EU AI Act High-Risk Deadline Moves to December 2027

The EU AI Act high-risk deadline that was due to bite on 2 August 2026 has moved to 2 December 2027 for standalone systems, and to 2 August 2028 for AI built into products already governed by EU product-safety law. The shift came through Regulation (EU) 2026/1744, the Digital Omnibus package amending the AI Act, which entered into force on 27 July 2026.

On this page

What moved, and to when

The Digital Omnibus was tracked through the European Parliament as a simplification measure and published in the Official Journal on 24 July 2026. Its effect on timing is narrow but consequential.

Annex III covers standalone high-risk systems — the categories such as biometrics, critical infrastructure, education, employment, essential services, law enforcement and administration of justice. Compliance for those moves from 2 August 2026 to 2 December 2027. Annex I covers AI embedded in products already regulated under EU product-safety legislation, and that moves to 2 August 2028.

The obligations themselves are unchanged in substance: risk management, data governance, technical documentation, record-keeping, human oversight, accuracy and robustness, cybersecurity, conformity assessment, post-market monitoring and incident reporting. Only the date on which they become enforceable has moved.

What did not move

This is where several summaries have gone wrong. Three tranches stayed on their original schedule.

Article 5 prohibited practices — the outright bans, including certain biometric categorisation and social scoring — have been in force since February 2025. General-purpose AI provider obligations have applied since August 2025. And Article 50 transparency duties, including the labelling of AI-generated content and disclosure when users are interacting with an AI system, took effect on 2 August 2026 as originally written.

So a provider of a large model selling into the EU gained nothing from the omnibus. A provider of, say, a CV-screening tool gained sixteen months.

The AI Office now has teeth

The other thing that happened on 2 August 2026 is that the European AI Office’s supervision and enforcement powers became exercisable. Analyses from firms advising on the file, including Gibson Dunn, set out the scope: the Office can request information from providers, demand access to models, order mitigation measures, and require withdrawal or recall from the EU market.

Those are enforcement powers attached to obligations that are already live, chiefly the general-purpose AI and transparency provisions. The practical exposure for frontier model developers is therefore now, not December 2027.

The reason given

The justification offered for the deferral is capacity rather than policy reversal: harmonised standards under the Act were not finalised, and notified body capacity to run conformity assessments was not in place. Without a standard to build against and an assessor to certify against it, providers could not have demonstrated compliance on the original date.

Critics read the same facts differently, as evidence that the Act’s conformity architecture was over-specified relative to what European standards bodies could deliver. Both readings are consistent with the text; the Commission’s own framing is the capacity one.

The deferral also lands in a year of hardening technology policy elsewhere. Our coverage of the US chip export bills and of China’s intelligent computing plan to 2030 traces the parallel tracks.

What providers should do with the extra time

The obvious risk of a sixteen-month deferral is that teams stand down. The obligations that arrive in December 2027 are documentation-heavy and retrospective — technical files, data governance records and post-market monitoring plans are easier to build while a system is being developed than to reconstruct afterwards.

Two near-term items remain unavoidable. Transparency labelling is live now for anyone shipping generative output into the EU. And for organisations that also build or deploy general-purpose models, the AI Office’s information-gathering powers are exercisable today. Our report on Microsoft’s AI code of conduct shows how large vendors are documenting these commitments ahead of formal requirements.

What people are asking about the delay

What is the new EU AI Act high-risk deadline?

Compliance for standalone high-risk systems listed in Annex III now falls due on 2 December 2027, moved from 2 August 2026. AI embedded in products already covered by EU product-safety law has until 2 August 2028.

Which obligations were not delayed?

Article 50 transparency and AI-content labelling duties, the general-purpose AI provider obligations in force since August 2025, and the Article 5 prohibited-practices regime in force since February 2025.

What changed on 2 August 2026?

The AI Office’s supervision and enforcement powers became exercisable, alongside the transparency obligations and the penalty framework for the provisions already in force.

Why did the EU postpone the high-risk rules?

The stated reason is that harmonised standards and notified body capacity were not ready in time for providers to demonstrate conformity.

Where is this written down?

Regulation (EU) 2026/1744, the Digital Omnibus simplification package amending the AI Act, published in the Official Journal on 24 July 2026 and in force from 27 July 2026.

Does the delay apply outside the EU?

The AI Act applies to providers placing systems on the EU market regardless of where they are established, so the revised dates matter to non-EU developers selling into Europe.

Further technology coverage