The high-risk dates moved. Start there
Most EU AI Act inventory guides were written against the original timetable, and they are now wrong on the part readers care about most. The Digital Omnibus entered into force on 27 July 2026 and deferred the high-risk obligations. Nothing else moved. If your programme is still sequenced around a 2 August 2026 high-risk deadline, you are spending this year's budget in the wrong order, and the fix is a re-plan rather than a re-classification. The Commission's own implementation timeline, checked on 2 September 2026, sets it out like this.
- 1 August 2024: the Act enters into force
- 2 February 2025: definitions, AI literacy duties and the prohibited practices apply
- 2 August 2025: general-purpose AI obligations apply and member states designate their authorities
- 2 August 2026: core enforcement begins, covering general-purpose AI, the prohibitions, Article 50 transparency and AI literacy
- 2 December 2026: new prohibitions covering deepfakes and child sexual abuse material, plus a transitional deadline for providers of synthetic content
- 2 December 2027: Annex III high-risk obligations apply, deferred from 2 August 2026
- 2 August 2028: Annex I high-risk applies, meaning AI built into products that EU law already regulates
Step 1. Find the systems, including the ones nobody registered
The register is only as good as the discovery behind it. Procurement records and the model provider invoices give you the obvious systems. The ones that catch organisations out arrive inside software you already bought: a summarisation feature a vendor switched on, an assistant bundled into the service desk, an extension a team installed on a corporate card. Ask each business owner what changed in their tooling over the past year, then check the invoices against what they tell you. Record one row per system per deployment context, because the same model doing two different jobs can land in two different risk categories.
- System name, the business job it does, and the accountable owner
- The supplier, the product and the model version in use
- Where it runs and where its data goes, including any transfer outside the EU
- Your role for that system: provider, deployer, importer or distributor
- The people affected by its outputs, and whether any decision is made without a human
- Date of last review and the person who signed it off
Step 2. Fix your role before you classify anything
Obligations follow the role, not the software. A provider puts the system on the market under its own name. A deployer uses it under its own authority. Importers and distributors sit in between. Most enterprises are deployers for what they buy and providers for what they build. The trap is the middle case: substantially modify a general-purpose model, change its intended purpose, or ship it under your own brand, and you can become the provider of a high-risk system without any procurement decision ever recording that you did. Write the role in the register, and write the reason beside it.
Step 3. Classify, and record why you classified it that way
Four outcomes matter. Prohibited practices have been unlawful since 2 February 2025, and no amount of documentation makes one available to you. Annex III covers standalone high-risk uses such as recruitment, credit scoring and access to public services. Annex I covers AI built into products that already carry EU safety law, medical devices being the obvious case. Article 50 sits outside the risk tiers entirely: a system that interacts with a person has to make clear it is an AI system, and synthetic audio, image, video or text has to be marked so a machine can detect it. That duty lands on 2 August 2026 and catches plenty of systems that are nowhere near high-risk. What is left is minimal risk, which still earns a row, because the reason a system was ruled out is the first thing a reviewer will ask about.
- On the Annex III list and you are the provider: high-risk, obligations bind on 2 December 2027
- A safety component of a product covered by Annex I product law: the date is 2 August 2028
- Interacts with a person, or generates synthetic content: Article 50 applies from 2 August 2026 whatever the tier says
- Deployer rather than provider: narrower duties, but human oversight, input data quality and monitoring still sit with you
- Nothing applies: record the reason, the date and a trigger that forces a re-check
Step 4. Attach the obligation, the owner and the evidence it needs
A register that lists systems without listing duties is a spreadsheet, not a control. Against each row, record the obligations that follow from role plus category, the person accountable for them, and the evidence that would satisfy a reviewer who asks. Article 99 sets the penalties in three tiers, and they are worth quoting properly rather than as one frightening number: up to EUR 35 million or 7 per cent of worldwide annual turnover for prohibited practices, up to EUR 15 million or 3 per cent for breaches of the high-risk and transparency obligations, and up to EUR 7.5 million or 1 per cent for giving authorities misleading information, with the lower figure applying to small and medium enterprises. If you also run a US or global programme, the four functions in the NIST AI Risk Management Framework (govern, map, measure, manage) cover the same ground, so this step maps across without rework.
Step 5. Connect the register to what the systems actually do
A register is a snapshot, and AI use changes faster than an annual review. The part that ages badly is not the classification. It is the claim that a system still behaves the way the register says it does. Difinity.ai closes that gap for agents and chat. Every governed run follows the same fixed sequence: the incoming message is checked, routing happens on the redacted text, the model is called, and the answer is checked before it goes back. A refusal at any stage stops the turn before it reaches a provider. What happened is written to an append-only run trail as it happens: the message, each guardrail verdict, each proposed action, the tool gateway's decision, approvals asked for and answered, and the outcome. Governed run records can contribute operational evidence to wider EU AI Act, ISO/IEC 42001, risk and audit processes. Difinity does not determine that an organisation or AI system is compliant, and it does not provide ISO/IEC 42001 certification. Legal, risk, information security and compliance owners stay responsible for deciding which obligations apply and how the evidence is used.
Where this register stops being true
Three honest limits. The deferral is five weeks old at the time of writing, and the Commission's timeline page carries no visible revision date, so anyone citing it in legal or contractual work should pull the instrument that codifies the Digital Omnibus rather than rely on a summary. Classification is a legal judgement, not a lookup: the same recruitment tool can be high-risk in one deployment and out of scope in another, and that call belongs to counsel. And the register goes stale the moment a vendor switches on a feature, which is why the review trigger from Step 1 earns more than the original mapping effort ever will. Redo the map when a system's purpose changes, when a supplier ships a model upgrade, or when your role moves from deployer to provider.
Frequently asked questions
When do the EU AI Act high-risk rules actually apply?
Annex III high-risk obligations apply from 2 December 2027 and Annex I product-embedded high-risk from 2 August 2028, after the Digital Omnibus that entered into force on 27 July 2026 deferred both. The prohibitions and the Article 50 transparency duties kept their original dates.
Does the deferral change how a system should be classified?
No. The risk categories and the tests behind them are unchanged. What moved is the date an obligation binds, so a system you classified as Annex III high-risk is still Annex III high-risk, with more time to meet the duties.
Does the inventory have to be a formal register?
The Act does not prescribe a format for a deployer's inventory. What matters is that you can show which systems exist, what role you play for each, how it was classified, who owns it, and when the classification was last reviewed.
What are the penalties under the EU AI Act?
Article 99 sets three tiers: up to EUR 35 million or 7 per cent of worldwide annual turnover for prohibited practices, up to EUR 15 million or 3 per cent for high-risk and transparency breaches, and up to EUR 7.5 million or 1 per cent for misleading information to authorities. Small and medium enterprises face the lower of the two figures in each tier.
Does Difinity make an organisation EU AI Act compliant?
No. Difinity contributes operational evidence from governed runs, such as identity, policy verdicts, the actions taken and their outcomes. Deciding which obligations apply, and whether they are met, stays with the organisation's legal and compliance owners.
Sources and further reading
- European Commission: EU AI Act implementation timeline (checked 2 September 2026) (opens in a new tab)
- European Commission: transparency obligations under Article 50 (checked 2 September 2026) (opens in a new tab)
- Regulation (EU) 2024/1689, Article 99: penalties (checked 2 September 2026) (opens in a new tab)
- Software Improvement Group: EU AI Act summary, August 2026 update, on the Digital Omnibus deferral (opens in a new tab)
- NIST AI Risk Management Framework 1.0 (January 2023) and Generative AI Profile (July 2024) (opens in a new tab)