The AI Omnibus just bought you 18 months. High-risk AI system obligations won't apply until December 2, 2027, for standalone systems and August 2, 2028, for embedded ones. Meanwhile, transparency requirements hit on August 2, 2026. This staggered timeline creates a strategic question: do you use the extra time to get high-risk compliance right, or do you treat the delay as permission to deprioritize?
The Case for Front-Loading High-Risk Preparation
Some compliance teams argue you should treat 2027 as your real deadline, not 2026. Here's their reasoning.
Product safety obligations don't retrofit well. The EU AI Act's high-risk requirements demand Technical Documentation (Annex IV) that covers your system's development lifecycle, risk management process, data governance, and validation evidence. If you're a financial services provider building credit scoring models or an HR tech company deploying candidate screening tools, you're entering product safety territory for the first time. You can't bolt conformity assessment onto a finished product like adding cookie banners for GDPR.
The standards aren't final yet. The EU's standardization committee hasn't published the harmonized standards that create a presumption of conformity. When those standards arrive, they'll define how you demonstrate compliance with each requirement. Organizations that start now can build their documentation frameworks around draft standards, then refine as final versions publish. Wait until 2027, and you're documenting systems after the fact while learning a new compliance regime.
Your suppliers need lead time too. If you're a deployer relying on third-party AI systems, your vendor's conformity declaration becomes your compliance foundation. Vendors building to the December 2027 deadline will prioritize customers who've already mapped their requirements and updated procurement contracts. Start those conversations in 2026, and you're negotiating from strength.
The Case for Prioritizing Transparency First
Other teams see the staggered timeline differently. They argue that transparency obligations create the more immediate operational risk.
Transparency affects more systems. The disclosure requirements for AI interaction and AI-generated content labeling apply to any organization with branded chatbots or content generation tools. That's a broader surface area than high-risk systems. A bank might have three high-risk credit models but 15 customer-facing chatbots. Getting those chatbots compliant by August 2026 requires coordination across product teams, UX designers, and model providers.
You can't outsource transparency easily. High-risk compliance leans heavily on your model provider's technical documentation. Transparency compliance requires you to implement disclosure workflows, train staff on when disclosure applies, and verify that machine-readable content marking actually works. These are operational capabilities you build internally, not contractual obligations you pass downstream.
The grace period is narrow. Providers have until December 2, 2026, to implement content marking for systems placed on the market before August 2, 2026. That's a four-month buffer, not an 18-month runway. If your model provider hasn't solved content marking by mid-2026, you're scrambling to find alternatives or explaining to your regulator why you're not compliant.
Market surveillance authorities are spinning up now. Member states missed the August 2, 2025, deadline for designating enforcement bodies, but designations are happening. The first enforcement actions will target visible violations: chatbots that don't disclose they're AI, deepfakes without labels. High-risk system audits require technical expertise and take months. Transparency violations get spotted in minutes.
Where Practitioners Actually Land
Most organizations split the difference. They're building transparency compliance now while mapping high-risk obligations for 2027 delivery.
The transparency work creates useful scaffolding. Implementing disclosure workflows forces you to inventory your AI systems, identify which ones interact with individuals, and document their intended use. That inventory becomes the foundation for your high-risk assessment. You're not doing the work twice; you're sequencing it strategically.
The high-risk mapping informs procurement decisions. Even if you're not building Technical Documentation yet, you need to know which systems will require it. That knowledge shapes your 2026 vendor negotiations. You can ask model providers about their conformity timelines, request draft documentation formats, and include AI Act compliance milestones in your contracts.
The real constraint is internal capacity. Compliance teams that try to tackle transparency implementation and high-risk documentation simultaneously burn out. The teams that succeed pick one as their 2026 focus and treat the other as planning work.
Our Take
Treat transparency as your 2026 deliverable and high-risk as your 2027 project, but don't treat them as independent workstreams.
Start with a complete AI system inventory by the end of 2025. Map every system to its transparency obligations and its potential high-risk classification. That single artifact drives both compliance tracks. For transparency, it tells you which systems need disclosure workflows and content marking. For high-risk, it tells you which systems need Technical Documentation and where to focus your vendor due diligence.
Build your transparency compliance with high-risk in mind. When you're documenting how your chatbot discloses AI interaction, capture the same information you'll need for Instructions for Use under Annex IV. When you're implementing content marking, document your technical approach in a format that could support a conformity assessment. You're not doing high-risk compliance early; you're avoiding rework later.
Use 2026 to test your vendor relationships. Ask your model providers for their AI Act roadmap. Request sample technical documentation. See how they respond. The vendors who can't articulate their compliance approach in 2026 won't magically have it solved by 2027. Use the transparency deadline as a forcing function to identify which vendor relationships need to change.
The 18-month extension isn't permission to delay. It's an opportunity to get product safety compliance right in a domain where most AI deployers have no prior experience. Organizations that use 2026 for transparency and preparation will find 2027 manageable. Organizations that treat both deadlines as distant problems will find themselves retrofitting compliance onto systems that weren't designed for it.


