The EU AI Act's high-risk obligations no longer switch on in August 2026. Under the Digital Omnibus, on which the Council and Parliament reached political agreement on 7 May 2026, two fixed calendar dates now govern the heaviest tier of duties: stand-alone high-risk systems listed in Annex III must comply by 2 December 2027, and high-risk AI built into regulated products under Annex I, a group that includes medical devices and in-vitro diagnostics, must comply by 2 August 2028. The risk tiers did not change. The clock did.
Key points#
- Annex III (stand-alone high-risk use cases) moves from 2 August 2026 to 2 December 2027, roughly a sixteen-month deferral.
- Annex I (AI inside products already covered by EU product-safety law) moves from 2 August 2027 to 2 August 2028, a one-year deferral.
- Bans on certain AI practices, general-purpose model rules, and most transparency duties are unchanged and already in force.
- The deferral buys time to finish technical standards. It does not soften the obligations themselves.
The two deadlines that actually changed#
Two dates carry most of the weight. The first covers Annex III, the use-case list that reaches into areas such as biometrics, critical infrastructure, education, employment, and access to essential services. Those duties were scheduled to apply from 2 August 2026 and now apply from 2 December 2027. The second covers Annex I, meaning AI that lives inside a product already governed by EU product-safety law, such as a device regulated under the Medical Device Regulation or the In Vitro Diagnostic Regulation. Those duties were set for 2 August 2027 and now apply from 2 August 2028. The Gibson Dunn analysis of the agreement sets both shifts against their original timelines.
It helps to picture the difference between the two annexes. Annex III is about what a system is used for. Annex I is about where a system sits: inside a product that already carries its own safety regime. A diagnostic algorithm sold as a standalone screening tool tends toward the Annex III side. That same algorithm embedded in a CT scanner or a lab analyzer tends toward Annex I, because the host product is already a regulated medical device.
Why the medical-device date is the one to watch#
If you build or evaluate clinical AI, 2 August 2028 is the date to circle. Software that qualifies as a medical device and also meets the AI Act's high-risk criteria falls under Annex I, and it has to satisfy both regimes at once. Until that date, such manufacturers are not yet required to layer the Act's full high-risk requirements, which cover risk management, data governance, technical documentation, human oversight, and conformity assessment, on top of the device obligations they already carry.
The word "yet" matters. A tool that is high-risk today is still high-risk in 2028. The classification logic, the documentation burden, and the conformity-assessment route are unchanged. What lengthened is the runway, not the distance.
What stayed exactly where it was#
A later start for high-risk duties is not a pause on the rest of the law, and reading it that way would be a costly mistake. Several parts of the Act remain live:
- The Article 5 prohibitions on certain AI practices have applied since February 2025.
- Obligations for general-purpose AI models took effect in August 2025.
- Transparency duties under Article 50, such as telling a person they are dealing with an AI system or that content was AI-generated, stay anchored to 2 August 2026, with only a narrow grace window for marking obligations on systems already on the market.
According to Covington's analysis, registration of high-risk systems in the EU database also stays in place. The architecture of the Act is intact. Only the high-risk compliance clock was reset.
The reasoning: standards before penalties#
The stated motive is sequencing, not retreat. High-risk conformity leans on harmonized technical standards and guidance that tell developers, in operational detail, how to prove a system meets the legal requirements. Those standards were not finished. Co-legislators concluded that firms should not be penalized for missing benchmarks that do not yet exist, and that standards bodies needed more time to produce documents auditors can actually apply. The European Commission's own regulatory-framework materials describe the Act as depending on harmonized standards to translate broad obligations into testable engineering practice, which is precisely the machinery that was running late.
There is a second change worth noting, one of method rather than dates. The original design carried a conditional trigger: high-risk rules would begin once the supporting standards and tools were ready. The final agreement dropped that trigger in favor of fixed dates. The trade-off is familiar from other corners of regulation, including how device transition periods are set. A conditional trigger creates uncertainty that is hard to plan around, because no quality team can schedule validation and audit work against a date that floats. A firm calendar date, even a later one, is something you can build an engineering program toward. Predictability often does more for real-world safety than an aggressive date most of the field cannot meet.
Planning around the new calendar#
The delay changes the schedule, not the destination. A few practical moves follow.
First, classify early. Whether your tool lands in Annex III, Annex I, or neither drives which deadline and which obligations apply, and that determination should not wait for the deadline to arrive.
Second, treat the interim standards work as the specification. When harmonized standards publish, they will define what adequate data governance and meaningful human oversight look like as evidence. Building toward a draft that can be revised later is cheaper than building toward nothing.
Third, keep the unchanged obligations on your calendar. Prohibited-practice and transparency rules are already live, and a device maker still answers to the MDR or IVDR no matter what the AI Act clock reads.
The Omnibus is a schedule change reached through political agreement, and its precise text becomes binding only on formal adoption and publication. The direction is clear enough to plan around: the same high-risk regime, on later fixed dates, with more room for the standards that make it enforceable.
Sources and further reading
Questions and answers
Did the Digital Omnibus weaken the EU AI Act?
No. It postponed when the high-risk tier of obligations starts to apply and swapped a conditional trigger for fixed dates. The obligations, the risk tiers, and the bans on prohibited practices are unchanged.
When must AI-enabled medical devices comply?
High-risk AI embedded in a product regulated under EU product-safety law, including medical devices and in-vitro diagnostics under Annex I, must meet the Act's high-risk requirements by 2 August 2028. Those products still have to satisfy the MDR or IVDR in the meantime.
What is the difference between Annex I and Annex III?
Annex III lists stand-alone high-risk use cases and now applies from 2 December 2027. Annex I covers AI built into products already governed by EU product-safety law and now applies from 2 August 2028.