Skip to content
449 days remaining

EU AI Act Deadline: High-Risk AI (Annex III) — December 2, 2027

The EU Artificial Intelligence Act became law on August 1, 2024. Its Art. 50 transparency obligations and general-purpose-AI (GPAI) rules already took effect on August 2, 2026. The high-risk-AI obligations (Annex III — hiring, credit, healthcare, education, and other consequential-decision AI) were deferred under the 2025 Digital Omnibus (Regulation (EU) 2026/1744) and now take effect December 2, 2027. Annex I product-safety AI was likewise deferred, from August 2027 to August 2, 2028. Non-compliant businesses face fines of up to €35,000,000 or 7% of global annual turnover once the relevant obligation applies.

Timeline

EU AI Act entered into force

August 1, 2024

Prohibited AI practices ban takes effect (Article 5)

February 2, 2025

GPAI model rules and governance provisions take effect

August 2, 2025

Art. 50 transparency obligations take effect (chatbot/AI-content disclosure)

August 2, 2026

TODAY

September 9, 2026

High-risk AI (Annex III) must comply — deferred from Aug 2026

December 2, 2027

Annex I product-safety AI must comply — deferred from Aug 2027

August 2, 2028

What happens if you don't comply

Regulators in EU member states (Bundesnetzagentur in Germany, ANSSI in France, national market surveillance authorities elsewhere) can investigate and fine non-compliant organizations once each obligation applies. Maximum fines are €35M or 7% of global turnover for prohibited practices, €15M or 3% for high-risk AI violations, and €7.5M or 1% for providing false or misleading information to authorities. The Art. 50 transparency obligations are already enforceable now; high-risk (Annex III) enforcement begins December 2, 2027.

Who is affected

Any organization that: (1) places an AI system on the EU market, (2) puts an AI system into service in the EU, (3) uses an AI system to interact with EU users, or (4) uses an AI system that processes data of EU residents — regardless of where the organization is based. Annex III (the December 2027 deadline) specifically covers AI used in employment, credit, education, healthcare, biometrics, critical infrastructure, law enforcement, and justice.

What to do right now

1

Confirm your Art. 50 transparency disclosures (chatbots, AI-generated content, emotion recognition) are already live — that obligation has applied since August 2, 2026

2

Complete an AI tool inventory — every AI system your organization uses or provides

3

Classify each system by risk tier: Prohibited, High-Risk (Annex III), Limited, Minimal

4

For any High-Risk (Annex III) AI: begin conformity assessment work well ahead of December 2, 2027 — this typically takes 4–12 weeks per system once started

5

Draft your AI Acceptable Use Policy for employees

6

Document your high-risk AI systems in a technical file

7

If outside EU: designate an EU authorized representative

8

Do not wait until late 2027 to start — conformity assessments for multiple systems take longer than most teams expect

Related Deadlines