Skip to main content

EU AI Act deadlines split: high-risk rules moved, model enforcement did not

4 min read

The EU moved major high-risk AI deadlines into 2027 and 2028, while enforcement powers for advanced general-purpose models are already live.

EU AI Act deadlines split: high-risk rules moved, model enforcement did not

If your EU AI Act plan still has one large red circle around August 2026, it is already wrong. EU AI Act deadlines now run on several clocks, and one of the strictest enforcement tracks has started.

The headline “EU AI Act delayed” hides the useful part

Regulation (EU) 2026/1744 moved the application dates for major high-risk AI duties. It did not pause the whole AI Act. The amendment was signed on July 8, published in the Official Journal on July 24, and entered into force on July 27, 2026.

The practical mistake would be to move every compliance task into 2027. Enforcement powers for providers of the most advanced general-purpose AI models began applying on August 2, 2026. A separate transition for older synthetic-media systems ends on December 2, 2026.

The new EU AI Act deadline map

Key dates after Regulation (EU) 2026/1744
DateWhat appliesWho should care
July 27, 2026Regulation 2026/1744 entered into force; Articles 102 to 110 applyProviders, deployers, regulators and product teams tracking enforcement
August 2, 2026AI Office enforcement powers apply for advanced general-purpose AI obligationsProviders of the most advanced general-purpose models
December 2, 2026Pre-August 2 synthetic audio, image, video and text systems must meet Article 50(2) marking dutiesProviders of generative and general-purpose AI systems
December 2, 2027Chapter III Sections 1-3 apply to Article 6(2)/Annex III high-risk systemsStandalone systems used in listed high-risk contexts
August 2, 2028The same sections apply to Article 6(1)/Annex I product-embedded high-risk systemsManufacturers and providers of regulated products with safety-related AI
Source: EUR-Lex Regulation (EU) 2026/1744 and the European Commission AI Act Service Desk.

These dates describe different obligations and system classes. They are not a general exemption from existing privacy, consumer, product-safety, cybersecurity, or sector rules.

High-risk systems received two different extensions

Sections 1, 2 and 3 of Chapter III now apply from December 2, 2027 to systems classified as high-risk under Article 6(2) and Annex III. That group covers listed use cases rather than AI built into a regulated product.

Systems classified under Article 6(1) and Annex I move to August 2, 2028. These are safety-related systems connected to products covered by EU harmonization legislation. The extra eight months reflects the product-regulation path, not a softer risk judgment.

Advanced model enforcement did not wait

The European Commission’s AI Act Service Desk says the AI Office can request information, request access to a model for evaluation, require risk-mitigation measures, and issue fines of up to 3% of global annual turnover. It may also ask a provider to restrict market availability, withdraw a model, or recall it.

The Commission says technical compliance dialogues remain its first tool. Formal powers are available when dialogue is not enough. For a frontier-model provider, that means the operational evidence behind systemic-risk assessment is no longer preparation for a distant date.

Moved high-risk dates do not cancel present general-purpose model duties. They sit on different tracks.

Synthetic-media marking has a nearer deadline

The amendment adds a four-month transition for providers of systems that generate synthetic audio, image, video, or text and were already on the market before August 2, 2026. Those systems must take the necessary steps to comply with Article 50(2) by December 2, 2026.

That date deserves its own workstream. Teams should verify whether output marking survives export, API delivery, post-processing, resizing, compression, and downstream editing. Our coverage of California’s AI transparency law shows why a watermark or disclosure promise is only useful when the implementation survives the actual content pipeline.

Build four calendars, not one

  1. Classify the system. Record whether it is general-purpose, a listed Annex III use case, embedded in an Annex I product, or outside those tracks.
  2. Record your role. Provider, deployer, importer, distributor, and product manufacturer can inherit different duties.
  3. Separate live duties from future duties. Put evidence requests, model evaluations, synthetic-content marking, and high-risk conformity work on their actual dates.
  4. Attach proof to every row. Keep technical documentation, evaluations, logs, controls, and named owners next to the obligation they support.

Builders running capable agents should also compare these legal tracks with operational controls. Our report on AI cyber-test incidents shows what happens when written scope and infrastructure permissions disagree. The law may define the duty; your control plane still has to enforce it.

My verdict: the extension buys implementation time, not idle time

Moving the high-risk dates gives standards, conformity bodies, and product teams more time to align. Use it to build the evidence trail, not to postpone classification. If you discover in late 2027 that a product sits on the 2028 track but its model provider is already subject to another track, the calendar will not rescue the architecture.

Read the primary sources

Which date is actually on your product calendar: 2026, 2027, or 2028?

Leave a comment

Your email address will not be published. Required fields are marked *