Security & Compliance

The AI Act's high-risk deadline moved to December 2027

Av Technspire TeamJuly 28, 20267 visningar

Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force yesterday, 27 July. It amends the AI Act and pushes the high-risk obligations for Annex III systems from 2 August 2026 to 2 December 2027, a sixteen-month reprieve that arrives one week before the original deadline would have hit. Annex I systems, meaning AI embedded as a safety component in regulated products such as machinery and medical devices, move to 2 August 2028. If your organisation runs AI in recruitment, credit scoring, biometrics, education or critical infrastructure, the compliance clock you have been racing just got reset. It did not get cancelled. Article 50 transparency obligations still apply from 2 August 2026, five days from now, and the Omnibus adds a brand-new prohibition with its own deadline in December 2026. For Swedish enterprises building on Azure, this is the moment to convert a panicked sprint into a properly sequenced programme.

What the Digital Omnibus actually changes

The regulation's full name is Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026, amending Regulations (EU) 2024/1689 (the AI Act), (EU) 2018/1139 (civil aviation) and (EU) 2023/1230 (machinery). Parliament approved it on 16 June by 423 votes to 57, the Council followed on 29 June, and publication came on 24 July with entry into force on the third day after, an unusually fast track that reflects how close the original August deadline was. The headline changes:

  • Annex III high-risk systems (standalone systems: biometric identification, recruitment and HR tools, credit scoring, education and vocational training, critical infrastructure management, and the other Annex III categories): full obligations now apply from 2 December 2027 instead of 2 August 2026.
  • Annex I high-risk systems (AI as a safety component in products covered by EU harmonisation law): obligations move from 2 August 2027 to 2 August 2028.
  • A new Article 5 prohibition: AI systems that generate or manipulate non-consensual intimate imagery of identifiable persons, or child sexual abuse material, are banned outright.
  • Content-marking grace period tightened: the marking obligations for AI-generated and AI-manipulated content apply to systems already on the market from 2 December 2026, with the grace period cut from six months to three.
  • SME relief extended to small mid-caps: the AI Act's simplified technical documentation and other SME accommodations now also cover small mid-cap enterprises, and the regulatory sandbox deadline moves to 2 August 2027 with an EU-level sandbox giving priority access to startups and SMEs.

The Commission also picked up new homework: guidelines on integrating AI Act compliance with existing sectoral processes are due by 1 August 2027, and post-market monitoring guidance by 2 September 2027. Both land comfortably before the new December 2027 deadline, which matters, because the absence of exactly this kind of guidance is a large part of why the deadline moved at all.

What still bites on 2 August 2026

Read the Omnibus carefully before you stand your compliance team down. Three sets of obligations are completely untouched by the deferral, and one is new.

Article 50 transparency: five days away

Article 50 applies from 2 August 2026 as originally scheduled. Concretely, that means: users must be informed when they are interacting with an AI system rather than a human (your customer-facing chatbots and voice bots), AI-generated or AI-manipulated content must be marked as such in a machine-readable way, and deepfakes must be disclosed. If you have shipped a Copilot-style assistant, a customer-service bot on Azure OpenAI, or any content-generation feature into production, verify the disclosure and marking behaviour this week, not in December 2027.

Obligations already in force stay in force

The Article 5 prohibitions (social scoring, certain biometric categorisation, and the rest) have applied since 2 February 2025. General-purpose AI model obligations have applied since 2 August 2025. Neither moves. The EU AI Office's enforcement powers and the governance framework also remain on schedule. The Omnibus adds one prohibition rather than removing any: the ban on non-consensual intimate imagery and CSAM generation described above.

The December 2026 marking deadline

Systems already on the market before 2 August 2026 get until 2 December 2026 to implement content-marking. That is a four-month runway for what can be a genuinely fiddly engineering task: watermarking or metadata-marking generated images, audio and text at the point of generation, surviving common transformations, and doing it for every generation pathway in your product. Treat this as the first milestone of your programme, because it is the first one with an enforcement date attached.

Why the deadline moved, and why that should worry you slightly

The recitals are candid: the deferral responds to the delayed availability of harmonised standards, common specifications and alternative guidance. CEN-CENELEC's standards work under JTC 21 has not delivered the harmonised standards that were supposed to give providers a presumption of conformity, and without them, every organisation would have been assessing itself against the bare legal text. The Commission proposed the Omnibus in November 2025 as part of its simplification agenda, and the co-legislators agreed that enforcing detailed technical obligations before the technical benchmarks exist served nobody.

Here is the uncomfortable implication for planning: the obligations themselves did not get simpler. Risk management systems, data governance under Article 10, technical documentation, logging, human oversight, accuracy and robustness requirements, conformity assessment, registration in the EU database. All of it still arrives, now with the expectation that harmonised standards will exist by then and that regulators will have had an extra sixteen months to staff up. A deferred deadline with better-prepared supervisors is not obviously softer than a rushed one with distracted supervisors. Organisations that interpret December 2027 as permission to stop will be rebuilding their programme from a cold start in mid-2027, against standards they have never read.

First, confirm what you actually are

Role check before anything else. Your obligations depend on whether you are a provider or a deployer, and the answer is less obvious than it looks. Work through these questions for every AI system in scope:

  • Do you develop the system, or have it developed, and place it on the market under your own name or trademark? Then you are a provider, with the full obligation set.
  • Do you use a vendor's system under your authority in a professional context? Then you are a deployer: lighter obligations, but real ones, including human oversight, input-data relevance, monitoring and log retention.
  • Have you substantially modified a vendor system, changed its intended purpose, or white-labelled it? You may have become the provider without meaning to. A fine-tuned model behind your own brand is the classic trap.
  • Is the system actually in an Annex III category, and does it materially influence decisions? Some systems that touch a high-risk domain perform only narrow procedural tasks and may fall outside the high-risk classification. Document the reasoning either way.

A realistic 16-month plan: August 2026 to December 2027

Sixteen months is enough time to do this properly and calmly, provided you sequence it. Here is a phased plan sized for a typical Swedish enterprise running its AI estate on Azure. Adjust the calendar to your audit cycles.

Phase 1: now through October 2026. Inventory, classify, fix transparency

  • Ship Article 50 compliance immediately. Audit every user-facing AI interaction for disclosure, and every generation feature for marking. This is due in days, not months.
  • Build the system inventory. Every AI system in production or procurement, its vendor, its Azure footprint (Azure OpenAI deployments, Azure AI Foundry projects, ML workspaces, third-party SaaS), its purpose, and the personal data it touches. Your Azure resource tagging discipline determines whether this takes a week or a quarter.
  • Classify against Annex III using the role check above. Output: a defensible register stating, per system, your role, the risk classification, and the reasoning.
  • Plan the December 2026 marking deadline for anything already on the market.

Phase 2: November 2026 through March 2027. Gap analysis and governance foundations

  • Run a gap analysis per high-risk system against Articles 8 to 15: risk management, data governance, technical documentation, record-keeping, transparency to deployers, human oversight, accuracy, robustness, cybersecurity.
  • Stand up the risk management system as a living process, not a document. Wire it into your existing ISO 27001 or ISMS machinery if you have one; the overlap is substantial.
  • Sort data governance early. Article 10's requirements on training, validation and testing data (relevance, representativeness, error examination, bias detection) take the longest to retrofit. On Azure, this is where Microsoft Purview cataloguing and lineage, plus documented dataset versioning in Azure AI Foundry or Azure ML, earn their keep.
  • Push vendors now. Every high-risk system you deploy needs provider documentation you can rely on. Get contractual commitments on AI Act deliverables into renewals this cycle, while you still have leverage.

Phase 3: April through August 2027. Implementation and evidence

  • Implement logging and traceability. Automatic event logging over the system's lifetime, retained under your control. Azure Monitor, diagnostic settings on Azure OpenAI, and Log Analytics retention policies map directly onto this.
  • Build the technical documentation while the Commission's integration guidelines (due 1 August 2027) land, and track the harmonised standards as they publish. Writing documentation against a standard beats writing it against a statute.
  • Design human oversight that a regulator would recognise: named roles, real intervention capability, and evidence it operates. A dashboard nobody watches is not oversight.
  • Test accuracy and robustness with repeatable evaluation runs and keep the results. Model and prompt changes should re-trigger evaluation automatically in your CI pipeline.

Phase 4: September through December 2027. Conformity and cutover

  • Run conformity assessment (internal control for most Annex III categories), draw up the EU declaration of conformity, affix CE marking where you are the provider.
  • Register in the EU database where required, and complete deployer-side duties, including fundamental-rights impact assessments where they apply.
  • Rehearse the audit. Have someone outside the programme walk the evidence chain for one system, end to end, and fix what they trip over.

The Swedish and EU angle

Procurement gets a new clause set. Swedish public-sector buyers were already writing AI Act compliance into upphandling requirements ahead of August 2026. Expect tender language to update quickly: vendors will be asked to commit to the December 2027 date, to interim transparency compliance, and to evidence obligations that survive the transition. If you sell AI-powered solutions to Swedish authorities, being able to show a phased programme like the one above is now a competitive answer to a standard question. If you buy, put the phase gates into the contract.

Most Swedish enterprises are deployers, and the deferral helps them most. The typical estate here is Azure OpenAI or Copilot-family services plus vendor SaaS with embedded AI, meaning deployer obligations dominate. The extra sixteen months is best spent on the two deployer duties that require organisational muscle rather than paperwork: human oversight arrangements and input-data quality. Both depend on people and process changes that were never going to be ready by August.

Data residency and GDPR work compounds, it does not duplicate. Article 10 data governance, GDPR Article 30 records and Schrems-era transfer mapping all draw on the same inventory of systems and data flows. Swedish organisations that invested in EU Data Boundary configurations and Purview-based data mapping can reuse most of that evidence. Build one register that serves the DPO, the CISO and the AI Act programme, because three separate spreadsheets will drift apart by 2027.

Supervision will be more organised by 2027. One acknowledged reason for the deferral was that member states, Sweden included, were still designating and resourcing competent authorities. By December 2027 the supervisory landscape will be staffed, guided by Commission guidelines, and equipped with harmonised standards to measure against. Plan for competent enforcement, not for the confusion an August 2026 start would have produced.

Takeaways

  • The high-risk deadline for Annex III systems is now 2 December 2027; Annex I embedded systems follow on 2 August 2028. Nothing about the obligations got lighter.
  • Article 50 transparency applies from 2 August 2026. Check chatbot disclosure and content marking this week.
  • Systems already on the market must implement content-marking by 2 December 2026.
  • The new prohibition on non-consensual intimate imagery and CSAM generation applies to everyone, providers and deployers alike.
  • Determine your role (provider vs deployer) per system before you scope anything else; substantial modification and white-labelling flip you into provider territory.
  • Spend the sixteen months in four phases: inventory and transparency now, governance foundations through Q1 2027, implementation and evidence through summer, conformity in the final quarter.
  • Reuse your GDPR and ISO 27001 machinery; build one shared system register for the DPO, CISO and AI programme.
  • Track the harmonised standards and the Commission guidelines due mid-2027, and leave slack in the plan to align with them.

Sources