EU AI Act: High-Risk Obligations Apply to AI Embedded in Annex I Regulated Products
The final deferred EU AI Act deadline arrives. Regulation (EU) 2026/1744, the Digital Omnibus on AI, moved the Chapter III obligations for AI systems classified as high-risk under Article 6(1) and Annex I, meaning AI that functions as a safety component of, or is itself, a product covered by existing EU product legislation such as the medical devices, in vitro diagnostic, machinery, and radio equipment regimes. Those obligations apply from August 2, 2028. Stand-alone Annex III high-risk systems ran to the earlier deferred date of December 2, 2027.
Key Analytics
Impact Analysis
Annex I got the longer runway because these products already sit inside a sectoral conformity assessment regime, and the AI Act's requirements have to be folded into that existing route rather than run beside it. For a medical device manufacturer that means the AI Act risk management, data governance, technical documentation, logging, human oversight, and accuracy and robustness requirements are assessed as part of the notified body process under the Medical Device Regulation, not as a separate certification. The practical risk is scheduling rather than substance: notified body capacity in these sectors is already the constraint on product launches, and a compliance date shared across every AI-enabled regulated product in the Union concentrates demand. Manufacturers who treat 2028 as distant will be competing for the same review slots as everyone else.
Recommended Actions
- Identify which of your products are covered by the Annex I sectoral legislation and contain AI that is a safety component or is itself the AI system, since that is the classification test under Article 6(1).
- Work the AI Act requirements into your existing sectoral conformity assessment and quality management system rather than building a parallel programme.
- Open the capacity conversation with your notified body early, because a single Union-wide date concentrates demand in sectors where review capacity is already the bottleneck.
- Align technical documentation so one file serves both the sectoral regime and the AI Act, and confirm logging and human oversight evidence is captured by the product itself.
- Hold the earlier December 2, 2027 date for any stand-alone Annex III systems you also provide, because the two deadlines run on separate tracks.
Always verify requirements with official regulatory sources.
Estimated Remediation Effort
Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.
A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.
- ›Gap assessment against current controls
- ›Readiness assessment
- ›Remediation sprint to date
- ›Attestation or filing preparation
The Cost of Waiting
Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.
Roughly 55 to 240 hours avoided by preparing early
Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.