The short answer on the new deadlines
Under the current EU implementation timeline, rules for high-risk AI systems listed in Annex III apply from 2 December 2027. For high-risk AI embedded in regulated products covered by Annex I, or constituting such a product, the date is 2 August 2028. The AI Omnibus entered into force on 27 July 2026 and extended these two deadlines. This guide supports planning and is not legal advice.
The extension does not mean that the entire AI Act was postponed. Prohibitions, rules for general-purpose AI models, Article 50 transparency duties and other provisions follow their own dates. Organisations should therefore avoid relying on one general deadline and assess each system, role and duty separately.
Distinguish Annex III from Annex I
Annex III covers specified sensitive use cases. Subject to the legal conditions, these include applications in education and vocational training, employment, essential private or public services, critical infrastructure, law enforcement, migration, justice and biometric contexts. Not every system in these sectors is automatically high-risk. Classification depends on the intended purpose and the statutory criteria.
Annex I concerns AI used as a safety component of a product, or constituting a product, covered by specified EU product safety legislation and requiring third-party conformity assessment. Examples may include certain medical devices, machinery, toys or lifts. Classification requires product and legal expertise and should not be based on a marketing label alone.
Assess the intended use, not only the tool
Start with the actual decision process. The same technical model can have very different legal implications when used as an optional writing assistant or in a candidate-screening system. Record the task the system performs, who receives the output, whether people are affected and which decision the output supports or makes.
- What specific intended purpose has been approved internally?
- Is the organisation a provider, deployer, importer, distributor or acting in several roles?
- Which people, decisions and fundamental rights may be affected?
- Which product or sector rules also apply?
What can be prepared before the application dates
Maintain an inventory of AI systems in use and under consideration. Link each entry to its intended purpose, responsible team, provider, data types, affected people, approval status and a preliminary risk classification. Mark assumptions and unresolved legal questions clearly so that an early hypothesis is not later treated as a confirmed classification.
Assign responsibilities for procurement, technical review, data protection, information security, legal review, business ownership and management. A clear escalation path helps when the purpose, data, model or supplier changes. Preparation means building structures that support sound decisions, not pre-empting a later conformity assessment.
Plan evidence across the lifecycle
The European Commission identifies risk management, data quality, documentation and traceability, transparency, human oversight, accuracy, cybersecurity and robustness among the requirements for high-risk systems. The evidence an organisation must create or obtain from a supplier depends on its role and the system. Procurement terms and technical handovers should therefore address the information needed.
For deployers, relevant areas include instructions for use, ongoing monitoring, action on risks or serious incidents and properly equipped human oversight. Review which of these capabilities already exist in operations and where roles, knowledge or decision authority are missing.
Keep duties already in force on the plan
The revised high-risk timeline does not change the application of every other rule. The official EU timeline lists 2 February 2025 for general provisions, prohibitions and AI literacy, 2 August 2025 for general-purpose AI model rules, and 2 August 2026 for Article 50 and other provisions. Certain older systems have a limited transition period for Article 50(2) until 2 December 2026.
Use a deadline register that assigns every duty to an owner and review date. Update it when guidance, harmonised standards or a system classification changes. A one-off slide with a single date is not enough for a reliable governance process.
Train decisions around your real use cases
Role-based governance training can bring product, procurement, business, IT, security and management together around one shared case. Participants can describe an intended use, distinguish roles, identify missing evidence, plan oversight and document a reasoned escalation. Training does not replace legal assessment and cannot promise automatic compliance.
NextNowa plans content, pricing and dates on request around your systems, roles and desired learning outcomes. Before booking, the agenda, responsible instructors, availability and delivery scope are confirmed in writing.
Sources and review date
Official information checked on 6 October 2026. General information, not legal advice.

