Which Date Is Yours?
Three deadlines are in play and most founders only need one of them. Find your row.
| If you | Your date | What it covers |
|---|---|---|
| Ship a product that generates text, images, audio or video | 2 December 2026 | AI-generated output must carry machine-readable marking. This date is the grace period for systems already on the market before 2 August 2026. |
| Build AI used in hiring, credit, education, essential services, biometrics, law enforcement or migration | 2 December 2027 | The full high-risk regime in Chapter III: risk management, documentation, human oversight, conformity assessment. |
| Put AI inside a product already regulated for safety, such as a medical device, machine, vehicle, lift or toy | 2 August 2028 | The same high-risk regime with a longer runway, on top of the sectoral rules you already follow. |
| Use AI for chat, search, recommendations or internal tooling | Nothing new | Article 50 transparency has applied since 2 August 2026: tell people when they are dealing with AI. The rest of this guide is not yours. |
Whichever row you are in, the first task is the same. Classify your systems now. You cannot build a 2027 programme without knowing in 2026 which of yours fall inside the regime, and classification is usually the part that takes longest to settle internally.
Is Your AI System High-Risk?
An AI system is classified as high-risk if it is used in contexts where errors or biases could significantly harm individuals' rights, safety, or livelihoods.
Approach 1: Safety Component
AI systems that are safety components of products covered by existing EU product safety legislation and require third-party conformity assessment.
Approach 2: Listed Use Cases (Annex III)
| Category | Examples |
|---|---|
| Biometrics | Remote biometric identification, emotion recognition |
| Critical Infrastructure | AI managing electricity, water, gas, traffic |
| Education | AI determining access, exam proctoring, student assessment |
| Employment | CV screening, interview assessment, hiring decisions |
| Essential Services | Credit scoring, insurance pricing, emergency dispatch |
| Law Enforcement | Risk assessment tools, evidence analysis |
| Migration/Border | Visa assessment, asylum processing |
| Justice | Systems assisting judicial authorities |
The Quick Classification Test
| If Your AI Does This... | Classification |
|---|---|
| Screens job applications | High-risk (Employment) |
| Assesses creditworthiness | High-risk (Essential Services) |
| Recommends products | Not high-risk |
| Generates marketing copy | Not high-risk |
| Analyzes contracts | Usually not high-risk |
| Detects fraud in payments | Potentially high-risk |
The Seven Requirements for High-Risk AI
Requirement 1: Risk Management System (Article 9)
A continuous process to identify, analyze, and mitigate risks throughout your AI system's lifecycle. Document all identified risks, implement measures, test under foreseeable misuse conditions, and maintain ongoing assessment.
Requirement 2: Data Governance (Article 10)
| Element | What You Need |
|---|---|
| Data sources | Where did training data come from? |
| Data collection | How was it collected? |
| Data preparation | What preprocessing was applied? |
| Bias assessment | How did you check for and address bias? |
| Data gaps | What limitations exist in your dataset? |
Requirement 3: Technical Documentation (Article 11)
Comprehensive records covering design, development, and operation. Retention: 10 years. Your 2026 documentation must be accessible until 2036.
Requirement 4: Automatic Logging (Article 19)
Logging capabilities appropriate to purpose. Minimum: period of use, reference databases, input data, identification of verifying persons. Retention: at least 6 months.
Requirement 5: Transparency (Article 13)
Clear documentation for deployers: identity, characteristics, intended purpose, misuse scenarios, human oversight instructions, performance metrics.
Requirement 6: Human Oversight (Article 14)
Humans must be able to understand outputs, decide not to use the system, intervene or interrupt operation. The key word is "effectively."
Requirement 7: Accuracy, Robustness, Cybersecurity (Article 15)
Appropriate levels of accuracy, resilience to errors, and protection against threats.
The Conformity Assessment
| Pathway | When It Applies | What It Involves |
|---|---|---|
| Self-Assessment | Most high-risk Annex III systems | Internal procedures, documentation review |
| Third-Party | Remote biometric ID and certain sectoral systems | Notified Body evaluation |
The Real Timeline: 8–14 Months
Phase 1: Assessment (4–8 weeks)
AI inventory, risk classification, gap analysis, resource planning.
Phase 2: Technical Implementation (12–20 weeks)
Risk management system, data governance framework, logging infrastructure, human oversight, cybersecurity.
Phase 3: Documentation (8–12 weeks)
Technical documentation, instructions for use, risk management records, training records.
Phase 4: Conformity Assessment (8–16 weeks)
Quality management setup, internal assessment, Notified Body (if required), registration.
You have more time than the original calendar suggested. Work backward from 2 December 2027 for standalone Annex III systems, or 2 August 2028 if your AI sits inside a regulated product. Classification is the piece to do now: you cannot plan a 2027 programme without knowing in 2026 which of your systems fall inside the regime.
Deployer Obligations
Not building AI? If you use a third-party high-risk AI system, you still have obligations:
| Obligation | What It Means |
|---|---|
| Technical measures | Implement according to provider instructions |
| Human oversight | Assign qualified persons to monitor |
| Data quality | Ensure input data is relevant |
| Monitoring | Watch for risks, report to provider |
| Staff training | Ensure users understand AI limitations |
What Changed for Smaller Companies
The 2026 Omnibus wrote SME and small mid-cap definitions into the AI Act itself and attached concrete relief to them. A small mid-cap is a company that has grown past the SME thresholds but is still not large. If you are in either group, four things apply to you that do not apply to a large provider.
| Relief | What it means in practice |
|---|---|
| Simplified technical documentation | A shorter documentation form for high-risk systems, in place of the full Annex IV set |
| Proportionate quality management | Quality management obligations scaled to your size, now extended across the whole SME category |
| Lower fine caps | Administrative fine ceilings are reduced, so the headline figures below are not your figures |
| Priority sandbox access | You go to the front of the queue for regulatory sandboxes, including the new EU-level one |
Regulatory Sandboxes (Article 57)
A controlled environment where you test an AI system under your regulator's supervision before going to market. Each Member State must have one operational by 2 August 2027, and the EU AI Office can now run one at Union level with priority access for SMEs and startups. Access is free for SMEs and startups under Article 58(6). It is worth applying only if you have a real classification question. Our sandbox guide covers how to apply.
Penalties
| Violation | Maximum Penalty |
|---|---|
| Non-compliance with high-risk requirements | €15M or 3% of global turnover |
| Providing incorrect information | €7.5M or 1% of global turnover |
These are the ceilings for large providers. The 2026 Omnibus reduced the caps for SMEs and small mid-caps, so if you are in either group your exposure is lower than the figures above.
The Bottom Line
The startups that treat compliance as a competitive advantage — not just a legal burden — will be the ones customers trust. Classify your systems. Assess your gaps. Plan your timeline. Start now.
Related: Product Liability Directive 2026: Software and AI now liable | GDPR reforms and AI training
High-risk classification is the deep end of the AI Act. Start with the broader picture in our EU AI Act compliance guide for seed-stage startups.



