EU AI法の2026年8月2日適用開始とは
EU AI法とは、EUが2024年8月1日に発効させたAI規制の包括法です。リスクの大きさに応じて4段階に分類し、段階ごとに違う義務を課します。2026年8月2日はこの法律が「原則として適用される日」として、当初から定められていた期日です。ただし欧州委員会自身が「例外つきで」と書いているとおり、この日に全部が始まるわけではありません。
適用開始の直前に前提が動いた点にも注意が要ります。AI法を簡素化する「AIオムニバス」規則が適用開始のわずか6日前、2026年7月27日に発効し、期日の一部を書き換えました。
EU AI法の適用スケジュール(欧州委員会の公表による)
| 時期 | 何が適用されるか | 状態 |
|---|---|---|
| 2024年8月1日 | 法律そのものが発効 | 適用済み |
| 2025年2月2日 | 禁止事項1〜8・AIリテラシー義務(AIを扱う従業員に十分な知識を持たせる義務) | 適用済み |
| 2025年8月2日 | ガバナンス規定・GPAIモデルへの義務 | 適用済み |
| 2026年8月2日 | 原則的な適用開始(透明性義務・GPAIへの執行) | 適用開始 |
| 2026年12月 | 禁止事項9(性的ディープフェイク・児童性的虐待コンテンツ〈CSAM〉の生成) | これから |
| 2027年12月2日 | 高リスクAI(付属書III・単独利用) | 延期後の期日 |
| 2028年8月2日 | 高リスクAI(付属書I・製品組み込み) | 延期後の期日 |
The AI Act defines 4 levels of risk for AI systems / The AI Act entered into force on 1 August 2024, and becomes on 2 August 2026, with some exceptions / prohibited AI practices and AI literacy obligations entered into application from 2 February 2025 / the governance rules and the obligations for GPAI models became applicable on 2 August 2025 / the rules for high-risk AI systems embedded into regulated products (Annex I) have an extended transition period until 2 August 2028 and the rules for high-risk use cases in certain sensitive areas (Annex III) have been extended to 2 December 2027 / Prohibition 9 comes into effect in December 2026 and was introduced as a part of the AI Omnibus package. / This legislative proposal (dubbed as the 'AI Omnibus') was adopted on 19 November 2025, a political agreement was reached on 7 May 2026 and entered into force on 27 July 2026. — リスク4段階の分類、発効日と2026年8月2日の適用開始(例外つき)、2025年の2つの適用開始日、高リスクと禁止事項9の延期先、およびAIオムニバスの発効日に関する記述より(原文の `becomes on` は出典サイトの表記のまま)
2026年8月2日から始まること
この日を境に実際に動き出すのは大きく2つです。1つは第50条の透明性義務で、AIと対話していることの告知や、生成コンテンツへの印付けが求められます。もう1つは執行体制です。欧州委員会のAI Office(AIオフィス)と加盟国当局が、AI法の実施・監督・執行を担う立場に正式に就きました。
ここが実務上いちばん重要な変化です。GPAIモデルへの義務そのものは2025年8月2日から存在していましたが、義務があることと、当局が実際に罰を科せることは別物でした。8月2日からはAI Officeが技術文書の提出を求め、モデルを評価し、是正を命じ、制裁金を科せます。「ルールはあるが執行されない」期間が、ここで終わりました。
From 2 August 2026, the AI Office and authorities of the Member States are responsible for implementing, supervising and enforcing the AI Act. The AI Office holds enforcement powers over GPAI models. It can request technical documentation, evaluate models, require corrective measures and issue fines for non-compliance. / The transparency rules of the AI Act will come into effect in August 2026. — ガバナンス・執行および透明性規定の適用時期に関する記述より
2026年8月2日には始まらないこと
逆にこの日から始まらないものを押さえておくと、過剰な身構えを避けられます。採用・与信・教育・重要インフラなど、生活に重い影響を与える用途の「高リスクAI」の義務は8月2日には始まりません。単独で使う高リスクAI(付属書III)は2027年12月2日、製品に組み込まれる高リスクAI(付属書I)は2028年8月2日へ延期されました。
延期の理由は、規格などの支援ツールが企業側に行き渡ってから適用するため、と説明されています。義務の中身が消えたわけではありません。動いたのは開始日だけです。延期の経緯そのものはEU AI法オムニバスの解説記事で詳しく扱っています。
9番目の禁止事項(同意のない性的画像やCSAMを生成するAI、いわゆる「ヌード化アプリ」)も8月2日ではなく2026年12月からです。禁止事項1〜8のほうは、2025年2月からすでに効いています。
the rules for high-risk AI systems embedded into regulated products (Annex I) have an extended transition period until 2 August 2028 and the rules for high-risk use cases in certain sensitive areas (Annex III) have been extended to 2 December 2027 as a result of the political agreement on the proposal to simplify the AI Act – 'AI Omnibus' / Prohibition 9 comes into effect in December 2026 and was introduced as a part of the AI Omnibus package. / AI systems that generate non-consensual sexually explicit and intimate content or child sexual abuse (CSAM) material, such as AI 'nudification' apps — 高リスクの適用スケジュール、および禁止事項9の中身と施行時期に関する記述より
8月2日から始まる透明性義務の中身
透明性義務は高リスクAIのような重装備の要求ではありません。「これはAIです」と相手に分かるようにする、それだけです。ただし対象は広く、AIを使ってサービスを提供している事業者の多くが該当します。義務は提供者(作る側)と利用者(使う側)に分かれて課されます。
第50条の透明性義務(誰に何が課されるか)
Deployers of an emotion recognition system or a biometric categorisation system shall inform the natural persons exposed thereto of the operation of the system, and shall process the personal data in accordance with Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable. — 感情認識・生体分類システムの利用者が、対象者へ作動を知らせる義務に関する規定より
チャットボットは「AIだと分かる」設計にする
第50条1項は人と直接やり取りするAIシステムについて、相手がAIと対話していると知らされるように設計・開発することを提供者へ求めます。例外は2つあります。1つは「合理的に事情を知り、注意深く、思慮のある人から見て明らかな場合」。もう1つは犯罪の探知・防止・捜査・訴追のために法律で認められたAIシステムで、第三者の権利と自由への適切な保護措置があることが前提です(ただし一般市民が犯罪を通報するために使えるシステムは除かれます)。後者は捜査機関向けの規定なので、一般の事業者に関係するのは前者だけです。自社サイトのAIチャット窓口は、その例外に頼らず明示しておくほうが無難です。
告知のタイミングも決まっています。1項から4項までの情報は、遅くとも最初のやり取りや接触の時点までに、明確で識別しやすい形で伝えなければなりません。会話の途中や利用規約の奥ではなく、入口で示せ、ということです。
Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use. This obligation shall not apply to AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences, subject to appropriate safeguards for the rights and freedoms of third parties, unless those systems are available for the public to report a criminal offence. / The information referred to in paragraphs 1 to 4 shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure. — 第50条1項(2つの例外を含む)および5項より
生成コンテンツには機械可読の印を付ける
2項は合成音声・画像・動画・テキストを生成するAIの提供者に対し、出力へ機械可読の形式で印を付け、人工的に生成・加工されたものだと検知できるようにすることを求めます。汎用AIシステムも対象に含まれると明記されました。人の目に見える「AI生成」表示ではなく、機械が読める形での埋め込みを求めている点が実装上のポイントです。
4項は使う側の義務です。ディープフェイクにあたる画像・音声・動画を生成または加工した利用者は、それが人工的に作られたものだと開示しなければなりません。作る側は印を付け、使う側は開示する。二段構えです。
なお欧州委員会はこの義務への対応を助けるため、AI生成コンテンツの表示・ラベル付けに関する行動規範(Code of Practice)と透明性ガイドラインを整備しています。このうち行動規範は、生成AIの提供者・利用者が透明性義務を満たすのを導く任意のツールと位置づけられています。強制ではありませんが、実務の当てにはなります。
Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated. / Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulated. — 第50条2項および4項より
The code will be a voluntary tool to guide providers and deployers of generative AI systems to comply with transparency obligations. — 行動規範の位置づけに関する記述より
行動規範もガイドラインも英語で、分量があります。条文の該当箇所だけを正確に拾うなら、WebページをMarkdownに変換してから読むほうが速く進みます。
GPAIモデルへの執行と制裁金の水準
もう一方の柱が汎用AIモデル(GPAI)に対する執行です。GPAIとは幅広い用途に使える基盤的なモデルを指し、EU域内の多くのAIシステムの土台になっています。この分野の監督権限は加盟国ではなく、欧州委員会のAI Officeに集約されました。AIオムニバスでもAI Officeの権限強化と監督の一元化が明記され、加盟国ごとにばらつく事態を避ける設計が採られています。
Reinforce the AI Office’s powers and centralise oversight of AI systems built on general-purpose AI models, reducing governance fragmentation — AIオムニバスによるAI Officeの権限強化と監督一元化に関する記述より
制裁金は1,500万ユーロか全世界売上高3%の高い方
GPAIモデルの提供者に対する制裁金は第101条にあります。上限は前会計年度の全世界年間売上高の3%か1,500万ユーロのいずれか高い方です。科すのは欧州委員会で、対象になるのは故意または過失による違反のほか、要求された文書・情報の不提出や誤解を招く情報の提供、委員会が求めた措置への不応、評価のためのモデルへのアクセス拒否などです。
手続き上の保護もあります。委員会は制裁金を科す前に暫定的な認定内容を提供者へ伝え、反論の機会を与えなければなりません。決定はEU司法裁判所が無制限の管轄権をもって審査・変更できます。「いきなり満額の罰金」ではなく、やり取りを経たうえでの制裁という組み立てです。
The Commission may impose on providers of general-purpose AI models fines not exceeding 3 % of their annual total worldwide turnover in the preceding financial year or EUR 15 000 000, whichever is higher. / when the Commission finds that the provider intentionally or negligently: / (a) infringed the relevant provisions of this Regulation; / (b) failed to comply with a request for a document or for information pursuant to Article 91, or supplied incorrect, incomplete or misleading information; / (c) failed to comply with a measure requested under Article 93; / (d) failed to make available to the Commission access to the general-purpose AI model or general-purpose AI model with systemic risk with a view to conducting an evaluation pursuant to Article 92. / Before adopting the decision pursuant to paragraph 1, the Commission shall communicate its preliminary findings to the provider of the general-purpose AI model and give it an opportunity to be heard. / The Court of Justice of the European Union shall have unlimited jurisdiction to review decisions of the Commission fixing a fine under this Article. It may cancel, reduce or increase the fine imposed. — 制裁金の上限と対象行為、事前の意見聴取、EU司法裁判所の審査権限に関する規定より
執行を担うのはAI Officeと加盟国当局
執行の担い手は二層構造です。GPAIモデルについてはAI Officeが直接の執行権限を持ち、それ以外のAIシステムについては加盟国当局が監督します。AI Officeにできることは、技術文書の提出要求、モデルの評価、是正措置の要求、そして制裁金の賦課です。
体制面の整備も進んでいます。欧州委員会は2026年7月にサイバーセキュリティとAIに関する行動計画を公表し、EU域内市場に投入される前のAIモデルを評価する能力を高める公募を行うとしています。この体制の稼働は2027年の見込みです。8月2日は執行の完成形ではなく出発点にすぎません。
The July 2026 action plan on Cybersecurity and AI sets out a coordinated approach to help Member States, businesses and public authorities address cybersecurity and resilience challenges posed by the most advanced AI models. The Commission will launch a call to increase EU evaluation capacity of AI models, before they are placed in the EU market. Expected to be operational by 2027, this will strengthen third-party assessment of AI capabilities and risks and contribute to the regulatory function of the AI Office. — 評価能力の増強に関する記述より
日本の事業者に効く範囲と確認すべきこと
日本国内の事業者にとって最初の分かれ道は「そもそも自社は対象なのか」です。AI法は所在地ではなく出力がどこで使われるかで線を引くため、日本にしか拠点がなくても対象になり得ます。
地域ごとの温度差も押さえておくと判断が楽になります。米国では連邦レベルのAIキルスイッチ法案が提出された段階にとどまり、州法のコロラドAI法は施行前に廃止されました。包括法の全面適用という段階に入っているのは、いま確認できる範囲ではEUが先行しています。ただし他国にも拘束力を持つAI法制はあるため、「EUだけ」と受け取るのは正確ではありません。
「出力がEU域内で使われる」なら適用される
第2条1項は適用範囲を7つに分けて定めており、そのうち(c)が第三国の事業者を捕まえる規定です。第三国に所在する提供者・利用者であっても、そのAIシステムが生み出した出力がEU域内で使われる場合は適用されると明記されています。EU向けにAIモデルを市場に出す提供者は(a)によって、所在地に関係なく対象です。
逆にEU域内の利用者を持たず、出力がEUで使われることもない純粋な国内向けサービスなら、直接の適用はありません。判断の起点は「EUの誰かが自社AIの出力を使っているか」の一点です。
providers placing on the market or putting into service AI systems or placing on the market general-purpose AI models in the Union, irrespective of whether those providers are established or located within the Union or in a third country / providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union — 第2条1項(a)および(c)より
いま確認すべき3点
対象に当たる可能性がある場合、8月2日時点で優先度が高いのは次の3点です。高リスク義務の対応は2027年12月まで猶予があるため、いま急ぐ必要はありません。
- EU域内の利用者に触れるチャットボットがあるか。あるなら、入口で「AIが応対している」と分かる表示になっているかを確認する
- AIで生成したコンテンツをEU向けに配信しているか。しているなら、機械可読の印付けに対応できているかを確認する
- 自社が使っているAIがGPAIに該当するか。該当する場合、提供元が透明性・著作権関連の義務に対応しているかを提供元に確認する
3点目は見落とされがちです。自社がモデルを作っていなくても、提供元の対応状況は自社サービスの継続性に直結します。「提供元任せ」にせず、契約更新のタイミングで確認事項へ加えておくのが実務的です。
欧州委員会のAI法関連ページやガイドラインはいずれも英語で、分量も相当あります。必要な条項だけを拾い読みするなら、WebページをMarkdownに変換してからAIに要約させると、見出しや箇条書きの構造が保たれて精度が上がります。画面のコピー&ペーストではナビゲーションや装飾情報が混ざりやすいため、本文だけを整えてから渡すのが確実です。
まとめ:確かめるのは「出力がEUで使われているか」の一点
2026年8月2日は、EU AI法が「文面上の規制」から「執行される規制」へ移った日です。ただしこの日から重い義務が一斉に降ってくるわけではありません。実際に始まったのは透明性義務と執行体制の2つ。企業に負担の大きい高リスク義務は2027年12月・2028年8月へずれました。日本の事業者がまず確かめるべきは、自社のAIの出力がEU域内で使われているかどうか。まずはこの一点だけです。該当するならチャットボットの告知と生成コンテンツの印付けから手を付ければ十分で、高リスク対応の設計はその先で構いません。条文や欧州委員会の解説を自分で確かめるときは、まずMarkdownに整えてから読むと条番号を落とさずに済みます。



