2027-12-02 · EU · 476 days from today
Providers and deployers of stand-alone high-risk AI systems (hiring, credit scoring, biometrics, education, essential services) must comply with the full EU high-risk regime by December 2, 2027. This obligation was deferred from August 2, 2026.
What it requires
High-risk systems must implement: risk management processes, data governance practices, technical documentation, event logging, human oversight mechanisms, conformity assessment procedures, and registration in the EU database. These requirements apply to stand-alone systems classified in Annex III of the AI Act, as amended by the Digital Omnibus. Your team should verify which of your systems fall into the listed high-risk categories and map each requirement to your current practices.
Who it binds
Providers developing or placing high-risk systems on the EU market, and deployers (organizations using these systems in the EU). This spans compliance teams, product managers, data governance leads, and legal counsel. Both in-house developed systems and vendor solutions are in scope if they perform hiring decisions, credit assessments, biometric identification, educational placement, or decisions on access to essential services.
How to check whether you comply
Audit your AI inventory to identify systems that perform hiring, credit scoring, biometric analysis, educational evaluation, or essential service decisions.
Map each high-risk system against the five obligations: risk management, data governance, documentation, logging, and human oversight. Verify which are already in place.
Confirm your conformity assessment approach—internal, third-party, or module-based—and document the decision.
Check the EU AI Registry format and confirm your registration plan and timeline.
What teams get wrong
The original deadline was August 2, 2026, but it was deferred to December 2, 2027 under the Digital Omnibus. Verify your implementation timeline reflects the updated date. This obligation is confirmed, but teams often underestimate the scope of 'stand-alone' systems or conflate high-risk requirements with lower-risk transparency rules.
This is one of 17 dated AI obligations we track
You have 476 days on this one. There are 16 others across the EU, UK, and US, and they do not arrive in a convenient order. The AI Compliance Deadline Radar lists every one of them with a live countdown.
Get The AI Reg Brief — free. Twice a month, three minutes. Every issue leads with a countdown to the next deadline that binds you, so the one about to land finds you rather than the other way round.
AI Act — Article 111(3), legacy GPAI models — EU, 2027-08-02
AI Act — Annex I high-risk AI in regulated products (as amended) — EU, 2028-08-02
AI Act — Article 50 marking, systems already on the market — EU, 2026-12-02
Source
Not legal advice. This summarizes a public source so you can act on it; verify against the primary text before you rely on it.
