AI Governance Institute

Not sure where to start? Answer 3 questions and get a tailored compliance action plan.

What applies to me? →
Must ComplyRegulationEUHigh risk

Regulation (EU) 2026/1744: AI Act Omnibus Amendment (High-Risk Deadline Deferral)

Issued by

European Parliament and Council of the European Union

liveEffective 2026-08-01EU AI Act High-Risk Deferral (2026/1744)Updated September 2026 · Last verified September 7, 2026
Official document →

Regulation (EU) 2026/1744 defers the AI Act’s high-risk compliance deadlines. Stand-alone Annex III systems move from August 2, 2026 to December 2, 2027. Product-embedded high-risk systems have until August 2, 2028. General-purpose AI (GPAI) duties remain applicable from August 2025. Prohibited practices and AI literacy requirements remain applicable from February 2026.

Applies To

AI deployerAI developerLarge enterprisePublic sector

Overview

Regulation (EU) 2026/1744, part of the European Commission's Digital Omnibus package, changes when the EU AI Act's high-risk obligations start to apply. The single date of 2 August 2026 is replaced by two later ones. Stand-alone Annex III systems have until 2 December 2027. These are high-risk systems that are not safety components of products already covered by EU product law. The deferral reaches all eight Annex III areas: biometrics; critical infrastructure; education and vocational training; employment and worker management; access to essential private and public services, including credit scoring and insurance pricing; law enforcement; migration, asylum, and border control; and the administration of justice and democratic processes. AI that is a safety component of a product regulated under existing EU harmonisation legislation, the Annex I category, is deferred further, to 2 August 2028. That aligns the AI Act obligations with the product certification cycles those sectors already run. Nothing already in force was rolled back. General-purpose AI (GPAI) model obligations have applied since 2 August 2025. The prohibitions on unacceptable-risk practices and the AI literacy duty have applied since 2 February 2026. Governance provisions and penalty rules keep their existing schedule.

Key Requirements

  • •Stand-alone Annex III high-risk systems: meet the full obligation set (risk management, data governance, technical documentation, record-keeping, human oversight, accuracy, robustness and cybersecurity, conformity assessment, and EU database registration) by 2 December 2027.
  • •Annex I product-embedded high-risk systems: the same obligation set by 2 August 2028.
  • •GPAI providers: no change. Obligations continue on their existing timeline.
  • •Prohibited practices and AI literacy: no change. Both have applied since 2 February 2026.
  • •Read the deferral as lead time, not a stand-down. Notified-body and conformity-assessment capacity is limited, and regulators can still act on prohibited-practice and transparency breaches today.

What Your Organization Must Do

  • →Reset any EU AI Act plan that assumed an August 2026 high-risk go-live. The anchor for stand-alone Annex III systems is now 2 December 2027.
  • →Keep classification work moving. Which systems are Annex III stand-alone and which are Annex I embedded now decides which of the two deadlines you are on.
  • →Hold the line on transparency, prohibited-practice, and literacy work. None of it was deferred.
  • →Expect a capacity crunch. A later deadline concentrates demand for notified bodies (independent assessors that check compliance) into 2027, so early engagement still pays.
  • →Fix board and audit-committee reporting so directors are not tracking a deadline that no longer applies.

Playbook Guidance

Step-by-step implementation guidance for compliance teams.

Frequently Asked Questions

Did Regulation (EU) 2026/1744 delay the whole EU AI Act?
No. It defers the high-risk obligations only. GPAI model duties (since August 2025) and the prohibited-practices and AI literacy requirements (since February 2026) are unchanged and still apply.
What are the new high-risk deadlines?
Stand-alone Annex III high-risk systems: 2 December 2027, moved from 2 August 2026. High-risk AI embedded as a safety component in products regulated under existing EU law (Annex I): 2 August 2028.
Which high-risk categories does the deferral cover?
All eight Annex III areas: biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration and border control, and administration of justice.