TL;DR: December 2, 2027 is the EU AI Act Annex III deadline for high-risk AI systems, extended from August 2, 2026 by the EU Digital Omnibus (May 2026). This roadmap covers the five compliance steps. Start with an inventory, classify against Annex III, document your highest-risk systems first.
December 2, 2027 is the EU AI Act's compliance deadline for Annex III high-risk AI systems. The EU Digital Omnibus (May 7, 2026) extended this from the original December 2, 2027 date. The core obligations for high-risk AI systems, technical documentation, risk management, human oversight, and conformity assessment requirements, are unchanged by the extension.
If your organization has been in wait-and-see mode, December 2027 gives you time to do this right. This guide is for teams that want a clear sequence of steps and want to know where to spend their compliance budget.
Why teams have not started yet
The EU AI Act has been law since August 2024. Why are so many organizations still scrambling?
The most common reason: the volume of guidance issued after the Act has made organizations feel they needed to wait for "final" answers before acting. Between national competent authority guidelines, harmonized standards development, GPAI code of conduct negotiations, and the digital omnibus amendments agreed in May 2026, there has been a steady stream of updates that created a sense that the compliance picture was still shifting.
That sense was partly correct. The Digital Omnibus extended the Annex III deadline to December 2027, but the compliance steps are identical. The core structure has not changed: if you use AI in a high-risk category, you have obligations.
The second reason: AI system inventories are harder than they sound. Most organizations do not have a complete list of the AI tools used across their business. Building that inventory before classifying and assessing is time-consuming and has blocked teams from starting the classification step.
The compliance roadmap below is designed to unblock both obstacles.
Week 1-2: Build the AI system inventory
Before you can classify your AI systems, you need to know what you have. The inventory should capture:
- Every AI tool or platform the organization uses, purchased or built
- What it does (functional description)
- Who uses it and in what context (HR, customer decisions, operations, security)
- Whether it is used in the EU or affects EU residents (jurisdictional trigger)
- Who provided it (vendor) and whether it already carries CE marking or an EU Declaration of Conformity
Start with the categories most likely to contain Annex III candidates: HR systems (recruiting, performance, scheduling), customer-facing decision systems (credit, insurance, onboarding), content moderation, and any AI used in access to services.
Shadow AI is a real problem here. Employees in many organizations have deployed AI tools through personal accounts or departmental credit cards that are not tracked centrally. A quick survey of department heads and a review of expense reports for AI subscriptions catches a significant portion of shadow deployments.
Week 1-2 output: A master list of AI systems, flagged by likely risk category, with responsible owner for each system identified.
Week 3: Classify against Annex III
With the inventory in hand, work through the Annex III list systematically. The categories are:
- Biometric identification and categorization
- Critical infrastructure management (power, water, transport)
- Education and vocational training (student assessment, access to education)
- Employment and worker management (CV screening, task allocation, performance monitoring, promotion/termination)
- Access to essential private services (credit scoring, insurance risk, life and health insurance)
- Access to public services and benefits
- Law enforcement (risk profiling, evidence assessment)
- Migration and asylum management
- Administration of justice
For each AI system in your inventory, assess whether it falls into any of these categories and whether it operates in an EU context (used by EU-based employees or affecting EU residents).
Systems that clearly are not high-risk (a Slack AI assistant, a document summarizer used internally, a coding assistant) can be moved to a low-priority queue. Systems that plausibly fall into Annex III categories need immediate attention.
Week 3 output: Each AI system in your inventory tagged as High Risk (Annex III), Limited Risk (Article 50 transparency requirements), or Minimal Risk (no specific EU AI Act obligations).
Week 4-5: Documentation and assessment for high-risk systems
For each system classified as high-risk, you need:
Technical documentation (Annex IV). This covers the system's purpose and intended use, performance characteristics and known limitations, data used in training and validation, the architecture and key design choices, and the human oversight measures in place. For systems you purchased from a vendor, the vendor should provide this documentation. Request it explicitly, citing the EU AI Act obligation.
Risk management system (Article 9). A documented, iterative process for identifying and analyzing risks the system creates, and measures to address them. This does not have to be elaborate for lower-stakes systems, but it must be documented and show ongoing attention.
Data governance (Article 10). Documentation of the data used, its provenance, and how it was validated. For purchased systems, this is vendor documentation.
Human oversight measures (Article 14). Documentation of what your operators do to review AI outputs, when they can override the system, and how they are trained. This is often the gap most organizations discover, they have bought an AI system but have not defined what "human oversight" means in practice.
Conformity assessment pathway. Most Annex III systems can be self-assessed (Annex VI procedure). A subset, including biometric systems, require third-party conformity assessment from a notified body. Confirm which pathway applies to your systems.
Week 4-5 output: Technical documentation files for each high-risk system, a completed risk management record, and a conformity assessment decision.
Week 6: Post-market monitoring and incident reporting setup
The EU AI Act does not just require you to be compliant at launch, it requires ongoing monitoring and incident reporting.
Post-market monitoring (Article 72 for providers, Article 26(5) for deployers). Establish a process for tracking system performance after deployment. For deployers, this means monitoring whether the AI system continues to perform as intended in your specific context, and reporting concerns back to the provider.
Serious incident reporting. If an AI system causes or contributes to a serious incident (harm to persons, significant disruption to essential services), the provider must report to the relevant national competent authority within 15 days of becoming aware of it. Deployers must inform the provider. Make sure your organization knows who is responsible for this notification and what the 15-day clock looks like.
Human fundamental rights impact assessment (deployers only). Deployers of Annex III AI systems in certain public sector contexts and for some private uses are required to complete a fundamental rights impact assessment before deployment. Confirm whether this applies to your context.
Week 6 output: Post-market monitoring procedure documented, incident reporting chain identified and tested, any pending impact assessments completed.
How to prioritize when you cannot do everything at once
Prioritize by stakes, not by completeness. A full compliance program for ten AI systems done halfway is less defensible than thorough compliance for three high-stakes systems with documented plans for the rest. The December 2027 deadline gives you time to work through all systems systematically.
The enforcement risk is highest for:
- AI systems in the highest-stakes Annex III categories (biometrics, employment decisions, credit decisions)
- Systems with no documentation at all
- Systems with known performance problems that have not been addressed
If your team is resource-constrained, focus weeks 4-5 on your two or three highest-risk systems and produce a documented remediation roadmap for the others. A written, dated plan for achieving compliance is better than no plan. For GPAI compliance, the August 2, 2026 enforcement date is not extended.
What "minimum viable compliance" looks like for small teams
The six-week sprint is designed for organizations starting from zero documentation. For small teams, minimum viable EU AI Act compliance is not a 500-page technical file, it is evidence that you took the regulation seriously and can demonstrate what you did and why.
Regulators investigating small deployers in the first years of enforcement are primarily looking for three things: whether you understood which of your AI systems were in scope, whether you had a process for human oversight and could document it, and whether you responded appropriately when problems arose. A clean, brief documentation package that shows a real process is more credible than a comprehensive document that is clearly a template filled in once and never revisited.
The minimum documentation set for a small team deploying a single Annex III AI system:
AI use case inventory (1-2 pages): Name the system, vendor, intended use, Annex III category, date of classification determination, and who made it. A one-page spreadsheet is fine.
Risk assessment (1-3 pages): What could go wrong, who is affected, how you are mitigating it. A structured table is sufficient.
Human oversight policy (1 page): Who reviews AI outputs, how, with what authority to override, and how reviews are documented. Name the specific role, not just "a human."
Incident log (ongoing): A running record of any cases where the AI produced unexpected output or where an override was triggered. Even a shared spreadsheet works.
Vendor documentation (filed, not created by you): The vendor's conformity declaration, technical summary, and instructions for use. Request these from your vendor and file them.
This five-component set, reviewed and updated quarterly, is what small-team compliance looks like before the market surveillance authorities start checking at scale.
The most common failure mode in early EU AI Act compliance is over-documentation on paper without corresponding operational reality. An 80-page technical file that no one in the organization actually uses is weaker than a 10-page document that reflects a real process and is visibly maintained. Regulators conducting interviews and audits will probe whether the documentation reflects what the organization actually does. Start with documentation that is true, then expand it as your governance program matures.
For the broader context of what EU enforcement looks like, the EU AI Act enforcement and what to expect guide covers what national competent authorities have said about enforcement priorities. The EU AI Act high-risk documentation templates provides fillable frameworks for the technical documentation.
Related Reading
-
Human-in-the-Loop AI: What EU AI Act Article 14 Actually Requires
-
EU AI Act enforcement starts August 2 2026: what to expect and how to prepare
-
EU AI Act Annex III high-risk AI systems: full category guide
-
EU AI Act conformity assessment process 2026: which pathway applies
-
EU AI Act high-risk AI documentation templates for August 2026
-
EU AI Act national competent authorities: who enforces and how
-
AI incident response plan: what regulators expect when your AI system fails
-
EU AI Act compliance checklist 2026: 35 items for providers and deployers
