When do the EU AI Act’s high-risk rules apply after the Digital Omnibus?

The EU AI Act’s high-risk rules apply from 2 December 2027 to AI systems classified as high-risk under Annex III, and from 2 August 2028 to those classified under Annex I, which lists EU product laws. The Digital Omnibus on AI moved both dates. Not everything moved: the transparency duties in Art. 50 have applied since 2 August 2026.

David McMillan, Governed AI Deployment. Checked against the sources on .

§01Art. 113, Regulation (EU) 2026/1744, Art. 6 + Annex III, Art. 111(2)

What moved

The Omnibus amended Art. 113, the article that sets when each part of the Act applies. The deferral covers Chapter III Sections 1 to 3: classification, the requirements for high-risk systems, and the duties of providers, deployers and others in the value chain. That is wider than the requirements alone. It includes the deployer duties in Art. 26 and the fundamental rights impact assessment in Art. 27. It excepts one provision, the Commission’s own duty to publish guidelines on classification.

WhatBeforeNow
Systems classified as high-risk under Annex III2 August 20262 December 2027
Systems classified as high-risk under Annex I2 August 20272 August 2028

Apart from the bans in Art. 5, a high-risk system placed on the market or put into service before its date comes under the Act only if its design changes significantly from that date (Art. 111(2)). AI systems that are part of the large EU IT systems set up by the laws listed in Annex X have their own rule. Providers and deployers of high-risk systems intended for use by public authorities must comply by 2 August 2030 whatever happens to the design.

§02Art. 50, Art. 5, Art. 113

What did not move

The transparency duties in Art. 50 apply from 2 August 2026, as the Act first set. They include telling people they are dealing with an AI system, and marking content an AI system generated.

Chapter III Section 5, on standards, conformity assessment, certificates and registration, also kept its date of 2 August 2026. Whether a given system needs any of these before its high-risk duties apply is a question for counsel.

One of the bans in Art. 5 has applied since 2 February 2025: AI systems that infer the emotions of people in the workplace or in education institutions, except where the use of the system is intended to be put in place or on the market for medical or safety reasons.

§03Art. 5, Art. 111(4), Art. 50(2)

What arrives on 2 December 2026

Two new bans in Art. 5 apply from 2 December 2026. In the article’s words:

(ba) the placing on the market, the putting into service or the use of an AI system that generates or manipulates realistic images, videos, audio or similar material of an identifiable natural person’s intimate parts, or of an identifiable natural person engaged in sexually explicit activities, without that person’s freely-given, specific, informed, unambiguous and explicit consent for that generation or manipulation;

(bb) the placing on the market, the putting into service or the use of an AI system that generates or manipulates material or performance within the meaning of Article 2, points (c) and (e), of Directive 2011/93/EU, except where a ‘without right’ defence applies under national law;

Art. 5

Paragraph 1a of the same article limits when placing such a system on the market, putting it into service or using it is banned, and paragraph 1b sets out what is not manipulation under the first ban.

The same day ends a transition under Art. 111(4). Providers of AI systems, general-purpose AI systems included, that generate synthetic audio, images, video or text and were placed on the market before 2 August 2026 have until then to mark that output as Art. 50(2) requires.

§04GDPR Art. 5(2), DORA Art. 28, DORA Art. 30, PRA SS1/23 Principle 1

What applies now

Other law reaches AI systems today. GDPR and UK GDPR apply to any AI system that handles personal data. The DORA regulation applies to EU financial firms and reaches their ICT suppliers through contract. The PRA’s model-risk principles (SS1/23) apply to the UK banks they cover. Banks already put AI questions in their vendor-risk questionnaires.

The AI Act’s high-risk duties are fixed in law for 2 December 2027 for systems classified as high-risk under Annex III and 2 August 2028 for those under Annex I. Until then they are a standard to build to.

Whether a system is high-risk, and which of these laws reach it, is for the organisation’s counsel to decide.

§06

Book a scoping call

Thirty minutes on one system: what it does, who is asking about it, and which engagement fits. Nothing to prepare. For firms in the UK and Europe.