The EU AI Act high-risk deadline is no longer 2 August 2026
A May 2026 political agreement pushed the EU AI Act high-risk obligations back by more than a year. Stand-alone high-risk systems now have until 2 December 2027, and AI inside regulated products until 2 August 2028.
For two years the date circled on every AI Act compliance plan was 2 August 2026. For high-risk systems, that date has moved, and a lot of timelines published before May 2026 are now wrong.
What changed
On 7 May 2026, EU lawmakers reached a political agreement, the digital omnibus, to postpone the AI Act high-risk obligations. The Parliament adopted it on 16 June 2026 and the Council on 29 June 2026, with publication in the Official Journal still to come, and it sets new dates that are already shaping how companies plan.
The new high-risk deadlines
- Stand-alone high-risk systems listed in Annex III, for example recruitment, credit-scoring, education and law-enforcement tools: 2 December 2027.
- AI embedded in regulated products under Annex I: 2 August 2028.
Which obligations actually moved
The postponed duties are the substantive ones, the requirements in Articles 8 to 15 of the Act. A stand-alone Annex III system does not have to meet these by 2 August 2026, it has until 2 December 2027.
- A risk-management system running across the lifecycle (Article 9).
- Data governance and quality controls for training and testing data (Article 10).
- Technical documentation and automatic record-keeping, the logs (Articles 11 and 12).
- Human oversight designed into the system (Article 14), plus accuracy, robustness and cybersecurity (Article 15).
- The provider duties tied to the same date, including the conformity assessment and EU database registration before the system reaches the market.
So a claim that Article 14 human oversight or the Article 9 risk file has to be in place by 2 August 2026 is reading a pre-omnibus timeline. Those duties bind stand-alone high-risk systems from 2 December 2027, and AI inside regulated products from 2 August 2028. Note this is separate from the Article 50 transparency rules, which are unrelated to the high-risk requirements and do still start on 2 August 2026.
What did not move
- The Article 50 transparency obligations still start on 2 August 2026.
- The prohibitions on unacceptable-risk uses have applied since 2 February 2025.
- The general-purpose AI model rules have applied since 2 August 2025.
The first question to answer
Whether any high-risk deadline binds you starts with one question: is your system high-risk at all? Most are not. Our free classifier walks the Annex III categories so you know which deadline, if any, is yours, before you spend a budget line on it.
Put it to work on your own case
The free tool below turns this into a result for your situation, in your browser, with no signup.
Check if your system is high-riskSources
More updates
The old ISO 27001:2013 certificate is dead: the transition window closed on 31 October 2025
The three-year window to move from ISO 27001:2013 to the 2022 edition closed on 31 October 2025, so a 2013 certificate held into 2026 is no longer valid. The 2022 standard reworked Annex A from 114 controls to 93 in four categories and added modern ones like threat intelligence, cloud security and secure coding. If your certificate lapsed, recertifying means a fresh initial audit rather than the lighter transition assessment, which changes the budget line for anyone pricing readiness this year.
Stripe now sells its own merchant of record, Managed Payments, at 3.5% on top of processing
Stripe now offers Managed Payments, its own merchant-of-record option, introduced in a 25 February 2026 release. Stripe becomes the seller of record for your digital products and takes on indirect tax (VAT, sales tax, GST) in more than 80 countries, plus fraud, disputes and buyer support, for a fee of 3.5% per successful transaction on top of the normal processing fee. That puts it in the same rough band as Paddle and Lemon Squeezy, and it can be switched on per transaction without moving to a separate platform.
Framer retired its Scale plan and cut editor seats to a flat $20 in its 2026 billing overhaul
Framer moved to a new billing system on 27 May 2026. It retired the $100-a-month Scale plan, leaving Basic at $10 and Pro at $30 as the two paid site plans, and made a full editor seat a flat $20 across every plan, down from $40 on the higher tiers. A new Content Editor seat costs $10 and gives content-only teammates CMS access without a full design seat. For a small team the per-seat line, not the plan price, is where most of the cost sits, so this shifts the real math.