EU AI Act 高風險期限押後至 2027 年 12 月 — 對採購方有何影響
AI Omnibus 於 2026 年 7 月 27 日生效,將高風險義務押後至 2027 年 12 月 2 日。義務沒有改變,改變的只是日期 — 而 16 個月夠做一次架構變更,並非兩次。
Software Tailor 團隊就受規管 AI 合規、本地部署模式、我們的產品,以及塑造這些產品的行業發展所撰寫的長篇文章。每項主張均註明出處;每篇文章均註明日期,並於相關事實有變動時更新。
AI Omnibus 於 2026 年 7 月 27 日生效,將高風險義務押後至 2027 年 12 月 2 日。義務沒有改變,改變的只是日期 — 而 16 個月夠做一次架構變更,並非兩次。
The sticky routing strategy maps each caller to a preferred worker by an identity hash, so multi-turn chats keep landing on the box where the model is loaded and the prompt cache is hot — a deterministic mapping with no session table to replicate.
Mark a worker canary and give the pool a percentage: that share of callers, assigned consistently by identity hash rather than per-request coin flips, prefer the canary while everyone else stays on stable — and the two groups remain each other's failover.
Per-worker concurrency limits keep each GPU box in its sweet spot. A saturated worker is skipped; a fully saturated pool returns 503 with Retry-After immediately — honest backpressure instead of a silently growing queue that ends in a thrash or an OOM.
A served AI Server deployment's security posture in plain statements: fail-closed serving, keys hashed at rest, two credential tiers in a farm, forwarded pseudonymous identity, fingerprint pinning, and private TLS to workers — the default behavior a security review reads.
Every AI Server hosts a live dashboard and native Prometheus metrics, and its content-free audit attributes each request to app, install, and serving worker — so per-team, per-app chargeback is native data, no metering sidecar required.
A gateway that discovers its workers over mDNS on the local network, so scaling a small site is plugging in a prepared box — it advertises itself, the gateway probes it, and within a health-check cycle it is serving. Static core and dynamic discovery compose.
Serve both generations at once during a migration: modern OpenAI-compatible clients on the governed primary port, and pre-v2 clients on a scoped compatibility listener that carries a compiled sunset date — no flag-day, no broken scripts.
The compliance-hardened deployment: region-aware governance that fails closed where content scanning is mandated, on-device moderation, per-key quotas and budgets, and a content-free, signed audit an external auditor can verify offline, independently.
Upgrade workers and the gateway while traffic keeps flowing. A draining /readyz probe, a configurable drain hold, and gateway failover cover the requests racing the drain — no maintenance window.
Run one AI Server on the office GPU box and serve every workstation on the LAN over an API-key-authenticated endpoint. The model loads once, the data never leaves the building, and there are no per-token bills.
Run AI Server as one container on a cloud VM or any Docker host: configured entirely by environment variables, with /livez and /readyz probes and JSON logs so orchestrators manage it correctly. The image is the artifact; the volume is the state.
Every AI Suite app creates one loopback AI Server on your machine. It binds 127.0.0.1 only, needs no keys or licence, and shares one model in memory across every app on the box — the zero-exposure default worth understanding before anything is networked.
A farm whose workers carry different model sets. The gateway routes each request to a box that already has the model warm, and advertises the union of every worker's models as one catalog — so callers see one model list and placement is the gateway's problem.
One URL and one key in front of a pool of worker AI Servers: health-checked load balancing, transparent failover, model-aware routing, and Kubernetes auto-discovery — with no vendor cloud in the request path.
A ground-up rebuild of the shared engine behind AI Suite: host, download and run the AI models every app uses — one download, one library, one set of keys, used everywhere. Free serves this machine; Pro serves your whole network with governance. Free on Windows from the Microsoft Store.
Every Software Tailor AI app — Chatbot, Translate, Rewrite, Notepad, PDF Reader, Image Generation and more — in one window, with the local AI engine built in. Each app keeps its own model and history; your work stays on your device, saved encrypted. Free on Windows from the Microsoft Store; one Pro subscription unlocks the whole suite.
The full private AI chat for Windows: multi-session chats, folders, a prompt library, conversation branching, document chat and durable memory — all free on a local model that works offline, with encrypted on-device history. Pro adds tool use, Agent mode and larger or cloud models. Your existing chats and prompts upgrade in place. Free from the Microsoft Store.
Type a prompt and an original picture appears on your own PC — a built-in FLUX.2 [klein] model, negative prompts, seeds, batch generation and a private encrypted gallery. Free at 512×512; Pro unlocks larger sizes, custom steps and optional bring-your-own-key cloud. Free on Windows from the Microsoft Store.
A photo assistant that turns a folder of pictures into a searchable collection — AI captions, object detection, OCR, opt-in face grouping and semantic search, all on your device. Organise, annotate and remove backgrounds. Free on Windows from the Microsoft Store.
A ground-up rebuild: pick a model, type, and a local AI model streams the reply back on your own device — with an encrypted local history, find and search, and two simple context controls. Deliberately slim. Free on Windows from the Microsoft Store.
A ground-up rebuild built for reasoning models that think step by step — maths, logic, code — with a collapsible Thinking panel showing the chain-of-thought and a larger reply budget so answers aren't cut off. Free DeepSeek R1 model. Free on Windows from the Microsoft Store.
Type any text and hear it spoken in a natural voice — and clone a voice of your own from a short clip — right on your device. Offline by default, encrypted at rest, with a seekable player and WAV/MP3 export. Free on Windows from the Microsoft Store.
A simple notepad that formats itself as you write — plain text to Word, automatically — with on-device AI writing help, ask-your-document Q&A with citations, ask-across-all-open-documents, annotations and a readable dark editor. Free on Windows from the Microsoft Store.
Turn speech into text on your device — from your microphone, your computer's audio, or an audio file. Export subtitles, replay and re-transcribe recordings, keep an encrypted local history. Free on Windows from the Microsoft Store.
A ground-up rebuild: paste or import text, choose an action, tone and length, and a local AI model rewrites it on your device — with match-my-style, document import and an encrypted local history. Free on Windows from the Microsoft Store.
A ground-up, cross-platform rebuild: open a PDF and ask questions answered on-device, with clickable page-exact citations — in a full reader with annotations and bookmarks that travel in the file. Windows, macOS, Linux, plus a headless CLI/MCP server.
企業 AI 架構於 24 個月內已轉換預設。EU AI Act 部署者義務、NIST AI RMF 對關鍵基礎設施的方向,以及 a16z 的交易週期數據,全部指向同一方向:駐留優先是新的雲端優先。
Software Tailor 在 19 年間交付定制軟件,沒有任何項目失敗。四條工程紀律支撐着這份紀錄。創辦人親述背後的紀律。
OECD AI Policy Observatory 追蹤逾 80 個司法管轄區的 AI 政策。2026 年 6 月的 AI Policy Toolkit、GPAI 與 OECD 的合併,以及 EU AI Act 綜合協議,是企業採購團隊應一併解讀的三個訊號。
AI Admin Console 提供六項能力 —— 成員、授權、AI Server 註冊、政策、審計、按組織用量。每一項都對應採購與合規團隊於 EU AI Act 與 NIST AI RMF 部署者義務之下會提出的特定問題。
AI Suite 的每一項管理動作都會落入一條 JSONL 審計列,包含時間戳、操作者及動作 —— 並且不含任何提示詞或回應內容。內容由部署者保存;我們則保留動作曾經發生的證明。
企業 AI 採購卡關的是部署者義務,而非技術本身。2026 年化解僵局的部署架構特性,以及為何「我們有 SOC 2」並非合規團隊現時所提問題的正確答案。
本法案的高風險部署者義務正於 2026 年逐步生效。本地部署並非規避法規 —— 但會改變哪些義務在實務上可達成,以及哪些是雲端 SaaS 根本無法滿足的。
本地推理、客戶掌控的審計,以及一套早已存在的採購流程。Software Tailor 的 AI 產品之所以是桌面安裝程式而非我們雲端中的一個租戶,有三個結構性原因。
我們每月新增更多文章。完整目錄,包括下一批待撰寫的清單,均於我們的儲存庫追蹤。
如果有任何法規、部署模式或行業議題希望我們撰文探討,請告訴我們。我們每月選一篇新文章。