EU AI Act High-Risk Registry Goes Live: Vendors Must Disclose
The European Commission has launched the mandatory EU AI Act high-risk system registry, requiring AI vendors operating in sensitive domains—hiring, credit scoring, law enforcement—to register their systems before the August 2026 deadline. Non-compliant vendors risk losing access to the EU market.
Original sourceThe European Commission has officially opened the EU AI Act high-risk system registry, a centralized database where AI vendors must formally disclose systems deployed in sensitive categories. The registry targets applications in areas including employment screening, creditworthiness assessment, biometric identification, and law enforcement tools. Vendors with existing deployments had until August 2026 to register; new entrants must register before deployment.
The registry is a core enforcement mechanism of the EU AI Act, which passed in 2024. It requires vendors to document intended use, risk mitigation measures, training data provenance, and human oversight procedures. The data will be publicly accessible in part, allowing regulators, researchers, and affected individuals to query which AI systems are operating in which domains across EU member states.
For vendors, the compliance burden is substantial. A registered high-risk system requires ongoing documentation, conformity assessments, and in some cases third-party audits before market entry. Companies that failed to register face fines of up to €15 million or 3% of global annual turnover, whichever is higher. Several large US-based AI vendors have already flagged the registry requirements as a significant operational overhead.
The launch marks the first major enforcement milestone of the EU AI Act and sets a precedent for AI governance frameworks globally. Canada, Brazil, and several Southeast Asian nations have cited the Act as a reference point for their own developing frameworks. Whether the registry produces meaningful accountability or becomes a compliance checkbox exercise will depend heavily on how actively EU national authorities audit and act on disclosed information.
Panel Takes
The Skeptic
Reality Check
“The registry exists, which is more than most AI governance initiatives can claim at this stage—so credit for that. But the real question is whether any national authority has the staff, budget, and mandate to actually audit what vendors self-report, because a database of unverified disclosures is just a compliance theater prop with a government URL. I'll believe this has teeth when the first major vendor faces a fine that wasn't settled for a fraction of the statutory maximum.”
The Founder
Business & Market
“The budget this pulls from is legal and compliance, not product—which means it's a cost center, not a purchasing decision, and every dollar spent here is money not spent on capability. The real market effect is a moat for incumbents: large vendors can absorb the documentation overhead and third-party audit costs; startups trying to sell hiring or credit tools into the EU just got a €500K compliance bill before their first euro of revenue. Watch for a wave of EU-market exits from early-stage US AI companies in the next 18 months.”
The Futurist
Big Picture
“The thesis here is falsifiable: centralized disclosure registries, if enforced, shift AI accountability from post-hoc litigation to pre-deployment governance—meaning the power to block harmful systems moves from courts to regulators before harm occurs. The second-order effect nobody is talking about is that this registry becomes a data asset: a structured, queryable map of which AI systems are making high-stakes decisions about EU citizens, which is exactly the kind of infrastructure that civil society organizations and investigative journalists will weaponize in ways the Commission didn't anticipate. The trend this rides is the Brussels Effect—the documented pattern of EU regulation becoming de facto global standard—and on that trend, this registry is precisely on time.”
The PM
Product Strategy
“The job-to-be-done for regulators is clear: know what AI systems are operating in high-stakes domains before something goes wrong. The registry technically delivers that, but only if the submission interface and data schema are opinionated enough to produce comparable, queryable disclosures rather than a pile of vendor-formatted PDFs that nobody can cross-reference. If the onboarding for vendors ends at 'upload your conformity assessment document,' this tool is complete enough to generate a deadline panic but not complete enough to generate actual accountability.”