The EU AI Act: The Growing Gap Between Risk Classification And Risk Perception In EHS Software

Blog
EHS Software & Services
23 Sep, 2026

On August 2, 2026, the EU AI Act reached a major implementation milestone, bringing enforcement powers into effect and moving AI governance firmly into present-day reality. For EHS software providers, much of the discussion around this development has focused on one question: does their AI fall within the Act's high-risk category? It's a critical question, but it may not be the most important one.

The real disruption for the EHS software market could come from a much larger group of AI applications – those that are not formally classified as high-risk, but are close enough to safety, workforce and operational decision-making that customers decide to treat them as if they are. In practice, there is often a significant difference between regulatory risk and buyer perception of risk.

Buyers don't think in regulatory categories

The EU AI Act follows a risk-based approach, with obligations determined by an AI system's intended purpose and use case rather than the software category it sits within. Being embedded within an EHS platform does not automatically make an AI application high-risk. However, EHS buyers rarely evaluate technology through the lens of regulatory classifications alone.

The challenge is that AI is rapidly moving beyond content generation and into operational workflows. Product roadmaps are increasingly focused on AI agents that can interpret incidents, identify likely root causes, prioritize risks, recommend corrective actions, assign tasks and trigger workflow changes. Not all of these capabilities will necessarily fall within the EU AI Act's formal high-risk categories, yet they increasingly influence decisions that affect workers and safety outcomes.

This creates a grey area that is likely to become an important dynamic in the EHS software market. The regulatory distinction between high-risk and limited risk AI may matter less than whether users perceive an AI system as influencing safety-critical decisions.

A new procurement standard is emerging

The industry's response to the AI Act has largely focused on compliance. Vendors are assessing classifications, mapping obligations and building governance processes to meet future requirements. However, buyers are increasingly asking for evidence that goes beyond compliance. They want to understand how models work, what data they rely on, how outputs are validated and where human oversight remains in place. The result is organizations applying high-risk levels of scrutiny to AI systems that are not legally considered high-risk.

This mismatch is particularly relevant in EHS, where the consequences of a poor recommendation can extend far beyond software performance metrics. When AI influences decisions about worker safety, risk prioritization or operational controls, AI trust becomes a board-level issue. The EU AI Act reinforces this by placing responsibilities not only on AI providers, but also on organizations deploying AI systems, with obligations to support AI literacy and maintain appropriate oversight of how AI is used in practice. For EHS leaders, AI governance is therefore becoming a shared responsibility.

For more insights on how AI is changing the EHS software market, read Verdantix Green Quadrant: EHS Software (2026).

Discover more EHS Software & Services content
See More