The 2027 Deadline for AI in Regulated Products Moved to 2028
10 min read · updated August 11, 2026
AI inside a regulated product — an infusion pump, a machine’s safety controller, a connected toy — is high-risk under a different route from the Annex III use cases, and that route has always been the last to switch on. The date was 2 August 2027. It is now 2 August 2028, and the reason for the deferral is not leniency: these products already have a conformity assessment regime the AI requirements must be folded into.
The date, and the instrument that moved it
Article 113(c) of Regulation (EU) 2024/1689 as adopted provided that Article 6(1) and the corresponding obligations apply from 2 August 2027. Article 6(1) is the limb of the high-risk classification rule that deals with AI in products covered by the Union harmonisation legislation listed in Annex I.
That date has moved. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was adopted on 8 July 2026, published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It amends the AI Act alongside Regulation (EU) 2018/1139 on civil aviation and Regulation (EU) 2023/1230 on machinery — two of the Annex I instruments this page is about — and it postponed the high-risk application dates: stand-alone Annex III systems from 2 August 2026 to 2 December 2027, and high-risk AI embedded in Annex I regulated products from 2 August 2027 to 2 August 2028.
The ordering survived the amendment, which is worth noticing. Before the change, the Annex I route ran a year behind the Annex III route; after it, it runs eight months behind. Both moved, the embedded case is still last, and the structural reason it is last is unchanged — which is the subject of this page and the part that will still be true whatever the calendar does next. The Annex III date has its own page: what still changes on 2 August 2026.
The Article 6(1) test
Article 6(1) classifies an AI system as high-risk where two conditions are cumulatively met. Both, not either:
- the AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I; and
- that product — the one whose safety component the AI system is, or the AI system itself where it is the product — is required to undergo a third-party conformity assessment with a view to being placed on the market or put into service under that Annex I legislation.
The second condition does substantial filtering. A great many products covered by Annex I legislation are self-assessed by their manufacturer rather than assessed by a third party — a low-risk medical device in class I, much machinery outside the higher-risk categories, many toys. Where the product does not require third-party assessment, Article 6(1) is not met, and the AI system is not high-risk by that route. It may still be caught by Annex III on a use-case basis, and the Article 50 transparency duties and the Article 5 prohibitions apply regardless.
“Safety component” is defined in Article 3: a component of a product or system which fulfils a safety function for that product or system, or the failure or malfunctioning of which endangers the health and safety of persons or property. A model that recommends a maintenance schedule is not obviously a safety component; a model in the control loop that stops a machine is.
What is on the Annex I list
Annex I is a list of existing Union harmonisation legislation, split into two sections. Section A covers instruments to which the AI Act’s conformity assessment integration applies directly, and includes machinery under Regulation (EU) 2023/1230, toys under Directive 2009/48/EC, recreational craft, lifts, equipment for use in potentially explosive atmospheres, radio equipment, pressure equipment, cableway installations, personal protective equipment, appliances burning gaseous fuels, medical devices under Regulation (EU) 2017/745 and in vitro diagnostic medical devices under Regulation (EU) 2017/746.
Section B covers transport and related sectors: civil aviation, two- and three-wheel vehicles and quadricycles, agricultural and forestry vehicles, marine equipment, rail interoperability, and motor vehicles including the general safety regulation. These behave differently, as the next section explains.
Why this route was always last
The deferral is an alignment measure. For an Annex III system, the AI Act creates a conformity assessment obligation where none existed. For an Annex I Section A product, one already exists — a manufacturer of a class IIb medical device is already running a notified body assessment under the Medical Devices Regulation, already maintaining a quality management system, already carrying out post-market surveillance and vigilance reporting.
Article 43 does not add a parallel AI procedure for these products. It folds the AI requirements into the sectoral one: the conformity assessment is the procedure required under the relevant Annex I Section A legislation, and the notified body already designated under that act assesses compliance with the Chapter III Section 2 requirements as part of it. That means three things have to happen before the obligation can bite in a workable way. Notified bodies designated under the sectoral acts need their designations extended to cover the AI requirements; the sectoral guidance and harmonised standards need to accommodate them; and manufacturers need to integrate AI documentation into technical files that are structured around a different regulation. Time for that sequencing is the visible reason Article 113(c) put this route last, and the same reasoning is the most plausible explanation for why the 2026 amendment moved it again rather than letting the two routes converge. Note that this is an inference about motive from the structure of the instruments, not a claim about the recitals of Regulation (EU) 2026/1744, which this page has not read.
The same logic runs through other provisions. Article 72(4) lets a provider integrate the AI post-market monitoring requirements into a monitoring plan that already exists under Annex I Section A legislation, where that achieves an equivalent level of protection. Article 73 limits serious incident reporting for medical devices and IVDs to the fundamental rights category, leaving the device vigilance system to handle the rest. And Article 48 makes the CE mark cumulative rather than duplicative. The pattern is consistent: one assessment, one mark, one monitoring system, extended in scope.
Section A and Section B behave differently
This distinction is easy to miss and it changes the answer materially. Article 2(2) provides that for AI systems classified as high-risk under Article 6(1) in relation to products covered by the Union harmonisation legislation listed in Section B of Annex I, only Article 6(1), Articles 102 to 109 and Article 112 apply.
Articles 102 to 109 are the amending provisions: they amend the aviation, vehicle, rail and marine instruments so that the AI Act’s requirements are taken into account when delegated or implementing acts are adopted under those regimes. In other words, for the Section B sectors the AI Act works through the sectoral regulator rather than directly on the manufacturer. A supplier of an AI component for a motor vehicle type approval does not follow the Chapter III procedures in the way an Annex III provider does; the requirements reach it via the vehicle legislation.
If your product is in a Section B sector, the practical next step is to watch the sectoral rulemaking rather than the AI Act’s own implementing acts. If it is in Section A, the AI Act applies to you directly, through the assessment you already run.
What applies in the meantime
The 2028 date defers Article 6(1) and its corresponding obligations. It does not defer the rest of the Regulation, and a manufacturer that reads a two-year postponement as a general exemption will be wrong on at least five points:
- Article 5 prohibitions have applied since 2 February 2025 and are not tied to any risk classification.
- Article 4 AI literacy has applied since the same date, to providers and deployers of any AI system.
- Article 50 transparency duties apply from 2 August 2026 where the system interacts with people or generates synthetic content, regardless of the product regime around it.
- The 2 December 2026 marking date. Under Regulation (EU) 2026/1744 the marking obligations for AI-generated content apply from 2 December 2026 to systems already on the market before 2 August 2026. A regulated product that generates synthetic content and predates that cut-off has a deadline well ahead of anything in the high-risk stack.
- Annex III still exists. A product covered by Annex I legislation can contain an AI system that independently falls into an Annex III use case — an employment or biometric function bundled into a regulated device — and that route runs on the Annex III calendar, now 2 December 2027, not on this one.
And the underlying sectoral obligations never went anywhere. A medical device incorporating a model has been subject to the Medical Devices Regulation throughout; the AI Act adds requirements to that regime rather than replacing it. See how the MDR and the AI Act overlap for where the two sets of duties meet.