EU AI Act 2028 Deadline: High-Risk AI in Regulated Products Explained
The EU AI Act 2028 Deadline applies to a specific category of high-risk AI systems: those covered by Article 6(1) and Annex I because they are integrated into certain regulated products or function as safety components of those products.
The European Commission has extended the application date for these rules to 2 August 2028. This is different from the 2 December 2027 deadline for high-risk AI systems classified under Article 6(2) and Annex III.
That distinction matters for manufacturers, AI providers, product teams, and organizations developing AI-enabled products for the European market. The 2028 deadline does not automatically apply to every AI system used in manufacturing, healthcare, transport, or other regulated industries. Classification depends on the AI system’s intended purpose, its relationship with the regulated product, the applicable Annex I legislation, and whether the product or AI system requires a third-party conformity assessment.
What Is the EU AI Act 2028 Deadline?
Under the amended implementation timeline, the rules for AI systems classified as high-risk under Article 6(1) and Annex I apply from 2 August 2028. The rules for AI systems classified under Article 6(2) and Annex III apply from 2 December 2027.
The difference comes from the two high-risk classification routes in Article 6.
| High-risk route | What it covers | Application date |
| Article 6(1) / Annex I | AI systems that are safety components of certain regulated products, or AI systems that are themselves products covered by specified Union harmonisation legislation and subject to third-party conformity assessment | 2 August 2028 |
| Article 6(2) / Annex III | AI systems used in specified high-risk areas and use cases listed in Annex III | 2 December 2027 |
The two dates should therefore not be treated as alternative deadlines for the same systems. They correspond to different classification routes.
Which AI Systems Fall Under the 2028 Deadline?
Article 6(1) focuses on AI systems connected to products covered by the Union harmonisation legislation listed in Annex I of the AI Act.
There are two cumulative conditions.
First, the AI system must either:
- be intended to operate as a safety component of a product covered by the relevant Union harmonisation legislation; or
- itself be a product covered by that legislation.
Second, the relevant product or AI system must undergo a third-party conformity assessment before being placed on the market or put into service.
This means that simply adding AI to a regulated product does not automatically make the AI system high-risk under Article 6(1).
The relationship between the AI system and the product matters.
Need to Check Whether Your AI System Is High-Risk?
AnnexOps helps you assess AI risk, identify applicable obligations, and understand where your AI systems may need further compliance preparation.
What Is a Safety Component?
The AI Act defines a safety component as a component of a product or AI system that performs a safety function, or whose failure or malfunction could endanger people’s health and safety or property.
The Commission’s examples include AI-based computer vision in a robotic cell that detects human presence and triggers a safe stop; AI that monitors gas concentrations and commands a shutdown; and AI used in trains to monitor speed limits and prevent collisions or derailments.
The intended purpose alone is not always enough to determine whether an AI system is a safety component. The consequences of malfunction can also matter.
For example, the Commission identifies lane-assistance AI in vehicles as a possible safety component because unexpected malfunction could contribute to a collision.
Which Regulated Products Are Covered?
Annex I refers to Union harmonisation legislation covering specific product categories.
The regulatory framework includes areas such as:
- machinery
- toys
- lifts
- equipment and protective systems for potentially explosive atmospheres
- radio equipment
- pressure equipment
- recreational craft
- medical devices
- in vitro diagnostic medical devices
- automotive products
- aviation
The precise scope depends on the applicable Union legislation and the conditions in Article 6(1).
This is why organizations should avoid using an industry label as a substitute for legal classification. Saying that an AI system is used in healthcare, automotive, manufacturing, or another regulated sector does not by itself establish that the system is high-risk under Annex I.
The classification needs to be assessed against the actual product, intended purpose, applicable legislation, and conformity assessment requirements.
How Is Annex I Different From Annex III?
This is one of the most important distinctions when researching the EU AI Act 2028 Deadline.
Annex III identifies high-risk AI use cases in areas such as biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and border control, and administration of justice and democratic processes.
Annex I works differently.
It connects high-risk classification to regulated products and their safety components. The product framework already contains its own conformity assessment structure, and Article 6(1) brings qualifying AI systems within the AI Act’s high-risk framework.
A company therefore needs to determine which route applies before choosing the applicable deadline.
For an AI system embedded in a regulated product, asking only “Is this AI high-risk?” is not enough. The next question should be: Under which Article 6 route?
If your AI system is being assessed under Annex III, the classification route and deadline are different from ffsrc zukse the Annex I route discussed here. Our EU AI Act Annex III high-risk AI systems guide explains which systems and use cases can fall within Annex III, with practical examples to help you assess whether a system may be in scope. For the revised 2027 timeline, see our complete guide to the Annex III deadline. If you are already preparing a high-risk system, our guide on how to prepare high-risk AI systems covers the next steps.
Does Every AI System Used in a Regulated Industry Become High-Risk?
No.
The AI Act’s classification is tied to the specific system and its intended purpose rather than simply the sector in which the system operates.
The Commission provides examples that illustrate this distinction. An AI system integrated into a product may perform an optimization or service-quality function without performing a safety function. Such a system may therefore fall outside the Article 6(1) route.
Consider two AI systems used in an industrial environment.
One predicts maintenance requirements to improve operational efficiency. Another monitors conditions and automatically triggers a protective shutdown when a dangerous condition is detected.
Their technical environments may be similar, but their regulatory analyses can be different because their intended purposes and safety functions differ.
That is why classification should start with the system’s intended purpose and its role within the product.
What Should Businesses Prepare Before 2 August 2028?
The extended deadline creates preparation time. It does not remove the need to understand the system now.
Organizations developing AI-enabled regulated products should establish a clear record of the AI systems involved in their products and assess how each system relates to the applicable product legislation.
1. Identify AI systems inside regulated products
Start with an inventory of products that contain AI or rely on AI for their operation.
For each system, record its intended purpose, product relationship, owner, development status, and deployment context.
This creates the starting point for classification.
2. Determine whether Article 6(1) applies
Next, assess whether the AI system is a safety component or is itself a product covered by the relevant Annex I legislation.
Then determine whether the associated product or AI system requires third-party conformity assessment.
Both conditions matter under Article 6(1).
3. Map the applicable requirements
Once a system is classified, teams need to understand the requirements that apply to it.
For high-risk AI systems, the Commission identifies requirements covering areas such as risk management, data quality, logging and traceability, technical documentation, information for deployers, human oversight, accuracy, robustness, and cybersecurity. )
These requirements should be connected to the individual system rather than maintained as a generic checklist.
4. Build technical documentation during development
Technical documentation should not be reconstructed shortly before a regulatory deadline.
For high-risk AI systems, documentation provides information needed to understand the system, its purpose, development, operation, and compliance.
his becomes particularly important for products that already have engineering, quality, product safety, and conformity assessment processes. AI compliance information needs to fit into those existing workflows.
5. Connect AI compliance with product compliance
For regulated products, AI governance is closely connected to product compliance.
Engineering teams may hold technical information. Product safety teams may manage conformity assessment. Compliance teams may track regulatory obligations. Legal teams may review responsibilities.
A connected workflow helps these groups work from the same system record.
What Happens When the AI System Changes?
AI-enabled products can evolve after their initial development.
A model may be updated. Its intended purpose may change. A new AI component may be introduced. The system may gain a new safety function.
These changes should trigger a review of the existing classification and documentation.
The Commission’s classification guidance emphasizes intended purpose as a central element of the assessment. It also recommends checking the relevant classification route and transitional rules as part of the analysis.
For product teams, this makes change management part of AI compliance rather than a separate administrative exercise.
Why the 2028 Deadline Should Not Become a 2028 Project
The EU AI Act 2028 Deadline may appear distant compared with the 2027 deadline for Annex III systems. But regulated products often involve longer development, testing, quality, and conformity assessment cycles.
Waiting until 2028 to identify AI components can create a documentation and ownership problem at exactly the point when teams need evidence for product assessment.
A better approach is to use the available time to establish the classification, assign ownership, document the system, identify applicable requirements, and track changes.
This also helps separate two questions that are often mixed together:
When do the legal requirements apply? When should the organization start preparing?The first has a defined date. The second depends on the product’s complexity and development lifecycle.
How AI Compliance Software Can Support 2028 Preparation
Managing regulated AI products can involve information spread across product, engineering, quality, legal, security, and compliance teams.
AI compliance software can provide a central workflow for identifying systems, assessing risk, mapping obligations, maintaining documentation, and managing evidence.
AnnexOps provides AI compliance software designed to help organizations operationalize EU AI Act and GDPR requirements. Its capabilities include AI system discovery, risk classification, obligation mapping, documentation management, evidence management, continuous monitoring, and audit-readiness workflows. The platform also includes a Risk Classification Engine and AI Auditor Engine for structured assessment and readiness checks.
For teams working with regulated AI products, this approach can link classification decisions to the documentation and evidence required throughout the AI lifecycle.
What Should Organizations Do Now?
The practical preparation path is straightforward:
Identify → Classify → Map → Document → MonitorStart by identifying which products contain AI.
Then determine whether each AI system falls within the Article 6(1) route. Check the applicable Annex I legislation and third-party conformity assessment requirements.
Once classification is established, map the relevant high-risk requirements and integrate them into existing product development and conformity processes.
Keep technical documentation and evidence up to date throughout the system lifecycle.
Finally, review the classification when the product, AI functionality, or intended purpose changes.
The 2 August 2028 date is the application deadline for high-risk AI systems classified under Article 6(1) and Annex I. It is not a blanket deadline for every AI system used in a regulated industry.
AnnexOps for EU AI Act Preparation
AnnexOps is AI compliance software that helps organizations manage EU AI Act and GDPR compliance operations through AI system discovery, risk classification, obligation mapping, documentation, evidence management, and continuous monitoring. Its Risk Classification Engine supports structured AI risk assessment, while its AI Auditor Engine provides automated readiness checks and gap analysis.For organizations preparing AI-enabled regulated products for the EU AI Act 2028 Deadline, the practical next step is to identify the AI systems that fall in scope, determine the applicable Article 6 route, and begin building the documentation and evidence needed throughout the product lifecycle.
Check your AI exposure with AnnexOps: AnnexOps AI Compliance SoftwareReady to Prepare for the EU AI Act 2028 Deadline?
AnnexOps helps you assess AI risk, map obligations, manage documentation, and build audit-ready evidence for your AI systems.
