EU AI Act High-Risk Deadline Guide — December 2027 Timeline
Compliance Hub · EU AI Act

The EU AI Act: what the 2027 deferral means for security and conformity teams.

The Digital Omnibus, formally adopted June 2026, moved the high-risk deadlines — but not the prohibitions, not the GPAI obligations, and not the scale of what conformity requires. Seventeen months of runway is preparation time, not a reprieve.

LAST REVIEWED: SEPTEMBER 10, 2026 · SOURCED FROM DIGITAL-STRATEGY.EC.EUROPA.EU
The Timeline

What moved — and what didn't.

Deferred by the Digital Omnibus
DECEMBER 2, 2027
{{ d1 }}
Applies to: Annex III high-risk providers/deployers
High-risk obligations — standalone systems

Annex III AI systems: biometrics, critical infrastructure, employment, credit, law enforcement, and other listed uses.

AUGUST 2, 2028
{{ d2 }}
Applies to: Annex I embedded high-risk providers
High-risk obligations — embedded systems

AI embedded in products already covered by EU product-safety regulation (Annex I).

Already in force — unchanged
SINCE FEBRUARY 2025
Prohibited practices

Social scoring, manipulative techniques, untargeted facial-image scraping, and other banned uses. Maximum penalty tier applies.

SINCE AUGUST 2025
GPAI obligations

Transparency, documentation, and copyright obligations for general-purpose AI model providers.

SINCE AUGUST 2, 2026
Article 50 transparency obligations

Disclosure duties for chatbots, synthetic content, emotion-recognition, and deepfakes. Attaches by function, not risk tier — untouched by the Digital Omnibus deferral. Read the full brief →

€35M / 7%
Maximum penalty for prohibited practices — of global annual turnover, whichever is higher
€15M / 3%
Maximum penalty for high-risk non-compliance
US ⟶ EU
Extraterritorial reach: US companies whose AI output touches the EU market are in scope
The Substance

What does high-risk conformity actually require?

For providers, Articles 9–17 define the obligations: a risk management system operating across the AI lifecycle, data governance for training and testing sets, technical documentation, automatic record-keeping, transparency to deployers, human oversight design, and accuracy, robustness, and cybersecurity requirements. Article 26 adds deployer obligations — usage monitoring, input-data relevance, and human oversight assignment.

The strategic framing: 17 months of runway is preparation time. Conformity assessments for complex AI systems take quarters, not weeks. Organizations that begin now avoid the 2027 assessor capacity crunch — the same dynamic FedRAMP CSPs are living through with 3PAOs this year.

Start with a baseline

The free self-assessment scores your AI security posture against BOD 26-04 and the AI Defense Matrix's 8 asset classes — five minutes for a baseline before you tackle EU AI Act conformity work.

Take the assessment — free →