High-Risk Annex III AI Obligations and Deadline

Deadline and scoping page for standalone high-risk AI systems under Annex III after the Digital Omnibus on AI.

Legal status. The Digital Omnibus on AI was published in the Official Journal of the EU on July 24, 2026 as Regulation (EU) 2026/1744 and entered into force on July 27, 2026. The deferred dates below are now binding law.
Status last verified:

Changed by Omnibus Original: August 2, 2026

Standalone high-risk AI obligations under Annex III apply

Obligations for standalone high-risk AI systems under Annex III, such as recruitment, credit scoring, education, essential services, law enforcement, migration, justice, critical infrastructure, and biometric identification, are moved from the original date by the Digital Omnibus on AI.

Changed by the Digital Omnibus on AI (Regulation (EU) 2026/1744), in force since July 27, 2026.

What the obligation actually requires

Annex III is about standalone high-risk AI systems. The deadline data names categories such as recruitment, credit scoring, education, essential services, law enforcement, migration, justice, critical infrastructure, and biometric identification. In plain terms, these are systems where an AI output can affect access, ranking, assessment, eligibility, enforcement, or other serious decisions about people or infrastructure.

The practical work starts with classification. A company needs to know whether the system sits in an Annex III category, whether it is acting as provider, deployer, importer, or distributor, and which teams own the evidence. Even before every detail is settled, a flagged company should be able to explain what the system does, who is affected, what data is used, who reviews outputs, and what records exist when something goes wrong.

Who usually triggers it

A hiring platform that ranks applicants or screens CVs is a typical example. A lender or fintech using AI to score creditworthiness can fall into the review path. A software company selling assessment tools to schools, public bodies, or essential-services providers should also check whether it is providing a standalone high-risk system rather than ordinary analytics.

The common misunderstanding

The biggest misunderstanding is assuming “high-risk” means any important AI system. Annex III is category-driven. A tool can be commercially important without falling into an Annex III category, and a modest-looking workflow can still matter if it affects recruitment, credit, education, essential services, law enforcement, migration, justice, critical infrastructure, or biometric identification.

What to do next

Build a system inventory around use cases, not vendor names. For every AI system, write one sentence on what decision it supports and who is affected. Match that use case against the Annex III categories in the deadline data. If a match is plausible, assign an owner for provider/deployer role analysis, evidence collection, and customer-facing information. The current and original dates are shown in the timeline above; do not use the delay as a reason to postpone classification.

Use the deadline checker View full timeline