{"id":9397,"date":"2026-08-15T01:04:15","date_gmt":"2026-08-14T23:04:15","guid":{"rendered":"https:\/\/cybernecs.com\/?p=9397"},"modified":"2026-08-15T01:04:15","modified_gmt":"2026-08-14T23:04:15","slug":"high-risk-ai-act-delayed-2027","status":"publish","type":"post","link":"https:\/\/cybernecs.com\/en\/high-risk-ai-act-delayed-2027\/","title":{"rendered":"High-risk AI rules delayed to 2027: what does not apply yet"},"content":{"rendered":"<p style=\"letter-spacing:.12em;text-transform:uppercase;font-size:12px;opacity:.7\">Regulation \u00b7 14 August 2026<\/p>\n<p>On 2 August 2026, part of the AI Act entered into application. It is not \u201cthe whole AI Act\u201d. High-risk systems under Annex III are postponed to 2 December 2027. Embedded systems under Annex I are postponed to 2 August 2028, via the Digital Omnibus (Regulation EU 2026\/1744, in force since 27 July 2026). A VSE or SME that reads alarmist headlines has an interest in separating what is already due from what is not. Panicking over a conformity assessment file whose deadline is 2027, while forgetting the chatbot disclosure, is the wrong trade-off.<\/p>\n<h2>The timetable, without shortcuts<\/h2>\n<p>Three layers now coexist.<\/p>\n<p>Already applicable, and for longer than is often said: prohibited practices, with fines of up to \u20ac35 million or 7% of worldwide turnover. Also already applicable since 2 February 2025: Article 4 on AI literacy, for providers and for deployers.<\/p>\n<p>Applicable since 2 August 2026: Article 50 transparency (information on interactions with AI, machine-readable marking of synthetic content, visible labelling of professional deepfakes, a mention on certain texts of public interest). Systems already on the market before that date have until 2 December 2026 for the machine-readable marking under Article 50(2). The AI Office may investigate providers of general-purpose models since 2 August 2026. Failures on the transparency strand expose you to up to \u20ac15 million or 3% of worldwide turnover.<\/p>\n<p>Not yet applicable: the full regime for Annex III high-risk systems (2 December 2027) and Annex I embedded systems (2 August 2028). That postponement is what many comments too quickly summarised as \u201cthe AI Act is delayed\u201d. No. One part is in force. Another is shifted.<\/p>\n<h2>What does not yet apply to a typical SME<\/h2>\n<p>Most of the agents we see in VSEs and SMEs (appointment booking, FAQ, quote follow-up, hotel reception, site tracking) are not, by that fact alone, high-risk systems within the meaning of Annex III. For as long as the postponement holds, you do not have to produce the assessment file, formalised risk management in the high-risk format, or the post-market monitoring duties of that regime.<\/p>\n<p>That does not mean your use is \u201coutside the AI Act\u201d. You remain a deployer. You remain subject to Article 50 if a human talks to the system. You remain subject to Article 4 if your teams deploy AI without a minimum of competence. You remain subject to the GDPR as soon as personal data transits.<\/p>\n<p>Also beware of an overly optimistic self-diagnosis. A tool that steers recruitment, scores candidates, assists a medical diagnosis or weighs on access to an essential service may fall into high-risk when the time comes. The postponement gives time to prepare. It does not turn a sensitive use into a trivial one.<\/p>\n<h2>What you still need to do, now<\/h2>\n<ul>\n<li><strong>Keep a register of uses.<\/strong> Which tool, which provider, which data, which audience (staff, customers, candidates). One up-to-date page is enough at the start. Without that base, you will be unable to say, in 2027, what has become high-risk.<\/li>\n<li><strong>Handle 2026 transparency.<\/strong> Chatbots, agents, generated content: Article 50 does not wait for 2027. That is this summer\u2019s priority job.<\/li>\n<li><strong>Do not wait until 2027 for literacy.<\/strong> Article 4 has been running since 2 February 2025. An <a href=\"https:\/\/cybernecs.com\/en\/training\/\">AI and cybersecurity training programme<\/a> is not a marketing side-show. It is a deployer obligation.<\/li>\n<li><strong>Secure the system, not only the discourse.<\/strong> An agent poorly ring-fenced, with too many rights over messaging or the customer file, is a cyber incident before it is an AI Act file. See our <a href=\"https:\/\/cybernecs.com\/en\/cybersecurity-ai-data-security\/\">AI cybersecurity<\/a> offering.<\/li>\n<li><strong>Cross-check GDPR and the AI Act.<\/strong> Purpose, legal basis, transfers outside the EU, retention of prompts: a <a href=\"https:\/\/cybernecs.com\/en\/gdpr-audit-and-compliance\/\">GDPR compliance audit<\/a> remains the most concrete way to see what actually circulates.<\/li>\n<li><strong>Document non-high-risk decisions.<\/strong> If you judge that a use is not Annex III, write why, on which date, on the basis of which facts. In 2027, that note will be worth more than a memory of a meeting.<\/li>\n<\/ul>\n<h2>Avoid two symmetrical mistakes<\/h2>\n<p>The first mistake is panic: freeze every AI project until 2027, or buy a \u201chigh-risk compliance pack\u201d for an FAQ chatbot. You spend, you think you are covered, and you still have not told the user they are talking to a machine.<\/p>\n<p>The second is denial: \u201cthis is only for the big platforms\u201d. The deployer of an SME is named in the text. Fine caps are also calculated as a percentage of worldwide turnover. For a group, the percentage weighs. For a VSE, reputational and contractual risk often weighs faster than the theoretical cap.<\/p>\n<p>Patrick Dajan Mouelle, director of Cybernecs, insists on this order of battle: first the inventory and the disclosure, then access security, then only the heavy files if a use truly approaches high-risk. The reverse order produces binders and opaque agents.<\/p>\n<h2>How to move without theatre<\/h2>\n<p>If you want a reading of your uses (what is already due, what can wait until 2027, what must be trained), contact us via <a href=\"https:\/\/cybernecs.com\/en\/contact-cybernecs\/\">the contact page<\/a>. We do not sell fear of 2 December 2027. We frame what is in force on 14 August 2026, and what you can reasonably plan between now and then.<\/p>\n<p>Sources: Artificial Intelligence Regulation (AI Act), Regulation EU 2026\/1744 (Digital Omnibus), Touteleurope, L\u2019Express.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>High-risk is postponed, not the whole AI Act. Transparency, literacy and prohibited practices are already due. How to avoid both panic and inaction.<\/p>\n","protected":false},"author":2,"featured_media":9346,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-9397","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-non-classe"],"_links":{"self":[{"href":"https:\/\/cybernecs.com\/en\/wp-json\/wp\/v2\/posts\/9397","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybernecs.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybernecs.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybernecs.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/cybernecs.com\/en\/wp-json\/wp\/v2\/comments?post=9397"}],"version-history":[{"count":1,"href":"https:\/\/cybernecs.com\/en\/wp-json\/wp\/v2\/posts\/9397\/revisions"}],"predecessor-version":[{"id":9398,"href":"https:\/\/cybernecs.com\/en\/wp-json\/wp\/v2\/posts\/9397\/revisions\/9398"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybernecs.com\/en\/wp-json\/wp\/v2\/media\/9346"}],"wp:attachment":[{"href":"https:\/\/cybernecs.com\/en\/wp-json\/wp\/v2\/media?parent=9397"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybernecs.com\/en\/wp-json\/wp\/v2\/categories?post=9397"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybernecs.com\/en\/wp-json\/wp\/v2\/tags?post=9397"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}