Strip away the discourse and the AI Act is a product regulation: providers of high-risk AI systems run a risk management system, govern their training data, document the system, log its operation, ensure accuracy, robustness and cybersecurity (Article 15), keep humans meaningfully in the loop, pass conformity assessment and affix a CE mark. Deployers get lighter duties; importers and distributors inherit the usual chain obligations. Anyone who has built a CRA or machinery-directive file recognises the architecture immediately.
High-risk status arrives by two roads: Annex III use cases — biometrics, critical infrastructure management, employment, credit, essential services, law enforcement — and AI as a safety component of products already under EU harmonisation law, where AI Act conformity folds into the existing product’s assessment. GPAI models carry their own regime, in force since August 2025, with systemic-risk models facing model evaluations and incident reporting under the Commission’s AI Office.
The honest mid-2026 picture: the high-risk obligations reach their main application milestone in August 2026, while the scaffolding is still going up — harmonised standards from CEN/CENELEC JTC21 are not finished, notified-body capacity is embryonic, and the Commission’s digital omnibus discussions have put timeline adjustments for parts of the high-risk regime on the table. Uncertainty about dates, however, changes nothing about direction: the evidence disciplines the Act demands take years to build, and they are the same disciplines the rest of your certification portfolio already requires.