High risk AI obligations have not yet taken effect for most systems: stand alone Annex III systems face a 2 December 2027 deadline, while high risk AI embedded in regulated products is due from 2 August 2028. The AI Act’s penalty framework can reach €35 million or 7% of worldwide annual turnover for prohibited pract...
Published byEdited with GPT-5.6 TerraImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: What did the European Union say AI companies must do to operate in the bloc as the EU AI Act’s high-risk-system rules took effect, what safe. Article summary: The premise needs one correction: the EU’s stand-alone high-risk AI rules have not taken effect yet. They are scheduled to apply from 2 December 2027, while high-risk AI embedded in regulated products is scheduled for 2 . Topic tags: general, government, general web, user generated, news. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermar
The key point is timing: the European Union’s full obligations for high-risk AI systems have been postponed, rather than already taking effect. Stand-alone high-risk systems listed in Annex III are scheduled to face the requirements from 2 December 2027. High-risk AI that forms part of certain regulated products has a later date of 2 August 2028. 1
8
For companies that plan to place these systems on the EU market, the practical task is to build a compliance process that can demonstrate safety, traceability and accountability before launch.
The high-risk category covers two broad groups:
In practice, the classification matters because high-risk status triggers a far more demanding set of lifecycle obligations than applies to ordinary AI tools.
Before a high-risk system can be placed on the EU market, its provider will need controls that are designed into the product lifecycle—not assembled only after a regulator asks questions.
Providers must establish risk-assessment and risk-mitigation measures. They must also use datasets of sufficient quality to reduce the risk of discriminatory outcomes. The Act’s high-risk framework emphasizes relevant, representative and appropriately governed training, validation and testing data. 1
15
High-risk systems must maintain logs that support traceability, alongside detailed technical documentation describing the system and its intended purpose. That evidence enables authorities to assess whether the system complies with the rules. 1
The EU also requires appropriate human-oversight measures and a high level of accuracy, robustness and cybersecurity. Providers must give deployers clear, adequate information so the system can be used as intended and with an understanding of its limitations. 1
Providers will need to complete the applicable conformity assessment before placing a high-risk system on the market. Where required, they must register the system, monitor performance after release and report serious incidents. These duties make compliance an ongoing operating function, rather than a one-time product approval exercise. 1
15
Organizations preparing for the 2027 and 2028 deadlines should be able to answer the following questions:
The AI Act uses penalties tied to both fixed euro amounts and worldwide annual turnover. The most severe tier—covering prohibited AI practices—can reach €35 million or 7% of worldwide annual turnover. Other non-compliance can carry penalties of up to €15 million or 3% of worldwide annual turnover. 3
The size of the potential penalties means a high-risk AI program should involve more than legal review. Product, security, data science, procurement, compliance and operational teams all need evidence that the safeguards are functioning.
The revised dates give companies more time to prepare, but the core requirements remain extensive. A provider that waits until late 2027 may still need to build documentation systems, revise model-development practices, implement logging, test oversight processes and establish post-market reporting workflows.
The most useful approach is to treat the EU AI Act as a product-governance standard: identify high-risk use cases early, collect evidence as the system is built, and make safety, traceability and human control part of the release process from the start. 1
15
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
High risk AI obligations have not yet taken effect for most systems: stand alone Annex III systems face a 2 December 2027 deadline, while high risk AI embedded in regulated products is due from 2 August 2028.
High risk AI obligations have not yet taken effect for most systems: stand alone Annex III systems face a 2 December 2027 deadline, while high risk AI embedded in regulated products is due from 2 August 2028. The AI Act’s penalty framework can reach €35 million or 7% of worldwide annual turnover for prohibited practices, and up to €15 million or 3% for other breaches.
The delay creates preparation time, not an exemption: teams selling or deploying AI in sensitive use cases should begin mapping systems, evidence and governance processes well before the applicable date.