European Union market surveillance authorities published their first coordinated list of high-risk artificial intelligence use cases on Tuesday, moving the AI Act from abstract obligation lists to named systems that must meet conformity assessments, human oversight rules, and incident logging before year-end.

What made the first cut

The document, circulated by the Commission’s AI Office and signed by regulators in Germany, France, the Netherlands, and Italy, highlights eight deployment patterns rather than individual vendors. Biometric identification at external EU borders, AI-assisted hiring platforms scoring video interviews, creditworthiness models used by non-bank lenders, and safety components in rail signaling software appear on the inaugural register.

Medical device software already regulated under MDR retains parallel AI Act duties where machine learning updates change risk profiles. Municipal “predictive policing” pilots—largely paused after court challenges—are named explicitly so cities cannot relabel them as generic analytics.

Deadlines deployers feel

Organizations operating listed systems must complete fundamental rights impact assessments by January 15, 2027, and maintain technical documentation accessible to regulators within 24 hours of a request. Providers outside Europe that sell into the single market face authorized representative requirements and possible fines up to seven percent of global turnover for the most serious breaches.

Smaller firms hoped micro-enterprise exemptions would shield them; regulators clarified Tuesday that exemptions vanish when a startup’s model feeds a high-risk use case, even if the startup itself never touches end users. That interpretation pushes liability questions up the value chain toward foundation-model hosts.

Human oversight in practice

Article 14 oversight rules require humans to interpret outputs, detect automation bias, and interrupt systems safely. The enforcement note attaches scenario cards: a border officer must be able to override a false biometric match without fighting the UI; a loan officer must document why they rejected an AI recommendation before declining an applicant.

Data protection authorities reminded deployers that GDPR DPIAs may need refreshes when AI Act logs reveal new data categories. The European Data Protection Board promised joint inspections with product safety agencies, reducing the forum-shopping some vendors relied on when privacy and product regulators disagreed.

Foundation models and GPAI

General-purpose AI providers face separate transparency duties, but Tuesday’s list focuses on applications. Still, several bullet points reference “systemic risk” models supplying embeddings to high-risk downstream tools. OpenAI, Mistral, and Google received letters asking whether European customers can export audit trails for embeddings used in hiring and credit cases.

Anthropic told InfoHandle it already ships model cards with eval summaries; the AI Office said those cards must map to specific high-risk annex III categories, not generic safety marketing.

Industry reaction

European banks welcomed clarity on credit scoring, arguing uniform rules beat fragmented national interpretations. Civil society groups said the first list is too narrow, noting absent categories like emotion recognition in schools and generative tutors grading exams without human review.

U.S. multinationals with EU cloud regions rushed legal reviews of whether fine-tuned customer models constitute “placing on the market.” The Commission’s FAQ suggests that hosting weights in Frankfurt for a U.S. parent still triggers duties if EU residents are scored.

Enforcement teeth

Market surveillance units can order withdrawals, mandate retrains, or impose administrative fines without waiting for criminal prosecutions. Tuesday’s release includes template inspection checklists—signals that audits will begin in Q1 2027 rather than after years of guidance drift.

Deployers should expect unannounced requests for training data summaries, bias test results, and shutdown drill logs. The AI Act’s ambition was always procedural rigor; the first high-risk names turn that rigor into calendar entries compliance officers must defend to boards.

Global spillover

UK and Swiss regulators said they would monitor the EU list for harmonization talks, while U.S. agencies cited it in comments on voluntary AI testing regimes. For multinational product teams, the practical effect is a single roadmap: if your feature appears on Tuesday’s register, privacy lawyers and safety engineers now share the same Gantt chart—and missing a milestone is measurable in euros.