← Blog
Also in:
The AI Act's High-Risk Deadline Moved. Here's What Didn't.
2026-08-11

The AI Act's High-Risk Deadline Moved. Here's What Didn't.

Nine days before the EU AI Act's high-risk obligations were due to bite, the date moved. The Digital Omnibus on AI — Regulation (EU) 2026/1744, in force from 27 July 2026 — pushes the obligations for stand-alone high-risk systems under Annex III from 2 August 2026 to 2 December 2027, and for AI embedded in regulated products under Annex I from 2 August 2027 to 2 August 2028.

Most companies will read that headline, conclude they have sixteen extra months, and stop reading. That conclusion is wrong, and why it is wrong is the whole point of this piece: the obligations that touch the widest range of ordinary businesses were not postponed at all. Several have been in force since February 2025. One started on 2 August 2026 and applies to companies that do not operate a high-risk system and never will.

What moved, and what did not

  • Article 5, prohibited practices — in force since 2 February 2025. Not moved, and now wider.
  • Article 4, AI literacy of staff — in force since 2 February 2025. Not moved; substance softened.
  • Articles 51-56, general-purpose AI models — in force since 2 August 2025. Not moved.
  • Article 50, transparency toward people — applies from 2 August 2026. Not moved. Live now.
  • Article 6(2) and Annex III, stand-alone high-risk systems — moved to 2 December 2027.
  • Article 6(1) and Annex I, high-risk AI inside regulated products — moved to 2 August 2028.

Read that list by what its items have in common, not one by one. Everything postponed concerns the classification of a system as high-risk. Everything else is live, and none of it depends on whether your system is high-risk.

Why the delay happened, and what it means for planning

The postponement was not a change of policy about whether high-risk AI should be regulated. It was an admission of an infrastructure problem: the harmonised technical standards that tell a provider how to comply were unfinished, notified bodies were not ready in sufficient number, and guidance had not arrived. Regulating against a standard that does not yet exist produces paperwork, not safety.

The planning consequence is precise. This is a deferral of an enforcement date, not a signal that the requirements will be softer when they arrive. A company that spends the sixteen months treating it as a reprieve will be in exactly the position on 1 December 2027 that it was in on 1 August 2026 — except with a documented sixteen-month record of having known and done nothing, which is a materially worse place to be when a regulator asks.

Article 50 is the one that will catch people

It started on 2 August 2026 and it is easy to miss precisely because it has nothing to do with high-risk classification. In plain terms: a person interacting with an AI system must be told so, unless that is obvious to a reasonably observant person; synthetic audio, image, video and text must be marked machine-readably as artificially generated or manipulated; people subject to emotion recognition or biometric categorisation must be informed; and deepfakes must be disclosed, as must AI-generated text published to inform the public on matters of public interest unless it went through human editorial review with someone holding editorial responsibility.

A four-month grace period runs to 2 December 2026 for marking synthetic content produced by systems already on the market before August 2026.

If you run a customer-facing chatbot, generate marketing copy or images with AI, or let AI draft anything published in your company's name, this applies to you today — whether or not you think of yourself as an AI company.

If you use AI in hiring

The most common high-risk exposure in an ordinary company is recruitment. AI used to place targeted job advertisements, to analyse and filter applications, or to evaluate candidates falls under Annex III, point 4(a). Point 4(b) covers promotion, termination, task allocation and performance monitoring.

If you bought the tool, you are almost certainly a deployer rather than a provider. The heavy obligations — risk management, data governance, technical documentation, logging, accuracy and robustness under Articles 8 to 15 — are the vendor's. Yours are in Article 26: use the system according to the instructions; assign human oversight to people with the competence, training and authority to actually exercise it; keep the input data you control relevant and representative; monitor operation and suspend use if the system presents a risk; retain logs under your control for at least six months; inform workers and their representatives before putting the system into service; and tell affected individuals when a decision about them was made with it.

Two things deserve emphasis. First, the duty to inform workers moves to December 2027 as an AI Act obligation — but in most member states the same disclosure is already required by national labour law and works-council rules that predate the AI Act entirely, and those did not move. Second, Article 6(3) is not an escape hatch you can use silently: an Annex III system escapes high-risk classification only if it performs a narrow procedural task and does not pose a significant risk to health, safety or fundamental rights, and that assessment must be documented before the system goes into use. Deciding it was not high-risk, without writing down why, is not a derogation — it is an unsupported assertion.

What to do in the next ninety days

  • Write down every place AI touches your business — which tool, who uses it, on whose data, producing what, seen by whom. Most companies find two or three systems nobody had counted, usually in marketing and recruitment. You cannot assess exposure you have not enumerated.
  • Fix Article 50 now. It is live, it is cheap, and it is the one obligation an outsider can check without entering your company: disclosure on the chatbot, marking on synthetic media, disclosure on AI-drafted published text.
  • Classify each system honestly. Where you rely on Article 6(3), write the reasoning down now, while it is fresh, not in 2027 when someone asks for it.
  • For anything in Annex III, request the provider's documentation today — not because you need it in 2027, but because you need to know now whether your vendor can supply it at all. Switching vendors takes longer than filing paperwork.
  • Give the people who operate these systems an hour of real training and keep the record. That is Article 4, and it is the cheapest line on this list.

The honest caveats

This is not legal advice and it is not a substitute for counsel who knows your business and your member state. It is a map of what changed and what did not, with the article numbers, so the conversation with your lawyer starts from the right place instead of from a headline.

And one caveat about our own sourcing, because we hold ourselves to the standard this piece recommends: the substantive dates above are confirmed by multiple independent legal sources. The amending regulation's number and its Official Journal publication date are as reported by those sources; we were not able to retrieve the Official Journal record directly at the time of writing. Verify the citation against the Official Journal before relying on it in a filing. The AI Act itself is Regulation (EU) 2024/1689.

We do this kind of assessment as a fixed-price task — the obligation matrix filled in against your actual systems rather than the general case, priced before it starts. But you do not need us for the first item on the ninety-day list, and that is the one that matters most.

Have a task like this in mind?

Try the free estimate on the homepage — no account needed.

Get a price in seconds →