EU AI Act: the high-risk deadline moves to 2027
5 min read

*Updated 13 September 2026: the delay has since been published in the Official Journal and is in force. We have brought this article in line with the rules as they now stand.*
For two years, 2 August 2026 sat in project plans as the day the high-risk rules of the EU AI Act would finally bite, and for a lot of mid-sized companies it was the reason to put an AI project off one more quarter. Just before it arrived, that deadline was gone. In the headlines it reads like a reprieve. Look closer and what you actually get is sixteen extra months and a list of work that has barely changed.
What happens on 2 August 2026, and what does not
The Digital Omnibus moves the obligations for high-risk AI under Annex III of the AI Act back by sixteen months, from 2 August 2026 to 2 December 2027. Systems built into regulated products, the Annex I cases, get until 2 August 2028.
It came together quickly: political agreement in trilogue on 7 May 2026, approval by the European Parliament on 16 June with 423 votes in favour, formal adoption by the Council on 29 June. It was published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744 and has been in force since 27 July 2026. The old date is off the table.
Two things the delay leaves alone. First, the substance. Risk management, data governance, technical documentation, human oversight: the requirements stand essentially as they were agreed in 2024. You get more time, not a lower bar. Second, what already applies keeps applying, slightly softer on AI literacy and stricter on prohibitions.
What the AI Act already asks of you today
These rules have been live for months, and they cover any company that uses AI, not only the ones that build it.
- Prohibited practices (Article 5), since 2 February 2025. Emotion recognition in the workplace, social scoring, manipulative systems. If one of those is running in your building, you do not have a deadline. You have a problem. Since 27 July 2026 the list also bans AI that generates intimate images of real people without their consent, and AI that generates child sexual abuse material.
- AI literacy (Article 4), also since 2 February 2025. Providers and deployers have to take measures that help their staff understand what the tool can do and where it gets things wrong. Since 27 July 2026 the Act no longer demands a specific level, and no certificate is required. A short record of who was trained, and when, is still sensible.
- Duties on model providers (Articles 53 to 55), since 2 August 2025. These reach you indirectly, through every model you buy in and through whatever documentation your supplier hands over with it.
Most mid-market systems were never high-risk
Here is the part that gets missed most often. An assistant that explains article master data to a sales team. A search across your own contracts. A classifier that pre-sorts incoming invoices. As a rule, none of it falls under Annex III.
Which means a good number of companies spent two years waiting on a deadline that would never have touched them. What they lost was not compliance headroom. It was two years.
The three things we do with customers now
- Build the AI inventory. One list: which system, what for, which data, which supplier, who makes the final call. It takes a morning, and it usually answers the classification question on its own. Without that list, every compliance discussion is guesswork.
- Write the classification down. One paragraph per system: high-risk yes or no, and why. Not for a regulator, but for your successor, your auditor, and the day somebody asks.
- Build the rest. Sixteen months is a window to gather experience before the requirements get harder. As a licence to do nothing it is worthless: start your first AI project in 2027 and you start it under time pressure, with documentation duties attached from day one.
An example from the work. A wholesaler wanted an assistant for its sales team, with one condition attached: pricing calculations and customer data do not leave the building. It runs today on the company's own hardware, inside its own network. The classification took twenty minutes: not an Annex III case, because the system assesses nobody, it answers questions about the company's own documents. The paperwork behind it fits on two pages.
Common questions about the EU AI Act deadline
Does the EU AI Act apply to small companies?
Yes. Unlike other rulebooks, the AI Act has no employee threshold. It sorts by role, provider or deployer, and by the risk the system carries. Small and mid-sized companies, and since July 2026 small mid-caps too, get lighter documentation, not an exemption. The prohibitions in Article 5 and the duty to support AI literacy in Article 4 apply whatever the headcount.
Is a chatbot with company knowledge a high-risk system?
In the vast majority of cases, no. Annex III names specific uses: recruitment, creditworthiness, critical infrastructure, law enforcement and a handful more. An assistant that pulls its answers out of internal documents normally sits outside that list. Since 2 August 2026, though, whoever provides the assistant has to make sure people can tell they are talking to a machine. The Act does not require a source for every answer. We recommend one anyway, because it builds trust and makes mistakes visible.
Can we push the AI project back to 2027 now?
Technically yes, commercially rarely. The delay moves obligations, not competitors. And thirteen years of project work say the same thing every time: the effort in an AI project almost never sits in the regulation. It sits in the data: how it is structured, who owns it, how carefully it has been kept. That work will not be a day shorter in 2027.
Where does the data have to live?
Your use case decides that, not the regulation. For plenty of projects a European cloud is the fastest and most economical route. Where pricing, personnel or design data is in play, customers more often choose to run the system in their own building. We build both ways. So the question is not cloud or no cloud. It is where your data does the most for you.
Our position: postponing is not a plan
The delay is genuinely good news for anyone building high-risk systems. For everybody else it is mainly permission to stop waiting on Brussels.
We have been building AI systems for mid-sized companies since before anyone had heard of the models, and we set them up so that the classification ends up as a paragraph rather than an investigation. If you want to know where yours stand, send us the list or give us half an hour. We will tell you honestly whether you need to do anything, including when the answer is nothing.
Hashfox GmbH
Written by the Hashfox team, from live projects, not from the drawing board.
AI that fits the way you work. Let’s talk about your use case.
Explore AI solutions