← All articles

EU AI Act High-Risk Deadline Delayed to December 2027

· Updated
EU AI Act high-risk deadline delayed to December 2027 AI-GENERATED IMAGE
EU AI Act high-risk deadline delayed to December 2027

Update — 11 May 2026: The resumed trilogue produced an agreement. The 2 December 2027 deadline for Annex III high-risk obligations described below is now the confirmed outcome of the Omnibus deal, pending formal adoption and publication in the Official Journal. See the follow-up: AI Act Omnibus Agreed: 2 December 2027 Deadline Confirmed.

Update — 6 May 2026: The trilogue on the AI Act Omnibus collapsed on 29 April without an agreement. At time of writing the proposed delay described below was not yet law and the original 2 August 2026 deadline still stood. See: AI Act Omnibus Talks Stalled: The August 2026 Deadline Still Stands.

On 26 March 2026, the European Parliament voted 569–45 to delay the application of high-risk AI system obligations under the EU AI Act. The original deadline of 2 August 2026 has been pushed back, but not for everything, and not by as much as some headlines suggest.

If you’ve been working towards August 2026 compliance, you have more time on the heaviest obligations. But several requirements are already enforceable, and the delay doesn’t change that.

Here’s what actually changed.

The new dates

The Parliament’s vote creates a tiered delay:

High-risk AI systems listed in Annex III, covering biometrics, critical infrastructure, education, employment, essential services, law enforcement, justice, and border management, now have until 2 December 2027.

AI systems regulated under EU sectoral legislation, those embedded in products like medical devices, radio equipment, and toys, have until 2 August 2028.

Marking requirements for AI-generated audio, images, video, and text move to 2 December 2026 (the grace period for providers was cut to three months).

ObligationOriginal deadlineNew deadline
High-risk AI systems (Annex III)2 Aug 20262 Dec 2027
AI in products under sectoral legislation2 Aug 20272 Aug 2028
Marking of AI-generated content2 Aug 20262 Dec 2026

What hasn’t changed

The delay applies specifically to high-risk system obligations. Several significant parts of the Act are already in force and are unaffected by this vote:

Prohibited practices (Article 5): in force since 2 February 2025. The AI systems that are outright banned remain banned. This includes manipulative AI, social scoring, most real-time biometric identification in public spaces, and emotion recognition in workplaces.

AI literacy (Article 4): in force since 2 February 2025. Organisations must ensure staff working with AI systems have a sufficient level of AI literacy.

GPAI model obligations (Articles 51–56): in force since 2 August 2025. Providers of general-purpose AI models already carry transparency, documentation, and copyright obligations.

Transparency obligations (Article 50): the date for these hasn’t been explicitly pushed back. If your chatbot interacts with people and doesn’t disclose it’s AI, you should be fixing that now regardless of the high-risk timeline.

New: nudifier AI ban

The Parliament introduced a new prohibition targeting AI systems that create or manipulate sexually explicit images resembling identifiable real persons without their consent. This covers so-called “nudifier” or “undressing” apps.

There’s a narrow exception for systems with “effective safety measures preventing users from creating such images,” but the ban is broad. If you operate anywhere near AI-generated imagery, check your product against this provision.

More breathing room for SMEs

The amendments extend existing SME flexibility measures to small mid-cap enterprises. The Act also now permits personal data processing by service providers specifically for detecting and correcting biases in AI systems, subject to strict necessity safeguards.

For smaller organisations, this is welcome. The compliance burden for a 50-person company building an AI hiring tool is materially different from what’s reasonable for a large enterprise, and the Act now acknowledges this more broadly.

This isn’t final yet

The Parliament’s vote is one step in the legislative process. These amendments still need to be negotiated with the EU Council before they become law. The official text of the AI Act, as published, still references 2 August 2026 as the enforcement date for high-risk obligations.

The Council will likely agree. The vote was overwhelming at 569–45. But until the trilogue process completes and the amended text is published in the Official Journal, the original dates technically stand.

What this means for your compliance planning

The temptation is to relax. Don’t.

If you’re building a high-risk AI system: You’ve gained roughly 16 months. Use them. The compliance requirements haven’t changed, only the deadline. A risk management system (Article 9), technical documentation (Annex IV), conformity assessment (Article 43), and a Declaration of Conformity (Article 47) still take months to prepare properly. December 2027 sounds far away. It isn’t, once you account for the actual work involved.

If you’re a deployer of high-risk AI: Your Fundamental Rights Impact Assessment (Article 27), monitoring obligations, and human oversight arrangements now have a later deadline. But your providers need to be working on their documentation in parallel, and that conversation should happen sooner rather than later.

If you’re not high-risk: Nothing has changed for you. Transparency obligations, prohibited practices, and AI literacy requirements are either already in force or arriving on roughly the original timeline. A customer service chatbot that doesn’t disclose it’s AI is non-compliant regardless of the high-risk delay.

If you’ve already started compliance work: You’re ahead. The organisations that began early will have the smoothest transition, and the extra time means you can be more thorough rather than rushing to meet August 2026. Don’t stop. Refine.

The worst outcome from this delay would be treating it as permission to do nothing until late 2027. GDPR had a two-year implementation period. Many companies waited until the final months and paid for it, both in fines and in the scramble itself.

The high-risk deadline moved. The amount of work didn’t.


This article is part of the ComplyDrive EU AI Act Knowledge Base. ComplyDrive publishes an EU AI Act compliance checklist and Sample Documentation — 47 checklist items across 5 phases, with 9 complete example compliance documents. Details at complydrive.ai.

Frequently asked questions

When is the EU AI Act high-risk deadline now?

The obligations for Annex III high-risk AI systems now apply from 2 December 2027, moved from the original 2 August 2026 by the Digital Omnibus. AI systems regulated under EU sectoral product legislation (medical devices, radio equipment, toys, etc.) have until 2 August 2028.

Did the Article 50 transparency deadline move to 2027 as well?

No. The deadline to mark AI-generated content moved only to 2 December 2026 (the grace period was cut to three months), and the general Article 50 disclosure duty still applies from 2 August 2026. Neither was pushed out to 2027. If your chatbot doesn't disclose it's AI, that is a near-term problem, not a 2027 one.

Which EU AI Act obligations are already in force?

Three blocks are unaffected by the delay. Prohibited practices (Article 5) and AI literacy (Article 4) have applied since 2 February 2025; general-purpose AI model obligations (Articles 51–56) have applied since 2 August 2025. The delay only touches the high-risk system obligations.

Does the delay mean I can wait until 2027 to start?

No. The deadline moved but the amount of work didn't. A risk management system (Article 9), technical documentation (Annex IV), conformity assessment (Article 43) and a Declaration of Conformity (Article 47) take months to prepare, and several obligations are already enforceable. The delay is runway, not a reprieve.

Written by
John Pitchers
John Pitchers
Founder, ComplyDrive

John holds editorial responsibility for all ComplyDrive content.

About the author →
The Toolkit

The 47-item checklist, an editable tracker, nine sample documents and nine fill-in templates.

Get the Toolkit

Free worked document

Get a complete Article 26 AI System Register, free.

One of the nine worked documents from the toolkit. A finished Article 26 AI System Register for a high-risk AI deployment, completed end-to-end so you can see exactly what a completed register looks like instead of starting from a blank page. Enter your email and we'll send you the download link. Unsubscribe at any time.