The EU AI Act's High-Risk Deadline Moved to December 2027. Most Sources Still Say August 2026.
Published August 7, 2026. Verified against the consolidated text on EUR-Lex, CELEX 02024R1689-20260727.
The short version: on 27 July 2026, Regulation (EU) 2026/1744 entered into force and moved the EU AI Act's high-risk obligations from 2 August 2026 to 2 December 2027 for Annex III systems and 2 August 2028 for systems embedded in regulated products. The deferral is unconditional. Nothing else moved. The Act still applies from 2 August 2026, and a great deal of it has been binding since February 2025.
I am not a lawyer, and nothing here is legal advice. I went looking because I was about to publish an argument that leaned on Article 14, found that the source I was citing had not been updated in two years, and decided the correction was more useful than the argument.
What actually changed
One provision. Article 113, third paragraph, point (c), which sets when Chapter III's high-risk obligations start applying.
| Date | What applies | Moved? |
|---|---|---|
| 2 Feb 2025 | Chapter I (scope, definitions, Article 4 AI literacy) and Chapter II (Article 5 prohibited practices) | No |
| 2 Aug 2025 | Chapter V (general-purpose AI models), notifying authorities, governance, most penalties | No |
| 2 Aug 2026 | General application. Chapter IV (Article 50 transparency), conformity assessment, registration, market surveillance, the new AI Office enforcement powers | No |
| 2 Dec 2026 | Two new prohibitions in Article 5(1); end of the Article 111(4) transitional for synthetic-content marking | New |
| 2 Aug 2027 | Legacy GPAI models must comply; national regulatory sandboxes operational | Sandboxes moved (+12 months) |
| 2 Dec 2027 | Chapter III, Sections 1–3 (Articles 6–27) for Annex III high-risk — risk management, data governance, technical documentation, Article 14 human oversight, Article 26 deployer duties | Moved (+16 months) |
| 2 Aug 2028 | The same obligations for Annex I high-risk, meaning AI embedded in regulated products | Moved (+24 months) |
Article 6(5), the Commission's duty to publish high-risk classification guidelines, is expressly carved out of the deferral and applies from 2 August 2026. That deadline was written as 2 February 2026 and has passed; the guidelines still appear to be in draft.
The part almost everyone has wrong
Two errors are circulating, and they point in opposite directions.
The first is staleness. A number of widely cited timeline pages still show 2 August 2026 for high-risk. One of the most linked unofficial AI Act references carries a footer reading "Last updated: 1 August 2024" and contains no mention of Regulation (EU) 2026/1744 or of 2 December 2027 anywhere on the page. If you have been quoting dates from it, you have been quoting law that has since been amended.
The second is more interesting, because it is a correct description of a text that was never enacted.
The Commission's November 2025 proposal, COM(2025) 836, did not propose flat dates. It proposed a trigger. High-risk rules would apply "following the adoption of a decision of the Commission confirming that adequate measures in support of compliance with Chapter III are available" — six months after that decision for Annex III systems, twelve months for Annex I. December 2027 and August 2028 appeared only as long-stop backstops if no such decision arrived. The explanatory memorandum described it as linking the timeline to the availability of standards.
That mechanism was removed during negotiation. The adopted text states calendar dates and nothing else. A full-text search of the regulation for the proposal's operative language — "confirming that adequate", "6 months after", "readiness", "in the absence of the adoption" — returns nothing. The only standards language that survived is hortatory, in recital 40, saying the Commission "should ensure that measures in support of compliance … are in place in due time."
So if you read that the high-risk rules will apply six months after the Commission confirms standards are ready, or you see a citation to Article 113, third paragraph, point (d) for the high-risk delay, that is the proposal. The enacted point (d) is about something else entirely — it moved Articles 102 to 110, the consequential amendments to other product legislation, earlier, to 27 July 2026.
I find this genuinely useful to know, because "the delay is conditional" and "the delay is fixed" imply completely different planning postures, and only one of them is the law.
The bigger correction: most of the Act is live right now
The headline "EU AI Act delayed" is doing real damage, because the sentence most people take from it is false.
Article 113's second paragraph reads "It shall apply from 2 August 2026." That paragraph was not amended. Only the third paragraph, which lists exceptions, was touched. Everything not carved out applies now.
What that means concretely, five days in:
- Prohibited practices under Article 5 have been binding since 2 February 2025. So has the Article 4 AI literacy duty, softened but not removed by the amendment.
- General-purpose AI model obligations have applied since 2 August 2025. That point of Article 113 is untouched base text. It is the single most-misreported delay in the coverage I read.
- Article 50 transparency applies from 2 August 2026. It sits in Chapter IV and is named in no exception. The amendment touched it only at paragraph 7. There is one carve-out worth knowing: under new Article 111(4), providers of synthetic-content systems already on the market before 2 August 2026 have until 2 December 2026 to meet the Article 50(2) marking duty.
- A second enforcement track went live on 2 August 2026. New Articles 75 and 75a through 75d give the AI Office exclusive competence over AI systems built on a provider's own general-purpose model, and over AI in designated very large online platforms and search engines, with power to investigate and fine directly. These articles appear nowhere in the November proposal. They are new.
There is one more distinction the coverage keeps collapsing, and it matters more than it sounds.
Entry into force is not application. The amendment entered into force on 27 July 2026, and from that moment its edits are part of the AI Act's text. When each edited provision operates is still governed by Article 113. So the much-reported narrowing of Article 6 — the new language on when a safety component counts as high-risk — is in force today and does not operate until December 2027 at the earliest. If you are planning against it, you are planning against something real that is sixteen months away from doing anything.
What I would actually do with this
Three things, in order.
Check whether any of it applies to you at all. The obligations that moved attach to high-risk systems as defined in Article 6. Most software is not in that population. The obligations that did not move — Article 5, Article 4, Article 50 — apply much more broadly, and Article 50 in particular reaches any system that interacts with people or generates synthetic content, regardless of risk class. The practical read for most builders is that the thing you were worried about moved and the thing you were ignoring is already live.
Re-check anything you wrote or filed against the old dates. If a compliance plan, a customer commitment, a security questionnaire response, or a roadmap slide says high-risk obligations land in August 2026, it is wrong by sixteen months in one direction, and possibly wrong about Article 50 in the other.
Stop citing unofficial timelines. Use the consolidated text. CELEX 02024R1689-20260727 is the AI Act as amended, dated to the day the amendment took effect, with every edit marked in the margin. Read Article 113. It is one page and it is the only source that cannot be stale.
One thing I want to be careful about, since the whole point of this post is not repeating other people's errors. This covers timing. It is not a compliance guide, I have not read all 47 recitals with a lawyer, and the classification question — whether a given system is high-risk at all — is genuinely hard and turns on facts about deployment rather than on the calendar. If the answer matters to your business, the dates above tell you how long you have, not what to do.
Why a memory company is writing about this
Two reasons, and I would rather state them than have you wonder.
The first is that I nearly published the error. I had a draft arguing that agent memory needs provenance and auditability, and it leaned on Article 14 becoming enforceable on 2 August 2026 as evidence that the industry was about to be forced into it. That was wrong, and it was wrong in the direction that flattered my argument, which is the direction you are least likely to check.
The second is what I concluded once I fixed it. The regulatory forcing function people keep pointing at is sixteen months further away than advertised, unconditional but distant, and would not cover most of the tools this argument is usually made about. Which means if you think an agent should be able to tell you where its stored beliefs came from, you have to want that on engineering grounds. There is no deadline coming to make you.
I still think it is worth doing. I just cannot borrow a legislature's urgency to say so. That argument, with the regulatory crutch removed, is here.
Frequently asked questions
- When do the EU AI Act's high-risk obligations apply?
- 2 December 2027 for systems classified as high-risk under Article 6(2) and Annex III, and 2 August 2028 for systems classified as high-risk under Article 6(1) and Annex I. Both dates come from Article 113, third paragraph, point (c), as replaced by Regulation (EU) 2026/1744. The previous date for both was 2 August 2026. Chapter III, Sections 1, 2 and 3 covers Articles 6 to 27, which includes the risk-management system, data governance, technical documentation, human oversight under Article 14, and deployer obligations under Article 26. Article 6(5) is expressly carved out of the deferral and applies from 2 August 2026.
- Is the EU AI Act's high-risk delay conditional on harmonised standards being ready?
- No. The adopted text sets flat calendar dates with no trigger of any kind. The conditional mechanism was in the Commission's November 2025 proposal, COM(2025) 836, which would have made the rules apply six months after a Commission decision confirming that support measures were available, with December 2027 and August 2028 as long-stop backstops. That mechanism was removed during negotiation. Anyone describing a standards-availability trigger is describing a text that was not enacted.
- Has the whole EU AI Act been delayed?
- No, and this is the most common error. Only Chapter III, Sections 1, 2 and 3 moved. The general application date in Article 113's second paragraph was not amended, so the Act still applies from 2 August 2026. Prohibited practices and AI literacy have applied since 2 February 2025. General-purpose AI model obligations, governance, notified bodies and most penalties have applied since 2 August 2025. Article 50 transparency, conformity assessment, registration, market surveillance and the new AI Office enforcement powers all apply from 2 August 2026.
- Did Article 50 transparency get delayed?
- No. Article 50 sits in Chapter IV, which is named in none of Article 113's exceptions, so it applies from 2 August 2026. The amendment touched Article 50 only at paragraph 7. There is one transitional carve-out: under the new Article 111(4), providers of systems generating synthetic content that were already on the market before 2 August 2026 have until 2 December 2026 to comply with Article 50(2), the machine-readable marking duty.
- What new obligations start on 2 December 2026?
- Two things. First, two new prohibited practices enter Article 5(1): point (ba) covering non-consensual intimate imagery and point (bb) covering child sexual abuse material, both bounded by new scope limits in Article 5(1a) and (1b). Second, the Article 111(4) transitional period ends for synthetic-content systems placed on the market before 2 August 2026, which must then meet Article 50(2).
- Where can I verify the EU AI Act application dates myself?
- Use the consolidated text on EUR-Lex, CELEX 02024R1689-20260727, which is the AI Act as amended and dated to the day the amendment entered into force. Read Article 113. The amending act is Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force from 27 July 2026. Do not rely on unofficial timeline pages; several have not been updated since 2024 and still publish the superseded dates.