Home / AI Act high-risk deadline
Guide — EU AI Act · last verified 31 July 2026

The EU AI Act high-risk deadline moved. Here is what actually applies.

On 27 July 2026 the Digital Omnibus on AI entered into force and pushed the high-risk obligations back by sixteen months. Most guidance published before that date still says 2 August 2026 — including pages currently ranking for this question. Here is the corrected timeline, and what genuinely still binds this weekend.

Last updated: 11 June 2026

Free interactive tool

Is your system actually high-risk?

Most systems people assume are Annex III are not — and the cost difference is enormous. Answer 4 questions and our EU AI Act risk checker classifies yours, with the obligations and the deadline that now applies to it.

Summarize with AI Prompt copied — paste it into the chat
Share
In short

Annex III high-risk obligations now apply from 2 December 2027, not 2 August 2026. Regulation (EU) 2026/1744 — the Digital Omnibus on AI — was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. AI embedded in regulated products under Annex I moves to 2 August 2028. The Article 50 transparency duties still start on 2 August 2026, Marking of AI-generated content is deferred to 2 December 2026 only for systems already on the market — anything placed after 2 August 2026 must comply immediately. Prohibited practices and the Article 4 AI-literacy duty have applied since February 2025 and did not move.

The corrected timeline

What changed, and what did not

The Omnibus is the first set of amendments to the AI Act since it was adopted in 2024. It was voted through Parliament on 16 June 2026, cleared Council on 29 June, was signed on 8 July, published on 24 July and took effect on 27 July. Only the high-risk timing changed — the risk categories themselves did not.

ObligationOld dateCurrent date
Prohibited practices (Art. 5)2 Feb 2025unchanged — already applies
AI literacy (Art. 4)2 Feb 2025unchanged — already applies
GPAI model obligations2 Aug 2025unchanged — already applies
Transparency (Art. 50)2 Aug 2026unchanged — applies 2 Aug 2026
Marking AI-generated content (Art. 50(2))2 Aug 20262 Dec 2026 only if already on market; immediate for new systems
High-risk, Annex III stand-alone2 Aug 20262 Dec 2027
High-risk, Annex I embedded in products2 Aug 20272 Aug 2028
What this does not mean

A delay is not a reprieve

Two things are worth being blunt about. First, the deferral applies to high-risk duties only — if you deploy a chatbot or generate content, Article 50 transparency lands on 2 August 2026 regardless. Second, the reason for the delay was that harmonised standards and national supervisory capacity were not ready, not that the requirements got easier. Conformity assessment, an Article 9 risk-management system, Article 12 logging, technical documentation, CE marking and EU database registration all still arrive — with sixteen more months to prepare rather than sixteen fewer.

The practical read for a Dutch or Belgian company: if you were about to spend heavily to hit 2 August, you have room to do it properly instead. If you were planning to ignore it, the deadline that moved was never the one that would have caught you first.

Who is affected

Is your system actually Annex III high-risk?

Annex III covers stand-alone systems used for biometrics, critical infrastructure, education, employment and worker management, access to essential services including credit scoring and insurance pricing, law enforcement, migration and border control, and the administration of justice. In SME practice the two that come up most often are recruitment screening and credit or insurance decisioning.

Annex I is different: AI acting as a safety component of a product already regulated under EU product law — machinery, medical devices, vehicles, lifts. That route runs through your existing product conformity process, which is why it was given until 2028.

Most business automation is neither. Invoice processing, demand forecasting, internal search and customer-service assistants normally sit in the limited or minimal tiers, where transparency and human oversight apply but conformity assessment does not.

Netherlands & Belgium

Who supervises this locally

The AI Act is a regulation, so the text binds identically in the Netherlands and Belgium — only enforcement is national. In the Netherlands the Autoriteit Persoonsgegevens coordinates algorithmic supervision alongside the RDI, and a regulatory sandbox is being stood up. Dutch employers also face a domestic constraint the AI Act does not mention: under article 27 of the Works Councils Act, introducing a system that assesses or monitors staff generally needs works council consent. In Belgium, CAO nr. 39 requires informing and consulting the works council before new technology with collective impact is introduced.

That local layer usually determines your real timeline. A recruitment screening tool can be AI Act compliant and still be unusable because the ondernemingsraad was not consulted.

What to do now

A sixteen-month plan that starts with classification

The first task is not documentation, it is classification — a surprising number of systems people assume are high-risk are not, and the cost difference is enormous. Start with the free risk checker, then confirm whether you are a provider (you build or rebrand the system) or a deployer (you use someone else's), because the obligation sets differ sharply.

If you land in Annex III, the work is a genuine engineering programme: a risk-management system under Article 9, data governance, technical documentation, logging under Article 12, human oversight design, and a conformity assessment before market placement. Crux Digits scopes that the same way as any build — a €2,500 audit to establish where you stand, then a fixed-scope programme. Our €950 AI Act Check remains the cheaper entry point if you only need to know your obligations.

FAQ

Frequently asked questions

Did the EU AI Act deadline of 2 August 2026 move?

For high-risk systems, yes. The Digital Omnibus moved Annex III stand-alone high-risk obligations to 2 December 2027 and Annex I embedded systems to 2 August 2028. Transparency duties under Article 50 were not moved and still start on 2 August 2026.

  • Regulation (EU) 2026/1744 was published on 24 July 2026 and entered into force on 27 July 2026.
  • Guidance written before late July still shows the old date — check the publication date on anything you read, including this page.

What still applies on 2 August 2026?

The Article 50 transparency obligations. You must tell people when they are interacting with an AI system, and deep-fake and synthetic content must be disclosed. Marking of AI-generated content under Article 50(2) has a grace period until 2 December 2026 for systems already on the market.

  • Prohibited practices and the Article 4 AI-literacy duty have applied since 2 February 2025 — those never moved.
  • GPAI model obligations have applied since 2 August 2025.
  • If you run a customer-facing chatbot, this is the date that matters to you.

Which systems count as Annex III high-risk?

Eight categories of stand-alone system, listed in Annex III. They cover biometrics, critical infrastructure, education, employment and worker management, access to essential services, law enforcement, migration and justice. For most SMEs only two are realistic candidates: recruitment screening, and credit or insurance decisioning.

  • Invoice processing, forecasting and internal search normally fall in the limited or minimal tiers.
  • Annex I is separate: AI as a safety component of an already-regulated product, deferred to 2 August 2028.
  • Our free risk checker classifies a system in four questions.

Does the delay mean we can stop preparing?

No — the requirements did not change, only the date. Conformity assessment, Article 9 risk management, Article 12 logging, technical documentation, CE marking and EU database registration all still arrive. The deferral exists because harmonised standards and supervisory capacity were not ready, not because the bar was lowered.

  • Sixteen extra months is roughly what a first conformity assessment takes to do properly rather than hastily.
  • Dutch employers face a nearer constraint: works council consent under WOR article 27 for staff assessment or monitoring systems.

Are we a provider or a deployer?

You are a provider if you build it or brand it. You are a deployer if you use someone else's system under your own authority. Providers carry the heavy obligations: conformity assessment, technical documentation, CE marking, registration. Deployers carry lighter ones around oversight, monitoring and input data.

  • Rebranding a third-party high-risk system as your own can make you the provider — check contracts before assuming otherwise.
  • Buying a compliant product does not transfer your deployer duties to the vendor.

Not sure which tier you are in?

Classify your system free in four questions, or book a consultation and we will tell you honestly whether the December 2027 date is even your problem.

Book a free consultation →