EU AI Act High-Risk AI Systems: What Businesses Need to Do Before December 2027

The high-risk compliance deadline moved to 2 December 2027 under Regulation (EU) 2026/1744, and to 2 August 2028 for AI embedded in regulated products. The obligations did not change. Here is what high-risk means, who is affected, what needs to happen before the deadline, and the 2 August 2026 date that did not move.

Updated 12 August 2026

Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and has been in force since 27 July 2026. It defers the high-risk obligations described below to 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for AI embedded in Annex I regulated products. The Article 50 transparency obligations were not deferred and have applied since 2 August 2026. The obligations set out in this article are unchanged in substance. Only the dates have moved.

The EU AI Act high-risk compliance deadline is now 2 December 2027 for stand-alone systems listed in Annex III, and 2 August 2028 for AI embedded in regulated products under Annex I. If your organisation builds, deploys, or distributes AI systems that fall under Annex III, the obligations themselves are unchanged, and breaches of them carry fines of up to €15 million or 3% of total worldwide annual turnover, whichever is higher. This article explains what high-risk means, who is affected, and what needs to happen before the deadline.

What makes an AI system high-risk

The EU AI Act (Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744) classifies AI systems into four risk tiers: unacceptable, high-risk, limited risk, and minimal risk. The distinction matters because high-risk systems face mandatory obligations including technical documentation, risk management systems, conformity assessment, and EU database registration. Limited risk systems face the transparency duties in Article 50 and nothing more, and minimal risk systems attract no mandatory obligations at all.

Annex III of the Act defines the categories of high-risk AI systems. These include AI used in biometric identification and categorisation of natural persons, management and operation of critical infrastructure, education and vocational training including exam scoring and admissions, employment and worker management including CV screening, interview evaluation, and promotion decisions, access to essential private services and public services including credit scoring, insurance pricing, and benefits eligibility, law enforcement, migration and border control, and the administration of justice.

The practical implication is that if your organisation uses AI for hiring decisions, credit assessments, insurance underwriting, patient triage, student evaluation, or infrastructure monitoring, you are almost certainly operating a high-risk system. The same applies if you build or sell AI tools used by others for these purposes, because the Act applies to providers who build, deployers who use, importers, and distributors.

Provider and deployer both carry obligations

One of the most common misunderstandings is that compliance is only the provider's problem. It is not. The Act assigns distinct obligations to both providers and deployers, and many organisations are both at once, using AI systems built by others while also building internal tools that qualify as AI systems under the Act's broad definition.

Providers must implement a risk management system (Article 9), ensure data governance for training data (Article 10), maintain technical documentation to Annex IV specifications (Article 11), design for transparency (Article 13), enable human oversight (Article 14), ensure accuracy and robustness (Article 15), operate a quality management system (Article 17), complete conformity assessment (Article 43), and register the system in the EU database (Article 49). A provider established outside the Union must also appoint an EU authorised representative by written mandate before the system is placed on the market (Article 22).

Deployers must implement appropriate technical and organisational measures, use the system in accordance with its instructions for use, ensure human oversight, monitor performance, report serious incidents, and conduct a fundamental rights impact assessment for certain high-risk use cases. A deployer who puts its own name on a system, or modifies its intended purpose, can become the provider itself under Article 25.

The nine-step compliance framework

Compliance for high-risk systems is not a single action. It is a structured programme covering nine distinct areas, each mapped to specific articles in the regulation.

Step 1: Classification. Determine whether each AI system is high-risk under Annex III. Document the classification with evidence, rationale, and a named owner. This is the foundation, and everything else depends on getting it right.

Step 2: Risk management (Article 9). Implement a continuous lifecycle risk management system rather than a one-time risk assessment, covering risk identification, analysis, evaluation, and mitigation, with a quarterly review cadence at minimum.

Step 3: Data governance (Article 10). Training, validation, and test datasets must be fit for purpose, traceable, and examined for bias. This is where GDPR and the AI Act intersect most directly, because data used to train systems that process personal data must satisfy both frameworks.

Step 4: Technical documentation (Article 11). Annex IV specifies the required structure and content. This is the primary evidence file for regulatory scrutiny, and it must describe the system's intended purpose, design choices, training methodology, performance metrics, and known limitations.

Step 5: Human oversight (Article 14). Systems must be designed so that people can effectively monitor, interpret, and intervene in their operation. That is not only a design requirement, because it also demands documented procedures, trained personnel, and override capability.

Step 6: Transparency (Article 13). Deployers must receive sufficient information to understand the system's capabilities, limitations, and intended use. Instructions for use must be clear, comprehensive, and accessible.

Step 7: Accuracy and robustness (Article 15). Systems must perform consistently under expected conditions and be resilient against adversarial manipulation and cybersecurity threats. Performance must be measurable and documented.

Step 8: Quality management (Article 17). Providers must operate a documented quality management system covering the full lifecycle, from design and development through testing, deployment, monitoring, and decommissioning.

Step 9: Conformity assessment and registration (Articles 43 and 49). Complete the conformity assessment procedure, sign the EU declaration of conformity, affix the CE marking, and register the system in the EU database. This must happen before the system is placed on the market or put into service.

Why AI alone cannot get you compliant

AI tools will draft risk management policies, generate technical documentation templates, and produce data governance frameworks that look close to finished. What they cannot supply is the interpretation, the judgement, the adaptation to your specific deployment, and the accountability.

When the AI Office or a national competent authority reviews your conformity documentation, they are not checking whether the document exists. They are checking whether it is accurate, complete, and reflects your actual system. A generated risk assessment listing generic risks without addressing your deployment context will not survive scrutiny, and a documentation package that follows the Annex IV structure but contains vague descriptions instead of precise specifications will be challenged.

More fundamentally, someone must sign the declaration of conformity. Someone must be the named contact for the national competent authority. Someone must take accountability for the programme's integrity. That someone cannot be a chatbot.

The Morclear approach

Morclear uses AI to carry the documentation volume and expert review to make the output defensible, then manages the programme continuously so it evolves alongside the regulation and your organisation.

A CORA™ (Compliance Operations & Risk Automation) Gap Assessment at €999, delivered in two weeks, maps your obligations, classifies your systems, scores your current maturity, and produces a prioritised remediation roadmap. From there a CORA™ Programme Build creates the full set of policies, documentation, controls, and procedures over eight to twelve weeks. CORA™ Managed Compliance then runs the programme continuously, monitoring for regulatory change, updating documentation, detecting drift, and reporting status to the board.

The timeline moved. The work did not.

2 December 2027 is a fixed calendar date in law rather than a conditional one. The Commission's November 2025 proposal had tied the deferral to a later assessment that harmonised standards and support tools were ready, which would have left the date open, and the adopted text removed that condition. There is no grace period beyond it, no phased enforcement, and no self-certification route for high-risk systems that require third-party conformity assessment.

The date that did not move is 2 August 2026. Since then the Article 50 transparency obligations have applied, meaning telling people when they are interacting with an AI system, marking synthetic audio, image, video and text in machine-readable form, disclosing deepfakes, and disclosing AI-generated text published to inform the public on matters of public interest. Those duties are not limited to high-risk systems, and from the same date the Commission and national market surveillance authorities gained the power to fine for breaches, so most organisations reading this are already in scope even where the high-risk date sits sixteen months further out. A narrow transition to 2 December 2026 applies only to the Article 50(2) marking obligation, and only for generative systems already placed on the market before 2 August 2026.

A gap assessment takes two weeks and a full build takes eight to twelve. The deferral buys planning room rather than a pause, and the organisations in the strongest position in December 2027 will be the ones that spent the extra time on conformity assessment, technical documentation, and human oversight design rather than standing the programme down. Notified body capacity for Annex III systems is finite and the queue does not get shorter by waiting.

The free AI Act assessment takes ten minutes. It costs nothing, requires no commitment, and returns a scored report showing where your obligations sit and which of the dates you are facing. If you have not yet classified your AI systems under the Act, that is the place to start.

Run Free AI Act Assessment Book a Scoping Call

Primary Regulatory Sources

Morclear resources are independently produced. They do not constitute legal, regulatory, financial, or professional advice.

TAKE ACTION

The August 2026 deadline is 4 months away.

Run your free assessment and download the playbook — both free, both ready now.

Run Free Assessment → Download Playbook
← Back to Morclear Brief