI regulations

  • 2026/08/02: Full application including high-risk requirements and transparency obligations

  • 2027/08/02: Grace period deadline for certain high-risk AI (embedded in existing systems)

  • 2030/12/31: Final grace period deadline for specific large-scale IT system components

Maximum Penalties:

  • Violation of prohibited AI: 35 million euros or 7% of turnover

  • Violation of high-risk requirements/transparency: 15 million euros or 3% of turnover

  • Providing misleading information: 7.5 million euros or 1% of turnover


Roadmap for Japanese Companies' Compliance

  1. Scope Confirmation: Inventory your company's AI use cases and identify the applicable risk categories.

  2. Risk Classification: Prioritize the evaluation of AI for high-risk applications (recruitment, education, healthcare, etc.).

  3. GPAI Compliance: Prepare technical documentation, copyright policies, and training data summaries.

  4. High-Risk Requirement Implementation: Integrate risk management, data governance, and cybersecurity into your QMS.

  5. Transparency Obligation Compliance: Incorporate labeling for synthetic content and user notifications into the UI.

  6. Transition Plan: Based on the application schedule from 2025 to 2027, execute the PDCA cycle of gap analysis → countermeasures → internal audits.

It is important for Japanese companies not to stop at mere "regulatory compliance," but to make the strengthening of AI governance an element of competitive advantage.


Summary

  • The EU AI Act is extraterritorial and risk-based, and Japanese companies are no exception.

  • GPAI has additional obligations (technical documentation, copyright compliance, training data summaries, and systemic risk assessment).

  • Fines of up to 7% for violations. You should prepare now, focusing on the dates of 2025/02/02, 2025/08/02, and 2026/08/02.

いいなと思ったら応援しよう!

びじほー よろしければサポートお願いします! いただいたサポートはクリエイターとしての活動費に使わせていただきます!