Blog

The EU AI Act High-Risk Deadline Just Moved: What Actually Changes

If you have been planning a Claude deployment, or any AI system, around the EU AI Act's 2 August 2026 high-risk deadline, the ground shifted under that plan this month. The Digital Omnibus on AI, the first significant amendment to the Act since it was adopted in 2024, defers the high-risk obligations that were due to apply from August 2026. The political and legislative process is essentially complete: the European Parliament formally adopted the text on 16 June 2026, the Council gave its final approval on 29 June, and the final act was signed on 8 July. What remains is publication in the EU's Official Journal, expected by the end of July, with the amendments entering into force three days after that.

This is worth a clear, accurate explanation rather than a headline, because the honest answer is more nuanced than "the deadline moved" and the nuance is exactly what determines whether you should relax or keep building.

What actually moved

The obligations for stand-alone high-risk AI systems, the category defined in Annex III of the Act, are deferred from 2 August 2026 to 2 December 2027, a sixteen-month postponement. Annex III covers a specific list of use categories, and it is worth naming them precisely because this is where most enterprise AI risk actually concentrates: employment and worker management (including recruitment and candidate assessment), access to essential services, education, credit scoring, law enforcement, and critical infrastructure, among others.

Separately, high-risk systems embedded in products already governed by EU product safety law, Annex I of the Act, covering things like medical devices and machinery, move from an August 2027 deadline to August 2028.

For an organisation running candidate-matching or workforce-management AI, or any of the other Annex III categories, this means the heaviest set of obligations, risk management systems, technical documentation, human oversight design, conformity assessment, registration, now has a runway measured in years rather than weeks.

What did not move

This is the part that gets lost in the relief of a deadline extension, and it matters.

Article 50 transparency obligations remain live from August 2026, unaffected by this delay. If you build or deploy chatbots, or systems that generate synthetic content, the requirement to make that clear to the people interacting with it was not part of what got deferred. Organisations that assumed the entire Act paused should check this specifically.

The prohibitions that took effect in February 2025 are unchanged. The Act's ban on certain AI practices, deemed to carry unacceptable risk, has applied since then and is not touched by this amendment.

The Act's underlying structure is unchanged. This is a targeted simplification package, not a rewrite. The risk-based approach, the classification categories, and the eventual obligations all remain exactly as they were. What changed is the calendar, not the substance.

One important caveat on timing. As of this writing, the amendment is adopted but not yet in force, pending that Official Journal publication. Until it is formally published, the original 2 August 2026 deadline remains, technically, the legal baseline. The gap between now and formal publication is expected to be measured in days, and every credible legal analysis we have reviewed treats the deferral as settled in substance. But if your compliance programme has a hard internal date, note precisely when the new dates take legal effect, not just when they were politically agreed.

Why extra time is not the same as no urgency

Several European law firms tracking this amendment have converged on the same piece of advice, and it is worth taking seriously: use the additional time, do not wait for it.

The reasoning is straightforward. December 2027 will arrive. The obligations that were deferred did not disappear, they were postponed, and the organisations that treat this as a reason to stop preparing will face the same compressed, expensive scramble in eighteen months that they were facing in weeks before this amendment landed. The organisations that use the runway well will spend it on the genuinely hard, genuinely time-consuming work: building the data governance that makes a system's decisions traceable, designing human oversight into the workflow rather than retrofitting it, and establishing the technical documentation discipline that a conformity assessment will eventually require. None of that work gets faster by waiting. It gets more expensive, because the people who understand why a system was built a certain way move on, and reconstructing that understanding under deadline pressure is always the hard way to do it.

There is also a quieter opportunity in this. Being visibly, demonstrably ready ahead of a deadline that most competitors will treat as distant is itself a differentiator, with regulators, with enterprise customers who ask about your AI governance in procurement, and with your own board. Governance built early is not a cost centre. It is evidence.

What this means if you are building on Claude

For any Claude deployment that touches an Annex III category, and for staffing and healthcare organisations in particular, candidate-matching AI is the clearest example, this changes the shape of the runway without changing the destination. Our recommendation, consistent with the method in our enterprise implementation playbook, is to classify honestly now: build the inventory of what you are running or planning, map each system against the Annex III categories, and get a written answer on where you sit. That conversation takes an afternoon. Skipping it and finding out the hard way later does not.

From there, the extra runway is best spent on the structural work: the data governance, human oversight design and audit logging that underpin our security and governance service, built into the architecture from the start rather than retrofitted against a looming date. The deadline moved. The discipline required to meet it well did not.

Where to start