The enacted EU AI Act sets its high-risk obligations to apply on 2 August 2026. That date is still the law. A proposal to defer it to 2027 and 2028 has reached a provisional political agreement, but it is not yet adopted, and a provisional agreement is not a date you can plan around. What the Act asks for does not change either way.
What changed
The AI Act has applied in phases since it entered into force in August 2024. Prohibited practices came first, then the rules for general-purpose AI. The largest tranche, the obligations on high-risk systems, applies from 2 August 2026 under the enacted regulation. That is current law in every Member State.
In November 2025 the Commission proposed the Digital Omnibus on AI (COM(2025) 836), a package that would, among other simplifications, defer the high-risk obligations. On 6 and 7 May 2026 the Parliament and Council negotiators reached a provisional political agreement on it. If adopted as agreed, Annex III high-risk systems, the use-based systems such as biometrics, employment and credit scoring, would move from 2 August 2026 to 2 December 2027. Annex I high-risk systems, the AI embedded in products already regulated under EU safety law such as medical devices, would move from their enacted date of 2 August 2027 to 2 August 2028.
The distinction that matters: none of this is law yet. A provisional trilogue agreement is a political commitment among negotiators. The deferral takes effect only after the Parliament’s plenary vote, the Council’s formal adoption, and publication of the amending regulation in the Official Journal. Until that sequence completes, the enacted dates stand and the binding high-risk date remains 2 August 2026. Formal adoption is expected before that date, but expected is not enacted. And whatever happens to the high-risk timeline, 2 August 2026 still brings the bulk of the Act into application, the start of enforcement, and the Article 50 transparency duties, including telling people when they are interacting with an AI system.
Who it applies to
For a pharmaceutical manufacturer the first question is whether the AI Act treats your system as high-risk at all, and the answer is more often no than the discussion suggests. AI used inside a GMP manufacturing process is not, on its own, an Annex III system. The high-risk classification reaches life sciences mainly where the AI is, or is a safety component of, a medical device already regulated under the MDR or the IVDR. Those are Annex I systems. Their enacted date is 2 August 2027, and the proposal would defer them to 2 August 2028 if it is adopted.
So a typical pharma AI workflow sits in a particular place. It is usually not high-risk under the AI Act. It is still subject to the Act’s general and transparency provisions from 2 August 2026. And it is squarely inside the sectoral GMP regime, where the draft Annex 22 sets AI-specific expectations that are closer and more directly binding than the horizontal Act for most manufacturing uses. The AI Act and Annex 22 are converging on the same questions from two directions.
Why it matters for AI workflows
A proposed deferral invites a pause, and the pause is a worse trap when the deferral is not even law. A plan that assumes 2 December 2027 is a plan built on an agreement that can still shift in the vote, the adoption, or the drafting. The enacted date is 2 August 2026, and it is the one a planner has to hold to until the Official Journal says otherwise.
The expectations did not soften in any case. When the high-risk articles apply, on whichever date binds, they ask a regulated AI system to show a risk-management process, governed and documented training data, technical documentation, logged records, human oversight, and demonstrated accuracy and robustness. Read that list next to the draft Annex 22 and it is, in substance, the same list a GMP inspector will ask for.
That overlap is the point. The two regimes are not asking for two evidence packages. They are asking, in different words, for one.
The preflight implication
A preflight produces that one package before the workflow runs: the intended use stated in scope terms, the provenance of the data the model learned from, the validation evidence tied to that intended use, the point at which a human must review rather than the system deciding alone, and the monitoring that would catch drift. Those five things are the common core of the AI Act’s high-risk requirements and of Annex 22.
Building that record now holds up against an uncertain calendar. Whether the binding date is 2 August 2026 under the enacted law, or 2 December 2027 and 2 August 2028 if the Omnibus is adopted, or the GMP adoption of Annex 22 somewhere in between, the evidence is the same and it already exists. The alternative, waiting for the date that finally applies and assembling the record under it, is the expensive path. A preflight makes the deadline a question of when you are asked for the file, not whether you have one.
What you can do now
Plan to the enacted date, not the proposed one. The binding high-risk date is 2 August 2026 until the Official Journal says otherwise, so treat any deferral as a possibility, not a reprieve. Identify which of your AI workflows could be in scope of the AI Act as device-related high-risk, and separate them from the larger set that the Act touches only through transparency and that GMP Annex 22 governs more directly. For both, stand up the five-part evidence record now and keep it current. One file, produced before the work runs, that answers whichever regime asks first.
Sources
- Regulation (EU) 2024/1689 (the EU AI Act), Article 113: high-risk obligations apply from 2 August 2026. Official Journal L 2024/1689. eur-lex.europa.eu
- European Commission. Proposal for a Regulation amending Regulation (EU) 2024/1689 (Digital Omnibus on AI), COM(2025) 836 final, CELEX 52025PC0836, procedure 2025/0359(COD). eur-lex.europa.eu
- Council of the European Union. Artificial intelligence: Council and Parliament agree to simplify and streamline rules. 7 May 2026, provisional political agreement. consilium.europa.eu
Status note: as of 11 June 2026 the Digital Omnibus on AI (COM(2025) 836) is a provisional political agreement and is not yet adopted or published in the Official Journal. The enacted high-risk date, 2 August 2026, remains binding until that happens. Dates here are verified against the primary EUR-Lex sources above. This item is reference-only and reproduces no regulatory text.