The EU AI Act high-risk deadline moved. Four things did not
The EU AI Act's high-risk regime moved to 2027 and 2028 in an amendment that took effect this month. A plain reading of what moved, what did not, and which duties still land on 2 August.

Key insights
- Regulation (EU) 2026/1744 entered into force on 27 July 2026 and moved the high-risk obligations to 2 December 2027 for stand-alone systems and 2 August 2028 for systems built into products.
- The new dates are fixed. The Commission had proposed tying them to the availability of standards, and the co-legislators removed that condition.
- Article 50 still applies from 2 August 2026, and three of its paragraphs bind the organisation using a system rather than the one that built it.
- The original prohibitions have applied since 2 February 2025 and the general-purpose model rules since 2 August 2025. Two new prohibitions arrive on 2 December 2026, and the penalty levels are unchanged.
What the amendment actually did
Regulation (EU) 2026/1744 was signed on 8 July 2026, published in the Official Journal on 24 July, and entered into force three days after that. It amends the AI Act in several places, but one change accounts for most of the coverage. The obligations for high-risk systems no longer apply from 2 August 2026.
They apply from 2 December 2027 for stand-alone systems classified under Annex III, and from 2 August 2028 for systems built into products covered by Annex I. Sixteen months for the first group, two years for the second.
The Commission proposed this in November 2025 with a condition attached. The dates would move only once the Commission confirmed that the standards and supporting tools were in place. Parliament and Council removed that condition and set fixed calendar dates instead. Nothing now suspends them, and nothing brings them forward.
The reason given for the delay is that the ground was not ready. No harmonised standard under the Act has been cited in the Official Journal, so the presumption of conformity those standards create still does not exist. The European standards bodies are working to an accelerated plan aimed at late 2026.
- Prohibited practices applyTogether with the obligation in Article 4 on the competence of the people who operate these systems.
- Obligations for general-purpose AI models applyThe governance structure and most of the penalty framework take effect on the same date.
- The general application dateArticle 50 on transparency in full, including the paragraphs that bind deployers, together with the market surveillance provisions.
- Two new prohibitions apply, and the marking grace period ends
- Regulatory sandboxes due in every member state
- High-risk obligations apply to stand-alone systemsSystems classified as high-risk under Annex III.
- High-risk obligations apply to systems built into productsSystems classified as high-risk under Annex I.
- Deadline for public authorities' existing systemsSystems intended for use by public authorities that were on the market before the date of application.
Source: Regulation (EU) 2024/1689 and Regulation (EU) 2026/1744
The amendment does other things. It reinstates the duty on providers to register high-risk systems in the EU database, including those claiming an exemption from the classification. It postpones national regulatory sandboxes to 2 August 2027. It adds two prohibitions.
None of that changed the headline, and the headline is what most compliance plans were built on.
The part that did not move
Article 50 applies from 2 August 2026, exactly as it always did. It is the transparency chapter, and it is the part of the Act that reaches ordinary organisations first. The market surveillance provisions in Articles 73 to 94 arrive on the same date, which is what gives the rest of it teeth.
Three of its paragraphs bind deployers rather than providers. Run a system that recognises emotions or sorts people by biometric data, and you have to tell the people exposed to it. Publish a deepfake, and you have to disclose it at first exposure.
The third is the one that catches communications teams. Text generated by AI and published to inform the public on a matter of public interest has to be labelled, unless a person has reviewed it and someone holds editorial responsibility for it.
No supplier can take over a duty the Act places on the organisation using the system.
That is the point most often missed. An organisation that has decided the Act is a problem for its suppliers has still bought the obligations in Article 50(3) to (5) along with the software, and cannot buy its way back out of them.
One transitional window follows, in a new Article 111(4). Providers whose generative systems reached the market before 2 August 2026 have until 2 December 2026 to bring their output into line with the marking duty in Article 50(2). Anything placed on the market after that date marks from the first day.
Two new prohibitions arrive on 2 December 2026 as well. They cover the generation of non-consensual intimate imagery of identifiable people, and child sexual abuse material. Because they sit in Article 5, they carry the heaviest penalty tier in the Act.
The part that was already due
The original prohibitions in Article 5 have applied since 2 February 2025. So has the obligation in Article 4 covering the competence of the people who operate these systems, although the amendment softened it from ensuring a sufficient level to taking measures that support its development. The new wording also adds that the duty does not require anyone to guarantee a particular level of AI literacy in individual people. The obligation became weaker in substance, not only in tone. The recitals to the amendment say at the same time that AI literacy should be a strategic priority regardless of whether it is a legal obligation and regardless of any penalties. That is unusually direct for a legal text: the case for competence is made on operational grounds, not on enforcement.
The rules for providers of general-purpose AI models have applied since 2 August 2025, together with the governance structure and most of the penalty framework.
Source: Regulation (EU) 2024/1689, Article 99
The levels are unchanged. The percentages apply to total worldwide annual turnover for the preceding financial year, and the higher of the two figures is the ceiling.
Small and medium enterprises get the lower of the two instead. The amendment extended a similar cap to small mid-caps, meaning firms of 250 to 750 employees, for the middle and lowest bands but not for a breach of the prohibitions.
Whether any of this reaches you
High-risk is a narrower category than the phrase suggests. Which side of the line a system falls on decides what the work has to cover, and the line rarely runs where people assume.
Annex III lists the stand-alone cases. Systems used in recruitment and in decisions about promotion or termination. Systems that decide access to education, or score examinations.
Also on the list: systems that determine eligibility for essential public benefits, for emergency services, for credit, or for the pricing of life and health insurance. Systems used in law enforcement, in migration and border control, and in the administration of justice.
Annex I is the other route, and it covers systems that are safety components of products already regulated at EU level, from machinery and medical devices to vehicles and lifts. Those move to 2 August 2028.
The amendment also narrowed what counts as a safety component. A system used only for non-safety-related aspects of user support, performance optimisation, service efficiency, automation, convenience or quality control is not a safety component, and so does not reach high-risk by that route. That lifts a whole class of systems out of the grey zone.
Public authorities get a transitional rule of their own. Systems intended for use by public authorities that were already on the market before the date of application have until 2 August 2030 to comply. Four years, and the longest period anywhere in the Act.
Most organisations run neither. What they run is a general-purpose assistant, a document tool, a service chatbot. Those usually fall outside the high-risk regime, and did before the amendment too, so the postponement moves nothing for them. What they do not fall outside is Article 50.
The contracts that now point at the wrong date
There is a practical consequence that surfaces in procurement before it surfaces anywhere else.
Supplier agreements signed in the past eighteen months routinely carry a clause requiring compliance with the AI Act by 2 August 2026. That clause now points at a date on which most of the obligations it refers to do not apply.
Whether it still binds the supplier to anything depends on how it was drafted. A clause tied to the Act as it stands from time to time survives the amendment. A clause tied to a fixed date does not, and the drafting was rarely that careful.
The same is true in the other direction. A public buyer who wrote the original date into a framework agreement may find a supplier reading the postponement as relief from a term the buyer thought was fixed. It is cheaper to find out now than at the first delivery review.
Who enforces it, and in Sweden that is still open
The Act applies whether or not a member state has finished appointing anybody. The Swedish arrangement is not finished, and the obligations hold regardless.
A government inquiry reported in October 2025 with a proposed structure. The Post and Telecom Authority would lead market surveillance, alongside the data protection authority, the financial supervisor, the medical products agency and the national accreditation body in their own domains.
It has not been enacted. There is no bill. The penalty framework, meanwhile, has been available since August 2025.
One exception is worth knowing. The amendment gives the AI Office exclusive supervision over systems built on a general-purpose model from the same provider, and over systems that form part of very large online platforms, with its own powers to investigate, inspect and impose penalties. For that part of the market, the Swedish appointments are not the deciding factor.
The practical consequence is small but real. If something goes wrong with a system you deploy this autumn, the question of who asks you about it, and under which statute, has no settled Swedish answer yet. That is a reason to keep your own record, not a reason to wait.
Why sixteen months is not a reprieve
The deadline moved backwards. Deployment did not.
In 2024, 13.5% of EU enterprises with ten or more employees used AI. In 2025 it was 20.0%. Sweden went from 25.1% to 35.0%, and among large EU enterprises the figure reached 55.0%.
Eurostat added a category for tools generating images, video and audio to the 2025 survey, so part of the increase is definitional.
Source: Eurostat, use of artificial intelligence in enterprises, December 2025
An organisation that files the postponement as time won will meet the high-risk regime in December 2027 with a larger estate than it has today, assembled faster, and documented no better.
The inventory does not get easier by being deferred. It gets longer.
There is a second cost, harder to see. Sixteen months is long enough for the people who built the first compliance plan to move on, and for the plan to become a document nobody can explain. The work that survives a postponement is the work that was written down properly.
What the sixteen months are for
Three things are worth doing before the end of this year, and none of them wait on standards that do not yet exist.
Know what you are running. Most organisations cannot produce a list of the AI systems in use across the business. It is the first document all of this requires and the slowest one to assemble, and nothing about December 2027 makes it shorter.
Sort that list against Annex III. The classification decides whether the new dates are a deadline or a non-event for you, and it decides which of the two dates applies. For a system that is a safety component of an already regulated product, that assessment is made together with the notified body.
Then read Article 50. It applies to how you use systems rather than what you build, and it is the part of the Act that most organisations will actually have to do something about.
The full calendar, every date and what applies from when, sits on our EU AI Act page.
Common questions
Less than the headlines suggest. The EU AI Act's high-risk obligations moved to 2 December 2027 and 2 August 2028, but Article 50 transparency still applies from 2 August 2026, the original prohibitions and the Article 4 AI literacy duty have applied since 2 February 2025, and the rules for general-purpose AI models since 2 August 2025. None of those dates moved.
The new EU AI Act dates are not conditional on anything. The Commission proposed making them depend on confirming that standards and supporting tools were available, and Parliament and Council removed that condition and set fixed calendar dates instead. They do not move again without a further amending regulation. No harmonised standard under the Act has been published yet.
Article 50 of the EU AI Act applies to deployers as well as providers. Paragraphs 3 to 5 bind the organisation deploying a system: notice to people exposed to emotion recognition or biometric categorisation, disclosure of deepfakes at first exposure, and labelling of AI-generated text published to inform the public on matters of public interest. They apply from 2 August 2026.
Article 99 of the EU AI Act places breaches of Article 50 in the band reaching 15 million euro or 3 per cent of total worldwide annual turnover, whichever is higher. Small and medium enterprises get the lower of the two figures instead, as do small mid-caps under a cap added by Regulation (EU) 2026/1744. The penalty regime has applied since 2 August 2025.
That depends on how the clause is drafted, not on the EU AI Act itself. A clause tied to applicable law as amended survives the change and now points at 2 December 2027 for Annex III. A clause locked to the fixed date of 2 August 2026 now names a day on which most of the duties it refers to do not yet apply. Contract drafting has rarely been that careful, so this is cheaper to settle now than at the first delivery review.
Sweden has not finished appointing its authorities, and the EU AI Act applies regardless. The Swedish Post and Telecom Authority (PTS) holds an interim mandate as national competent authority until 31 December 2026, and a public inquiry has proposed it for the permanent role. The Swedish Authority for Privacy Protection covers AI that processes personal data, Finansinspektionen the financial sector, Läkemedelsverket medical devices and care, and Swedac accredits the notified bodies.
If this lands on your desk, we should talk.
Ampliro Insights
New analysis, roughly weekly.
We write when the rules change and when something turns out to work in practice. One piece at a time, no sequences, and you can leave from any issue.
We store your address to send Ampliro Insights, and for nothing else. More in the privacy policy.