Explanations and enforcement
The 2027 and 2028 safeguards
The practical judgement
The 2027 and 2028 rules mainly strengthen the systems surrounding high-risk AI. They impose risk controls, information, oversight and assessment duties on organisations. They do not guarantee that an affected person can demand a different outcome.
Regulation (EU) 2026/1744 entered into force on 27 July 2026 and changed earlier dates. As of 12 September 2026, the enacted dates are 2 December 2027 for Annex III high-risk systems and 2 August 2028 for high-risk AI embedded in Annex I regulated products.1
The following figure adds the deferred safeguards to the 2026 field and shows who bears them.
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 590 440" width="590" height="440" font-family="system-ui, sans-serif" font-size="14">
<title>Deferred high-risk AI safeguards added in 2027 and 2028</title>
<rect x="20" y="18" width="550" height="62" rx="8" fill="none" stroke="currentColor" stroke-width="2"/>
<text x="295" y="44" text-anchor="middle" fill="currentColor" font-size="16">2026: prohibitions, transparency, model duties, complaints</text>
<text x="295" y="67" text-anchor="middle" fill="currentColor" font-size="16">Explanations: practical reach unresolved until 2 December 2027</text>
<line x1="295" y1="80" x2="295" y2="116" stroke="currentColor" stroke-width="2"/>
<polygon points="295,116 288,104 302,104" fill="currentColor"/>
<rect x="20" y="118" width="265" height="224" rx="8" fill="none" stroke="currentColor" stroke-width="2"/>
<text x="152" y="146" text-anchor="middle" fill="currentColor" font-size="16">Annex III from Dec 2027</text>
<text x="42" y="180" fill="currentColor">Provider risk controls</text>
<text x="42" y="212" fill="currentColor">Designed human oversight</text>
<text x="42" y="244" fill="currentColor">Trained deployer oversight</text>
<text x="42" y="268" fill="currentColor">Notice for systems making or</text>
<text x="42" y="290" fill="currentColor">assisting decisions about people</text>
<text x="42" y="318" fill="currentColor">Selected impact assessments</text>
<rect x="305" y="118" width="265" height="224" rx="8" fill="none" stroke="currentColor" stroke-width="2"/>
<text x="437" y="146" text-anchor="middle" fill="currentColor" font-size="16">Annex I from Aug 2028</text>
<text x="327" y="180" fill="currentColor">Provider risk controls</text>
<text x="327" y="212" fill="currentColor">Designed human oversight</text>
<text x="327" y="244" fill="currentColor">Trained deployer oversight</text>
<text x="327" y="276" fill="currentColor">Product-embedded systems</text>
<text x="327" y="308" fill="currentColor">No Article 86 expansion</text>
<line x1="152" y1="342" x2="152" y2="378" stroke="currentColor" stroke-width="2"/>
<line x1="437" y1="342" x2="437" y2="378" stroke="currentColor" stroke-width="2"/>
<line x1="152" y1="378" x2="437" y2="378" stroke="currentColor" stroke-width="2"/>
<line x1="295" y1="378" x2="295" y2="400" stroke="currentColor" stroke-width="2"/>
<polygon points="295,400 288,388 302,388" fill="currentColor"/>
<rect x="90" y="400" width="410" height="34" rx="8" fill="none" stroke="currentColor" stroke-width="2"/>
<text x="295" y="423" text-anchor="middle" fill="currentColor">Operator safeguards, not guaranteed personal reversal</text>
</svg>
Figure: Deferred dates add provider and deployer safeguards, with different effects for Annex III and Annex I systems.
Under Article 16, providers must ensure that high-risk systems meet Articles 8 to 15, covering risk management, data governance, logging, documentation, instructions, oversight, accuracy, robustness and cybersecurity. National market-surveillance authorities or the AI Office within its remit enforce that provider duty from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems.2
Articles 14 and 26 require providers to design effective oversight and deployers to appoint people with suitable competence, training, authority and support. The same authorities enforce those respective duties from 2 December 2027 for Annex III and 2 August 2028 for Annex I.2
For Annex III systems that make or assist decisions about people, Article 26 requires the deployer to tell affected people that the system is being used. National market-surveillance authorities or the AI Office within its remit enforce that deployer duty from 2 December 2027.2 Article 27 also requires public bodies, public-service providers and deployers of specified creditworthiness and life or health insurance systems to assess fundamental-rights effects before deployment. Those authorities enforce the covered deployer’s assessment duty from the same date.2
Article 86 applied from 2 August 2026, but its practical reach remains unresolved until 2 December 2027 because Annex III classification was deferred.4 The deployer bears the explanation duty, enforced by market-surveillance authorities or the AI Office within its remit. It applies only to adverse decisions with legal or similarly significant effects and excludes specified critical-infrastructure systems.2
You need not wait to use the GDPR where personal data support a decision. Its access, rectification, objection, automated-decision, complaint and court routes already apply and can continue alongside applicable AI Act mechanisms.3
Boundary. The 2028 Annex I rules do not expand Article 86, which is confined to Annex III. Article 111 also limits the new regime for unchanged non-public systems already in service: providers and deployers comply only after a significant design change, with the relevant market-surveillance authority or AI Office enforcing from the applicable 2027 or 2028 date. Pre-existing systems intended for public-authority use have a separate 2 August 2030 compliance date under Article 111, enforced by those authorities.2
参考文献
测验
What is the main practical effect of the deferred high-risk safeguards?
- They add organisational controls, notices and human-oversight duties
- They guarantee every affected person a successful personal appeal under these safeguards
- They replace existing GDPR routes for decisions using personal data
The later rules primarily regulate providers and deployers. They strengthen decision systems but do not guarantee reversal or replace the GDPR.
For an unchanged non-public high-risk system already in service, later compliance may depend on ____.
- a significant change to its design
- the number of complaints received
- the location of its programmers
The transition rule does not automatically pull every unchanged legacy private system into the deferred regime on the main application date.
评论
还没有评论,来说第一句吧。