Skip to main content
Should Your High-Risk AI Follow Sectoral Law or the AI Act?EU AI Act & GPAI
6 min readFor AI Governance Leaders

Should Your High-Risk AI Follow Sectoral Law or the AI Act?

The Council of the European Union has extended your compliance deadlines, adding complexity to your decision-making. With high-risk AI deadlines now set for 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, you're faced with a strategic choice: which regulatory framework governs your AI system?

This isn't just theoretical. If you're deploying AI in medical devices, industrial machinery, or financial services, you're likely covered by both sectoral law and the EU AI Act. Recent amendments clarify when sectoral rules take precedence but don't eliminate your decision burden. They shift it.

The Decision You're Facing

Your AI system is high-risk under the EU AI Act. You also operate in a sector with existing product safety or financial regulation. Do you:

  • Build your compliance program around the AI Act's requirements (Technical Documentation per Annex IV, risk management systems, human oversight protocols)?
  • Rely on your existing sectoral compliance framework and treat the AI Act as supplemental?
  • Maintain parallel compliance tracks until the regulatory landscape is clearer?

Choosing incorrectly could mean duplicated effort or audit gaps. The right choice depends on three factors the amendments now make explicit.

Key Factors That Affect Your Choice

Factor 1: Which Annex lists your system?

Annex I systems are already regulated by sectoral laws, medical devices under MDR, toys under the Toy Safety Directive, machinery under the Machinery Regulation. Annex III systems are high-risk by their use case (employment decisions, credit scoring, law enforcement) but may not have equivalent sectoral coverage.

If you're in Annex I, the amendments limit the AI Act's application where sectoral laws already impose AI-specific requirements similar to the Act's. If you're in Annex III, you're building from the AI Act as your primary framework.

Factor 2: Does your sectoral law already address AI risks?

The amendments introduce a critical test: do your existing sectoral requirements cover the same AI-specific risks that the AI Act targets? If your medical device regulation already requires bias testing, explainability documentation, and post-market surveillance specifically for AI components, the AI Act may not add obligations.

But "similar" is key. The EU Commission will provide guidance to minimize compliance burden, but until then, you're interpreting similarity yourself. If your sectoral law addresses software validation but doesn't explicitly cover training data quality or model drift monitoring, you likely need both frameworks.

Factor 3: Who supervises your system?

The amendments clarify the AI Office's competence for General-Purpose AI Models and systems built on them, except where national authorities retain control. If you're deploying AI in law enforcement, border management, judicial systems, or financial institutions, national regulators remain your primary supervisors even if the AI Office oversees the underlying foundation model.

This matters because enforcement priorities differ. National financial regulators will emphasize prudential risk and model governance (think SR 11-7 or equivalent). The AI Office will emphasize fundamental rights and systemic risk. Your compliance program needs to address the supervisor who'll actually audit you.

Path A: Build from Sectoral Law (Annex I systems with robust AI coverage)

Choose this path when:

  • Your system is listed in Annex I and your sectoral law explicitly addresses AI risks.
  • You've already implemented conformity assessment procedures under that sectoral framework.
  • Your sector's notified bodies or conformity assessment bodies are equipped to evaluate AI components.
  • The EU Commission guidance (once published) confirms your sectoral requirements meet AI Act equivalence.

What this means in practice:

You treat the AI Act as a compliance check, not a compliance build. Your Technical Documentation already exists under sectoral requirements, you audit it against Annex IV to confirm coverage. Your risk management system already operates under your sector's safety standards, you verify it addresses algorithmic bias and data quality, not just physical safety.

You still monitor AI Act developments because the machinery exemption shows how quickly "exempt" can become "conditionally exempt pending secondary legislation." Products covered by the Machinery Regulation are now exempt from direct AI Act applicability, but the Commission can adopt secondary legislation adding health and safety requirements. If your sector follows that pattern, exemption is temporary relief, not permanent immunity.

Your compliance calendar:

  • Now through 2027: Strengthen sectoral compliance documentation to explicitly address AI-specific risks (training data provenance, model validation evidence, bias testing results).
  • 2027: Await EU Commission guidance on Annex I compliance burden minimization.
  • 2027-2028: Conduct gap analysis between your sectoral documentation and AI Act Technical Documentation requirements.
  • Before your Annex I deadline (2 August 2028): Finalize any supplemental AI Act documentation your gap analysis identifies.

Path B: Build from the AI Act (Annex III systems or Annex I without AI-specific sectoral coverage)

Choose this path when:

  • Your system is listed in Annex III (employment, credit scoring, law enforcement, critical infrastructure).
  • Your sectoral law doesn't explicitly address AI risks, it covers your product category but not algorithmic decision-making.
  • You're launching a new AI capability in a regulated sector and don't yet have conformity assessment history.
  • Your national supervisor has indicated they'll enforce AI Act requirements directly.

What this means in practice:

The AI Act is your primary compliance framework. You're building Technical Documentation per Annex IV, implementing risk management systems that address both fundamental rights and technical robustness, and establishing human oversight mechanisms that meet Article 14 requirements.

You still track sectoral law because it governs your product's non-AI aspects. But your AI governance program, your model validation protocols, your bias testing cadence, your post-market monitoring for model drift, follows the AI Act's structure.

Your compliance calendar:

  • Now through 2026: Establish AI Management System foundation (consider ISO/IEC 42001 alignment).
  • 2026: Implement transparency measures for AI-generated content (deadline 2 December 2026).
  • 2026-2027: Build Technical Documentation, conduct conformity assessment preparation.
  • Before 2 December 2027: Complete conformity assessment, CE marking for Annex III systems.

Path C: Maintain Parallel Tracks Until Guidance Clarifies (Annex I systems with uncertain sectoral coverage)

Choose this path when:

  • You're in Annex I but your sectoral law's AI coverage is ambiguous.
  • You operate across multiple EU member states with different national supervisor interpretations.
  • Your system incorporates a General-Purpose AI Model and you're uncertain whether the AI Office or national authorities will supervise.
  • The EU Commission guidance on compliance burden minimization could materially change your obligations.

What this means in practice:

You're building compliance capabilities that satisfy both frameworks until the regulatory interpretation solidifies. This is more expensive in the short term but reduces the risk of choosing wrong and rebuilding later.

Document your AI development and deployment using the AI Act's structure (it's more comprehensive than most sectoral frameworks). Simultaneously, maintain your sectoral compliance processes. When the Commission publishes guidance on Annex I compliance burden minimization, you'll have the evidence to demonstrate equivalence if it exists, or the AI Act documentation ready if it doesn't.

Your compliance calendar:

  • Now through 2027: Dual-track documentation (sectoral + AI Act Technical Documentation).
  • 2027: Evaluate Commission guidance, make final framework choice.
  • 2027-2028: Consolidate compliance tracks based on guidance.
  • Before your deadline: Finalize conformity assessment under whichever framework applies.

Summary Matrix

Factor Path A: Sectoral Law Path B: AI Act Path C: Parallel Tracks
Annex classification Annex I with AI-specific sectoral rules Annex III or Annex I without AI coverage Annex I with ambiguous coverage
Existing compliance Robust sectoral framework Limited or non-AI-focused Sectoral framework exists but AI scope unclear
Supervisor clarity National authority, clear mandate AI Office or national authority with AI Act focus Uncertain or multi-jurisdictional
Resource commitment Lower (use existing) Higher (build new) Highest (dual-track until clarity)
Risk of rework Low if guidance confirms equivalence Low (AI Act is definitive) Medium (intentional redundancy)
Primary deadline 2 August 2028 2 December 2027 Earlier of the two

The amendments bought you time, not simplicity. Use the extended deadlines to make an informed choice about your compliance architecture, not to delay the choice itself. By 2027, you need documentation that satisfies whoever shows up to audit you.

You Might Also Like