EU AI Act High-Risk Deadline Moved to December 2027: What Changes — and What Doesn't
Published: July 2026
On 29 June 2026, the Council of the EU gave final approval to the AI Act simplification package, deferring the high-risk obligations many compliance teams had spent two years preparing for. Standalone high-risk AI systems now have until 2 December 2027. AI embedded in regulated products gets until 2 August 2028.
If your first reaction was relief, that's fair. But the deferral changes less than the headlines suggest — and the AI systems you will have to account for in 2027 are being deployed inside your organisation right now.
What was decided, by whom, and when
The European Parliament endorsed the simplification package on 16 June 2026; the Council of the EU gave it final approval on 29 June 2026. The package moves the application date for high-risk obligations — originally due in August 2026 — to 2 December 2027 for standalone high-risk systems (the Annex III use cases: hiring, credit, education, access to essential services and similar) and to 2 August 2028 for AI embedded in products already covered by EU product-safety legislation.
The package did not only delay. It also expanded the Act's list of prohibited practices: generating non-consensual intimate content and child sexual abuse material are now explicitly banned.
One more date matters. The European Commission published draft guidelines on high-risk classification under Article 6 in May 2026, with a targeted consultation running to 23 July 2026. The classification guidance is arriving now, not in 2027 — a clear signal of when the Commission expects scoping work to happen.
Why the deadline moved
The deferral sits inside a broader EU push to simplify digital regulation and reduce implementation burden. The unglamorous reality behind it: much of the supporting infrastructure — harmonised technical standards, classification guidance, conformity-assessment capacity — was still catching up to the law's original timeline. Organisations faced binding obligations without the practical guidance needed to meet them.
That framing matters for how you read the extra time. This was a delay to let implementation mature, not a retreat from the substance. The obligations that apply in December 2027 are the same obligations that were due in 2026: risk management, data governance, technical documentation, human oversight, logging, and post-market monitoring for high-risk systems.
What did not change
Four things survived the simplification package intact:
- GPAI obligations already apply. General-purpose AI rules have been in force since August 2025. If you provide or build on general-purpose models, you carry duties today, not in 2027.
- Prohibitions remain in force — and grew. The banned-practices list was expanded, not relaxed.
- The high-risk categories are unchanged. Nothing was reclassified out of scope. The deadline moved; the definitions did not. A system that was high-risk in the 2026 framing is high-risk in the 2027 one.
- Other jurisdictions are not waiting. The Colorado AI Act took effect on 30 June 2026, bringing a duty of care on algorithmic discrimination, risk-management programs, and impact assessments. If you operate across markets, the EU deferral does not clear your calendar.
Eighteen months of runway — while the AI estate keeps growing
The trap in a deferred deadline is treating it as a pause. Your obligation is fixed in time, but the thing you must govern is not: Gartner projects that roughly 40% of enterprise applications will include embedded AI agents by the end of 2026, up from under 5% in 2025. Gartner has also warned that over 40% of agentic AI projects may be cancelled by 2027 — citing cost, unclear value, and weak risk controls. Weak risk controls are precisely what a governance program exists to fix.
This is already visible in everyday tooling. Atlassian shipped AI agents into Jira in 2026 — Rovo agents can be assigned work, mentioned in comments, and embedded in workflows. The system you use to track work now contains AI systems of its own.
A hypothetical to make it concrete: a support team wires an agent into its Jira triage workflow in Q3 2026. It routes customer issues, quietly influences response priorities, and appears in no inventory anywhere. That agent belongs in your December 2027 classification exercise — but only if someone finds it first.
A practical readiness plan: inventory, classify, owners, evidence
1. Inventory. You cannot classify what you have not found. Export your Jira or Azure DevOps projects (or any CSV) and run AI-system discovery across them — AI work hides in tickets labelled "automation", "ML pipeline", or "copilot integration", not in a tidy list. If you want to see the shape of the output first, try our sample files. Teams on Jira Cloud can also run discovery through the Atlassian Marketplace app, which runs entirely inside your Atlassian tenant with no data egress.
2. Classify. Map each discovered system against the EU AI Act's risk tiers, using the Commission's draft Article 6 guidelines as your current best reference. Our guide to EU AI Act mapping for Jira teams walks through the tiers in practice.
3. Owners. Every high-risk candidate needs a named accountable owner before anyone drafts documentation. A shared, risk-scored AI risk register is where ownership stops being implied and starts being recorded.
4. Evidence. Boards and regulators eventually ask the same question: show me. A governance score and a board-ready report — see a full example report — turn the register into something an executive can act on, mapped to the EU AI Act, ISO/IEC 42001, and NIST AI RMF.
One clarification worth stating plainly: AI Governance Hub provides governance evidence and executive analysis, not legal certification or a guarantee of compliance. Treat the output as the working record your legal counsel and auditors build on.
Frequently asked
When is the new EU AI Act high-risk deadline? High-risk obligations now apply from 2 December 2027 for standalone systems and 2 August 2028 for AI embedded in regulated products, following final Council approval of the simplification package on 29 June 2026.
Did the delay change which AI systems count as high-risk? No. The high-risk categories are intact, and the European Commission published draft Article 6 classification guidelines in May 2026 to help organisations scope them.
Do any EU AI Act rules apply before December 2027? Yes. General-purpose AI obligations have applied since August 2025, and the prohibited-practices rules remain in force — the simplification package actually expanded them.
The deadline moved; the work didn't. See what your own AI estate looks like in a risk-scored register: upload a Jira, Azure DevOps, or CSV export and get a free preview on your own data — no credit card required, founding pricing from ₹199.