EU AI Act deadlines shift for high-risk deployments
The EU AI Act classifies AI systems by intended purpose and context rather than underlying technology, creating obligations for providers, deployers, importers, distributors, and general-purpose AI model providers. It entered into force on August 1, 2024, and applies beyond the bloc when an AI system’s output is used by people in the EU.
The regulation uses four risk tiers: unacceptable, high, limited, and minimal. Unacceptable practices are banned, high-risk systems face conformity assessment, documentation, and oversight duties, limited-risk systems must meet transparency requirements, and minimal-risk systems carry no specific EU AI Act obligations. The same model can fall into different tiers depending on deployment, with Article 6(3) carve-outs narrowing some Annex III high-risk classifications.
The 2026 Digital Omnibus on AI changed compliance planning by delaying high-risk obligations for stand-alone Annex III systems to December 2, 2027, and systems embedded in already-regulated products under Annex I to August 2, 2028. Other rules still proceed earlier, including Article 5 prohibitions and Article 50 transparency duties.
Security teams are expected to inventory AI systems, classify use cases, map data flows, review third-party model contracts, and monitor sanctioned and shadow AI tools. Penalties under Article 99 reach up to 35 million EUR or 7 percent of worldwide annual turnover for prohibited practices, up to 15 million EUR or 3 percent for most other obligations, and up to 7.5 million EUR or 1 percent for incorrect or misleading information.