AI LAW RADAR · Daily Last verified 8 Aug 2026

Topic dossier

High-risk & high-impact AI obligations

How the major risk-based regimes define high-risk or high-impact AI, and the assessments, oversight and documentation that classification triggers. 12 obligations across 9 jurisdictions — 6 in force, 2 proposed. Next dated deadline: 15 Aug 2026.

Risk-tiering is the architecture of most comprehensive AI laws: a system classified as high-risk — or high-impact — attracts the heaviest duties, typically a pre-deployment assessment, human oversight, risk management, technical documentation and sometimes registration. The EU AI Act’s Annex III is the reference model; South Korea, Vietnam, Peru, Brazil and the DIFC each run their own variant. The obligations below are the high-risk tier of each regime.

The Register

12 obligations · 9 jurisdictions

European Union 2

EU Comprehensive

High-risk AI obligations (Annex III)

Binds Providers & deployers of Annex III high-risk AI (employment, credit, education, biometrics, law enforcement, migration). Omnibus (Reg. EU 2026/1744, OJ L 2026/1744 published 24 Jul 2026) defers high-risk obligations for standalone Annex III systems from 2 Aug 2026 to 2 Dec 2027.

Regulation (EU) 2026/1744 (Digital Omnibus) published in the Official Journal; application of the Annex III high-risk obligations is deferred to 2 December 2027.

Stated maximum penalty — Up to 3% turnover or €15M

Applies 2 Dec 2027 checked 8 Aug 2026 EU AI Act (Digital Omnibus) ↗ high confidence
EU Comprehensive

EU AI Act high-risk obligations (Annex I — product-embedded)

Binds Providers and deployers of AI systems embedded in regulated products listed in Annex I (medical devices, general product safety, machinery, toys, aviation, automotive, railway). Omnibus (Reg. EU 2026/1744, OJ L 2026/1744 published 24 Jul 2026) defers high-risk obligations for AI embedded in Annex I regulated products (medical devices, machinery, toys, aviation) from 2 Aug 2026 to 2 Aug 2028.

Regulation (EU) 2026/1744 (Digital Omnibus) published in the Official Journal; application of the Annex I product-embedded high-risk obligations is deferred to 2 August 2028.

Stated maximum penalty — Up to 3% global turnover or €15M

Applies 2 Aug 2028 checked 8 Aug 2026 EU AI Act (Digital Omnibus amendment) ↗ high confidence

United States 2

US · CO Binding

Colorado AI Act (SB 26-189)

Binds Developers & deployers of automated decision-making tech in consequential decisions. ADMT documentation, consumer notice & appeal rights.

Stated maximum penalty — AG enforcement; per violation

Applies 1 Jan 2027 checked 8 Aug 2026 SB 26-189 ↗ high confidence
US · Federal Proposed

AI Kill Switch Act (Lieu-Moran)

Binds AI system developers meeting both: $100M+ training compute and $500M+ annual gross AI revenue. Frontier AI developers meeting dual thresholds ($100M dev compute, $500M annual AI revenue) must implement kill-switch capability; 15-day DHS incident reporting; DHS/CISA authority to compel emergency shutdown.

Introduced Jul 23, 2026 by Reps. Lieu (D) and Moran (R) as H.R. 9917; referred to the House Committee on Homeland Security same day; triggered by OpenAI/Hugging Face hack incident. 119th Congress.

Stated maximum penalty — Up to $2M/day (general); up to $20M/day (defying shutdown order)

Proposed checked 8 Aug 2026 AI Kill Switch Act ↗ high confidence

China 1

China Binding

China AI Agents Implementation Opinions (CAC/NDRC/MIIT)

Binds Developers and deployers of AI agent services in China; mandatory compliance for healthcare, transportation, media, and public safety sectors; guidance-level for others. First national policy framework for AI agents. Mandatory for 19 priority sectors (healthcare, transport, media, public safety): filing, compliance testing, product recall provisions. Establishes three-tier decision authority model. AI-generated content labeling required. Enforceable via existing CSL/DSL/PIPL frameworks.

Published and operative from May 8, 2026 (jointly issued by CAC, NDRC, MIIT). Three-tier decision authority model: decisions requiring human-only authority; decisions requiring user approval; decisions agent may handle autonomously. High-risk sector filing and testing obligations enforceable under Cybersecurity Law, Data Security Law, PIPL. No standalone penalty regime; enforcement via existing frameworks.

Stated maximum penalty — Enforcement via CSL/DSL/PIPL (no standalone penalties specified)

In force · 8 May 2026 checked 2 Aug 2026 CAC/NDRC/MIIT AI Agents Implementation Opinions (May 2026) ↗ high confidence

South Korea 1

S. Korea Comprehensive

AI Basic Act — high-impact AI duties

Binds Operators of high-impact AI and advanced / high-compute AI. Risk management, human oversight and impact assessment for high-impact / advanced AI (MSIT enforcement grace period through 2026).

MSIT is running a one-year enforcement grace period from 22 Jan 2026; fines expected to resume ~22 Jan 2027.

Stated maximum penalty — Admin fine up to ₩30M

In force · 22 Jan 2026 checked 7 Aug 2026 AI Basic Act ↗ high confidence

Brazil 1

Brazil Proposed

AI Act bill (PL 2338/2023) advancing

Binds Would bind AI providers / deployers once enacted. Risk-based, EU-style framework; Senate-approved Dec 2024, now before the Chamber of Deputies.

Senate-approved Dec 2024; before the Chamber of Deputies Special Committee. Rapporteur Dep. Aguinaldo Ribeiro (PP-PB) has not yet presented opinion ("parecer"); no plenary vote scheduled as of Jul 28, 2026. 35 related bills consolidated. Plenary vote not expected before late 2026.

Stated maximum penalty — Bill: up to R$50M / 2% revenue

Proposed checked 6 Aug 2026 PL 2338/2023 ↗ high confidence

Vietnam 2

Vietnam Comprehensive

Law on AI — risk-tiered obligations

Binds AI developers / providers / deployers / users; extraterritorial (local representative required). Three-tier risk classification; high-risk AI needs conformity assessment + registration (general grace to 1 Mar 2027).

Sector-differentiated grace period: 12 months (to 1 Mar 2027) for most sectors; 18 months (to 1 Sep 2027) for healthcare, education and finance. Implementing Decree 142/2026/ND-CP in force 1 May 2026.

Stated maximum penalty — Admin fines up to ₫2B (decree-set)

In force · 1 Mar 2026 checked 8 Aug 2026 Law 134/2025/QH15 ↗ high confidence
VN Comprehensive

Vietnam Decision 33 — 46 High-Risk AI Systems List

Binds Operators and providers of the 46 designated high-risk AI systems in Vietnam. Designates 46 specific AI systems as high-risk; new deployments require pre-deployment conformity assessment from Aug 15 2026.

Existing systems have transition period: March 1, 2027 (most sectors) or September 1, 2027 (healthcare, education, banking).

Stated maximum penalty — Enforcement under Vietnam AI Law 134/2025 / Decree 142

Applies 15 Aug 2026 checked 8 Aug 2026 Decision 33/2026/QD-TTg ↗ high confidence

Peru 1

Peru Comprehensive

AI Law 31814 + Reglamento — risk-based regime

Binds Public and private AI developers / deployers. Prohibited / high-risk / acceptable tiers; high-risk AI needs prior evaluation, human oversight and transparency.

Stated maximum penalty — Referral to data-protection / Indecopi

In force · 22 Jan 2026 checked 3 Aug 2026 Ley 31814 + DS 115-2025-PCM ↗ high confidence

United Arab Emirates 1

UAE Binding

DIFC Data Protection Regulation 10

Binds Controllers / operators deploying autonomous or AI systems processing personal data in the DIFC. Binding rules for autonomous / AI systems processing personal data in the DIFC; high-risk needs certification or an Autonomous Systems Officer.

DIFC free-zone scope; enforcement from early 2026. General certification guidance still pending. Proposed amendments to Regulation 10 (plus new Regulation 11 on accreditation) were under 30-day public consultation (Consultation Paper No. 3 of 2026); comment period closed 18 Jul 2026. Final amended regulations pending.

Stated maximum penalty — DIFC data-protection fines

In force · 1 Jan 2026 checked 29 Jul 2026 DIFC Regulation 10 ↗ high confidence

Germany 1

DE Binding

Germany AI Market Surveillance Act (KI-MIG)

Binds AI providers, importers, distributors, and deployers of AI systems operating in Germany under EU AI Act scope (Reg. EU 2024/1689). Designates Bundesnetzagentur (BNetzA) as Germany's lead AI authority; establishes enforcement architecture for EU AI Act in Germany, including AI regulatory sandboxes (KI-Reallabore) and domestic penalty regime.

National implementing law for EU AI Act. EU phased obligations still apply: Art.50 transparency in force Aug 2, 2026; high-risk Annex I AI → Aug 2, 2027; full high-risk Annex III → Dec 2, 2027.

Stated maximum penalty — €35M or 7% global turnover (prohibited AI practices); €15M or 3% (high-risk violations); €50K for domestic procedural violations (KI-MIG §§15–17)

In force · 29 Jul 2026 checked 8 Aug 2026 KI-MIG ↗ high confidence

Questions & answers

From the data

What is a high-risk AI system?

A system whose use could materially affect safety or fundamental rights — for example in employment, credit, essential services, biometrics or critical infrastructure. The EU AI Act lists these uses in Annex III; other regimes use comparable high-risk or high-impact categories with their own lists.

What does a high-risk classification require?

Usually a pre-deployment or conformity assessment, human oversight, risk management, technical documentation and sometimes registration. The precise package depends on the instrument — see each row’s primary source.

When do the EU AI Act’s high-risk rules apply?

The Annex III high-risk obligations were set for 2 August 2026. The Digital Omnibus, adopted by the European Parliament on 16 June 2026, proposes deferring them to 2 December 2027; until the Council adopts it and it is published in the Official Journal, the original date legally stands.

Which jurisdictions does AI Law Radar track for high-risk ai systems?

We currently track high-risk ai systems obligations across 9 jurisdictions: European Union, United States, China, South Korea, Brazil, Vietnam, Peru, United Arab Emirates and Germany. Each is dated and linked to its primary source on this page.