EU AI Act Deadline: High-Risk AI (Annex III) — December 2, 2027
The EU Artificial Intelligence Act became law on August 1, 2024. Its Art. 50 transparency obligations and general-purpose-AI (GPAI) rules already took effect on August 2, 2026. The high-risk-AI obligations (Annex III — hiring, credit, healthcare, education, and other consequential-decision AI) were deferred under the 2025 Digital Omnibus (Regulation (EU) 2026/1744) and now take effect December 2, 2027. Annex I product-safety AI was likewise deferred, from August 2027 to August 2, 2028. Non-compliant businesses face fines of up to €35,000,000 or 7% of global annual turnover once the relevant obligation applies.
Timeline
EU AI Act entered into force
August 1, 2024
Prohibited AI practices ban takes effect (Article 5)
February 2, 2025
GPAI model rules and governance provisions take effect
August 2, 2025
Art. 50 transparency obligations take effect (chatbot/AI-content disclosure)
August 2, 2026
TODAY
September 9, 2026
High-risk AI (Annex III) must comply — deferred from Aug 2026
December 2, 2027
Annex I product-safety AI must comply — deferred from Aug 2027
August 2, 2028
Regulators in EU member states (Bundesnetzagentur in Germany, ANSSI in France, national market surveillance authorities elsewhere) can investigate and fine non-compliant organizations once each obligation applies. Maximum fines are €35M or 7% of global turnover for prohibited practices, €15M or 3% for high-risk AI violations, and €7.5M or 1% for providing false or misleading information to authorities. The Art. 50 transparency obligations are already enforceable now; high-risk (Annex III) enforcement begins December 2, 2027.
Any organization that: (1) places an AI system on the EU market, (2) puts an AI system into service in the EU, (3) uses an AI system to interact with EU users, or (4) uses an AI system that processes data of EU residents — regardless of where the organization is based. Annex III (the December 2027 deadline) specifically covers AI used in employment, credit, education, healthcare, biometrics, critical infrastructure, law enforcement, and justice.
What to do right now
Confirm your Art. 50 transparency disclosures (chatbots, AI-generated content, emotion recognition) are already live — that obligation has applied since August 2, 2026
Complete an AI tool inventory — every AI system your organization uses or provides
Classify each system by risk tier: Prohibited, High-Risk (Annex III), Limited, Minimal
For any High-Risk (Annex III) AI: begin conformity assessment work well ahead of December 2, 2027 — this typically takes 4–12 weeks per system once started
Draft your AI Acceptable Use Policy for employees
Document your high-risk AI systems in a technical file
If outside EU: designate an EU authorized representative
Do not wait until late 2027 to start — conformity assessments for multiple systems take longer than most teams expect