Regulation (EU) 2026/1744 moved the stand-alone Annex III deadline from 2 August 2026 to 2 December 2027. Here is what changed, what did not, and what you should do now.
Last updated 6 August 2026
The Short Answer
If your compliance guide, whitepaper, or roadmap lists 2 August 2026 as the EU AI Act high-risk AI deadline, that date is now outdated for most high-risk AI systems.
Regulation (EU) 2026/1744, the Digital Omnibus amendment to the EU AI Act, moved the application date for stand-alone Annex III high-risk AI system obligations from 2 August 2026 to 2 December 2027. The amendment entered into force on 18 July 2026 and applies across all EU member states without national transposition.
Before June 2026, every major compliance guide, whitepaper, legal briefing, and regulatory roadmap used the August 2026 date. Many of these have not been updated. This article explains what changed, the current legal position, and what it means for your compliance program.
What Is Regulation (EU) 2026/1744
Regulation (EU) 2026/1744, known as the Digital Omnibus AI amendment, is a directly applicable EU regulation that amends Regulation (EU) 2024/1689, the EU AI Act. It was provisionally agreed between the European Parliament and the Council on 7 May 2026, approved by the European Parliament on 16 June 2026, formally adopted by the Council, and published in the Official Journal of the European Union. It entered into force on 18 July 2026.
The Digital Omnibus does not run alongside the AI Act. Instead, it directly amends the AI Act. The updated AI Act, with the Omnibus changes, has been the law since 18 July 2026.
The Deadline Changes: Before and After
| Stand-alone Annex III high-risk AI systems (use-based route) | 2 August 2026 | 2 December 2027 | 16-month extension |
| Annex I product-embedded high-risk AI systems (product safety route) | 2 August 2027 | 2 August 2028 | 12-month extension |
| Article 50(2) machine-readable synthetic content marking (systems already on market) | 2 August 2026 | 2 December 2026 | 4-month extension |
| National AI regulatory sandbox establishment | 2 August 2026 | 2 August 2027 | 12-month extension |
| Prohibited practices (Article 5) | 2 February 2025 | Unchanged | No change |
| AI literacy obligation (Article 4) | 2 February 2025 | Unchanged | No change |
| GPAI model obligations (Articles 51-56) | 2 August 2025 | Unchanged | No change |
| Authorised Representative for GPAI providers | 2 August 2025 | Unchanged | No change |
| Two new Article 5 prohibitions (NCII and CSAM) | Not in original Act | 2 December 2026 | New obligation added |
What Is Stand-Alone Annex III
To know which systems the December 2027 deadline covers, you need to understand the two-pathway classification in Article 6 of the AI Act.
The first pathway, Article 6(1), covers AI systems that are safety components of products regulated under EU harmonisation laws in Annex I, such as medical devices, machinery, vehicles, and aviation safety equipment. These product-embedded systems now have a deadline of 2 August 2028.
The second pathway, Article 6(2), covers AI systems used in any of the eight domains listed in Annex III, whether or not they are part of a regulated product. These stand-alone Annex III systems now have a deadline of 2 December 2027.
Annex III covers the following domains:
| Biometric identification and categorisation | Remote biometric identification, emotion recognition, biometric categorisation |
| Critical infrastructure | AI managing energy, water, transport, or digital infrastructure |
| Education and vocational training | Access decisions, student assessment, exam monitoring |
| Employment and workers management | CV screening, candidate ranking, performance monitoring, task allocation |
| Access to essential private and public services | Credit scoring, insurance risk assessment, emergency services dispatch |
| Law enforcement | Recidivism risk assessment, crime analytics, evidence reliability evaluation |
| Migration, asylum, and border control | Application risk assessment, document verification, border monitoring |
| Administration of justice and democratic processes | AI assisting courts, election influence systems |
If your AI system fits any of these domains under Article 6(2), the December 2027 deadline applies to your provider and deployer obligations in Chapters II and III of the Act.
What the Extension Does Not Cover
The sixteen-month extension is specific. It only covers obligations in Chapters II and III for stand-alone Annex III systems. Other parts of the AI Act, including some obligations already in force, remain unchanged.
What Is Already Enforceable and Unchanged
Prohibited practices under Article 5 have been in effect since 2 February 2025. The Digital Omnibus added two new prohibitions, AI systems generating non-consensual intimate imagery and AI systems generating child sexual abuse material, applying from 2 December 2026. The original eight prohibitions are unaffected and have been enforceable for eighteen months.
The AI literacy obligation in Article 4 has applied since 2 February 2025 to all providers and deployers, no matter the risk level of their systems. This rule is not just for high-risk AI systems. It applies to everyone.
GPAI model obligations under Articles 51 to 56 have applied since 2 August 2025. The Digital Omnibus made no changes to the GPAI framework or its application dates.
The Authorised Representative requirement for GPAI model providers has applied since 2 August 2025. Non-EU providers of GPAI models that have been placing their models on the EU market since that date without an EU-established Authorised Representative are already in breach. The Digital Omnibus did not fix this.
What the Extension Does Not Change About Classification
Most compliance roadmaps overlook this point.
The extension changes when you must meet the obligations under Chapters II and III, but it does not change when you need to determine whether your system is high-risk.
The Article 6(3) exception, which allows providers to argue their Annex III system does not pose a significant risk of harm and therefore does not require the full high-risk compliance treatment, requires the provider to document and register that determination.
The Commission’s draft guidelines on high-risk classification, published alongside the Omnibus process, made clear that this exception is narrower than most providers have assumed. Systems generating rankings, scores, recommendations, or credibility assessments that shape a decision cannot rely on Article 6(3).
If you planned to do your classification analysis near the original August 2026 deadline, the extension gives you more time to put compliance measures in place. However, it does not give you extra time to decide whether your system is high risk. That analysis should already be done or in progress.
The Machinery Regulation Fork
The Digital Omnibus made one structural change to the AI Act that has received almost no coverage outside specialist practice: the Machinery Regulation was moved from Section A to Section B of Annex I.
Under the original AI Act, the Machinery Regulation (EU) 2023/1230 was listed in Annex I Section A, meaning AI systems that are safety components of machinery and require third-party conformity assessment were automatically classified as high-risk under Article 6(1). The product safety route applied directly.
Under the amended Act, the Machinery Regulation is in Annex I, Section B. This means AI-enabled industrial systems are no longer automatically considered high risk under the product safety route on the same basis. Instead, the Commission must adopt delegated acts amending the Machinery Regulation itself to incorporate AI-specific requirements, with a deadline of 2 August 2028.
Until those delegated acts are adopted and published, there is a real legal gap for industrial AI companies. The product safety route no longer applies automatically to machinery. The use-based route in Annex III might still apply, depending on what the AI system does. Industrial AI companies that based their compliance on Annex I product safety rules should review their classification approach.
What Changes for Providers
If you are a provider of a stand-alone Annex III high-risk AI system, the December 2027 deadline means you have additional time before the following obligations must be satisfied:
| Risk management system | Article 9 | 2 December 2027 |
| Data governance | Article 10 | 2 December 2027 |
| Technical documentation (Annex IV) | Article 11 | 2 December 2027 |
| Record-keeping and logging | Article 12 | 2 December 2027 |
| Transparency and instructions for use | Article 13 | 2 December 2027 |
| Human oversight design | Article 14 | 2 December 2027 |
| Accuracy, robustness, cybersecurity | Article 15 | 2 December 2027 |
| Quality management system | Article 17 | 2 December 2027 |
| Conformity assessment | Article 43 | Before market placement |
| CE marking | Article 48 | Before market placement |
| EU Declaration of Conformity | Article 47 | Before market placement |
| EU database registration | Article 49 | Before market placement |
| Post-market monitoring | Article 72 | 2 December 2027 |
| Serious incident reporting | Article 73 | 2 December 2027 |
| Authorised Representative (non-EU providers) | Article 22 | 2 December 2027 |
Conformity assessment and CE marking must be done before you place a high-risk AI system on the EU market, not by a set date. If you launch a new high-risk AI system after 2 December 2027, you must complete conformity assessment first.
What Changes for AI Deployers
If you are a deployer of a stand-alone Annex III high-risk AI system, the December 2027 deadline also moves your Chapter III obligations:
| Human oversight implementation | Article 26(1) | 2 December 2027 |
| Follow provider instructions | Article 26(3) | 2 December 2027 |
| Staff competence for oversight | Article 26(4) | 2 December 2027 |
| Operational monitoring | Article 26(5) | 2 December 2027 |
| Log retention (6 months) | Article 26(6) | 2 December 2027 |
| Individual notification | Article 26(8) | 2 December 2027 |
| Fundamental Rights Impact Assessment | Article 27 | 2 December 2027 |
The AI literacy obligation in Article 4 still applies to deployers right now, no matter the December 2027 deadline for Chapter III obligations.
The Transitional Provisions: Legacy Systems
Article 111 of the Act, as amended by the Digital Omnibus, sets out transitional provisions for systems already on the market before the applicable obligations entered into force.
| Stand-alone Annex III systems placed on market before 2 December 2027, without substantial modification after that date | 2 December 2028 |
| Annex I product-embedded systems placed on market before 2 August 2028 | 2 August 2029 |
| GPAI models placed on market before 2 August 2025 | 2 August 2027 |
The rule on substantial modification has not changed. If a system is substantially modified after the deadline, it is treated as a new system and must meet all obligations from the date of the change. A substantial modification is any change that affects compliance with the Act or changes the system’s intended purpose.
Why the August 2026 Date Is Still Appearing
Every compliance document published before the Digital Omnibus agreement on 7 May 2026 used the August 2026 date. Because of publication and update cycles, many whitepapers, legal guides, training materials, and roadmaps still show the old date.
This creates a real compliance risk for organisations that relied on third-party content instead of the main legal text. The Digital Omnibus, Regulation (EU) 2026/1744, is published in the Official Journal of the European Union and is the current law. Any document that does not reflect this is now out of date, no matter how reliable the source.
Organisations should check the dates in their compliance roadmaps, vendor checklists, or legal briefings directly against Regulation (EU) 2026/1744.
What You Should Do Now
The extension is significant, but it does not remove the need for compliance work. It only changes the deadline for completing it. The steps below are suitable for most organisations affected.
Immediately
Check your classification. If you have not finished a documented Article 6 classification analysis for each AI system you develop or use in an Annex III context, do it now. The Omnibus did not change this requirement. The Commission’s draft guidelines have also made the Article 6(3) exception much narrower.
Check your GPAI status. If you provide a GPAI model and are not based in the EU, you have been required to appoint an Authorised Representative since 2 August 2025. If you have not done this, you are already in breach, and the Omnibus did not change this.
Make sure you meet the Article 4 AI literacy requirement. This now applies to all staff who work with AI systems, regardless of risk level. Keep records of what training has been given and to whom.
Review Article 5. The two new bans on non-consensual intimate imagery and CSAM generation take effect from 2 December 2026. If your system could create this type of content, make sure you address it before that date.
Between now and mid-2027
Start technical documentation scoping under Annex IV. This process helps you find gaps in data governance, system design, and risk assessment, which can take time to fix. For most organisations, starting this work eighteen months before the deadline is best.
Start designing your quality management system under Article 17. The QMS is the framework that supports all other obligations. It usually takes longer to design than to put in place.
Check if you need a notified body. Systems that require third-party conformity assessment under Annex VII must use a notified body. Since their capacity is limited, you should start this process well before the deadline.
By mid-2027
Finish your Annex IV technical documentation. Complete your risk management system under Article 9. Arrange conformity assessment if needed. Prepare your EU Declaration of Conformity and registration materials for the EU database.
By 2 December 2027
Make sure all Chapters II and III obligations are met for stand-alone Annex III systems. Affix the CE marking. Complete registration in the EU database. Set up post-market monitoring and incident reporting procedures.
FAQ
My compliance consultant told me the deadline is August 2026. Who is right?
Regulation (EU) 2026/1744, effective from 18 July 2026, changed the stand-alone Annex III deadline to 2 December 2027. Any advice using the old August 2026 date is based on the previous version of the AI Act and is no longer correct. The current law is Regulation (EU) 2026/1744 as published in the Official Journal of the European Union.
Does the extension apply to all high-risk AI systems?
No. The extension to December 2027 only applies to stand-alone Annex III systems under Article 6(2). Annex I product-embedded systems now have a deadline of August 2028. GPAI model obligations were not extended and have applied since August 2025. Prohibited practices and AI literacy rules have also been in force since February 2025.
We are already compliant with August 2026 requirements. Do we need to do anything differently?
No. Being compliant early does not put you at a disadvantage. If you have already finished conformity assessment, technical documentation, and set up your quality management system, your system meets the December 2027 requirements and you are well prepared. The extension mainly helps organisations that have not finished their compliance work yet.
We are a deployer, not a provider. Does the December 2027 deadline apply to us?
Yes. Both provider obligations in Chapter II and deployer obligations in Articles 26 and 27 now have a deadline of December 2027 for stand-alone Annex III systems. However, the AI literacy obligation in Article 4 still applies to deployers, regardless of the new deadline.
We are a non-EU company. Does the extension apply to us?
Yes. The December 2027 deadline also applies to non-EU providers of stand-alone Annex III high-risk AI systems selling in the EU. The Authorised Representative requirement for high-risk AI providers also moves to December 2027. However, if you provide a GPAI model, you have needed an Authorised Representative since August 2025, and the Omnibus did not change this.
What happened to the Machinery Regulation under the Omnibus?
The Digital Omnibus moved the Machinery Regulation from Annex I Section A to Section B. Now, AI systems that are safety components of machinery are not automatically classified as high-risk under the product safety route. The Commission must update the Machinery Regulation by August 2028. Until then, there is a legal gap for industrial AI companies that planned compliance around Annex I product safety rules. These companies should urgently review their classification approach.
If your organisation is working from a compliance roadmap that references the August 2026 deadline and has not been updated for Regulation (EU) 2026/1744, contact Grecta for a current compliance gap assessment.
This article reflects the text of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, published in the Official Journal of the European Union, and applicable guidance issued by the European AI Office through August 2026. It is published by European Compliance Suite for general informational purposes and does not constitute legal advice. Providers and deployers of AI systems should obtain advice specific to their products, operations, and regulatory context.