
Seven weeks. That’s the gap between today and August 2, 2026 — the date the EU AI Act’s high-risk obligations become enforceable.
Annex III covers AI systems in biometrics, critical infrastructure, employment, education, law enforcement, and migration. From August 2, every deployer and provider of high-risk systems must have risk management frameworks, technical documentation, conformity assessments, human oversight mechanisms, and post-market monitoring in place.
Penalties for non-compliance: up to €15 million or 3% of global annual turnover.
Here’s the complication. The European Commission’s Digital Omnibus package, provisionally agreed on May 7, proposes deferring this deadline to December 2, 2027. Sixteen additional months. But the Digital Omnibus has not been formally enacted — it still requires European Parliament and Council approval.
What this means for your compliance team:
→ The legal obligation is August 2, 2026. Not December 2027. Planning around an unenacted extension is material enterprise risk.
→ Harmonised standards arrived in October 2025 — six months late. That compressed the implementation window for every organisation that was waiting for technical guidance before building.
→ Algorithm registers and system intake workflows must be operational, not planned. “In progress” is not compliant.
→ August 2 falls in the middle of European summer holidays. Key compliance, legal, and technical staff will be out. If your implementation isn’t complete before teams break up in July, it won’t be complete by the deadline.
→ If you operate across the EU and the US, note that Colorado’s AI Act — the first US state-level AI regulation — takes effect January 1, 2027. Cross-jurisdictional AI compliance is no longer theoretical.
At S8fe.ai, we help organisations map AI systems against regulatory obligations across jurisdictions — so compliance teams can assess exposure against the deadline that exists, not the one they’re hoping for.
Betting on an extension that hasn’t been enacted is not a compliance strategy. It’s a risk position.
Sources:
• https://labs.cloudsecurityalliance.org/research/csa-research-note-eu-ai-act-high-risk-compliance-deadline-20/
• https://www.legalnodes.com/article/eu-ai-act-2026-updates-compliance-requirements-and-business-risks
• https://www.pearlcohen.com/new-guidance-under-the-eu-ai-act-ahead-of-its-next-enforcement-date/
