What is the key point?
Regulation (EU) 2026/1744 confirmed amended high-risk dates, but buyer evidence requests are already active. Organisations still need an inventory, defensible classification, supplier records, controls and reusable answers for procurement and assurance.
What changed
Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It confirms that high-risk obligations apply from 2 December 2027 for Annex III systems and 2 August 2028 for AI embedded in Annex I regulated products. Read the official amending regulation on EUR-Lex.
That is useful to know. It does not change the commercial situation most AI companies are already in.
What has not changed
The AI Act is in force. AI literacy obligations applied from February 2025. Enterprise buyers, procurement teams, investors and boards are already asking AI evidence questions regardless of formal enforcement dates.
Buyers ask because they need to manage supplier risk, data exposure and internal policy. A regulatory calendar does not change that pressure.
The practical question
If a customer asked today for your AI system inventory, EU AI Act role classification, risk rationale and oversight controls, could you answer without starting from scratch?
That is the question worth preparing for. Regulatory deadlines may move. Customer trust timelines usually do not.
AI Act Ready helps you build that evidence pack: inventory, role map, risk view, supplier record, controls and reusable procurement responses.
Primary source
Frequently asked questions
When do the amended high-risk AI rules apply?
Regulation (EU) 2026/1744 confirms 2 December 2027 for Annex III systems and 2 August 2028 for Annex I product-embedded systems.
Why are buyers asking for AI evidence before the deadline?
Buyers must manage supplier, data, security, operational and regulatory risk now, so procurement timelines often move faster than statutory application dates.
What evidence should a supplier prepare first?
Prepare an AI inventory, role and risk rationale, supplier and data records, oversight controls, policies, incident process and evidence of responsible operation.
Recommended next step
Use the relevant guide to deepen your understanding, or move straight to a practical assessment.