Most explanations of the EU AI Act’s conformity assessment regime are now out of date, and the way they are wrong matters. They tell you high-risk obligations bite on 2 August 2026. They do not. They also imply everything has been delayed, which is worse — because the obligations that apply right now are the ones being ignored.
Here is the position as of August 2026.
What conformity assessment actually is
Conformity assessment is the EU’s standard mechanism for regulated products, borrowed wholesale for AI. Before a high-risk AI system goes on the market, someone must check it against the Act’s requirements and document that check. Pass, and the provider draws up an EU declaration of conformity and affixes CE marking.
The important structural point: for most high-risk AI, you assess yourself.
- Annex VI — internal control. The provider performs the assessment against its own quality management system and technical documentation. No external body is involved. This is the default route for most standalone high-risk systems under Annex III.
- Annex VII — notified body. An accredited third party reviews the quality management system and technical documentation. Required in narrower circumstances, including where harmonised standards do not exist, are not available, or the provider has not applied them.
So “CE marked AI” mostly means the provider assessed itself and signed a declaration. That is not a criticism — it is how the CE regime works for most products — but anyone treating a CE mark as independent validation has misread it.
Why the deadline moved
The Commission proposed the Digital Omnibus on AI on 19 November 2025. Parliament voted it through on 16 June 2026, the Council approved it on 29 June, and it was published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744, entering into force on 27 July. This is settled law, not a proposal. The high-risk application dates are now:
| Original | Now | |
|---|---|---|
| Annex III — standalone high-risk systems | 2 August 2026 | 2 December 2027 |
| Annex I — high-risk AI embedded in regulated products | 2 August 2027 | 2 August 2028 |
The reason is unglamorous and instructive: the harmonised standards needed to make Annex III compliance operable were not going to exist in time. European standardisation bodies had slipped delivery toward the end of 2026, which would have left providers legally obliged to conform to requirements with no agreed technical means of doing so.
It is worth being precise about what this is. The Omnibus is the first formal set of amendments to the AI Act since its adoption in June 2024, and it changes the dates rather than the obligations. Nothing about what a high-risk system must do has been relaxed.
What did not move
This is the part that gets lost:
- Article 50 transparency obligations — disclosure that a user is interacting with an AI system, marking of synthetic content, deepfake labelling — are unchanged.
- Article 4 AI literacy duty — the obligation on providers and deployers to ensure staff dealing with AI have adequate literacy — is unchanged.
- Prohibited practices under Article 5 have applied since February 2025.
- General-purpose AI model obligations have applied since August 2025.
An organisation that reads “the AI Act has been delayed” and stands down is exposed on duties that are already live. The AI literacy duty in particular is widely unmet and easy to breach without noticing: it applies to deployers, not just builders, and most organisations deploying AI have done nothing about staff competence.
What the extra sixteen months are actually for
Not waiting. The delay removes the deadline, not the work, and the work is slow-to-produce evidence:
An inventory that includes what you bought. You cannot classify what you cannot see, and the systems that get missed are the ones nobody procured as AI — features switched on inside software the organisation already owned.
Classification decisions, with reasons. Whether a system is high-risk under Annex III is a judgement. Make it, write down why, and date it. A defensible wrong answer is recoverable; an undocumented right answer is not.
Technical documentation built as you go. Annex IV documentation is far cheaper to assemble during development than reconstructed afterwards from people who have left.
A quality management system that exists. Annex VI conformity assessment is an assessment against your QMS. If there is no QMS, there is nothing to assess, and this is where ISO/IEC 42001 does real work — see ISO/IEC 42001 explained.
Three misreadings worth avoiding
“CE marking means it was independently checked.” Usually it means self-assessment under Annex VI. Ask which route was used.
“We use AI, so the Act applies to us as a provider.” Provider and deployer obligations differ substantially. Deployers of high-risk systems have real duties — human oversight, input data relevance, monitoring, logging — but they are not the same duties, and conflating them produces work in the wrong place.
“Conformity means it is safe.” Conformity assessment establishes that requirements were met and documented. It is not an opinion on whether the system is fit for your deployment. That gap is what assurance exists to fill — see AI assurance vs AI audit vs AI risk assessment.
If you do one thing
Produce a dated, written classification of every AI system you provide or deploy: not high-risk, high-risk under Annex III, or high-risk under Annex I, with the reasoning. Everything downstream — documentation, oversight design, assessment route — depends on that judgement, and it is the artefact a regulator will ask for first.
Scoping and evidencing that judgement is assessed in the Certified AI Audit Professional track.
This is general information, not legal advice. Confirm the current position before relying on any date in this article.
Sources: EU AI Act, Article 43 — Conformity Assessment · Annex VI · European Parliament Legislative Train — Digital Omnibus on AI · White & Case, EU agrees Digital Omnibus deal · White & Case, EU AI Omnibus enters into force · Regulation (EU) 2026/1744, OJ 24 July 2026