High-risk moved to December 2027, and the runway became the story
Standalone Annex III high-risk obligations apply from 2 December 2027 and embedded Annex I obligations from 2 August 2028, both as a result of Regulation (EU) 2026/1744 in force since 27 July 2026.
- In force since
- 27 July 2026
- Reviewed and published
- 24 August 2026
- modules reviewed
- 206
- competencies touched
- 18
A postponement is the easiest change to get wrong in training material, because a date sits in dozens of sentences and every one of them has to move at the same time. This one also carried Article 27, since the fundamental rights impact assessment follows the high-risk regime.
What changed
- Standalone high-risk obligations under Annex III moved from 2 August 2026 to 2 December 2027.
- High-risk AI embedded in regulated products under Annex I applies from 2 August 2028.
- Article 27, the fundamental rights impact assessment, follows the high-risk regime and lands on 2 December 2027.
What it means for your people
- There is runway, and runway is only worth something if it is used. Registration and an evidence file are heavy, and neither gets lighter by starting later.
- The scope of Article 27 is narrower than most summaries suggest. It covers public bodies, private providers of public services, and deployers under Annex III point 5(b) and 5(c). Critical infrastructure under point 2 is not in scope.
- For most teams the practical consequence is sequencing rather than relief: transparency is live now, high-risk lands later.
What we changed in the platform
- Re-dated 18 competencies, covering 206 modules, so no module still teaches the old August 2026 date.
- Kept the Article 27 scope explicit in every module that mentions it, because the wrong scope is a more expensive error than the wrong date.
- Added the timeline to the automated freshness check, so a future shift surfaces as a review task rather than as a customer question.
Obligations this entry is anchored to
Annex III: high-risk AI
praxikon:eu:ai-act:obligation:annex-iii-high-risk
sha256 c0afd1789ed393ba3f9ce04205bd74b4831ff0fd58146108fdd8dd08d2f4f6c9
Each obligation carries the payload hash of the object version this entry was written against, so the claim can be verified rather than trusted. Implementation graph release: 2.1.0.
Questions people ask about this change
- Does the postponement mean we can wait?
- It means the deadline moved, not that the work shrank. Registration, documentation and an evidence file take time to assemble, and the transparency duties that apply today are unaffected by this change.
- Does every deployer of a high-risk system have to do a FRIA?
- No. Article 27 applies to public bodies, private providers of public services, and deployers under Annex III point 5(b) on creditworthiness and 5(c) on life and health insurance. Critical infrastructure under point 2 is excluded.
Official sources
See which of your roles this reaches
The 5-minute scan maps your AI use to the people around it and shows where evidence is still thin.