Compliance Colleague · Answers · EU AI Act

When do the EU AI Act's high-risk obligations apply to Annex III and Annex I systems?

Standard: EU AI Act · Answered by Compliance Colleague on September 30, 2026

Question as asked: When do the EU AI Act high-risk obligations apply to Annex III systems such as CV-screening tools, and to Annex I product safety components?

Application dates for high-risk obligations

Annex III systems (e.g., CV-screening tools under Annex III point 4(a) – "analysing and filtering job applications, evaluating candidates"): The high-risk obligations in Chapter III, Sections 1–3 of Regulation (EU) 2024/1689 apply from 2 December 2027 (Art. 113, third paragraph, point (c)(i), as amended by Regulation (EU) 2026/1744). This date was pushed back by the Digital Omnibus from the original 2 August 2026 cut-off.

Annex I systems (safety components of products subject to third-party conformity assessment, e.g., machinery, medical devices): These obligations apply from 2 August 2028 (Art. 113, third paragraph, point (c)(ii), as amended). This too was deferred by the Omnibus from the original date.

Transitional rule for systems already on the market — Art. 111(2)

For high-risk systems (other than Annex X large-scale IT components) already placed on the market or put into service before the relevant application date above, Regulation (EU) 2024/1689 applies to providers and deployers only if the system undergoes a significant design change on or after that date (Art. 111(2), as replaced by Regulation (EU) 2026/1744). Key points:

  • This is a grace period, not an exemption. A legacy CV-screening tool placed on the market before 2 December 2027 stays outside Chapter III obligations until it undergoes a significant design change on or after that date — at which point full compliance, including conformity assessment, is triggered.
  • A significant change made before the application date does not start the obligations early; no one is subject to Chapter III high-risk obligations before 2 December 2027 (Annex III) or 2 August 2028 (Annex I), regardless of updates made in the interim.
  • The grace period is without prejudice to Art. 5 (prohibited practices) and does not affect Art. 50 transparency duties, which run on their own separate timeline.
  • Public-authority systems are an exception: high-risk systems intended for use by public authorities must comply by 2 August 2030 regardless of whether a significant design change occurs (Art. 111(2), second sentence).
  • A system first placed on the market after the applicable date gets no grace period at all.

Missing fact that would change the answer: whether the CV-screening tool (or Annex I component) was already placed on the market/put into service before its respective application date, and whether the deployer is a public authority. If it's a new system launching after 2 December 2027 (Annex III) or 2 August 2028 (Annex I), full obligations apply immediately with no transition.

Research aid, not legal or audit advice. This answer reflects the standard as of the date above; verify it against the official text before relying on it.

This is one answer from Compliance Colleague, which answers questions like this against 30+ security, privacy and AI governance standards, with the clause cited, and reviews your policies against them. Ask your own question free, no card required →

More answers