Nz News Pulse Go
NZ Voice Nz News Pulse Guides
Blog Business Local Politics Tech World

Trade Me Houses for Sale: Fees, Tips & Comparison

James Freddie Howard Bennett • 2026-08-09 • Reviewed by Sofia Lindberg

The EU AI Act is already reshaping how providers must build, test, and deploy systems for European users. High-risk obligations begin binding most systems in August 2026, but prohibited practices are already enforceable as of February 2025.

Quick snapshot

1Regulatory gravity
  • The AI Act classifies systems into unacceptable, high, limited, and minimal risk tiers (EU AI Act Explorer).
  • High-risk systems must pass a conformity assessment and maintain human oversight (European Parliament).
  • Unacceptable risk (e.g., social scoring, real-time biometric surveillance in public) is outright banned (European Commission).
2Timeline pressure
3Global ripple effect
  • U.S. state laws (e.g., Colorado AI Act) and emerging frameworks in Japan, Canada, and Brazil mirror EU risk-tiering (OECD AI Policy Observatory).
  • China’s 2023 generative AI regulation diverges sharply on content control but aligns on transparency (CSET Georgetown).
  • Compliance with the EU Act is a de facto global standard for any non-EU firm serving EU users (Bloomberg).
4Enforcement structure
  • AI Office within the European Commission oversees general-purpose AI (European Commission AI Office).
  • National market surveillance authorities handle local enforcement and fines (EPRS).
  • Fines can reach up to 7% of global annual turnover or €35 million, whichever is higher (Council of the EU).

The core structure: risk-based tiers

The AI Act doesn’t apply a single rule to all systems. It uses a four-tier pyramid: unacceptable risk (banned), high risk (regulated), limited risk (transparency obligations), and minimal risk (no obligations). The burden is intentionally graduated. Systems classified as “unacceptable risk” — including social scoring by governments, real-time remote biometric identification in public spaces for law enforcement, and manipulative AI that exploits vulnerabilities — are simply prohibited from the February 2025 compliance date. There is no grace period for these systems.

“High risk” is where the heavy operational lift sits. This includes AI used in critical infrastructure, education, employment, law enforcement, migration, and access to essential services like credit and insurance. High-risk providers must implement a risk management system, ensure data governance and transparency, enable human oversight, and achieve accuracy and cybersecurity standards. Crucially, these systems require a conformity assessment — often self-declaration unless the system is a biometric or safety component of a regulated product, in which case a notified body must review it. A dedicated “high-risk” list is maintained by the European Commission and will be updated as applications evolve.

The lower-risk tiers impose lighter but real duties. Limited-risk systems (like chatbots or deepfake generators) must comply with transparency obligations: users must know they are interacting with an AI. This includes labeling deepfakes and disclosing that generated content is AI-produced. Minimal-risk systems, such as AI-powered video games or spam filters, face no mandatory requirements under the Act, though providers may voluntarily adopt codes of conduct. The message is clear: the higher the risk to fundamental rights or safety, the higher the compliance cost.

What this means: The risk classification process is the most consequential upfront decision for any provider. Self-classification is the default, but national surveillance authorities can review and reclassify systems. A mistake in classifying a high-risk system as limited risk can lead to fines that are multiples of the cost of upfront compliance. The burden falls hardest on SMEs and startups that lack in-house legal capacity to navigate the tier definitions.

Timeline in motion

The phased implementation means some obligations are already law. The February 2025 deadline for unacceptable-risk prohibitions is already in force. By August 2026, high-risk rules for most AI systems become enforceable, including obligations for providers and deployers to maintain human oversight and transparency.

For high-risk systems that fall within the scope of existing product safety legislation — such as medical devices, aviation, and machinery — an additional year is granted, pushing full compliance to August 2027. General-purpose AI models, including foundation models like GPT-4 and Llama, face a separate regime: providers must be transparent about training data (including a summary of copyrighted content used) and meet cybersecurity standards, with additional obligations for “systemic risk” models (measured by cumulative compute exceeding 10^25 FLOPs).

The clock is tight. Any provider still relying on early 2024’s grace periods should note that the regulatory machinery is already staffed: the EU AI Office is actively engaging with industry, and national authorities are appointing market surveillance bodies. The gap between rule and enforcement is closing.

The trade-off: The phased timeline gives providers time to adapt, but it also creates a multi-speed compliance landscape within the same regulation. Systems that hit the August 2026 deadline first will face a window where some competitors may still be running legacy systems under the older timelines. The strategic play is to front-load risk classification and conformity assessments, regardless of the compliance deadline, because the work required is the same regardless of the date on the calendar.
Confirmed facts

The EU AI Act officially entered into force August 1, 2024, and the February 2, 2025 deadline for prohibited practices has passed. The next major deadline — August 2, 2026 — triggers high-risk rules for most non-embedded systems. Fines scale with global turnover up to 7%, not just EU revenue. The “Brussels effect” is visible: South Korea, Japan, and Brazil are actively modeling risk-tier legislation on the EU structure, according to the OECD AI Policy Observatory.

Global alignment and divergence

The AI Act’s reach extends far beyond the EU’s borders through the “Brussels effect.” Any company that develops or deploys AI for use within the EU — regardless of where the company is headquartered — must comply. This has already reshaped how global firms approach AI governance. The U.S. National Institute of Standards and Technology (NIST) AI Risk Management Framework has been mapped by some firms to the EU’s high-risk requirements, even though it remains voluntary at the federal level.

State-level activity in the U.S. adds a complicating layer. Colorado’s AI Act (SB 24-205), effective 2026, uses a similar risk-tier approach and requires impact assessments for high-risk systems, creating a patchwork of compliance obligations for firms operating across multiple states. Unlike the EU’s single regulatory authority, U.S. firms face fragmentation across state lines. Meanwhile, China’s 2023 AI regulation focuses heavily on content control, data sovereignty, and alignment with socialist core values, diverging sharply on the ground of free expression but converging on transparency and model registration. Japan has taken a soft-law approach, pushing guidelines rather than binding regulation, while Canada’s proposed AIDA (Artificial Intelligence and Data Act) closely follows the EU’s risk-tier model.

The net effect: the EU Act functions as the most comprehensive binding framework globally, and non-EU nations are using it as a reference point. This creates both an opportunity and a risk for multinational providers: aligning with the EU’s standard can streamline compliance in other jurisdictions, but it may also require over-compliance in regions with lighter legal frameworks, increasing operational cost for no local benefit.

The implication: For any AI provider with international users, the EU standard is effectively the baseline. The cost of non-compliance in the EU is existential; the cost of aligning too early with EU standards in jurisdictions that are still debating their rules is a business judgment. The emerging pattern is that EU compliance is becoming a prerequisite for any serious business-to-business AI deployment, regardless of geography.

Enforcement and the stakes

The enforcement structure is a dual-key system. The European Commission’s AI Office handles general-purpose AI and cross-border cases, while national authorities (like Ireland’s DPC or Germany’s BfDI) handle local surveillance. This mirrors the GDPR’s structure but with a key difference: the AI Office has direct enforcement power over foundation models, not just oversight. Fines of up to 7% of global annual turnover or €35 million — whichever is higher — apply to violations of prohibited practices. Non-compliance with high-risk obligations draws up to 3% or €15 million, while incorrect information to regulators attracts 1.5% or €7.5 million.

The comparison with GDPR fines is instructive. GDPR’s maximum is 4% of global turnover, and the average GDPR fine, though growing, remains in the low millions. AI Act fines are structurally higher — up to 7% — and the expectation is that the first high-profile enforcement will be a deterrent case. The European Consumer Organization (BEUC) has already signaled it will file complaints on unfair AI practices, suggesting enforcement will not rely solely on regulator surveillance but will also be driven by civil society and competitor complaints.

Individual rights are also embedded in the Act. Anyone affected by a high-risk AI system has the right to an explanation of the decision, the right to complain to a national authority, and the right to seek judicial redress. This opens the door to litigation beyond regulatory fines, including class actions from consumer groups.

What’s unclear

The definition of “substantial modification” — a change to a high-risk system that triggers a new conformity assessment — remains vague. Guidance from the European Commission’s AI Office is expected but not yet published. Providers face a practical risk: if they continuously update a system via machine learning, each update could technically be a “substantial modification,” requiring a new assessment. The line between routine improvement and substantial change is the single biggest operational ambiguity in the Act. Additionally, the interplay between the AI Act and the GDPR on data processing for AI training — particularly the legal basis for using personal data — remains contested among EU data protection authorities.

What comes next

The AI Act is not a static document. The European Commission is already tasked with producing delegated acts that will refine technical specifications, update the high-risk list, and define the scope of general-purpose AI obligations. Codes of practice for general-purpose AI — including transparency and copyright compliance — are due to be finalized by mid-2025. The first practical stress test will be how the AI Office handles foundation model enforcement, particularly for non-EU developers like OpenAI and Google.

Providers should expect the period between August 2026 and August 2027 to be a litigation-heavy phase as the boundaries of high-risk classification are tested. The real-world political economy of AI regulation will also matter: a future European Commission could tighten or loosen obligations depending on market competitiveness concerns, though the current structure is designed to be difficult to reverse.

The biggest uncertainty is enforcement intensity. The GDPR created a cottage industry of data protection advisors and litigation, but its enforcement has been uneven across member states. The AI Act learns from that experience by centralizing power in the AI Office and standardizing conformity assessments. Whether that actually produces uniform enforcement or creates a new two-tier compliance market — fast-track for funded firms, slow-lane for everyone else — remains to be seen.

Why this matters: The AI Act is the first comprehensive attempt to regulate AI as a product, not just as a data processing activity. It forces providers to bake compliance into the engineering lifecycle. For legal and compliance teams, it creates a permanent new workflow: pre-market risk classification, development documentation, incident reporting, and post-market monitoring. The era of shipping AI with no regulatory oversight is over in the EU, and increasingly, everywhere else.
Bottom line: The EU AI Act is not a distant compliance exercise — it is a live regulatory framework with prohibitions already enforced and high-risk rules coming in 2026. Legal and compliance teams must begin risk classification mapping and conformity assessment documentation now, because reclassification after an audit is exponentially more expensive. Product and engineering leads must incorporate transparency logging and human oversight controls at the architecture level — retrofitting compliance later will delay deployment by months and invite regulator scrutiny. Investors and executives must treat the cost of compliance as a fixed overhead for any AI company targeting the EU market, factor 7% turnover fine risk into any valuation model, and treat the EU as the de facto global standard for AI governance.

James Freddie Howard Bennett

About the author

James Freddie Howard Bennett

Coverage is updated through the day with transparent source checks.