EU AI Act Delays: Why High-Risk Deadlines Moved to 2027 and 2028

SEO & GEO for WordPress websites

The EU AI Act’s high-risk compliance deadlines have moved. What was originally set for August 2026 now sits at December 2027 for standalone high-risk systems, and August 2028 for AI embedded in regulated products. These are not provisional targets or political promises. The Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force on 27 July 2026, making the new dates binding law across all EU member states.

For businesses building, deploying, or procuring AI systems in the EU, the shift matters in two directions at once. The extra time is real and welcome. But the underlying obligations have not changed, several other deadlines remain exactly where they were, and the fines for non-compliance remain among the steepest in global tech regulation. Here is what actually happened, why it happened, and what it means for your compliance strategy.

The original EU AI Act timeline, explained

The EU AI Act (Regulation (EU) 2024/1689) was published in the Official Journal of the European Union on 12 July 2024 and entered into force on 1 August 2024. That date started the compliance clock. The Act does not apply all at once. Its obligations roll out in four phases, each targeting a different category of AI system.

Phase 1 brought the sharpest rules first. Prohibited AI practices under Article 5, covering things like social scoring systems and manipulative AI, became enforceable on 2 February 2025. AI literacy obligations under Article 4 applied from the same date, meaning every business in the EU already carries a baseline duty to develop AI awareness among staff who work with AI tools.

Phase 2 followed on 2 August 2025, when obligations for General Purpose AI (GPAI) model providers kicked in. Providers of foundation models like GPT-4, Claude, and Gemini were required to publish technical documentation, comply with copyright rules, and report serious incidents from that date.

Phase 3, covering Article 50 transparency obligations, was set for 2 August 2026 and was not moved. Any business deploying a chatbot, AI-generated content tool, or deepfake-adjacent system must now label AI-generated outputs and inform users when they are interacting with an AI system.

Phase 4 was where the delays hit. High-risk AI systems under Annex III (standalone systems in areas like hiring, credit scoring, and biometrics) were originally due to comply by 2 August 2026. Systems under Annex I, meaning AI embedded in regulated products like medical devices and machinery, faced a 2 August 2027 deadline. Both of those dates have now changed.

What changed and which deadlines were pushed

The Digital Omnibus on AI extended two specific deadlines and left everything else untouched. Standalone high-risk AI systems listed under Annex III now have until 2 December 2027 to comply, a 16-month extension from the original August 2026 date. High-risk AI embedded in regulated products under Annex I now has until 2 August 2028, a 12-month extension from the original August 2027 deadline.

The legislative path to these new dates moved quickly by EU standards. The European Commission proposed the Digital Omnibus in November 2025 as part of a broader drive to simplify the EU’s digital rulebook. The Council and Parliament reached provisional agreement on 7 May 2026. Parliament gave final approval on 16 June 2026, the Council followed on 29 June 2026, and the regulation was signed on 8 July 2026 before entering into force on 27 July 2026.

The Omnibus also added a new prohibited practice to Article 5: AI systems that generate or manipulate non-consensual intimate imagery are now banned, effective 2 December 2026. Systems of this type already on the market before 2 August 2026 have a short watermarking grace period running to the same December date. New systems entering the market after 2 August 2026 must comply immediately.

One structural point worth noting: the original Commission proposal would have tied the start of high-risk obligations to the availability of harmonized technical standards, making the trigger conditional. The final agreed text replaced that mechanism with fixed calendar dates. December 2027 and August 2028 are firm outer limits, not floating targets. The Commission does retain the ability to pull the deadline forward by six months once it formally confirms that the necessary standards and guidance are in place, but it cannot extend beyond those dates.

Why regulators extended the high-risk compliance windows

The primary reason for the delay is straightforward: the technical infrastructure needed to comply with high-risk obligations did not arrive on time. The EU AI Act’s high-risk rules depend heavily on harmonized technical standards developed by European standardization bodies CEN and CENELEC. Those standards were supposed to be ready by April 2025. They were not.

CEN and CENELEC were mandated in May 2023 to develop approximately 35 harmonized standards across five working groups, involving more than 1,000 European experts. As of mid-2026, none of those deliverables has been cited in the Official Journal, which means none of them yet grants presumption of conformity. The current estimate for first standards is Q4 2026 at the earliest, though that projection remains uncertain.

The Commission formally acknowledged the problem in an implementing decision in June 2025, recording “significant delays” in the coming standards. The Commission also missed its own statutory deadline for issuing classification guidance under Article 6, which was due by 2 February 2026. The designation of national competent authorities and conformity assessment bodies, the bodies businesses need to engage for conformity assessment, also fell behind schedule in multiple member states.

The Commission’s official FAQ states the position plainly: “The delayed availability of the standards puts in jeopardy the successful entry into application of the high-risk rules on 2 August 2026. The AI Omnibus therefore extends the timeline to 2 December 2027 for high-risk AI systems and 2 August 2028 for AI embedded in products.”

Industry groups had pushed hard for the extension, arguing the original timetable was unworkable without functional standards, guidance, and testing infrastructure. The European Data Protection Board and European Data Protection Supervisor expressed concerns in Joint Opinion 1/2026 that later dates could affect fundamental rights protections, but the extension proceeded. The standardization challenge is genuinely difficult: the AI Act asks for standards in areas where no established state of the art exists, making the process inherently slower than previous EU product safety exercises.

Industries and use cases most affected by the delays

Annex III of the EU AI Act defines the high-risk use cases that trigger the most demanding compliance obligations. The list covers eight broad areas: biometrics, critical infrastructure, education and vocational training, employment and workforce management, essential public and private services, law enforcement, migration and border control, and the administration of justice.

Annex III: standalone high-risk systems (deadline: December 2027)

Specific Annex III use cases include AI systems used in hiring and personnel management, credit scoring and loan decisions, critical infrastructure management such as energy grids and transport networks, border control, biometric identification, educational admissions, and law enforcement tools. Companies deploying AI in any of these areas were originally facing an August 2026 compliance deadline and now have until December 2027.

One nuance worth flagging for financial services: a credit-scoring system that produces a recommendation for a human underwriter still falls inside Annex III Point 5(b), regardless of whether the system makes the final lending decision. The human-in-the-loop does not remove the high-risk classification.

Annex I: AI embedded in regulated products (deadline: August 2028)

Annex I covers 18 regulated product categories, including medical devices, machinery, motor vehicles, in vitro diagnostic devices, civil aviation equipment, and rail systems. AI embedded in these products now has until 2 August 2028 to comply. For medical device manufacturers, the first relevant standard covering quality management systems entered public enquiry in October 2025, already eight months behind the original schedule.

The Digital Omnibus also introduced a provision that AI systems embedded in products covered by the Machinery Regulation will be largely exempted from AI Act obligations. For medical devices specifically, the Commission gained authority to adopt delegated acts that can exempt specific AI Act high-risk requirements where the Medical Device Regulation or In Vitro Diagnostic Regulation already mandates equivalent standards, reducing duplication across regulatory frameworks.

What businesses should still be doing now

The extended high-risk deadlines do not mean compliance work can wait. Several obligations are already live, and the foundational preparation for December 2027 takes longer than most businesses expect.

The most immediate live obligation is Article 50 transparency. Businesses deploying chatbots, AI-generated content tools, or any AI system that interacts with users must now label AI-generated outputs and disclose when users are interacting with an AI. This deadline was not moved. For businesses focused on the high-risk delay narrative, this is the compliance blind spot most likely to create exposure right now.

Penalty levels are unchanged across all provisions. Violations of prohibited practices carry fines of up to €35 million or 7% of global annual turnover. Violations of high-risk and transparency obligations carry fines of up to €15 million or 3% of global annual turnover. The extended deadlines shift when those fines become applicable for high-risk systems, not whether they apply.

The single most important foundational task for any business is determining which AI systems are in scope and which are high-risk. Every subsequent obligation, from technical documentation to risk management systems to conformity assessment, depends on getting that classification right. Most organizations have not completed this inventory.

Beyond classification, practical preparation includes building technical documentation, establishing risk management processes, reviewing vendor contracts to determine who carries provider obligations in the AI supply chain, and adding AI Act clauses covering compliance, documentation, audit rights, and incident notification to contracts with EU clients and suppliers. Technical documentation and logging systems take months to build properly. Morgan Lewis advises businesses to treat the extended deadlines as additional time to complete compliance efforts, not as a relaxation of the underlying obligations.

One further point: the underlying legal risk does not move with the AI Act dates. AI-caused harm in 2026 is still subject to existing sectoral law, including product liability rules, GDPR, the Medical Device Regulation, anti-discrimination statutes, and sector regulators. The AI Act delay changes your regulatory compliance timeline, not your exposure under existing law.

How the delays affect AI adoption strategy for SMBs

The Digital Omnibus introduced several changes that directly benefit smaller businesses, and those changes are worth understanding separately from the headline deadline extensions.

The Omnibus formally added definitions for SMEs and a new “small mid-cap” category covering companies that are not SMEs, employ fewer than 750 people, and have annual turnover not exceeding €150 million. Both categories receive simplified technical documentation templates that notified bodies must accept, more proportionate quality management system requirements, reduced fine caps, and priority access to AI regulatory sandboxes. The Commission’s stated goal was to reduce administrative burden by at least 35% for SMEs specifically.

The Article 4 AI literacy obligation was also softened. The original duty to “ensure a sufficient level” of AI literacy across the organization was replaced with a duty to “take measures to support the development of” literacy. This change reflects sustained pressure from smaller businesses and gives SMBs more flexibility in how they approach staff training, though the obligation itself has applied since February 2025.

For most SMBs, the compliance path is less demanding than the high-risk narrative suggests. European Commission data indicates that only around 13.5% of EU businesses are currently using AI technologies. For the majority of SMBs that find no high-risk systems in their AI inventory after conducting a proper classification exercise, the compliance path involves transparency notices and AI literacy training, both achievable in weeks rather than months.

SMBs that use AI through SaaS platforms carry a different set of obligations as deployers rather than providers. The practical steps here include requesting AI Act documentation or a compliance roadmap from SaaS vendors, verifying that any high-risk systems are registered in the EU database, and adding AI Act clauses to contracts. GDPR-mature organizations will find this process more familiar, since data protection impact assessments can be extended with AI-specific risk evaluations.

The national regulatory sandbox deadline for member states was deferred from August 2026 to August 2027, and the Omnibus created a separate EU-level sandbox operated by the AI Office with priority access for SMEs, start-ups, and small mid-caps. These sandboxes allow businesses to test AI systems in real-world conditions under regulatory supervision before full market deployment, and they represent a practical route for SMBs developing AI products to build compliance evidence while still in development.

For SMBs navigating this landscape, the compliance challenge and the content challenge often overlap. Businesses that need to produce AI Act-related documentation, publish transparency notices, and maintain a visible presence in AI-generated search results are managing both regulatory and visibility requirements simultaneously. Scaling content output with a hybrid AI and human approach can help businesses stay visible and credible as the regulatory environment continues to develop, without adding headcount or agency retainers to an already stretched operation.

The December 2027 deadline is firm, not distant. For businesses with high-risk systems, the gap between now and then will fill up with classification work, documentation, vendor negotiations, conformity assessments, and staff training. Starting that process now, while the regulatory infrastructure is still being built, is the position that gives the most room to course-correct.

This content was generated with the help of AI and it may contain mistakes

Your customers are asking AI. Are you part of the answer?

In a quick demo, we show how WP SEO AI tracks your AI visibility, finds content gaps, and helps your website appear in ChatGPT, Google AI Overviews and more.

Dive deeper in