EU AI Act High-Risk Deadline: What Applies Now
The EU AI Act high-risk deadline was meant to hit on 2 August 2026 and moved to December 2027. What still applies today, what shifted, and what to do next.
Today, 2 August 2026, was supposed to be the day the EU AI Act's high-risk rules took effect. It is not. A simplification package finalised earlier this year pushed standalone high-risk obligations to 2 December 2027 and product-embedded ones to 2 August 2028. Plenty of other obligations did land today, though, and the gap between "the deadline moved" and "nothing applies" is where companies get into trouble.
Here is what is actually live, what moved, and what the new dates mean if you are building with AI in or into Europe.
What moved, and to when
The delay came through the digital omnibus package, which the European Parliament and Council finalised after months of negotiation. Both Pinsent Masons and Gibson Dunn set out the same two new dates.
Category | Original date | New date |
|---|---|---|
Annex III standalone high-risk systems | 2 August 2026 | 2 December 2027 |
Annex I high-risk AI embedded in regulated products | 2 August 2027 | 2 August 2028 |
Annex III is the list most software companies would land on if they landed anywhere: recruitment and worker management, credit scoring and access to essential services, education, law enforcement, migration, and biometric categorisation. Annex I is AI inside products already covered by EU product safety law, such as medical devices, machinery, and vehicles.
That is a sixteen-month reprieve on the standalone list and twelve months on the embedded one.
What did not move
This is the part worth reading twice. Four things went live today or are already live.
Article 50 transparency. Unchanged and enforceable. If a person is interacting with an AI system, they have to be told. AI-generated or manipulated content has to be marked in a machine-readable way and be detectable as artificial. Deepfakes require disclosure. We went through the detail in the EU AI Act transparency rules post, and it is by far the most likely part of the Act to touch an ordinary software product.
General-purpose AI model obligations. The GPAI regime and the enforcement powers attached to it proceed on the original schedule. This is aimed at model providers rather than people building on top of models, but it shapes what your vendors can offer you.
The prohibitions. Article 5's banned practices have been enforceable since February 2025 and were extended, not delayed. The omnibus added a new prohibition on AI systems generating non-consensual intimate imagery or child sexual abuse material absent adequate safeguards, with a transitional period running to 2 December 2026.
AI Office operations. The institutional machinery for supervision is running.
The four-month watermarking grace period
One detail buried in the omnibus is genuinely useful and almost nobody has flagged it: AI systems already placed on the market before 2 August 2026 get until 2 December 2026 to implement machine-readable markers on generated content, per Gibson Dunn's analysis of the final text.
If you shipped a generative feature before today, you have four months rather than zero. If you ship one tomorrow, you do not. That is a meaningful difference for a small team, and it changes the sequencing of a compliance backlog.
Vendors are already moving on this. OpenAI began embedding SynthID watermarks in its GPT-Live voice output on 31 July, one day before today's deadline, and shipped a verification API alongside it. Using a vendor that watermarks by default removes part of the machine-readable marking obligation from your own build list, though not the disclosure obligation, which is a product decision.
What the delay is actually for
Two readings, and both are partly true.
The official case is readiness. Harmonised standards, the technical specifications that turn "risk management system" into something an engineer can implement against, were not finished. Asking companies to certify against standards that do not exist is not a compliance regime, it is a lottery. The delay buys time for the standards bodies.
The unofficial case is competitiveness pressure. European industry argued loudly that the original timeline put EU-based AI companies at a disadvantage, and the simplification agenda that produced the omnibus is explicitly about reducing regulatory load. Read the deferral as the compromise it is.
What the delay is not: a signal that the high-risk regime will be watered down or quietly dropped. The obligations are unchanged in substance. Only the clock moved.
What to do with the extra sixteen months
If you might be in Annex III, the honest answer is that the work is the same and you now have time to do it properly rather than in a panic.
Settle whether you are actually high-risk. Most software is not. The Annex III categories are narrower than the anxiety around them suggests, and there are carve-outs for systems that perform a narrow procedural task or improve the result of a previously completed human activity. This determination is worth doing once, in writing, with a lawyer.
Sort out your role. Provider and deployer carry different obligations, and integrating a third-party model into your own branded product can make you a provider even when you did not train anything.
Do the transparency work now, not in 2027. It is live today, it applies far more widely than the high-risk regime, and it is cheap to build if you do it while designing rather than retrofitting.
Keep a paper trail from the start. Technical documentation, data governance records, and logs are dramatically cheaper to accumulate as you go than to reconstruct eighteen months later.
Watch the standards. The harmonised standards are the practical spec. When they publish, the vague requirements become concrete, and that is the moment to plan the real work.
For anyone whose product touches user data, the neighbouring question of how safe it is to give AI access to your data is worth working through in the same sitting, since the answers feed the same documentation.
Frequently asked questions
Does the EU AI Act apply to me if I am not in the EU?
It can. The Act reaches providers placing AI systems on the EU market and, in some cases, providers outside the EU whose system output is used in the EU. Being incorporated elsewhere is not by itself an exemption.
Is my app high-risk just because it uses AI?
No. High-risk is defined by use case, not by the technology. An AI system is high-risk if it falls in an Annex III category or is a safety component of a product covered by Annex I legislation. Most business software, content tools, and app builders are outside both lists.
What happens if I miss an obligation that is already live?
Penalties under the Act are tiered, with the heaviest reserved for prohibited practices and lower bands for other breaches, and enforcement runs through national market surveillance authorities. Article 50 transparency breaches sit in the lower bands but are also the easiest for anyone to spot from the outside.
Did the transparency deadline move too?
No. Article 50 applies from 2 August 2026 as originally scheduled. The only related relief is a four-month window, to 2 December 2026, for systems already on the market to implement machine-readable content marking.
Will the December 2027 date move again?
Nobody can promise it will not, but treating a deferral as a pattern is a bad bet. The substance of the obligations did not change, and the delay was tied to standards that are being actively developed.
Other jurisdictions are taking different, less transparent approaches to the same problem. See the White House AI framework for a comparison point.
Related: keeping an audit trail of AI use
How did this land?
About the author

Senior Editor, AI & Product
Cecilia leads the Swarmz editorial desk. She has spent a decade turning complex AI and product topics into writing people actually finish, and she owns the blog's quality bar.


