The EU AI Act high-risk timetable has changed. Learn what the December 2027 and August 2028 deadlines mean for businesses using AI.
What changed?
If your compliance plan still says August 2026 for high-risk AI, it may need updating. The AI Omnibus changed the implementation timetable after the EU concluded that important support measures, including harmonised standards, would not be ready in time for the original schedule.
The revised law now separates two important groups. Requirements for high-risk systems classified under Annex III apply from 2 December 2027. Requirements for high-risk AI systems covered through the product-safety route apply from 2 August 2028.
- 2 December 2027: certain high-risk uses in areas such as biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and the administration of justice.
- 2 August 2028: high-risk AI that forms part of, or is itself, a safety component of regulated products such as certain machinery, medical devices, toys and lifts.
Does this affect your business?
Potentially, particularly where AI supports decisions about people or sits inside a regulated product. These uses can require substantially more attention than everyday productivity tools.
Classification still depends on the specific system, intended purpose and context. Describing software as 'AI-powered' does not automatically make it high-risk, and a screening result is not a definitive legal classification.
- Screening or ranking job applicants.
- Evaluating employees or supporting workforce decisions.
- Influencing access to certain important private or public services.
- Operating certain biometric systems.
- Supporting regulated products such as medical devices or machinery.
Can businesses wait until 2027?
The later dates provide useful preparation time, but they do not place the rest of the AI Act on hold. Prohibited-practice and AI-literacy provisions have applied since 2 February 2025. Rules for general-purpose AI models began applying in August 2025, and important governance, enforcement and transparency provisions applied from August 2026.
Businesses also need time to discover what AI they actually use. High-risk obligations cannot be assessed properly if nobody has identified the AI inside recruitment platforms, HR software, customer systems, machinery or other third-party tools.
What should businesses do now?
- Create an AI inventory covering systems used across departments and AI functionality embedded in third-party software.
- Look at purpose rather than marketing labels. Record what the system does and whether its output affects employees, candidates, customers or other people.
- Identify your role. Obligations can differ depending on whether you develop, provide, integrate or use the system.
- Review potentially higher-risk uses first, particularly recruitment, employee management, biometrics and significant decisions about people.
- Use the additional time to establish policies, AI literacy, supplier checks, ownership and governance responsibilities rather than postponing the work.
Blanche perspective
The extension is useful breathing room while technical standards and implementation support continue to develop. But the first compliance question has not changed: do you know where AI is being used in your business?
Start with visibility, ownership and proportionate governance now. Detailed high-risk compliance work can then follow where the actual system, purpose and organisational role require it. More time is most valuable when it is used deliberately.
Sources
Primary and authoritative sources used for this Insight.