When do the EU AI Act's high-risk obligations apply to Annex III and Annex I systems?
Question as asked: When do the EU AI Act high-risk obligations apply to Annex III systems such as CV-screening tools, and to Annex I product safety components?
Application dates for high-risk obligations
Annex III systems (e.g., CV-screening tools under Annex III point 4(a) – "analysing and filtering job applications, evaluating candidates"): The high-risk obligations in Chapter III, Sections 1–3 of Regulation (EU) 2024/1689 apply from 2 December 2027 (Art. 113, third paragraph, point (c)(i), as amended by Regulation (EU) 2026/1744). This date was pushed back by the Digital Omnibus from the original 2 August 2026 cut-off.
Annex I systems (safety components of products subject to third-party conformity assessment, e.g., machinery, medical devices): These obligations apply from 2 August 2028 (Art. 113, third paragraph, point (c)(ii), as amended). This too was deferred by the Omnibus from the original date.
Transitional rule for systems already on the market — Art. 111(2)
For high-risk systems (other than Annex X large-scale IT components) already placed on the market or put into service before the relevant application date above, Regulation (EU) 2024/1689 applies to providers and deployers only if the system undergoes a significant design change on or after that date (Art. 111(2), as replaced by Regulation (EU) 2026/1744). Key points:
- This is a grace period, not an exemption. A legacy CV-screening tool placed on the market before 2 December 2027 stays outside Chapter III obligations until it undergoes a significant design change on or after that date — at which point full compliance, including conformity assessment, is triggered.
- A significant change made before the application date does not start the obligations early; no one is subject to Chapter III high-risk obligations before 2 December 2027 (Annex III) or 2 August 2028 (Annex I), regardless of updates made in the interim.
- The grace period is without prejudice to Art. 5 (prohibited practices) and does not affect Art. 50 transparency duties, which run on their own separate timeline.
- Public-authority systems are an exception: high-risk systems intended for use by public authorities must comply by 2 August 2030 regardless of whether a significant design change occurs (Art. 111(2), second sentence).
- A system first placed on the market after the applicable date gets no grace period at all.
Missing fact that would change the answer: whether the CV-screening tool (or Annex I component) was already placed on the market/put into service before its respective application date, and whether the deployer is a public authority. If it's a new system launching after 2 December 2027 (Annex III) or 2 August 2028 (Annex I), full obligations apply immediately with no transition.
Research aid, not legal or audit advice. This answer reflects the standard as of the date above; verify it against the official text before relying on it.
More answers
- Can we use SAQ A with a payment processor's iframe, and do we still need ASV scans? (PCI DSS v4.0.1)
- How many Annex A controls are in ISO 27001:2022, and how are they grouped? (ISO/IEC 27001:2022)
- How long do we have to answer a GDPR subject access request, and can we extend it? (GDPR)
- Does India's DPDP Act apply to a US SaaS company with no Indian entity, and to paper records? (India DPDPA)