- The Annex III high-risk deadline moved to 2 December 2027. This is now law, not a proposal: Regulation (EU) 2026/1744.
- Article 50 transparency obligations took effect 2 August 2026, on schedule and without deferral for all AI products interacting with users.
- Most SaaS AI features are not Annex III high-risk. Hiring tools, credit scoring, and education AI are; a product recommendation engine or support chatbot is not.
- Even if your product is not high-risk, Article 50 likely applies. Disclose that your chatbot is an AI. Label generated content. That is the minimum action right now.
If you have been watching the EU AI Act and wondering whether the 2 August 2026 high-risk deadline was real or deferred, the answer is now settled.
The deferral happened. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal of the EU on 24 July 2026.
It entered into force on 27 July 2026, six days before the original deadline.
The high-risk obligations for Annex III standalone systems are now due 2 December 2027. The obligations for AI embedded in regulated products (Annex I) are due 2 August 2028.
That is the good news if you were not going to be ready by August. The rest of the news requires more attention.
Article 50 of the AI Act, covering transparency obligations, was not deferred. It took effect on 2 August 2026, on schedule.
If your product includes a chatbot, generates synthetic content, uses emotion recognition, or produces deepfakes, those obligations apply to you right now, regardless of whether Annex III high-risk rules cover your system.
The deferral gave you more time on the hardest requirements. It did not pause the ones that apply to the widest range of AI products.
This blog gives you the 3 things the CV brief said this persona needs: a clear answer on what changed, a quick check on whether your product is in scope, and a short action list that works given where the deadlines now stand.
What the Digital Omnibus on AI actually changed
The Digital Omnibus on AI is the first formal amendment to the EU AI Act since it entered into force on 1 August 2024. It changed 3 things that matter for a founder with an AI product.
What changed
| What changed | Original deadline | New deadline | Status |
|---|---|---|---|
| Annex III high-risk AI obligations (standalone systems: hiring, credit, education, essential services, law enforcement, biometrics) | 2 August 2026 | 2 December 2027 | Deferred. Now law. 16-month extension. |
| Annex I high-risk AI (AI embedded in regulated products: medical devices, machinery, toys) | 2 August 2027 | 2 August 2028 | Deferred. Now law. 12-month extension. |
| Article 50(2) watermarking for AI systems already on the market before 2 August 2026 | 2 August 2026 | 2 December 2026 | 4-month grace period for legacy systems only. New systems must comply from launch. |
| New prohibition: AI-generated non-consensual intimate imagery and child sexual abuse material | Not in original Act | 2 December 2026 | New obligation added by the Omnibus. |
What didn’t change?

Two things did not change and are in force now. Article 5 prohibited practices (real-time biometric surveillance in public spaces, social scoring, subliminal manipulation) took effect 2 February 2025 and remain in force.
Article 50 transparency obligations (chatbot disclosure, synthetic content marking, deepfake labeling, emotion recognition disclosure) took effect 2 August 2026, on schedule.
The deferral is a deferral, not a cancellation. The fundamental architecture of the EU AI Act, its risk-based approach, governance structure, and core obligations, remains intact.
2 December 2027 is a new deadline for the same obligations. Organizations that use the extension to do the classification and documentation work will enter the enforcement window in a defensible position.
Organizations that treat the deferral as permission to stop planning will face the same work under a tighter timeline.
Read the EU AI Act official text and timeline for more details.
Does the EU AI Act apply to what you are building?
The EU AI Act applies to any provider or deployer of an AI system placed on the market or put into service in the EU, regardless of where the company is incorporated. A U.S. or Indian SaaS company with EU users is in scope.
The question of which tier of the Act applies depends on what your system does. Run through the 3 tiers in order.
Step 1: Are you doing anything prohibited?
These practices are banned outright, with no exceptions for small companies or early-stage products. They have been in force since 2 February 2025.
- Real-time remote biometric identification of individuals in publicly accessible spaces (with narrow law enforcement exceptions)
- AI systems that exploit vulnerabilities based on age, disability, or social or economic situation to manipulate behavior
- Social scoring by public authorities based on personal characteristics
- AI systems that infer political opinions, religious beliefs, or sexual orientation from biometric data
- AI-generated non-consensual intimate imagery (effective 2 December 2026 per the Omnibus)
If your product does any of these, stop. The penalties reach €35 million or 7% of total worldwide annual turnover, whichever is higher.
Step 2: Does your system fall under Annex III high-risk?
Annex III lists 8 categories of standalone AI systems classified as high-risk. The compliance deadline for these is 2 December 2027. Check whether your system is used for any of the following:
| Annex III category | What qualifies | Common SaaS examples |
|---|---|---|
| 1. Biometric identification and categorisation | Real-time or post-hoc remote biometric identification; AI categorising individuals by biometric data into sensitive characteristic groups | Facial recognition products; biometric authentication in high-stakes contexts |
| 2. Critical infrastructure management | AI managing or operating critical digital, road, water, gas, heating, or electrical infrastructure | Niche infrastructure management SaaS; most B2B SaaS is not in scope |
| 3. Education and vocational training | AI determining access to educational institutions or vocational programs, or directly influencing student outcomes | Admissions scoring systems; automated grading that determines progression; proctoring AI |
| 4. Employment and worker management | AI used for recruitment, CV screening, candidate ranking, interview analysis, employment decisions, task allocation, or monitoring performance and behavior of workers | Hiring platforms with AI screening; HR performance management AI; workforce management with algorithmic task assignment |
| 5. Essential private and public services | Creditworthiness assessment; credit scoring; life and health insurance risk assessment and pricing; benefits eligibility determination | Credit scoring features; insurance pricing AI; benefits eligibility tools for public services |
| 6. Law enforcement | AI used to assess risk of criminal offending; polygraph tools; crime analytics for predicting individual behavior; evidence reliability assessment | Specialist law enforcement SaaS only; most commercial SaaS is not in scope |
| 7. Migration, asylum, and border control | AI used in migration risk assessment, asylum claim evaluation, visa eligibility, border control | Government immigration SaaS only |
| 8. Administration of justice and democratic processes | AI for legal research supporting judicial decisions; AI for election campaigns influencing voters | Legal research AI in judicial decision support; political campaign AI |
Most SaaS AI features are not on this list. A product recommendation engine, a support chatbot, a sales forecasting tool, a content generation feature, and a churn prediction model are all outside Annex III.
The categories that catch the most founders by surprise are employment (hiring tools, HR performance AI) and essential services (anything touching credit or insurance pricing). If your product is used by enterprise customers to make employment or credit decisions, check carefully.
There is also a narrow Article 6(3) exception: a system listed in Annex III is not automatically high-risk if it does not pose a significant risk to health, safety, or fundamental rights in the specific context of use. However, systems that profile individuals remain high-risk regardless of this exception.
This is a legal determination. If you think the exception might apply, get legal advice and avoid self-classifying out of scope.
See the European Commission's classification guidance for worked examples.
Step 3: Do Article 50 transparency obligations apply?
Article 50 is separate from the Annex III high-risk classification. It applies based on what your system does, not on whether it is high-risk.
It took effect on 2 August 2026. If your product includes any of the following, Article 50 applies now:
| Article 50 obligation | Who it applies to | What it requires |
|---|---|---|
| Chatbot disclosure (Art. 50(1)) | Providers of AI systems that interact directly with people, including customer support bots, virtual assistants, and conversational AI | Ensure users are informed they are interacting with an AI, at the point of first interaction. Exceptions: systems used for criminal investigation (law enforcement) and disclosed creative or fictional contexts. |
| Synthetic content marking (Art. 50(2)) | Providers of generative AI systems that produce audio, image, video, or text | Apply a machine-readable mark to AI-generated content enabling detection. For systems already on the market before 2 August 2026: grace period until 2 December 2026. New systems must comply from launch. |
| Emotion recognition and biometric categorisation disclosure (Art. 50(3)) | Deployers (users of AI systems, not just providers) using emotion recognition or biometric categorisation in contexts outside explicit permissions | Inform individuals exposed to these systems that they are being assessed. Carve-out for law enforcement systems permitted by law. |
| Deepfake and AI text disclosure (Art. 50(4)) | Deployers using AI to create deepfakes or AI-generated text on matters of public interest without human review | Disclose that content is AI-generated or manipulated. For artistic, creative, or satirical works: limited disclosure in appropriate manner. |
Penalties under Article 50: up to €15 million or 3% of total worldwide annual turnover, whichever is higher. For SMEs and startups, the lower figure applies.
The action list: what to do right now, and what can wait

The CV brief for this blog said the persona optimizes for speed and minimum hassle. This is the version of the action list that reflects where the deadlines actually stand.
Do this now (Article 50 is in force)
- Add AI disclosure to any chatbot or conversational AI feature: a clear notification at the point of first interaction that the user is talking to an AI. This is a product change, not a compliance document.
- Apply machine-readable marking to AI-generated content (images, audio, video, text) produced by your system. For systems already live before 2 August 2026: you have until 2 December 2026. For new deployments: comply from launch.
- If your product creates deepfakes or AI-generated text on public-interest topics published without human review, add disclosure. This is likely to be a narrow obligation for most SaaS products; check whether your use case falls within it.
- Document that you have reviewed Article 50 applicability and implemented the required disclosures. Keep the record. This is the evidence an investor, enterprise buyer, or regulator will ask for first.
Do this before December 2027 (Annex III high-risk, if it applies)
- Determine whether your system falls into an Annex III category. If you are unsure, take an hour to read the Annex III category descriptions and match them against your system's intended purpose. If it is genuinely ambiguous, get legal advice.
- If Annex III applies: start the risk management system documentation now. The conformity assessment, technical documentation, human oversight architecture, and post-market monitoring requirements are 12 to 18 months of work for most organizations. December 2027 is not far away.
- If Annex III applies: check whether your system needs to register in the EU AI Act database before being placed on the EU market. The registration database is being stood up by the EU AI Office.
- If Annex III does not apply: document that determination. Keep a short written record of why your system is not in scope, referencing the Annex III categories you reviewed. This protects you if the classification is ever questioned.
Use the deferral window for this (December 2026 through December 2027)
- Establish an AI governance process. The EU AI Act, ISO 42001, and enterprise buyer questionnaires are converging on the same expectation: document what AI systems you use, what data they process, who is accountable, and how decisions are reviewed. This documentation is useful regardless of which deadline applies.
- Add AI systems to your vendor inventory. If you use third-party AI models (OpenAI, Anthropic, Google, etc.) as part of your product, document them as subprocessors or AI system providers. This is relevant for EU AI Act compliance, GDPR, and enterprise buyer due diligence simultaneously.
- Map your AI features against the four-tier risk framework: prohibited, high-risk (Annex III), transparency-only (Article 50), and minimal risk. The mapping exercise itself is what produces the documentation that satisfies compliance, investor, and customer questions.
The investor and enterprise buyer question
The specific use case the CV brief identified: something is blocking a deal or a round. Here is what to say.
If the question is about EU AI Act compliance in a fundraising context: the high-risk deadline (Annex III) has been deferred to December 2027. Article 50 transparency obligations are in force from 2 August 2026, and we have implemented the required disclosures.
We have mapped our AI features against the four-tier risk framework and documented our classification. If the investor wants the documentation, it exists.
If the question is about EU AI Act compliance in a sales cycle: if the prospect's legal team is asking about the August 2026 deadline, the headline answer is that the Annex III high-risk deadline moved to December 2027 per Regulation (EU) 2026/1744. Article 50 transparency requirements are in force, and we have implemented chatbot disclosure and AI-generated content marking as required.
Our AI features do not fall under Annex III high-risk classification [if applicable]. If they want the classification documentation, we can provide it.
The documentation that makes this conversation quick is the same documentation that produces actual compliance. A one-page AI feature inventory with risk tier classification for each feature, the Article 50 disclosure implementation record, and the Annex III review memo covers 90% of what investors and enterprise buyers ask about in the current market.
How Scrut supports EU AI Act readiness
EU AI Act governance overlaps with the same control infrastructure that powers SOC 2, ISO 27001, and GDPR compliance programs. The AI feature inventory required for EU AI Act classification is the same asset inventory that feeds SOC 2 CC9.2 vendor management criteria and ISO 27001 Annex A 5.19 supplier relationships.
The AI governance documentation is the same documentation that satisfies enterprise buyer AI security questionnaires. See the 2026 Business Impact of Compliance Automation report for benchmarks on how organizations that build compliance infrastructure once reuse it across multiple frameworks simultaneously.
Scrut's control library maps across SOC 2, ISO 27001, HIPAA, GDPR, NIST, and now emerging AI governance frameworks including ISO 42001 and EU AI Act obligations. For founders with an AI product and a growing compliance surface, building the inventory and governance documentation once and reusing it across frameworks is the operational model that makes compliance achievable without a dedicated compliance team.
See how Scrut helps AI-enabled SaaS companies build compliance programs that scale across SOC 2, ISO 27001, GDPR, and the EU AI Act. Request a demo.
It is enacted law. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal of the EU on 24 July 2026, and entered into force on 27 July 2026. The Annex III high-risk compliance deadline for standalone AI systems is 2 December 2027, and the deadline for AI embedded in Annex I regulated products is 2 August 2028. Neither date requires further Commission action to take effect.
Yes. The EU AI Act has extraterritorial scope similar to GDPR, applying to providers of AI systems placed on the EU market, deployers of AI systems in the EU, and providers and deployers located outside the EU whose AI systems are used within the EU. A U.S. or Indian SaaS company with EU users is in scope. The critical question is not where the company is incorporated but where the AI system is placed on the market or put into service.
Yes, Article 50(1) applies from 2 August 2026. If your system interacts directly with people, you must ensure those people know they are interacting with an AI, at the point of first interaction. This applies regardless of whether your chatbot qualifies as high-risk under Annex III. The obligation is a product design requirement: add a disclosure at the opening of any AI-driven conversation. Exceptions exist for systems used in disclosed creative or fictional contexts, and for law enforcement systems.
Likely yes. Annex III point 4 covers AI used for recruitment, CV screening, candidate ranking, interview analysis, and employment decisions. If your product is used by an employer to filter, rank, or make decisions about job candidates, it is in scope for high-risk classification. The Article 6(3) exception (no significant risk) is narrow and does not apply to systems that profile individuals. If you are unsure, the European Commission published draft classification guidelines on 19 May 2026 with worked examples for employment AI. The 2 December 2027 deadline gives you time to complete the conformity assessment and risk management documentation, but the classification decision needs to be made now so the work can start.
2 things. First: implement Article 50 transparency disclosures. These are both in force from 2 August 2026. If your product includes a chatbot, add an AI disclosure at first interaction. If your product generates AI content (images, audio, video, text), apply machine-readable marking. Second: classify your AI features against the four-tier framework (prohibited, Annex III high-risk, Article 50 transparency-only, minimal risk) and document that classification. The documentation itself is the compliance artifact that satisfies investor and enterprise buyer questions while you work toward full compliance on the December 2027 timeline.

Susmita Joseph is a cybersecurity and compliance writer specializing in governance, risk, and regulatory content. She focuses on making complex subjects such as AI governance, cybersecurity compliance, and risk management accessible to growing and mature organizations. With a particular interest in the intersection of AI and GRC, her work explores how emerging technologies are reshaping compliance expectations and security operations.

Team Scrut is a collective of compliance, security, and risk practitioners sharing practical guidance on building audit-ready, scalable programs. We write about SOC 2, ISO 27001, continuous compliance, third-party risk, cloud security, and GRC automation, blending regulatory depth with operator experience to help fast-growing companies strengthen trust, streamline audits, and stay ahead of evolving security demands.

%20(1).png)























