欧盟《人工智能法案》到底说了什么?The EU AI Act, Minus the Legalese
全球第一部综合性 AI 法律已经生效。它如何按风险给系统分级、把少数危险用途彻底禁掉,以及这一切在 2026 年对你的权利意味着什么,下文一次说清。
The first comprehensive AI statute anywhere is now in force. Here is how it grades systems by risk, outlaws a small set of dangerous uses altogether, and what any of that changes for your rights in 2026.
多数人已经知道欧盟通过了这部覆盖广泛的 AI 法律,但一份 400 多页的文件显然不适合随手翻阅。这些问题在现实中的一面,我们在 普通用户会遇到的 AI 风险 那篇里谈过;本文讲的是另一半——立法者如何回应同样的问题,并把它变成有约束力的规则。
抛开术语,背后的逻辑其实很朴素:按系统可能造成的危害给它定级,规则随等级加码。风险越高,绳子越短。下面看它在现实中如何落地,以及截至 2026 年年中出现了哪些变化。
01四级风险体系怎么运作
整套立法的核心是四级风险框架。监管者不会把所有系统混为一谈,而是先问:这个工具实际在做什么?一旦失效或被滥用,最坏会坏到什么程度?欧盟委员会在 委员会自己写的分级说明 里用通俗语言解释了各级分类。
不可接受风险
高风险
有限风险
最小风险
02哪些 AI 做法被禁止?
对「不可接受风险」这一类,立法者没有设置任何合规条件清单——答案就是不行。落入这一档的系统,不得在欧洲任何地方销售或运行,没有例外。具体条文见法案第 5 条,可在 EUR-Lex,欧盟立法公布平台 上查阅。
- 操纵性 AI:使用下意识暗示或欺骗性手段扭曲人的行为,并造成心理或身体伤害。
- 利用脆弱性:以年龄、残障或经济困境为由锁定特定人群,并对其造成伤害。
- 社会评分:用机器依据毫不相干的个人数据,给某人的「可信度」打分。
- 无差别人脸识别:抓取互联网内容或监控录像,大规模建立人脸识别数据库。
03高风险 AI 要承担哪些义务
医疗器械、招聘筛选、基本公共服务、执法工具:只要系统参与的是切实影响个人命运的决策,就被归为高风险。整部法案真正的分量,主要压在这里。
要让这类系统达标,需要严格的测试、嵌入流程的人工监督,以及监管者真能审计的技术文档。如果你想了解这类安全工作日常怎么做,我们那篇 各家实验室如何让模型变安全 对红队测试和对齐测试有更深入的介绍。
有一点值得注意:时间表改了。欧盟委员会关于如何界定高风险系统的指引原定 2026 年 2 月出台,但直到 2026 年 5 月才以草案形式露面,随后一份「Digital Omnibus on AI」方案又调整了时间安排。按更新后的时间线,独立式高风险 AI 系统的义务从 2027 年 12 月 2 日起适用,而不是 2026 年,好让监管机构与标准组织有时间跟上。完整细节见 欧盟官方监管框架页面。
04披露义务与通用 AI
在「有限风险」这一档,一条原则做了大部分工作:你有权知道对面是机器。在和客服机器人对话?它必须表明自己是 AI,这样你才能判断该对它说的话信几分。
「通用 AI」另有一套规则手册,指的就是支撑当下多数聊天机器人的大语言模型。开发者必须公开描述训练所用数据的概要,并对 AI 生成的内容(包括深度伪造)作出清晰标注。
05罚款与执行
这些罚则里的数字不是摆设。定得这么高,就是要让不合规比合规更贵。
| 违规类型 | 最高罚款 | 或者按营业额比例 |
|---|---|---|
| 被禁止的 AI 做法 | 3500 万欧元 | 全球营业额的 7% |
| 高风险义务不合规 | 1500 万欧元 | 全球营业额的 3% |
| 向监管机构提供虚假信息 | 750 万欧元 | 全球营业额的 1% |
适用规则很简单:两个数字里取更高的那个——固定金额或营业额比例。想了解执行层面的具体机制,可看 artificialintelligenceact.eu 提供的高层摘要,这是由 AI 法案研究者持续更新的独立法律参考资料。
06读者最常问的问题
用最通俗的话说,欧盟 AI 法案是什么?
这部法案从什么时候开始适用?
欧盟以外的公司也受它约束吗?
法案禁止哪些 AI 做法?
违规罚款有多高?
Most people know by now that the EU enacted a wide-ranging law on AI, though a document running beyond 400 pages is hardly a casual read. The practical dimension of those issues was the subject of our piece on the AI risks ordinary users face; this article is the other half — the same problems addressed by legislators, and turned into binding rules.
Behind the terminology, the underlying logic is plain. Systems are graded according to the harm they are capable of, and the obligations attached to them scale with that grade. The greater the risk, the shorter the rope. Below is how that plays out on the ground, plus the changes that landed by mid-2026.
01How the Four Risk Tiers Work
A four-tier framework sits at the centre of the legislation. Regulators do not lump every system together; they ask what a given tool actually does, and how badly things could go if it fails or is abused. The Commission sets out its own plain-English account of the tiers on the Commission's own guide to the tiers.
Unacceptable Risk
High Risk
Limited Risk
Minimal Risk
02Which Uses Are Outlawed?
For systems in the "unacceptable risk" bracket, no checklist of conditions was written — the answer is simply no. Anything falling here may not be sold or operated anywhere in Europe, without exception. The statutory language sits in Article 5, available on EUR-Lex, where EU legislation is published.
- Manipulative AI: subliminal or deceptive tactics deployed to twist someone's behaviour in a way that produces psychological or physical harm.
- Exploiting vulnerabilities: targeting people on grounds of age, disability or financial hardship in order to do them harm.
- Social scoring: official assessment of a person's "trustworthiness" by machine, drawing on personal data that has nothing to do with it.
- Untargeted facial recognition: harvesting the web or CCTV recordings to assemble facial recognition databases at scale.
03The Obligations Attached to High-Risk AI
Medical devices, hiring screens, essential public services, policing tools: wherever a system feeds into decisions that materially shape someone's life, it is classed high-risk. And that is where the bulk of the legislation's force is concentrated.
Compliance for such a system means demanding testing, human oversight embedded in the process, and technical documentation that a regulator can genuinely audit. If you want to know how safety work of this kind is done day to day, our article on how labs go about making their models safe goes deeper into red-teaming and alignment testing.
One development worth noting: the schedule moved. Guidance from the European Commission on classifying high-risk systems had been expected by February 2026, but only appeared in draft form in May 2026, and a subsequent "Digital Omnibus on AI" package redrew the timetable once more. On the revised dates, duties for stand-alone high-risk AI systems begin on December 2, 2027 instead of 2026, giving regulators and standards bodies room to catch up. The official EU regulatory framework page carries the full detail.
04Disclosure Duties and General-Purpose AI
Under the "limited risk" heading, a single principle does most of the work: you are entitled to know a machine is on the other side. Chatting with a support bot? It must identify itself as AI, which lets you judge how far to trust what it says.
"General purpose AI" gets its own rulebook — the category covering the large language models that power most current chatbots. Developers must publish summaries describing the data used in training, and must label AI-generated output clearly, deepfakes included.
05Penalties and How They're Enforced
The numbers attached to these penalties are not decorative. They are pitched so that non-compliance ends up dearer than compliance.
| Type of Breach | Top Penalty | Or, as a Share of Turnover |
|---|---|---|
| Practices that are banned | €35 Million | 7% of global turnover |
| Failing high-risk duties | €15 Million | 3% of global turnover |
| Giving regulators false information | €7.5 Million | 1% of global turnover |
The rule is simple: the larger of the two figures — the fixed sum or the percentage — is what must be paid. For how enforcement works in practice, see the high-level summary at artificialintelligenceact.eu, an independent legal reference kept up to date by AI Act researchers.