Regulation (EU) 2026/1744 moved the stand-alone Annex III deadline from 2 August 2026 to 2 December 2027. Here is what changed, what did not, and what you should do now.

Last updated 6 August 2026

The Short Answer

If your compliance guide, whitepaper, or roadmap lists 2 August 2026 as the EU AI Act high-risk AI deadline, that date is now outdated for most high-risk AI systems.

Regulation (EU) 2026/1744, the Digital Omnibus amendment to the EU AI Act, moved the application date for stand-alone Annex III high-risk AI system obligations from 2 August 2026 to 2 December 2027. The amendment entered into force on 18 July 2026 and applies across all EU member states without national transposition.

Before June 2026, every major compliance guide, whitepaper, legal briefing, and regulatory roadmap used the August 2026 date. Many of these have not been updated. This article explains what changed, the current legal position, and what it means for your compliance program.

What Is Regulation (EU) 2026/1744

Regulation (EU) 2026/1744, known as the Digital Omnibus AI amendment, is a directly applicable EU regulation that amends Regulation (EU) 2024/1689, the EU AI Act. It was provisionally agreed between the European Parliament and the Council on 7 May 2026, approved by the European Parliament on 16 June 2026, formally adopted by the Council, and published in the Official Journal of the European Union. It entered into force on 18 July 2026.

The Digital Omnibus does not run alongside the AI Act. Instead, it directly amends the AI Act. The updated AI Act, with the Omnibus changes, has been the law since 18 July 2026.

The Deadline Changes: Before and After

Stand-alone Annex III high-risk AI systems (use-based route)2 August 20262 December 202716-month extension
Annex I product-embedded high-risk AI systems (product safety route)2 August 20272 August 202812-month extension
Article 50(2) machine-readable synthetic content marking (systems already on market)2 August 20262 December 20264-month extension
National AI regulatory sandbox establishment2 August 20262 August 202712-month extension
Prohibited practices (Article 5)2 February 2025UnchangedNo change
AI literacy obligation (Article 4)2 February 2025UnchangedNo change
GPAI model obligations (Articles 51-56)2 August 2025UnchangedNo change
Authorised Representative for GPAI providers2 August 2025UnchangedNo change
Two new Article 5 prohibitions (NCII and CSAM)Not in original Act2 December 2026New obligation added

What Is Stand-Alone Annex III

To know which systems the December 2027 deadline covers, you need to understand the two-pathway classification in Article 6 of the AI Act.

The first pathway, Article 6(1), covers AI systems that are safety components of products regulated under EU harmonisation laws in Annex I, such as medical devices, machinery, vehicles, and aviation safety equipment. These product-embedded systems now have a deadline of 2 August 2028.

The second pathway, Article 6(2), covers AI systems used in any of the eight domains listed in Annex III, whether or not they are part of a regulated product. These stand-alone Annex III systems now have a deadline of 2 December 2027.

Annex III covers the following domains:

Biometric identification and categorisationRemote biometric identification, emotion recognition, biometric categorisation
Critical infrastructureAI managing energy, water, transport, or digital infrastructure
Education and vocational trainingAccess decisions, student assessment, exam monitoring
Employment and workers managementCV screening, candidate ranking, performance monitoring, task allocation
Access to essential private and public servicesCredit scoring, insurance risk assessment, emergency services dispatch
Law enforcementRecidivism risk assessment, crime analytics, evidence reliability evaluation
Migration, asylum, and border controlApplication risk assessment, document verification, border monitoring
Administration of justice and democratic processesAI assisting courts, election influence systems

If your AI system fits any of these domains under Article 6(2), the December 2027 deadline applies to your provider and deployer obligations in Chapters II and III of the Act.

What the Extension Does Not Cover

The sixteen-month extension is specific. It only covers obligations in Chapters II and III for stand-alone Annex III systems. Other parts of the AI Act, including some obligations already in force, remain unchanged.

What Is Already Enforceable and Unchanged

Prohibited practices under Article 5 have been in effect since 2 February 2025. The Digital Omnibus added two new prohibitions, AI systems generating non-consensual intimate imagery and AI systems generating child sexual abuse material, applying from 2 December 2026. The original eight prohibitions are unaffected and have been enforceable for eighteen months.

The AI literacy obligation in Article 4 has applied since 2 February 2025 to all providers and deployers, no matter the risk level of their systems. This rule is not just for high-risk AI systems. It applies to everyone.

GPAI model obligations under Articles 51 to 56 have applied since 2 August 2025. The Digital Omnibus made no changes to the GPAI framework or its application dates.

The Authorised Representative requirement for GPAI model providers has applied since 2 August 2025. Non-EU providers of GPAI models that have been placing their models on the EU market since that date without an EU-established Authorised Representative are already in breach. The Digital Omnibus did not fix this.

What the Extension Does Not Change About Classification

Most compliance roadmaps overlook this point.

The extension changes when you must meet the obligations under Chapters II and III, but it does not change when you need to determine whether your system is high-risk.

The Article 6(3) exception, which allows providers to argue their Annex III system does not pose a significant risk of harm and therefore does not require the full high-risk compliance treatment, requires the provider to document and register that determination.

The Commission’s draft guidelines on high-risk classification, published alongside the Omnibus process, made clear that this exception is narrower than most providers have assumed. Systems generating rankings, scores, recommendations, or credibility assessments that shape a decision cannot rely on Article 6(3).

If you planned to do your classification analysis near the original August 2026 deadline, the extension gives you more time to put compliance measures in place. However, it does not give you extra time to decide whether your system is high risk. That analysis should already be done or in progress.

The Machinery Regulation Fork

The Digital Omnibus made one structural change to the AI Act that has received almost no coverage outside specialist practice: the Machinery Regulation was moved from Section A to Section B of Annex I.

Under the original AI Act, the Machinery Regulation (EU) 2023/1230 was listed in Annex I Section A, meaning AI systems that are safety components of machinery and require third-party conformity assessment were automatically classified as high-risk under Article 6(1). The product safety route applied directly.

Under the amended Act, the Machinery Regulation is in Annex I, Section B. This means AI-enabled industrial systems are no longer automatically considered high risk under the product safety route on the same basis. Instead, the Commission must adopt delegated acts amending the Machinery Regulation itself to incorporate AI-specific requirements, with a deadline of 2 August 2028.

Until those delegated acts are adopted and published, there is a real legal gap for industrial AI companies. The product safety route no longer applies automatically to machinery. The use-based route in Annex III might still apply, depending on what the AI system does. Industrial AI companies that based their compliance on Annex I product safety rules should review their classification approach.

What Changes for Providers

If you are a provider of a stand-alone Annex III high-risk AI system, the December 2027 deadline means you have additional time before the following obligations must be satisfied:

Risk management systemArticle 92 December 2027
Data governanceArticle 102 December 2027
Technical documentation (Annex IV)Article 112 December 2027
Record-keeping and loggingArticle 122 December 2027
Transparency and instructions for useArticle 132 December 2027
Human oversight designArticle 142 December 2027
Accuracy, robustness, cybersecurityArticle 152 December 2027
Quality management systemArticle 172 December 2027
Conformity assessmentArticle 43Before market placement
CE markingArticle 48Before market placement
EU Declaration of ConformityArticle 47Before market placement
EU database registrationArticle 49Before market placement
Post-market monitoringArticle 722 December 2027
Serious incident reportingArticle 732 December 2027
Authorised Representative (non-EU providers)Article 222 December 2027

Conformity assessment and CE marking must be done before you place a high-risk AI system on the EU market, not by a set date. If you launch a new high-risk AI system after 2 December 2027, you must complete conformity assessment first.

What Changes for AI Deployers

If you are a deployer of a stand-alone Annex III high-risk AI system, the December 2027 deadline also moves your Chapter III obligations:

Human oversight implementationArticle 26(1)2 December 2027
Follow provider instructionsArticle 26(3)2 December 2027
Staff competence for oversightArticle 26(4)2 December 2027
Operational monitoringArticle 26(5)2 December 2027
Log retention (6 months)Article 26(6)2 December 2027
Individual notificationArticle 26(8)2 December 2027
Fundamental Rights Impact AssessmentArticle 272 December 2027

The AI literacy obligation in Article 4 still applies to deployers right now, no matter the December 2027 deadline for Chapter III obligations.

The Transitional Provisions: Legacy Systems

Article 111 of the Act, as amended by the Digital Omnibus, sets out transitional provisions for systems already on the market before the applicable obligations entered into force.

Stand-alone Annex III systems placed on market before 2 December 2027, without substantial modification after that date2 December 2028
Annex I product-embedded systems placed on market before 2 August 20282 August 2029
GPAI models placed on market before 2 August 20252 August 2027

The rule on substantial modification has not changed. If a system is substantially modified after the deadline, it is treated as a new system and must meet all obligations from the date of the change. A substantial modification is any change that affects compliance with the Act or changes the system’s intended purpose.

Why the August 2026 Date Is Still Appearing

Every compliance document published before the Digital Omnibus agreement on 7 May 2026 used the August 2026 date. Because of publication and update cycles, many whitepapers, legal guides, training materials, and roadmaps still show the old date.

This creates a real compliance risk for organisations that relied on third-party content instead of the main legal text. The Digital Omnibus, Regulation (EU) 2026/1744, is published in the Official Journal of the European Union and is the current law. Any document that does not reflect this is now out of date, no matter how reliable the source.

Organisations should check the dates in their compliance roadmaps, vendor checklists, or legal briefings directly against Regulation (EU) 2026/1744.

What You Should Do Now

The extension is significant, but it does not remove the need for compliance work. It only changes the deadline for completing it. The steps below are suitable for most organisations affected.

Immediately

Check your classification. If you have not finished a documented Article 6 classification analysis for each AI system you develop or use in an Annex III context, do it now. The Omnibus did not change this requirement. The Commission’s draft guidelines have also made the Article 6(3) exception much narrower.

Check your GPAI status. If you provide a GPAI model and are not based in the EU, you have been required to appoint an Authorised Representative since 2 August 2025. If you have not done this, you are already in breach, and the Omnibus did not change this.

Make sure you meet the Article 4 AI literacy requirement. This now applies to all staff who work with AI systems, regardless of risk level. Keep records of what training has been given and to whom.

Review Article 5. The two new bans on non-consensual intimate imagery and CSAM generation take effect from 2 December 2026. If your system could create this type of content, make sure you address it before that date.

Between now and mid-2027

Start technical documentation scoping under Annex IV. This process helps you find gaps in data governance, system design, and risk assessment, which can take time to fix. For most organisations, starting this work eighteen months before the deadline is best.

Start designing your quality management system under Article 17. The QMS is the framework that supports all other obligations. It usually takes longer to design than to put in place.

Check if you need a notified body. Systems that require third-party conformity assessment under Annex VII must use a notified body. Since their capacity is limited, you should start this process well before the deadline.

By mid-2027

Finish your Annex IV technical documentation. Complete your risk management system under Article 9. Arrange conformity assessment if needed. Prepare your EU Declaration of Conformity and registration materials for the EU database.

By 2 December 2027

Make sure all Chapters II and III obligations are met for stand-alone Annex III systems. Affix the CE marking. Complete registration in the EU database. Set up post-market monitoring and incident reporting procedures.

FAQ

  1. My compliance consultant told me the deadline is August 2026. Who is right?

    Regulation (EU) 2026/1744, effective from 18 July 2026, changed the stand-alone Annex III deadline to 2 December 2027. Any advice using the old August 2026 date is based on the previous version of the AI Act and is no longer correct. The current law is Regulation (EU) 2026/1744 as published in the Official Journal of the European Union.

  2. Does the extension apply to all high-risk AI systems?

    No. The extension to December 2027 only applies to stand-alone Annex III systems under Article 6(2). Annex I product-embedded systems now have a deadline of August 2028. GPAI model obligations were not extended and have applied since August 2025. Prohibited practices and AI literacy rules have also been in force since February 2025.

  3. We are already compliant with August 2026 requirements. Do we need to do anything differently?

    No. Being compliant early does not put you at a disadvantage. If you have already finished conformity assessment, technical documentation, and set up your quality management system, your system meets the December 2027 requirements and you are well prepared. The extension mainly helps organisations that have not finished their compliance work yet.

  4. We are a deployer, not a provider. Does the December 2027 deadline apply to us?

    Yes. Both provider obligations in Chapter II and deployer obligations in Articles 26 and 27 now have a deadline of December 2027 for stand-alone Annex III systems. However, the AI literacy obligation in Article 4 still applies to deployers, regardless of the new deadline.

  5. We are a non-EU company. Does the extension apply to us?

    Yes. The December 2027 deadline also applies to non-EU providers of stand-alone Annex III high-risk AI systems selling in the EU. The Authorised Representative requirement for high-risk AI providers also moves to December 2027. However, if you provide a GPAI model, you have needed an Authorised Representative since August 2025, and the Omnibus did not change this.

  6. What happened to the Machinery Regulation under the Omnibus?

    The Digital Omnibus moved the Machinery Regulation from Annex I Section A to Section B. Now, AI systems that are safety components of machinery are not automatically classified as high-risk under the product safety route. The Commission must update the Machinery Regulation by August 2028. Until then, there is a legal gap for industrial AI companies that planned compliance around Annex I product safety rules. These companies should urgently review their classification approach.

If your organisation is working from a compliance roadmap that references the August 2026 deadline and has not been updated for Regulation (EU) 2026/1744, contact Grecta for a current compliance gap assessment.

This article reflects the text of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, published in the Official Journal of the European Union, and applicable guidance issued by the European AI Office through August 2026. It is published by European Compliance Suite for general informational purposes and does not constitute legal advice. Providers and deployers of AI systems should obtain advice specific to their products, operations, and regulatory context.

Back to Blog