NEWVenvera speaks your language: the full platform, in English, German, Spanish and Bulgarian.See what’s new →
EU AI Act High-Risk Deadline: Why 2 August 2026 Moved to 2027
Learn

EU AI Act High-Risk Deadline: Why 2 August 2026 Moved to 2027

·Alexander Sverdlov

If you have the 2 August 2026 EU AI Act high-risk deadline circled on a compliance calendar, move the circle. As of 29 June 2026 the Council of the EU formally adopted the Digital Omnibus on AI, and it postpones the obligations for high-risk AI systems: standalone systems in the Annex III use-cases now apply from 2 December 2027, and high-risk AI embedded in regulated products under Annex I from 2 August 2028. The date that survives on 2 August 2026 is the EU AI Act transparency regime under Article 50, not the full high-risk conformity package.

This guide answers the question people are actually searching: what does 2 August 2026 now bind, where did the high-risk deadline go, and what do providers of high-risk systems still have to build. It walks the amended timeline, the Article 6 line between Annex III and Annex I high-risk, the provider obligations under Articles 8 to 17, and the penalty exposure. First, the facts at a glance.

Governing lawRegulation (EU) 2024/1689 (the EU AI Act), as amended by the Digital Omnibus on AI (the "Omnibus VII" simplification package).
Entered into force1 August 2024.
Already in forceProhibited practices and AI literacy (2 February 2025); general-purpose AI, governance and penalties (2 August 2025).
What binds on 2 August 2026Article 50 transparency obligations (disclose AI interaction, label deepfakes and synthetic content). Machine-readable marking of existing generative output has a grace period to 2 December 2026. High-risk provider duties do not apply on this date.
Standalone high-risk (Annex III)2 December 2027 - postponed from 2 August 2026 by the Digital Omnibus.
Product-embedded high-risk (Annex I)2 August 2028 - postponed from 2 August 2027.
What "high-risk" meansEither an Annex III use-case (Article 6(2)) - credit scoring, insurance, employment, biometrics and more - or a safety component of an Annex I product needing third-party conformity assessment (Article 6(1)).
Maximum penalty (high-risk)Up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher (Article 99).
Editorial illustration for the EU AI Act high-risk compliance deadline and its postponement to December 2027

What changed: the Digital Omnibus postponement

For most of the AI Act's life, 2 August 2026 was the day the high-risk regime went live. That is no longer the operative date. In late 2025 the European Commission proposed a simplification package, the Digital Omnibus on AI, that reworks the high-risk timeline. The European Parliament approved the final text on 16 June 2026 and the Council formally adopted it on 29 June 2026. It enters into force on publication in the Official Journal, expected in July 2026.

The core change is a straight deferral of the high-risk obligations. Standalone high-risk systems - the ones classified through the Annex III use-case list - move from 2 August 2026 to 2 December 2027. High-risk AI embedded in products regulated under existing EU product-safety law (Annex I) moves from 2 August 2027 to 2 August 2028. An earlier draft tied the delay to whether harmonised standards and support tools were ready; the adopted text drops that conditional trigger and sets fixed calendar dates instead, which removes the ambiguity but also removes any argument that the clock restarts if standards slip again.

Two cautions. First, "postponed" is not "cancelled." The substantive obligations in Articles 8 to 17 are unchanged; only their start dates moved. Second, the Omnibus does not touch the parts of the Act already in force, and it explicitly leaves the Article 50 transparency duties on their original schedule. So August 2026 is still a live date, just a much narrower one than the headlines suggested.

The amended EU AI Act timeline

The AI Act was always phased, and the Omnibus stretches the back half. Here is the full sequence as it stands after adoption, with the high-risk dates in their new positions.

Phased application timeline of the EU AI Act from entry into force in 2024 through the postponed high-risk deadlines in 2027 and 2028
1 August 2024Entry into force. No obligations apply yet.
2 February 2025Prohibited practices (Article 5) and AI literacy (Article 4) apply. Already in force.
2 August 2025General-purpose AI obligations, governance, notified bodies, confidentiality and penalties apply. Already in force.
2 August 2026Article 50 transparency obligations apply. Machine-readable marking of existing generative content has a grace period to 2 December 2026. High-risk provider duties do not start here.
2 August 2027Deadline for national authorities to establish AI regulatory sandboxes (postponed from 2 August 2026).
2 December 2027Standalone high-risk systems (Annex III) must comply. Conformity assessment, technical documentation, QMS, human oversight, registration - the full package.
2 August 2028Product-embedded high-risk systems (Annex I) must comply under the Article 6(1) route.

What actually binds on 2 August 2026

If the high-risk regime has moved, what does August 2026 leave on the table? The transparency obligations in Article 50, which were never part of the deferral. These reach far more organisations than the high-risk rules, because they attach to ordinary generative and interactive AI, not just the sensitive use-cases.

From 2 August 2026, providers must ensure that AI systems interacting with people make clear that a person is dealing with an AI, unless it is obvious. Providers of generative systems must mark synthetic audio, image, video and text in a machine-readable way as artificially generated. Deployers of systems that produce deepfakes or that generate or manipulate text published to inform the public on matters of public interest must disclose that the content is artificial. For synthetic content from systems already on the market, the machine-readable marking duty carries a grace period to 2 December 2026.

Everything already switched on stays on. The Article 5 prohibitions have applied since February 2025, and the Omnibus added a new prohibition on AI used to generate non-consensual intimate imagery and child sexual abuse material, with a transitional period to 2 December 2026. General-purpose AI obligations have applied since August 2025. AI literacy duties under Article 4 have been in force since February 2025. None of that pauses because the high-risk date moved.

What "high-risk" means: Annex III versus Annex I

The two high-risk deadlines exist because the Act has two doors into the high-risk category, set out in Article 6. Which door your system comes through decides which deadline you face.

Article 6(2), the Annex III route, catches AI used in a listed set of sensitive use-cases. The list includes remote biometric identification and categorisation, safety components of critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services - which expressly covers creditworthiness and credit scoring, and risk assessment and pricing in life and health insurance - law enforcement, migration and border control, and the administration of justice. These are the standalone high-risk systems, and they now apply from 2 December 2027. A narrow escape hatch in Article 6(3) lets a listed system avoid high-risk status if it performs only a narrow procedural task and poses no significant risk, but any system that profiles individuals is always high-risk.

Article 6(1), the product-safety route, catches AI that is a safety component of, or is itself, a product already regulated under the EU harmonisation legislation listed in Annex I - machinery, medical devices, toys, lifts and the like - where that product must undergo third-party conformity assessment. These embedded systems apply from 2 August 2028. For a financial institution, most exposure is Annex III; for a manufacturer of connected products, it is Annex I. Getting the classification right is the first task, because the deadline and the assessment route both follow from it.

An AI system inventory with EU AI Act risk classification, mapping each system to its Annex III or Annex I route
An AI system inventory with risk classification under the EU AI Act.

Provider obligations for high-risk systems

The extra time is real, but the workload it buys is large, so it is worth being concrete about what a high-risk provider has to have in place by its deadline. Chapter III Section 2 sets the substantive requirements, and Section 3 sets the placing-on-the-market duties.

  • Risk management system (Article 9) - a continuous, documented process running across the whole lifecycle, covering foreseeable misuse.
  • Data and data governance (Article 10) - documented collection, preparation and validation, with bias examination and representativeness checks on training, validation and test data.
  • Technical documentation (Article 11) - the Annex IV file, detailed enough for an authority to assess the system, kept current.
  • Record-keeping (Article 12) - automatic logging of events over the system's lifetime to support traceability.
  • Transparency and information to deployers (Article 13) - instructions that let deployers understand and use the system correctly.
  • Human oversight (Article 14) - measures that let a person understand, override and intervene, which for automated credit decisions means real review and appeal paths.
  • Accuracy, robustness and cybersecurity (Article 15) - consistent performance and resilience against data poisoning, model poisoning and adversarial attacks.
  • Quality management system (Article 17) - an organisation-wide QMS covering the full AI lifecycle.

On top of the requirements come the market-entry duties in Article 16 and beyond: run the conformity assessment for the system's category (Article 43, using internal control under Annex VI or a notified body under Annex VII), draw up the EU declaration of conformity (Article 47), affix the CE marking (Article 48), and register the system in the EU database (Article 49) before it is placed on the market or put into service. A deployer that substantially modifies a high-risk system, or puts its own name on it, is treated as a provider and inherits these duties.

Penalties

Article 99 sets a tiered penalty regime. The delay to 2027 does not soften it; it just pushes back when the high-risk tier can bite.

Prohibited AI practices (Article 5)Up to EUR 35 million or 7% of worldwide annual turnover.
Breaching high-risk provider or deployer obligationsUp to EUR 15 million or 3% of worldwide annual turnover.
Supplying incorrect or misleading informationUp to EUR 7.5 million or 1% of worldwide annual turnover.

In each tier the figure is whichever is higher, and for SMEs and start-ups the cap is whichever of the two is lower. The transparency duties that do land in August 2026 sit in the same enforcement structure, so a generative-AI provider that ignores Article 50 is not waiting until 2027 to be in scope.

Why the extra time is not a reason to stop

An AI credit-scoring model mapped across the EU AI Act, DORA and GDPR, showing overlapping control requirements

For a regulated financial institution, an AI credit-scoring model is not only an AI Act problem. The same model is an ICT asset under DORA, which is already in force and expects it in your register of information with resilience testing and incident reporting. It is an automated decision under GDPR Article 22, needing a data protection impact assessment. It is subject to sector rules on model risk and to national consumer-protection law on automated lending. The AI Act documentation you will build for 2027 overlaps heavily with all of that.

That overlap is the argument for not treating the postponement as a pause. The data-governance evidence, logging, risk assessments and human-oversight controls you stand up now do double duty, and the earlier you map a control once and reuse it, the less you rebuild under deadline pressure later.

Frequently Asked Questions

Is the 2 August 2026 high-risk deadline still real?

No, not for high-risk systems. The Digital Omnibus on AI, formally adopted by the Council on 29 June 2026, postpones standalone high-risk obligations (Annex III) to 2 December 2027 and product-embedded high-risk obligations (Annex I) to 2 August 2028. What remains on 2 August 2026 is the Article 50 transparency regime.

Which high-risk systems face 2027 and which face 2028?

Standalone systems classified through the Annex III use-case list - credit scoring, insurance, employment, biometrics, critical infrastructure and the rest - apply from 2 December 2027. Systems that are a safety component of a product regulated under Annex I product-safety law, classified via Article 6(1), apply from 2 August 2028.

Does anything about AI compliance actually happen in August 2026?

Yes. The Article 50 transparency obligations apply: disclosing that users are interacting with AI, labelling deepfakes, and marking generative output as artificial. Marking of content from systems already on the market has a grace period to 2 December 2026. Prohibitions, AI literacy and general-purpose AI duties are already in force from earlier phases.

Is a bank's AI credit-scoring model high-risk?

Generally yes. Creditworthiness evaluation and credit scoring sit in the Annex III list of essential private services, so such a model is high-risk under Article 6(2) unless the narrow Article 6(3) exemption applies - and it will not apply where the system profiles individuals. That puts it on the 2 December 2027 deadline.

What are the penalties for high-risk non-compliance?

Under Article 99, breaching high-risk provider or deployer obligations can draw up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher. Prohibited practices carry up to EUR 35 million or 7%, and supplying incorrect information up to EUR 7.5 million or 1%.

Getting ready with Venvera

Classification comes first, because the deadline and the conformity route both follow from it. The Venvera EU AI Act module maps the Article 6 tests and the Annex III and Annex I routes into a structured gap assessment, so you can see for each AI system whether it is high-risk, which door it comes through, and which 2027 or 2028 date it faces. Because AI systems in a regulated firm sit under several regimes at once, the crosswalk lets you reuse evidence from DORA, GDPR and NIS2 rather than documenting the same control three times.

If you want a fast read on where you stand against the amended timeline, run a free compliance check and use the classification questions above as your starting point.

Primary sources

This guide is drawn from the regulation and official EU material, cross-checked against legal commentary on the Omnibus amendments: Regulation (EU) 2024/1689 (the AI Act, including Article 6 classification, Articles 8 to 17 requirements, Article 50 transparency, Article 99 penalties and Article 113 application dates); the European Commission's AI Act policy pages; and the AI Act implementation timeline, which reflects the Digital Omnibus postponement of high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). The Omnibus adoption dates (Parliament 16 June 2026, Council 29 June 2026) come from the Council's own announcement of the final green light. Always confirm the current consolidated text before relying on a specific date or figure.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

RELATED POSTS