UPDATE (July 2026): this calendar has changed
The Digital Omnibus package, adopted by Parliament on 16 June 2026 and by the Council on 29 June 2026, deferred the high-risk obligations: 2 December 2027 for Annex III (stand-alone systems) and 2 August 2028 for Annex I (AI embedded in regulated products). The Article 50 transparency duties remain confirmed for 2 August 2026. The text below is the version published before the amendment and is kept for documentary continuity.
Deadline August 2, 2026
From August 2, 2026, the obligations of articles 26 and 27 of the AI Act apply for deployers (users) of high-risk AI systems. If your client uses AI systems for recruiting, credit scoring, HR management, biometrics, student evaluation, or critical public services, you have less than 3 months to implement the compliance framework.
The 8 high-risk categories (Annex III)
- Biometrics (identification, categorization, emotion recognition)
- Critical infrastructure (traffic management, water/gas/electricity supply)
- Education and training (admission, evaluation, monitoring)
- Employment, worker management, access to self-employment
- Access to essential private/public services
- Law enforcement (crime risk, polygraphs, evidence reliability)
- Migration, asylum, border control
- Administration of justice and democratic processes
DPO's role: 5 concrete actions by July 2026
- Inventory of AI systems used by your clients
- Risk classification: assess if each system falls under Annex III
- Map provider-deployer contracts
- Update GDPR Art. 30 registers with AI references
- Prepare FRIA template based on EDPB guidelines 02/2026
Practical tip
If you are DPO of a company with more than 100 employees, it's very likely that at least one AI system in HR (CV screening, performance management) falls under Annex III. Start there.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free