COMPLIPATHDOC complipath.io/guides/eu-ai-act-high-risk-deadlineRENDERED 2026-08-23ENGINE 2026-08-09.1CORPUS 2024/1689 + 2026/1744 + Commission guidelines
Guides/Deadlines ·By Yobel Tzegai ·Updated 13 August 2026

Which EU AI Act high-risk obligations apply from 2 December 2027?

Updated 9 August 2026 for Regulation (EU) 2026/1744.

From 2 December 2027, the full high-risk regime applies to Annex III AI systems: classification under Articles 6 and 7, the requirements in Articles 8–15, provider obligations under Article 16 and deployer obligations under Article 26. Article 113, third paragraph, point (c)(i), as amended by Regulation (EU) 2026/1744, sets that date — sixteen months later than the 2 August 2026 originally enacted. This is the gap audit.

Quick answer

What exactly becomes applicable on 2 December 2027?

Article 113, third paragraph, point (c), as amended, lifts Chapter III, Sections 1, 2 and 3 off the Act's general 2 August 2026 date. For Annex III systems that moves classification (Articles 6 and 7), the requirements (Articles 8–15) and the provider and deployer obligations (Articles 16 and 26) to 2 December 2027. Article 6(5), the Commission's guidelines duty, is expressly excepted and stays on the general date. The full EU AI Act timeline has every date.

Article 6(2) provides that "AI systems referred to in Annex III shall be considered to be high-risk". One further deferral: safety components of Annex I regulated products fall under Article 6(1), which applies from 2 August 2028 under Article 113, third paragraph, point (c)(ii) — the medical-device path through Annex I is worked through in is healthcare AI high-risk. Not classified yet? Start with classification first.

Which requirements does your system have to meet?

Article 8 requires compliance with all of the following; in brief:

Who carries which obligation — provider or deployer?

Unsure which role you hold? Read provider vs deployer.

Providers (Article 16) must ensure the system meets Articles 8–15, run an Article 17 quality management system, keep the Article 18 documentation, keep the automatically generated logs "when under their control" (Article 16, points (d) and (e) — the control qualifier attaches to the logs, not to the documentation), complete conformity assessment under Article 43 before market placement, draw up the EU declaration of conformity, affix CE marking and register under Article 49(1).

Deployers (Article 26) must follow the instructions for use, assign human oversight to people with the necessary competence, training and authority, ensure input data is relevant where they control it, monitor operation — suspending use if the system presents a risk — and keep logs under their control for at least six months. Employers must inform workers' representatives and affected workers before workplace use, and Article 26(11) requires telling natural persons subject to Annex III decisions.

Do you need a conformity assessment and registration before the deadline?

Yes — and after the omnibus the two duties sit in different parts of Chapter III. The obligation to have the assessment done is Article 16, point (f), in Section 3, so it moves to 2 December 2027: it requires the conformity assessment "prior to its being placed on the market or put into service". Article 43 (the procedures) and Article 49 (registration in the EU database, with point 2 of Annex III systems registering nationally instead under Article 49(5)) are in Section 5, which point (c) does not defer, so they keep the general 2 August 2026 date. Regulation (EU) 2026/1744 does not say how Section 5 is to operate while the Section 1 classification rules are not yet applicable; that gap is unresolved on the face of the text.

Biometric systems in point 1 of Annex III choose between internal control (Annex VI) and a notified body (Annex VII) where harmonised standards or common specifications were applied; without applying either, Annex VII is mandatory (Article 43(1)). Points 2 to 8 of Annex III — most commercial use cases — follow internal control with no notified body (Article 43(2)). One trap: an Article 6(3) not-high-risk conclusion must itself be documented and registered (Article 49(2)).

The Article 40 harmonised standards were still incomplete at the time of writing — one of the reasons recited for the new dates. That is not a defence once they land, only heavier demonstration work in the meantime.

Is your existing system grandfathered?

Only within narrow limits. Article 111(2), as replaced by Regulation (EU) 2026/1744, applies the Regulation to operators of high-risk AI systems placed on the market or put into service "before the date of application of Chapter III referred to in Article 113" — no longer the fixed 2 August 2026 — "only if, as from that date, those systems are subject to significant changes in their designs". Article 113 now carries two such dates, 2 December 2027 and 2 August 2028, and the amending text does not state which of them governs a given system. The paragraph then adds: "In any case, the providers and deployers of high-risk AI systems intended to be used by public authorities shall take the necessary steps to comply with the requirements and obligations laid down in this Regulation by 2 August 2030."

Grandfathering never covers systems placed on the market from the applicable Chapter III date, significant design changes, or Article 5 — the prohibited practices bind legacy systems too (Article 111(2)). What counts as a "significant change" is examined in legacy AI systems: the grandfathering rules.

What does non-compliance cost?

Breaching Article 16 (providers) or Article 26 (deployers) carries fines of up to €15 million or, for an undertaking, up to 3% of total worldwide annual turnover for the preceding financial year, whichever is higher (Article 99(4)). Supplying incorrect, incomplete or misleading information to authorities carries up to €7.5 million or 1% (Article 99(5)); for SMEs, each fine is capped at the lower of the two (Article 99(6)). No fining track record exists yet — assume exposure, not leniency; the full penalty ladder has every tier.

What this means for you

If you're a provider: Audit in the order an authority asks: (1) a documented classification for every system, including Article 6(3) conclusions and their Article 49(2) registration; (2) Annex IV documentation, current by then; (3) conformity assessment done, declaration of conformity signed, CE marking affixed; (4) Article 49(1) registration; (5) risk management reviews and log retention. Complipath's guided risk classification and register keeps each system's classification, obligations and evidence in one place.

If you're a deployer: Your gaps are organisational: named, trained people assigned to oversight; a monitoring routine tied to the instructions for use; six months of logs you control; workers informed before workplace use; affected persons informed under Article 26(11). None of it is delegable: Article 26 binds you, and Article 99(4) fines you, directly.

Which of your systems carry that date?

Classify your system now — 7 questions on the main line, plus follow-ups where they apply, no account, and the classification runs in your browser: answers stay there unless you choose to keep the result.

FAQ

When does the high-risk deadline bite? 2 December 2027 for Annex III systems and 2 August 2028 for Annex I safety components, under Article 113, third paragraph, point (c), as amended by Regulation (EU) 2026/1744. Both dates are still ahead: the omnibus moved Chapter III, Sections 1 to 3 off the Act's general 2 August 2026 date.

Does the deadline apply to systems already on the market? Only partially. Under Article 111(2), as amended, systems placed on the market or put into service before the date of application of Chapter III referred to in Article 113 are subject to the Regulation only if their designs change significantly from that date. Public-authority high-risk systems must comply by 2 August 2030 regardless.

Do all high-risk AI systems need a notified body? No. Under Article 43(2), systems in points 2 to 8 of Annex III — most commercial use cases, including employment and credit scoring — follow internal control under Annex VI, with no notified body. Point 1 (biometrics) systems need a notified body unless harmonised standards or common specifications were applied (Article 43(1)).

What is the penalty for missing the high-risk obligations? Up to €15 million or 3% of total worldwide annual turnover, whichever is higher, for non-compliance with Article 16 (providers) or Article 26 (deployers), under Article 99(4). For comparison, breaching the Article 5 prohibitions carries up to €35 million or 7% (Article 99(3)).


Sources: Regulation (EU) 2024/1689 (EUR-Lex), Articles 6, 8–16, 26, 43, 49, 99, 111 and 113, as amended by Regulation (EU) 2026/1744 (EUR-Lex) — in particular Article 1, points (39) and (40), which replace Article 111(2) and Article 113, third paragraph, points (a) and (c). The Article 40 harmonised standards and the Article 11(1) simplified documentation form were still pending at the time of writing; the obligations apply on the dates stated regardless.

← All guides
Complipath

Complipath is EU AI Act compliance software for AI-heavy software companies without a compliance team — an AI system register, deterministic risk classification, the obligations that follow, and the evidence behind every decision.

Complipath is built by Yobel Tzegai in Gothenburg, Sweden.

Complipath provides legal information, not legal advice. Every guide cites its source on EUR-Lex — Regulation (EU) 2024/1689, and Regulation (EU) 2026/1744 where that has amended it; where the law is still settling, the guide says so.

We measure page views with Vercel Web Analytics. It uses no third-party cookies. Visitors are identified by a hash derived from the incoming request, which is discarded after 24 hours, and no identifier is stored that could follow a visitor to another site. What is collected: the time of the visit, the URL, the referring page, filtered query parameters, city-level location, operating system, browser and device type.