heldr.Compliance radar

The EU AI Act deadlines moved to 2027 and 2028. This is what changes

Written by Heldr compliance team28 September 20268 min read

Rules for high-risk AI in areas such as employment now apply from 2 December 2027. For AI embedded in regulated products, the date is 2 August 2028. Other duties already apply.

In brief

  • Annex III high-risk rules apply from 2 December 2027. Product-related high-risk rules follow on 2 August 2028.
  • Your AI inventory determines which duties apply and who owns them.
  • The postponement does not apply to every AI Act obligation.

What actually changed?

The change concerns the rules for high-risk AI systems. For uses listed in Annex III, including certain systems for employment, education and essential services, the rules apply from 2 December 2027. High-risk AI embedded in regulated products listed in Annex I follows on 2 August 2028.

This is not a general postponement of the entire AI Act. Rules on prohibited AI practices already apply. The revised framework also does not remove the need to understand how AI is used inside your organisation.

For SMBs, the practical starting point is not a legal memo. It is one reliable register of every AI tool, supplier, data source and responsible owner.

Imagine a recruitment team using an AI assistant to rank applications while marketing uses the same provider to draft social posts. The brand name is identical, but the impact is not. One use may influence a person's access to work, while the other mainly creates a quality and reputation risk. That difference is why an inventory must record use cases, not just software names.

Use the time you gained

Assign an owner to every system, record its purpose and data access, and decide what evidence must exist before use continues. That turns compliance into an operating rhythm instead of a last-minute project.

Do not try to document everything at once. Begin with systems that affect people, money, safety or essential operations. For each one, answer five questions: what is the intended purpose, who is affected, which data enters the system, what can the output trigger and who can stop or correct it?

What management should ask this month

Ask each team lead to name the AI tools already used in daily work, including features hidden inside existing software. Then compare that list with procurement records and access logs. The gaps between those lists are often where unmanaged use appears.

Choose one person who owns the register and set a monthly update moment. New tools should not enter through a policy document alone. Procurement, IT, privacy and the business owner need one short approval route that people can actually follow.

A deadline is not the goal

The useful outcome is not a folder marked compliant. It is a business that can explain where AI is used, make deliberate risk decisions and produce evidence without a scramble. That also makes vendor selection faster and incidents easier to contain.

Treat dates in summaries and news reports with care. The official regulation and European Commission guidance remain the leading references. Translate every legal milestone into an internal owner, decision and piece of evidence.

Sources and further reading

Last reviewed on 28 September 2026. Legislation and official guidance may change.

Not compliant yet?

Start the free AI Compliance Scan and know where you stand in 30 minutes.

Start the scan

Related within this theme