AlpacaX

Insights

EU AI Act high-risk deadline moved to 2027. What didn't?

Article 50 stayed in force. Two new bans arrive in December. Only the classification clock moved—to 2027.

Eunyoung Jeong
Eunyoung JeongFounder & CEO · August 26, 2026

Article 50 stayed in force. Two new bans arrive in December. Only the classification clock moved—to 2027.

On 27 July 2026, the EU's Digital Omnibus (Regulation 2026/1744) entered into force (eur-lex.europa.eu; NicFab) and pushed the EU AI Act's (Regulation 2024/1689) Annex III high-risk deadline sixteen months down the road, from 2 August 2026 to 2 December 2027. If you build or deploy a high-risk system under Annex III—recruitment, credit scoring, law enforcement, education, border control—the takeaway sounds simple: exhale, you have until the end of 2027.

That's not quite what happened. The Omnibus split the Act into two speeds. The heavy machinery for your system—Annex III classification, conformity assessment, quality-management paperwork—moved. The lighter transparency regime didn't move—and the Omnibus added two brand-new prohibitions on its way through. If your compliance plan is "wait for December 2027," you're building on only half the timeline that actually binds you.

Two speeds, not one delay

The base EU AI Act (Regulation 2024/1689) already had a staggered rollout before the Omnibus touched it. Chapters I–II, including the original Article 5 prohibited-practices list, took effect 2 February 2025. Governance, GPAI obligations, and penalties (Chapter III Section 4, Chapter V, Chapter VII, Chapter XII, and Article 78, except Article 101) took effect 2 August 2025.

Article 6(1)—the classification rules for high-risk AI embedded in regulated products—was set for 2 August 2027 (artificialintelligenceact.eu, Article 113).

The Omnibus amended two of those dates and left the rest alone. Annex III standalone high-risk systems—recruitment, credit scoring, law enforcement, education, and border-control tools, among others—move from 2 August 2026 to 2 December 2027 (Gibson Dunn).

Annex I embedded high-risk systems, including AI inside medical devices regulated under MDR/IVDR, move from 2 August 2027 to 2 August 2028 (NicFab). Both are real reprieves—sixteen and twelve months—and if your system falls cleanly into one of those two buckets, the relief narrative is accurate.

What the Omnibus didn't touch: Article 50.

EU AI Act key deadlines at a glance:

RequirementOriginal dateCurrent dateStatus
Annex III high-risk (recruitment, credit scoring, law enforcement, education, border control)2 Aug 20262 Dec 2027Deferred 16 months
Annex I embedded high-risk (e.g., AI in MDR/IVDR medical devices)2 Aug 20272 Aug 2028Deferred 12 months
Article 50 transparency (provider + deployer duties)2 Aug 20262 Aug 2026Unchanged, in force
Two new Article 5 bans (non-consensual intimate imagery, AI-generated CSAM)2 Dec 2026New prohibition, not a deferral
EN 18286:2026 QMS standard (supports Article 17)PublishedAlready public

What still landed on schedule

Article 50—the Act's transparency chapter—splits its duties by actor. Providers must design AI systems so people are told when they're interacting with one, unless that's obvious, and must mark AI-generated audio, image, video, or text with a machine-readable label (Article 50(1), 50(2)). On the deployer side: deployers of emotion-recognition or biometric-categorization systems must tell the people exposed to them (Article 50(3)), and deployers who publish deepfakes must disclose that the content is artificially generated (Article 50(4)) (artificialintelligenceact.eu, Article 50).

None of that moved. It has applied since 2 August 2026, and the enforcement regime went live with it—the Commission's AI Office and national authorities began enforcing the Act from that date (Help Net Security, 4 August 2026), with fines up to €15 million or 3% of global turnover—whichever is higher—for non-compliance (artificialintelligenceact.eu, Article 99).

Two things land on 2 December 2026, and they are not the same kind of thing. Providers whose synthetic-content systems were already on the market before 2 August 2026 get until that date to add the Article 50(2) machine-readable marking—a grace period for existing systems, not a delay in the obligation itself (NicFab).

And the Omnibus didn't only defer things—it added two new Article 5 prohibitions, covering non-consensual intimate imagery and AI-generated child sexual abuse material, both phasing in on that same calendar date (NicFab), and both carrying the Act's steepest penalty tier—up to €35 million or 7% of global turnover, roughly double the Article 50 figure above (artificialintelligenceact.eu, Article 99). Two different kinds of obligation sharing one date is easy to conflate. Don't: one is a compliance deadline for systems already on the market; the other is a brand-new set of bans that didn't exist in the original text at all.

There's also a standard to build against now, not eventually. EN 18286:2026, the first standard published in support of AI Act implementation, gives high-risk providers something concrete for the Article 17 quality-management-system requirement—and it's already public, well ahead of the deferred 2027 date (CEN-CENELEC). If you're a provider and you've been waiting for "the standard" before starting QMS work, it exists.

The Act defines no agent category. That's not an exemption.

Here's the objection I hear most from teams building an Annex III product—a hiring tool, a credit-decisioning flow, an eligibility screen—on top of an agent loop wrapped around a foundation model: "we didn't build the underlying model, we just orchestrate it—the AI Act is the model vendor's problem, not ours." The European Commission's own FAQ says otherwise: "the definitions of an AI system in Article 3(1) AI Act and of a GPAI model in Article 3(63) AI Act are sufficient to cover AI agents," and "the rules applicable to AI systems and GPAI models under the AI Act also apply to AI agents" (AI Act Service Desk FAQ).

The Act regulates by risk tier, not by who built the underlying model versus who orchestrates it into a product. The Act never defines "AI agent" as a category of its own—that's a different fact from agents being exempt from it, and only the first one is true.

A recent preprint aimed at providers goes further, arguing that a genuinely autonomous, high-risk agent with untraceable runtime behavioral drift may struggle to satisfy the Act's essential requirements as currently written (arXiv, "AI Agents Under EU Law"). That's one paper's interpretation, not settled law. But the operational problems it names are real regardless of where the classification debate lands: proving what an agent's intent was at the moment it acted, evidencing oversight across a multi-step chain of tool calls, and catching behavioral drift after the system is already live in production.

What you owe, and when it starts

Which side of the Act you're on—provider or deployer—decides which duties are yours, and for an Annex III system built by wrapping a foundation model in an agent loop, that line isn't where it looks. Article 3(11) defines "putting into service" to include supplying a system "for own use in the Union for its intended purpose"—read together with Article 3(3)'s definition of provider, a team that builds its own agentic product and runs it internally can be that product's provider, not only its deployer (artificialintelligenceact.eu, Article 3). Article 25(1) can also pull a deployer into the Article 16 provider obligations: putting your name on a high-risk system already on the market, substantially modifying one, or changing its intended purpose all count—the last of which is exactly how an internal system built for one purpose ends up reclassified into another (artificialintelligenceact.eu, Article 25).

Your duties as a deployer travel with the deferral, not around it. Article 26 sits in Chapter III Section 3, and the Digital Omnibus deferred Chapter III Sections 1 through 3 together—so the Article 26(2) duty to assign human oversight to competent people, and the Article 26(6) duty to keep "the logs automatically generated by that high-risk AI system to the extent such logs are under their control," for "a period appropriate to the intended purpose of the high-risk AI system, of at least six months" (artificialintelligenceact.eu, Article 26), move to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems right alongside everything else in that section.

So does Article 6 itself: its classification rules—bar Article 6(5), the Commission's own duty to publish implementation guidelines, which the Omnibus left in place (artificialintelligenceact.eu, Article 6)—sit in Section 1, deferred on the same schedule.

Article 26 reaches you because what you're running is high-risk under Annex III in the first place: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, or the administration of justice and democratic processes (artificialintelligenceact.eu, Annex III)—the category this piece is written for.

Landing in one of those areas starts the classification question rather than closes it: Article 6(3) takes a system back out of high-risk where it "does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons" (artificialintelligenceact.eu, Article 6; confirmed live in the Omnibus text at eur-lex.europa.eu, recital 22). If that derogation doesn't apply to your system, the sixteen months (twelve, for Annex I) aren't a grace period to spend on something else. They're lead time for building the Art. 26(2) human-oversight and Art. 26(6) log-retention controls before the deferred regime lands.

Not everyone agrees the Omnibus struck the right balance getting here. In a joint opinion on the Commission's proposal, the EDPB and EDPS said they support streamlining AI Act implementation only if it does not lower the level of fundamental-rights protection, and asked co-legislators to consider keeping the original timeline for some obligations, including transparency (EDPB press release; Joint Opinion 1/2026), and the Jacques Delors Centre has argued the broader Digital/AI Omnibus package moves in the wrong direction (Jacques Delors Centre). This is stakeholder criticism, not litigation—but it's a live enough tension that "the deadline moved, case closed" undersells how contested the move actually is.

Where an execution-control layer helps—and where it doesn't

Article 50 binds you narrowly and specifically by role: 50(1) and 50(2) are provider duties (system design, content marking); 50(3) reaches you only if you're running emotion-recognition or biometric-categorization; 50(4) reaches you only if your system publishes deepfakes. Check which of the four actually names your system, and whether you're wearing the provider hat or the deployer hat for it—that's a scoping exercise, not a reprieve. Either way, the bigger lead-time item is Article 26: your system is Annex III high-risk, so its oversight and retention duties are coming, just not yet. That lead time is what you spend building toward Art. 26(2) human oversight and Art. 26(6) log retention before the deferred regime lands—and none of that compliance work is what an execution-control layer does; it's a separate, narrower problem worth solving regardless of your Art. 26 timeline: what actually runs.

A denylist can tell you a command is dangerous. It can't tell you the command doesn't belong to what this session said it was doing. Alpacon's execution-control layer judges the commands an agent runs through its exec lane—the command API, MCP, an agent's execute—against what the session declared it was for: rules first, then LLM intent judgment. A command the risk lane scores in the grey zone can be held for out-of-band human approval before it runs.

What Alpacon doesn't do: your Article 6 classification, your conformity assessment, the legal determination of whether a given system is high-risk in the first place, or your Article 26(2)/26(6) oversight-and-retention compliance program. That work still sits with your compliance team. This is AI-native PAM for the execution layer underneath that determination, not a substitute for it.

The takeaway

The calendar moved. The obligations that actually landed this year didn't: Article 50 has applied since the start of the month, two new prohibitions land in December, and the standard to build a quality-management system against already exists—all while your Annex III clock sits at December 2027. That clock isn't idle time. Article 26 attaches because your system is Annex III high-risk, and the runway the Omnibus just handed you is for building the Art. 26(2) oversight and Art. 26(6) retention controls before that deadline lands—not for waiting to see if you'll need them.

FAQ

Does the Digital Omnibus delay all EU AI Act obligations? No. It deferred Annex III high-risk classification (to 2 December 2027) and Annex I embedded high-risk systems (to 2 August 2028). Article 50 transparency duties were unchanged and have applied since 2 August 2026, and the Omnibus added two new Article 5 prohibitions phasing in 2 December 2026.

Are AI agents exempt from the EU AI Act because the Act doesn't define them? No. The European Commission's own FAQ states the AI system and GPAI model definitions in Articles 3(1) and 3(63) are sufficient to cover AI agents, and the Act's rules apply to them accordingly. The Act regulates by risk tier, not by who built the underlying model versus who orchestrates it into a product.

Tags:
  • EU AI Act
  • Digital Omnibus
  • AI compliance
  • AI governance
  • Regulatory compliance
  • Execution control
Eunyoung Jeong
About the authorEunyoung JeongFounder & CEO

Eunyoung Jeong is the founder and CEO of AlpacaX, where he's building Alpacon—AI-native PAM with runtime execution control for AI agents. He spent over a decade in national-scale network security research and created mTCP, a scalable user-level TCP stack published at USENIX NSDI '14 (USENIX Community Award, 2K+ GitHub stars). He writes on AI agent security and the gap between access control and execution control.


EU AI Act high-risk deadline moved to 2027. What didn't? | AlpacaX