Status: Political Agreement Reached May 7, 2026 to Delay Annex III High-Risk System Deadlines. Rules for high-risk AI systems — including biometric identification, biometric categorisation, emotion recognition, critical infrastructure, education, employment, migration, and law enforcement — will now apply from December 2, 2027 (previously August 2, 2026). Product-integrated AI systems (e.g., lifts, toys) will apply from August 2, 2028.
Regulation: Regulation (EU) 2024/1689 ("AI Act"), Annex III high-risk classifications
Jurisdiction: European Union (27 Member States)
Category: AI Governance, High-Risk System Conformity Assessment, Biometric Regulation
Industries: Physical Security, Biometric Identification Providers, Critical Infrastructure, Healthcare, Education, Employment Technology, Border Control, Law Enforcement Technology
Enacted Date: AI Act in force August 1, 2024; high-risk Annex III deadline revised by political agreement May 7, 2026
Effective Date: December 2, 2027 (Annex III high-risk systems); August 2, 2028 (product-integrated AI systems)
Summary: The EU AI Act is the European Union's comprehensive risk-based framework for artificial intelligence, classifying AI systems by risk level and imposing corresponding obligations. The Act's prohibitions (Article 5) and general-purpose AI obligations took effect on staggered dates beginning February 2025. The high-risk system obligations — the most operationally significant for physical security AI providers, biometric vendors, and any deployer of AI in critical infrastructure, education, employment, or law enforcement contexts — were originally scheduled to apply from August 2, 2026. On May 7, 2026, the European Parliament and Council reached political agreement to delay Annex III high-risk deadlines by approximately 16 months. The new effective date for Annex III high-risk system obligations is December 2, 2027.
What Counts as a High-Risk System (Annex III, Relevant Categories):
- Biometric Identification: Remote biometric identification systems, biometric categorisation systems using sensitive attributes, and emotion recognition systems (insofar as not prohibited under Article 5).
- Critical Infrastructure: AI used as safety components in the management and operation of critical digital infrastructure, road traffic, and water, gas, heating, and electricity supply.
- Education and Vocational Training: AI used to determine access, evaluate learning outcomes, assess appropriate education level, or monitor student behavior during tests.
- Employment, Workers Management, and Self-Employment Access: AI used in recruitment, selection, decisions affecting terms of work, task allocation, or monitoring and evaluation of workers.
- Law Enforcement: AI used by law enforcement for assessing crime risk, evaluating evidence, or profiling.
- Migration, Asylum, and Border Control: AI used for risk assessment, polygraphs, document verification, and processing of applications.
High-Risk System Obligations (Once Effective):
- Pre-Market Conformity Assessment: Providers must demonstrate compliance with risk management, data quality, documentation, traceability, transparency, human oversight, accuracy, robustness, and cybersecurity requirements before placing the system on the EU market.
- Technical Documentation: Comprehensive documentation maintained for at least 10 years after market placement.
- Logging and Traceability: Automatic logging of events throughout the system lifecycle.
- Human Oversight: Effective oversight measures by natural persons during the period the system is in use.
- Post-Market Monitoring: Continuous monitoring with serious incident reporting to national competent authorities.
- EU Database Registration: Registration in the EU public database for high-risk AI systems before deployment.
Affected Entities: AI system providers placing high-risk systems on the EU market, EU deployers of such systems, and importers/distributors in the AI supply chain. Non-EU providers must designate an EU authorised representative.
Compliance Outlook: The 16-month delay gives multinational physical security and biometric vendors a substantially longer runway to build conformity assessment programs, technical documentation, and post-market monitoring infrastructure. The delay does not change the substance of the obligations; it changes the deadline. U.S. operators serving EU customers should treat December 2, 2027 as the planning target for high-risk system readiness. Vendors that have already begun conformity work should not pause — the documentation burden is substantial and early movers gain market access advantage as deadlines approach.
IntelliSee Relevance: Adjacent for U.S.-only deployments; Direct for EU-facing customers. IntelliSee's primary market is the United States, and the platform's privacy-preserving architecture (no facial recognition, no biometric template persistence, no unique-individual identification) places it outside several of the EU AI Act's most-burdensome biometric high-risk categories. For multinational customers with EU operations — particularly hospital networks, university systems, and enterprise security teams — the revised December 2027 deadline provides a clearer planning horizon. Security leaders evaluating layered AI platforms for EU deployment should confirm vendor positions on (1) biometric identification capability, (2) emotion recognition capability, (3) technical documentation availability, and (4) conformity assessment readiness. See the State-by-State AI Security Legislation Tracker and the Biometric Privacy Compliance Briefing for cross-jurisdictional vendor evaluation context.