Back to blogCompliance

    AI Act: what actually happens on 2 December 2027

    The Digital Omnibus moved high-risk obligations to 2027 and 2028. Counting the work it takes to arrive ready, fourteen months is a tight deadline.

    ZeroFive.AI October 7, 2026 7 min

    In short. The Digital Omnibus moved the obligations on high-risk systems under Annex III from 2 August 2026 to 2 December 2027, and those on systems embedded in regulated products to 2 August 2028. The common reading is that there is time. Counting the actual work it takes to arrive ready, fourteen months is a tight deadline for an organisation that today doesn't know which AI systems it has in production.

    Regulation (EU) 2026/1744 entered into force on 27 July 2026, days before the deadline that would have made high-risk obligations applicable. The practical result is that many companies stopped work they had just started, reading the delay as permission to postpone. That is the reading that costs most.

    What was delayed and what wasn't

    The delay covers a precise perimeter. Prohibited practices and the AI literacy obligation under Article 4 remain applicable, in force since February 2025, as do obligations for providers of general-purpose AI models since August 2025, and from 2 August 2026 the general application of the regulation with the transparency obligations of Article 50, national authorities and the penalty regime.

    WhatFrom when
    Prohibited practices and the AI literacy obligation2 February 2025
    Obligations for providers of general-purpose AI models2 August 2025
    General application, Article 50 transparency, penalties2 August 2026
    Standalone high-risk systems under Annex III2 December 2027
    High-risk systems embedded in regulated products2 August 2028
    High-risk systems intended for public authorities2 August 2030

    A chatbot that doesn't declare itself an automated system is out of line today, and recruitment software remains subject to the GDPR and labour law, with every obligation that follows, whatever the date the AI Act ones start to bite.

    Fourteen months, counted properly

    The distance between today and December 2027 looks generous until the work is laid out. This is the sequence we see in real projects, with the durations we observe in mid-sized organisations.

    PhaseTypical duration
    AI system inventory, including modules inside software already in use6-10 weeks
    Risk classification and role identification, provider or deployer4-6 weeks
    Gap analysis on systems that turn out to be high risk4-8 weeks
    Contract renegotiation with suppliers on documentation and logs3-6 months
    Documentation, risk assessment, human oversight4-6 months
    Role-based training with individual evidencecontinuous
    Internal verification ahead of the deadline2 months

    The phases don't all run in sequence, but two of them depend on third parties and won't compress. Renegotiating with a supplier who has never produced the required documentation takes the time of their release cycle, not yours.

    Which framework does your company actually need?

    AI Rating measures maturity across the four areas of the model and shows where to start, with priorities and estimated effort.

    Start your AI Rating

    The recurring mistake is handing preparation to legal or compliance and waiting for the result. Those functions can read the regulation, they don't know which systems are switched on across the company, and they can't know, because the information sits split between whoever signed the contracts, whoever activated the modules and whoever uses them daily.

    The first step is technical and organisational at once. It takes a survey starting from active software contracts and systems in use, asking each function which predictive modules have been switched on over the last two years. In the projects we have run, between a third and half of the relevant systems were unknown to whoever handled compliance.

    The second step concerns the role. A company using a supplier's model is a deployer, with its own obligations, and can become a provider if it substantially modifies the system, rebrands it or uses it for a purpose other than the one the supplier declared, and in that case the volume of work changes by an order of magnitude. That distinction belongs before any plan is built.

    Who arrives late, and how to spot them

    Organisations arrive late when they wait for harmonised technical standards before starting, because those standards serve to demonstrate conformity by presumption, while knowing which systems you have, who authorised them and what they actually do is work that depends on no standard and can be done now.

    Whoever treats the deadline as a one-off project also arrives late. High-risk systems require post-market monitoring, documentation upkeep and incident recording, so an organisation building everything in the three months before the deadline reaches the line with its paperwork in order and without the oversight it needs from the next day.

    Where to start

    The prerequisite is the AI system inventory, followed by risk classification and the AI systems register.

    The detail of what has been binding since 2 August 2026 is in AI Act: what is binding, while the content of the package that moved the dates is in Digital Omnibus.

    To measure the distance between where you stand and what December 2027 will require, see the AI Rating page. For an assessment you can book a session or start the self-assessment.

    Want to discuss this for your company?

    30 minutes with us to figure out where to start, or an AI Rating to measure your starting point.

    #AI Act#Digital Omnibus#high risk#deadlines#Annex III
    Share

    Keep reading