⏰ EU AI Act — High-risk deadline deferred to 2 December 2027 (Digital Omnibus, in force 27 July 2026) · Article 50 transparency duties apply since 2 August 2026

EU AI Act Compliance Guide

EU AI Act Consulting — What High-Risk AI Providers Need Before 2 December 2027

The EU Artificial Intelligence Act (Regulation 2024/1689) sets the first horizontal rules for AI worldwide. The Digital Omnibus (Regulation (EU) 2026/1744) pushed the eight high-risk obligations from 2 August 2026 to 2 December 2027 for stand-alone Annex III systems — the duties themselves are unchanged, and fines still reach 35 million euros.

Published 15 April 2026 · Last updated: August 2026 ✓ Verified 18.08.2026
In 60 seconds — plain language

An EU AI Act consultant is a product-safety engineer for AI systems — the role that translates legal text from Brussels into a working risk management system, technical documentation and a conformity assessment your auditors can sign off.

Why now? High-risk AI Act obligations were deferred from 2 August 2026 to 2 December 2027 by the Digital Omnibus — but they are the same eight obligations, and they still take 9–12 months of focused work. Meanwhile the Article 50 transparency duties have applied since 2 August 2026. Fines up to €35 million or 7% of worldwide annual turnover for prohibited practices; up to €15 million or 3% for high-risk non-compliance.

What this page delivers: how systems qualify as high-risk, the eight provider obligations, what good consulting actually covers, and how to vet a consultant. Reading time: ~8 minutes.

This page is for you if …
  • Your company is a provider or deployer of AI systems placed on the EU market
  • You work in AI/ML engineering, Risk, Compliance or the C-suite
  • Your organisation has no in-house AI governance function and needs external support
  • You need to meet the 2 December 2027 high-risk deadline — or the Article 50 transparency duties already in force

The EU Artificial Intelligence Act entered into force on 1 August 2024 and is being phased in in stages. Prohibited practices have been banned since 2 February 2025. Obligations for general-purpose AI models took effect on 2 August 2025. The broadest milestone — the requirements for high-risk AI systems — was originally set for 2 August 2026, but the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) moved it to 2 December 2027 for stand-alone Annex III systems and to 2 August 2028 for AI embedded in products already covered by EU product-safety law under Annex I. The deferral does not change the substance of the obligations — it changes only when providers and deployers must have them in place.

For most organisations this is not a paperwork exercise. Building a compliant risk management system, producing the technical documentation required by Annex IV, setting up post-market monitoring, and running a conformity assessment typically takes 9 to 12 months of focused work. With the Annex III date now at 2 December 2027, a company starting today has roughly 16 months of runway — comfortable, but not generous once the harmonised CEN-CENELEC standards land and notified-body capacity tightens in the final quarters before the date.

Key facts about the EU AI Act

Legal basis: Regulation (EU) 2024/1689, entered into force 1 August 2024

Amending act: Regulation (EU) 2026/1744 (Digital Omnibus on AI), OJ 24 July 2026, in force 27 July 2026

High-risk obligations, stand-alone Annex III systems, apply from: 2 December 2027 (deferred from 2 August 2026)

High-risk obligations, Annex I embedded systems, apply from: 2 August 2028

Article 50 transparency obligations apply from: 2 August 2026 (not deferred)

General-purpose AI rules apply from: 2 August 2025

Maximum fine: 35 million euros or 7% of worldwide annual turnover

Fine for high-risk non-compliance: up to 15 million euros or 3% of turnover

Eight high-risk areas listed in Annex III (employment, credit, education, law enforcement, migration, critical infrastructure, biometrics, essential services)

What qualifies as a high-risk AI system

Annex III of the AI Act lists eight areas in which an AI system is presumed high-risk. These include biometric identification, critical infrastructure management, education and vocational training, employment and worker management, access to essential private and public services, law enforcement, migration and border control, and the administration of justice.

A second pathway to high-risk status runs through Annex I: AI components used as safety components in products already regulated by existing EU harmonisation law, such as machinery, toys, medical devices, lifts or radio equipment. Here the AI Act obligations layer on top of the existing CE marking regime.

Not every AI system used in these areas automatically qualifies. Article 6(3) introduces a filter: systems that perform narrow procedural tasks, improve the result of a human activity, detect decision patterns without replacing human assessment, or prepare an assessment relevant for the listed use cases can be exempted — provided the provider documents the reasoning and registers the exemption.

The eight obligations for high-risk providers

Risk management system (Article 9): a continuous, iterative process to identify, estimate, evaluate and mitigate the risks an AI system poses to health, safety and fundamental rights.

Data and data governance (Article 10): training, validation and testing data must be relevant, representative, free of errors and complete. Data governance practices must address bias, data gaps and the appropriateness of the data for the intended purpose.

Technical documentation (Article 11, Annex IV): a complete dossier containing a general description of the system, its intended purpose, the hardware it runs on, the algorithms used, the training data, the validation and testing metrics, the risk management system and the instructions for use.

Record-keeping (Article 12): high-risk systems must automatically log events to ensure a level of traceability appropriate to the intended purpose, and those logs must be kept for a minimum of six months.

Transparency and information to deployers (Article 13): instructions for use must describe the system's intended purpose, the level of accuracy, robustness and cybersecurity it was validated against, its known limitations, and the measures the deployer must take to ensure human oversight.

Human oversight (Article 14): oversight measures must enable a human to understand the system's capacities and limitations, interpret its output correctly, decide not to use it, override it, or intervene in its operation.

Accuracy, robustness and cybersecurity (Article 15): systems must perform consistently throughout their lifecycle and be resilient against errors, faults and attempts to alter their use or performance through adversarial inputs.

Conformity assessment and CE marking (Articles 43, 48): before being placed on the market, the system must pass a conformity assessment. For most Annex III systems this is an internal procedure; biometric identification systems require a notified body.

ExampleA fintech with 140 employees uses a machine learning model for credit-scoring retail customers — an Annex III high-risk use case. Compliance effort: ~12 days of engineering to stand up a risk management system (Article 9), ~20 days to produce Annex IV technical documentation, ~8 days on logging (Article 12) and ~5 days on human oversight (Article 14). Remediation + consulting budget: €85,000–140,000 over 6 months, plus a €12,000–18,000 annual maintenance load for model updates.

What good EU AI Act consulting covers

Consulting engagements on the AI Act typically begin with an inventory and classification sprint. Every AI component already in use or on the roadmap is mapped against Article 6 and Annex III to determine whether it is prohibited, high-risk, subject to transparency obligations only, or out of scope.

The next phase is a gap assessment against the eight obligations. This usually surfaces missing documentation, undocumented training datasets, unclear accountability for model updates, and oversight procedures that exist on paper but not in practice. A realistic remediation plan assigns each gap to a named owner with a deadline tied to the 2 December 2027 milestone — and treats the Article 50 transparency duties, which are already in force, as the immediate work package.

The third phase is implementation: drafting the Annex IV technical documentation, setting up the logging infrastructure, writing instructions for use, and preparing for the conformity assessment. Where the provider relies on a general-purpose AI model from a third party, the consultant also verifies that the upstream provider delivers the information required by Article 53.

Implementation timeline

2 February 2025 — Ban on prohibited AI practices (Article 5)

2 August 2025 — GPAI model obligations apply

2 August 2026 — Article 50 transparency obligations apply; Commission gains enforcement powers over GPAI models

27 July 2026 — Digital Omnibus on AI (Regulation (EU) 2026/1744) enters into force and defers the high-risk dates

2 December 2027 — High-risk obligations apply in full for stand-alone Annex III systems

2 August 2028 — High-risk obligations apply for products covered by Annex I (e.g. medical devices, machinery)

Now: comply with Article 50 transparency, inventory AI use cases, classify risk, start technical documentation

How to choose an AI Act consultant

A credible EU AI Act consultant combines three things: fluency in the regulation's text (including the delegated acts and the harmonised standards being developed by CEN-CENELEC JTC 21), hands-on experience with machine learning engineering, and familiarity with existing product-safety conformity assessment procedures. Pure legal advisors without engineering depth tend to produce paperwork that fails a technical audit; pure engineers without regulatory depth tend to miss documentation requirements that become fatal at the conformity assessment stage.

The market is young and uneven. When evaluating providers, ask for a sample Annex IV technical documentation redacted from a real engagement, ask how they handle GPAI upstream dependencies, and ask which harmonised standards they are tracking. Consultants who cannot answer these three questions concretely are not yet ready to carry a high-risk project to the 2 December 2027 deadline.

What AI Act consulting typically costs

Seniority Day rate (net) Typical scope
Junior Consultant€900 – €1,200Interviews, inventory, documentation drafts
Senior Consultant€1,400 – €1,700Gap assessment, workshops, technical lead
Principal / Partner€2,100 – €2,600Strategy, conformity sign-off, regulator-facing
ML/MLOps Specialist€1,600 – €2,200Model-level risk assessment, logging setup, bias audit
Example project budgetMid-sized SaaS provider with 3 high-risk AI systems and 220 employees: inventory and classification (6 PT Senior, 3 PT Junior) = €11,400–€15,300. Gap assessment across 3 systems (18 PT mixed) = €24,000–€32,000. Remediation — drafting Annex IV, logging, oversight (42 PT mixed + 8 PT ML specialist) = €70,000–€95,000. Conformity assessment prep (5 PT Principal) = €10,500–€13,000. Total: €115,000–€155,000 for full AI Act readiness.
Deal-breakers when choosing a consultant
  • Cannot name which CEN-CENELEC JTC 21 harmonised standards they are currently tracking
  • No redacted Annex IV technical documentation to show as a reference
  • Promises "AI Act certification" — no such thing exists, only conformity assessment
  • Day rate below €900 for advertised "senior" staff (red flag for expertise)
  • No experience with upstream GPAI dependencies (Article 53)
  • No answer on how they handle liability if conformity assessment fails

Frequently asked questions

What is the EU AI Act?

The EU AI Act (Regulation (EU) 2024/1689) is the first comprehensive, horizontal AI regulation in the world. It entered into force on 1 August 2024 and classifies AI systems into four risk tiers: unacceptable risk (banned), high risk (strictly regulated), limited risk (transparency obligations) and minimal risk (unregulated). It applies to providers placing AI systems on the EU market, to deployers using them in the EU, and, in certain cases, to providers outside the EU whose output is used in the Union.

Which deadlines apply in 2026?

The picture changed on 27 July 2026, when the Digital Omnibus on AI — Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 — entered into force. It deferred the high-risk obligations that were due on 2 August 2026: stand-alone Annex III systems now apply from 2 December 2027, and AI systems that are safety components of products regulated under Annex I from 2 August 2028. What did take effect on 2 August 2026 as planned: the Article 50 transparency duties (chatbot disclosure, marking of AI-generated content, deepfake labelling) and the Commission’s enforcement powers over general-purpose AI models. Prohibited practices under Article 5 have been banned since 2 February 2025.

What is a high-risk AI system?

A high-risk AI system is one that falls into an area listed in Annex III of the AI Act (for example biometric identification, critical infrastructure, education, employment decisions, access to essential services, law enforcement, migration and justice) or is used as a safety component in a product covered by Annex I Union harmonisation law. Article 6(3) allows exceptions for narrow procedural or preparatory systems, but providers must document the justification and register the exemption in the EU database.

What fines apply for non-compliance?

The AI Act sets three tiers of administrative fines. Violating the prohibitions in Article 5 can trigger fines of up to 35 million euros or 7% of the provider's worldwide annual turnover, whichever is higher. Non-compliance with high-risk obligations or transparency obligations can reach 15 million euros or 3% of turnover. Providing incorrect, incomplete or misleading information to authorities can reach 7.5 million euros or 1% of turnover. For SMEs and start-ups, the lower of the two values applies.

What does EU AI Act consulting cover?

A typical consulting scope covers four phases: first, an inventory and risk classification of all AI systems in use; second, a gap assessment against the eight obligations for high-risk systems; third, remediation — drafting technical documentation under Annex IV, setting up logging, designing human oversight, and verifying data governance; and fourth, preparation for the conformity assessment, including EU declaration of conformity, CE marking where applicable, and registration in the EU database.

How long does AI Act compliance take?

For a provider with a single high-risk system and mature MLOps practices already in place, a realistic timeline is 6 to 9 months. For organisations with multiple systems, fragmented data governance or no prior experience with product-safety conformity assessments, the realistic range is 9 to 15 months. The Digital Omnibus moved the Annex III deadline to 2 December 2027, which restores roughly 16 months of runway — but only for the high-risk obligations. Classification and gap assessment should still come first, because the Article 50 transparency duties already apply and the harmonised standards that make conformity assessment routine are not finished yet.