EU AI Act Article 10 High-Risk AI Data Governance Enforceable from August 2 — GDPR Chapter V Cross-Border AI Data Transfers Now Simultaneously Regulated
The EU AI Act's high-risk AI system obligations — including Article 10 data governance requirements — became enforceable on 2 August 2026, creating a new layer of data-sovereignty obligations that operate simultaneously with existing GDPR Chapter V cross-border transfer requirements. For law firms and their enterprise clients deploying or procuring high-risk AI systems: Article 10 requires documen
BY FRONTIER DESK · AUGUST 6, 2026 · 1 MIN READ
The EU AI Act's high-risk AI system obligations — including Article 10 data governance requirements — became enforceable on 2 August 2026, creating a new layer of data-sovereignty obligations that operate simultaneously with existing GDPR Chapter V cross-border transfer requirements. For law firms and their enterprise clients deploying or procuring high-risk AI systems: Article 10 requires documented data governance practices covering training data collection, bias examination, and data access controls — and this obligation sits with the organisation deploying the system, not the LLM vendor. Organisations using non-EU LLM providers for high-risk applications must satisfy both Article 10 and GDPR Chapter V simultaneously; holding a Standard Contractual Clause does not satisfy Article 10 data governance. A conformity assessment under Article 43 is required before placing a high-risk AI system on the EU market, and Article 10 documentation is a prerequisite for passing it. Fines for high-risk AI violations: up to €15 million or 3% of global annual turnover; fines for prohibited AI practices: up to €35 million or 7% of global annual turnover. The "sovereignty gap" identified by NeuralTrust is operationally significant: where a law firm or legal department uses an AI system that processes EU personal data and routes inference to a non-EU provider, both regimes apply; the vendor's data governance documentation must be independently obtainable and sufficient for the deployer's own compliance record. For law firms advising enterprise clients: Article 10 compliance work is already overdue for clients who have not started. The EU AI Act database registration requirement (Article 71) applies to providers of high-risk systems.