✨ New — try Standpoint free for 14 days: full access to all 15 frameworks. A card is required, but you won’t be charged. Start your free trial →
Standpointby AI Service Pro
Security Intelligence / EU AI Act
Guide

The EU AI Act's high-risk rules were postponed to December 2027. Here's what that actually means.

M
Mohammad
Founder, AI Service Pro · 8 min read

Short answer: On 29 June 2026 the Council of the EU gave final approval to the "Digital Omnibus" simplification package, which pushed the compliance deadline for stand-alone high-risk AI systems (the ones listed in Annex III) from 2 August 2026 to 2 December 2027 — a 16-month deferral. High-risk systems that are regulated as products under Annex I moved separately, from 2 August 2027 to 2 August 2028. Nothing else in the Act was cancelled. The transparency and general-purpose AI (GPAI) obligations that were scheduled for 2 August 2026 still apply on that date. So if you read a headline saying "the EU AI Act was delayed," the accurate version is narrower: one tranche of obligations was delayed, and it may not be the tranche that touches you.

What exactly was postponed?

Two different categories of high-risk system moved on two different clocks. The distinction matters because most founders don't know which one they're in.

Annex III high-risk systems are the "use-based" ones — an AI system is high-risk because of what it's used for, regardless of the product it sits inside. This is the list most software companies care about: AI used in employment and hiring, access to essential services, credit scoring, biometric identification, education, and critical infrastructure. These obligations moved from 2 August 2026 to 2 December 2027 (Gibson Dunn; Inside Privacy).

Annex I high-risk systems are the "product-regulated" ones — AI that is a safety component of a product already covered by existing EU product law, such as medical devices, lifts, and radio equipment. These moved from 2 August 2027 to 2 August 2028, a one-year deferral (Gibson Dunn).

Quotable definition: A high-risk AI system under the EU AI Act is not "risky-sounding" AI — it is AI used for one of a specific, enumerated set of purposes (Annex III) or embedded as a safety component in an already-regulated product (Annex I). If your use case isn't on those lists, the high-risk obligations don't apply to you at all, delayed or not.

Why was it delayed?

The delay wasn't a political retreat from the Act — it was an admission that the machinery to comply with it isn't finished. The high-risk obligations require conformity assessments, technical documentation, and third-party testing against harmonised standards that European standards bodies (CEN-CENELEC) have not yet published. The postponement gives those bodies additional time to produce the standards that the requirements depend on (Inside Privacy; Travers Smith). In plain terms: you can't be asked to conform to a standard that doesn't exist yet.

That framing is useful for planning, because it tells you the delay is about readiness of the rulebook, not about whether the obligations are coming. They are coming. December 2027 is roughly 17 months away as of this writing.

What is the "Digital Omnibus" and when did it become real?

The Digital Omnibus is a European Commission simplification package launched in late 2025 to streamline overlapping EU digital rules. For the AI Act specifically:

  • 7 May 2026 — the Council and the European Parliament announced a provisional political agreement on the targeted amendments.
  • 29 June 2026 — the Council of the EU gave final approval, formally moving the Annex III high-risk deadline to 2 December 2027 (Gibson Dunn).
  • 24 July 2026 — the package was published in the Official Journal as Regulation (EU) 2026/1744, and it entered into force on 27 July 2026. This is the date that makes the deferral legally real.

Why the two dates matter: a lot of the content ranking for this query was written off the May provisional agreement and never updated after the June final approval. If a source you're reading only cites May 2026, check whether it reflects the final text.

What still applies on 2 August 2026?

This is the question that actually protects you, because the delay creates a false sense of "nothing's due." Two sets of obligations were not postponed and land on schedule:

  1. Article 50 transparency obligations. If you deploy AI that interacts with people (chatbots), or that generates synthetic audio, image, video, or text (including deepfakes), you must disclose that to users, and AI-generated content must be marked in a machine-readable way. These apply 2 August 2026.
  1. GPAI (general-purpose AI) model obligations. Providers of general-purpose AI models — the foundation-model layer — carry documentation, copyright-policy, and transparency duties from 2 August 2026 as well.

And already in force since 2 February 2025: the Article 5 prohibitions on "unacceptable-risk" practices (social scoring, certain biometric categorisation, manipulative systems). Those never moved.

So the honest 2026 picture is: prohibited-practice rules are live now, transparency and GPAI rules land in August, and the heavy high-risk conformity machinery is what got pushed to December 2027.

Does the delay change what you should do this year?

No — and here's the reasoning. The single most useful compliance artefact for the EU AI Act is an AI system inventory: a list of every AI system you build or use, what it does, whose data it touches, and which risk category it falls into. You need that inventory to answer the only question that matters first — are any of my systems high-risk at all? That question is unchanged by the delay. The delay only changes when the high-risk obligations attach; it does nothing to change whether a given system is in scope.

Teams that use the extra 16 months well will spend it doing the unglamorous work the deadline was always going to require: building the inventory, assigning an owner to each system, classifying risk, and closing documentation gaps before the standards land. Teams that treat "delayed" as "cancelled" will rediscover all of this in mid-2027 with less runway than they have now.

the questions people ask next

  • Is the EU AI Act delayed entirely? No — only Annex III (Dec 2027) and Annex I (Aug 2028) high-risk obligations moved.
  • What is the difference between Annex I and Annex III high-risk? Product-regulated vs. use-based; different deadlines.
  • Did the Article 5 prohibitions change? No — in force since 2 Feb 2025.
  • Do the GPAI rules still start in August 2026? Yes.
  • Does Article 50 transparency still start in August 2026? Yes.
  • Who decided the delay? The Council of the EU (final approval 29 June 2026), following the provisional agreement with Parliament on 7 May 2026.
  • Why was it delayed? Harmonised standards from CEN-CENELEC aren't ready.
  • Does the delay apply to US companies? Yes — the Act is extraterritorial; the same deadlines apply if you place systems on the EU market or your output is used in the EU.
  • How do I know if my system is high-risk? Check it against the Annex III use-case list and the Annex I product list.
  • What should I do during the delay? Build an AI inventory, classify risk, assign owners, close documentation gaps.
  • Is December 2027 the final deadline? It is the current deadline under the Digital Omnibus final text; monitor for further amendments.
  • Does this affect my SOC 2 or ISO 42001 work? No — those are separate; an ISO 42001 AI management system helps you operationalise AI Act readiness but is not required by it.

FAQ

Was the EU AI Act delayed?

Only in part. Under the Digital Omnibus (final Council approval 29 June 2026), high-risk obligations for Annex III use-based systems moved from 2 August 2026 to 2 December 2027, and Annex I product-regulated systems moved from 2 August 2027 to 2 August 2028. The transparency, GPAI, and prohibited-practice rules were not delayed.

What still applies on 2 August 2026?

Article 50 transparency obligations (disclosing AI interactions and marking AI-generated content) and general-purpose AI model obligations both apply from 2 August 2026. Article 5 prohibitions have applied since 2 February 2025.

Why were the high-risk rules postponed?

The harmonised technical standards that high-risk conformity assessments depend on (from CEN-CENELEC) are not yet finished. The deferral gives standards bodies time to publish them.

Does the delay apply to US companies?

Yes. The EU AI Act applies based on where a system is placed on the market or where its output is used, not where the provider is based, so the same deadlines apply to US companies serving EU users.

What should I do during the postponement?

Build an AI system inventory, classify each system's risk category, assign an accountable owner, and close documentation gaps. Whether a system is high-risk is unchanged by the delay — only the compliance deadline moved. A free EU AI Act readiness check can tell you where you stand today.

See where you stand — free
2-minute check · no card · runs in your browser
Run your free check →
Newsletter
Practical AI-governance & security tips, monthly

No fluff, no fear-selling. Unsubscribe anytime.

// Keep reading