In This Article
- Executive Summary
- What Moved, What Did Not, and When Each Obligation Bites
- Why the Date Moved: The Standards Gap
- The Runway Is Shorter Than the Calendar Suggests
- Scoping: Annex III, Annex I, or Neither
- Running the Scoping Exercise
- The Classification Filter and the Registration Duty
- What Did Not Move at All
- The GxP Obligations the Deferral Does Not Touch
- Using the Runway: A Plan Through December 2027
- Conclusion
- For Further Reading
- References & Sources
Executive Summary
The EU AI Act’s high-risk obligations did not take effect on 2 August 2026. They moved. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was signed on 8 July 2026, published in the Official Journal on 24 July 2026, and entered into force on 27 July 2026. It pushed the obligations for stand-alone high-risk systems listed in Annex III from 2 August 2026 to 2 December 2027, and the obligations for high-risk AI embedded in products regulated under Annex I, which includes medical devices and in vitro diagnostics, from 2 August 2027 to 2 August 2028.1 What did apply from 2 August 2026 is the Article 50 transparency regime.2 Everything else that was already in force stayed in force.
The central argument of this article is that the deferral is not free time. The reason the date moved is that the technical standards that will define how to demonstrate conformity were not ready, and the national authorities that will enforce the rules were not in place. Recital 40 of the amending regulation says so in plain terms. An organization cannot build a conformity assessment against a standard that does not yet exist, which means the real preparation window is not sixteen months long. It is whatever is left after the standards are published, and that is a much smaller number.
This article gives you a before-and-after timeline you can put in front of a steering committee, a scoping method for deciding which of your AI systems are high-risk under Annex III, which are captured through the Annex I product route, and which are neither, and a clear statement of what the deferral does not change: your obligations under EU GMP Annex 11, the draft Annex 22, and 21 CFR Part 11 are entirely unaffected.
What Moved, What Did Not, and When Each Obligation Bites
If your organization has been told three different things about the AI Act in the last twelve months, that is a reasonable reaction to what actually happened. The Commission tabled the Digital Omnibus package on 19 November 2025. Parliament adopted its negotiating position on 26 March 2026 and the Council its mandate on 13 March 2026.3 Negotiators reached a provisional political agreement in trilogue in the early hours of 7 May 2026, which the institutions announced the same day, and Member State representatives in the Council confirmed the text on 13 May 2026.4 Parliament voted the agreed text through on 16 June 2026, the Council gave final adoption on 29 June, the act was signed on 8 July, published on 24 July, and in force on 27 July.1 It entered into force on the third day after publication rather than the usual twentieth, because 2 August was too close to leave the text hanging.
Along the way, every one of those steps produced a wave of commentary. Some of it described a proposal, some described a provisional agreement, and some described law. The table below is the settled position as of August 2026. It is the version worth keeping.
| Obligation | Original date | Date now | Change |
|---|---|---|---|
| Prohibited AI practices (Article 5) | 2 February 2025 | 2 February 2025 | No change. Already in force. |
| AI literacy duty (Article 4) | 2 February 2025 | 2 February 2025 | Date unchanged. Wording softened on 27 July 2026 to a duty to take measures supporting AI literacy. |
| General-purpose AI model obligations (Chapter V) | 2 August 2025 | 2 August 2025 | No change. Already in force. |
| Governance, notifying authorities, penalties (Chapter III Section 4, Chapters VII and XII) | 2 August 2025 | 2 August 2025 | No change. The AI Office and Member State designations were due a year before the high-risk rules. |
| Transparency obligations (Article 50) | 2 August 2026 | 2 August 2026 | Not deferred. This is what actually landed in August 2026. |
| Machine-readable marking of output from generative systems already on the market | 2 August 2026 | 2 December 2026 | Four-month grace period for systems placed on the market before 2 August 2026. |
| New prohibition on AI generating non-consensual intimate imagery and child sexual abuse material | New provision | 2 December 2026 | Added by the Omnibus with a transitional period. |
| Member States to have at least one AI regulatory sandbox operational (Article 57) | 2 August 2026 | 2 August 2027 | Deferred 12 months. |
| Stand-alone high-risk systems listed in Annex III (Article 6(2) and the Chapter III obligations) | 2 August 2026 | 2 December 2027 | Deferred 16 months. |
| High-risk AI that is, or is a safety component of, a product regulated under Annex I (Article 6(1)), including devices under the MDR and IVDR | 2 August 2027 | 2 August 2028 | Deferred 12 months. |
| High-risk systems used by public authorities that were already in service | 2 August 2030 | 2 August 2030 | No change to the outer date in Article 111(2). |
The one sentence to correct in your internal materials. High-risk obligations did not take effect on 2 August 2026. If a slide, a policy, or an internal audit finding in your organization says they did, it is wrong, and it will send teams chasing a conformity assessment that no notified body is yet designated to perform.
What the Omnibus changed besides the dates
The deferral got the headlines, but the same regulation made several structural changes worth knowing. AI-embedded machinery products were moved out of the group of Annex I legislation that triggers automatic high-risk classification, with the Commission able to set AI-specific requirements through the Machinery Regulation instead.5 For pharmaceutical manufacturing, that matters: a vision inspection system on a fill and finish line is a machinery question, not an AI Act high-risk question, unless something else pulls it in. The definition of a safety component was clarified so that AI functions that merely assist an operator or optimize performance, without creating a health or safety risk, do not automatically trigger the high-risk regime.6 Notified bodies gained the ability to make a single application and undergo a single assessment for designation under both the AI Act and the MDR or IVDR.7 And the AI Office gained exclusive supervisory competence over AI systems built on a general-purpose model provided by the same undertaking.5
Why the Date Moved: The Standards Gap
It would be easy to read the deferral as a political concession to industry lobbying, and there was certainly pressure. But the legal text says something more specific, and it is the part that should shape your planning. Recital 40 of Regulation (EU) 2026/1744 states that “the delayed availability of standards, common specifications, and alternative guidance and the delayed establishment of national competent authorities lead to challenges that jeopardise the effective entry into application of those obligations.”1 The European Parliament’s own briefing on the file makes the same point, noting that timely application faced delays “particularly regarding the designation of national competent authorities and the publication of harmonised standards and compliance tools for high-risk AI requirements.”3
Read that carefully. The legislature did not say the requirements were too demanding. It said the machinery for demonstrating that you meet them was not built.
How conformity assessment is supposed to work
The AI Act follows the standard European product-safety pattern. The regulation states essential requirements at a high level. A European standardization body, in this case the CEN-CENELEC joint technical committee JTC 21, writes technical standards that spell out how to meet those requirements. The Commission then cites those standards in the Official Journal. Once cited, Article 40 gives a system that conforms to the standard a presumption of conformity with the corresponding requirement.8 That presumption is the whole point. It is what turns an abstract requirement about “appropriate levels of accuracy, robustness and cybersecurity” into something an engineer can test against and an auditor can verify.
The standardization request went to CEN and CENELEC in May 2023 with an original delivery deadline of 30 April 2025, later revised. The committee’s own chair indicated the work would likely run to the end of 2025.9 In October 2025, CEN and CENELEC adopted what they described as an exceptional package of measures to accelerate delivery of the key standards.10 The scholarship on the file has been blunt about why this happened: the standards bodies were asked to translate fundamental rights concepts into testable technical criteria, which is not the kind of work their consensus process was designed for.11
The practical consequence. Until a harmonized standard is cited in the Official Journal, there is no presumption of conformity to rely on. A provider can still demonstrate conformity by other means, but it has to construct the argument itself, defend the method, and hope a market surveillance authority agrees. No quality organization wants to be the one that invents the evidence model for a new regulatory regime and then finds out the published standard took a different approach.
The other half of the gap
Standards are only one side. The other is institutional. Member States were required to designate their notifying authorities and market surveillance authorities by 2 August 2025, a year before the high-risk rules were due to apply, and that designation was uneven. Notified bodies for AI Act conformity assessment have to be designated by those authorities, and the designation process only opened in August 2025.12 A high-risk system that requires third-party assessment cannot get one from a body that does not yet exist. This is exactly the constraint the Omnibus responded to when it allowed a single joint designation process for AI Act and MDR or IVDR notified bodies.7
There is no stop-the-clock mechanism
The Commission’s original proposal would have tied the application of the high-risk rules to the availability of standards and support tools, which would have created a moving date. The co-legislators rejected that and put fixed calendar dates in the text instead.4 This is important for planning. The high-risk obligations will apply on 2 December 2027 and 2 August 2028 whether or not the standards are complete by then. There is no automatic further extension, and no conditional trigger to wait for. If the standards arrive late, the burden of that lateness falls on you, not on the deadline.
The Runway Is Shorter Than the Calendar Suggests
Sixteen months sounds generous. Work backward from 2 December 2027 with a realistic view of what has to happen in sequence and it stops sounding generous quickly.
A high-risk AI system under the AI Act needs, among other things, a documented risk management system that runs across the whole lifecycle, data governance covering training, validation and testing datasets, technical documentation, automatic logging, instructions for use, human oversight measures, and evidence of accuracy, robustness and cybersecurity. A provider needs a quality management system covering all of it, and either an internal control conformity assessment or, for some categories, third-party assessment. If your organization is a deployer rather than a provider, the burden is lighter but not trivial: you must use the system in line with the instructions, assign competent human oversight, keep logs, and monitor operation.
Now sequence it against the standards timeline.
Standards published and cited
Assume the accelerated JTC 21 work lands and the Commission cites the core standards in the Official Journal during 2027. Citation is a separate step from publication, and it takes time. Nothing about your evidence model can be finalized before you can read the cited text.
Interpretation and gap analysis
Quality and regulatory teams read the standards against what the organization already does under GAMP 5 and existing computerized system validation practice, and identify what is genuinely new. In a large pharma organization, agreeing an interpretation across quality, IT, legal and the business units takes a quarter, not a week.
Procedure and template build
SOPs, risk management templates, technical documentation templates, logging specifications, human oversight definitions, and post-market monitoring procedures. Each one goes through your own change control and approval cycle. This is the step organizations consistently underestimate.
Evidence generation per system
Every in-scope system needs its own documentation package built and approved. Where the data governance work has not been done, this is where it surfaces, and it is slow. Data lineage and dataset documentation cannot be produced retroactively in a fortnight.
Conformity assessment and registration
Internal control assessment, or a notified body slot for systems that need one. Notified body capacity is finite and every affected organization in Europe will be competing for it in the same window. Then registration in the EU database before the system is placed on the market or put into service.
Steps 2 through 5 are twelve to eighteen months of serious work for an organization with a real portfolio of AI systems, and step 1 is not under your control. If the standards are cited in mid-2027, the remaining calendar is roughly six months. That arithmetic does not work, which means the sensible response is to do steps 2 through 4 on a provisional basis now, using the draft standards and the regulation text, and accept that some rework will follow.
The distinction that matters. There are two kinds of work in front of you. The first kind depends on the final standards: the specific test methods, the acceptance criteria, the precise structure of the technical file. The second kind does not: knowing which systems you have, who is the provider and who is the deployer for each one, which are in scope, where the training data came from, and who is accountable for oversight. The second kind is most of the effort, none of it is wasted regardless of what the standards say, and almost no organization has finished it.
Scoping: Annex III, Annex I, or Neither
Ask a pharma or biotech leadership team which of their AI systems are high-risk under the AI Act and you will usually get one of two answers. Either “all of them, we assume” or “none of them, we are not a device company.” Both are wrong, and both are expensive in different ways. The first triggers an enormous compliance program against requirements that mostly do not apply. The second misses the systems that genuinely are in scope, which in a pharma organization are usually not the ones anyone is watching.
There are three routes into high-risk classification, and they have different dates.
Route one: the Annex I product route (Article 6(1))
An AI system is high-risk if it is itself a product, or is a safety component of a product, covered by the Union harmonization legislation listed in Annex I, and that product must undergo third-party conformity assessment. Annex I Section A lists the Medical Devices Regulation (EU) 2017/745 and the In Vitro Diagnostic Regulation (EU) 2017/746.13 It does not list the medicinal products legislation.7
That single fact is the most useful thing a pharma organization can know about AI Act scoping. Medicinal products are not an Annex I product category. A model that predicts dissolution profiles, a system that optimizes a chromatography step, a tool that forecasts batch yield: none of these becomes high-risk because the product it helps make is a medicine. They may be heavily regulated under GMP, and they almost certainly are, but that is a different regime with a different evidence model.
Where the Annex I route does bite for pharma and biotech is at the edges of the portfolio: companion diagnostics regulated as IVDs, digital health products that meet the definition of a medical device, software offered to clinicians, and any device business sitting inside a larger group. For those, the date is 2 August 2028, and the AI Act requirements sit alongside the MDR or IVDR conformity assessment rather than replacing it.14
Route two: the Annex III use-case route (Article 6(2))
Annex III lists eight areas where a system is high-risk because of what it is used for, regardless of what product it sits in. The areas are biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services, law enforcement, migration and border control, and administration of justice and democratic processes.15 The date for this route is 2 December 2027.
For a pharma or biotech company, the realistic Annex III exposure is concentrated in a small number of places, and none of them is in R&D or manufacturing:
- Employment and worker management. AI used to screen or filter job applications, to evaluate candidates, to allocate tasks based on individual behavior or personal traits, or to monitor and evaluate performance. Large pharma organizations hire at scale and a great many of them have already deployed applicant tracking and screening tools with AI features. This is the single most likely Annex III system in the building, and it usually sits with HR rather than with quality or IT compliance.
- Access to essential services. Creditworthiness assessment and life and health insurance risk assessment. Relevant if the group includes an insurance or patient-financing arm, or runs a patient assistance program that assesses eligibility for benefits.
- Biometrics. Emotion recognition and biometric categorization systems. Relevant to some site security and access control deployments, and occasionally to research settings.
- Critical infrastructure. Safety components in the management of water, gas, heating or electricity supply. Relevant only to a small number of very large manufacturing sites operating their own utilities.
Route three: neither
The largest category, by a wide margin, is systems that are in neither annex. Drug discovery models, target identification, clinical trial site selection, protocol optimization, medical writing assistance, pharmacovigilance case triage support, demand forecasting, commercial analytics, document search, and the general-purpose assistants now in every knowledge worker’s hands. None of these is high-risk under the AI Act.
They are not, however, unregulated. Article 50 transparency applies to some of them. The GPAI obligations apply to the model providers. And, critically, the GxP framework applies with full force to any of them that touches a regulated process. More on that below.
| Example system in a pharma or biotech organization | AI Act route | Date it applies |
|---|---|---|
| CV screening and candidate ranking in recruitment | Annex III, employment | 2 December 2027 |
| Performance monitoring or task allocation based on individual behavior | Annex III, employment | 2 December 2027 |
| Eligibility scoring for a patient assistance or benefits program | Annex III, essential services (fact dependent) | 2 December 2027 |
| AI in a companion diagnostic regulated as an IVD | Annex I, IVDR | 2 August 2028 |
| Clinical decision support software placed on the market as a medical device | Annex I, MDR | 2 August 2028 |
| Vision inspection on a fill and finish line | Machinery route, moved out of automatic high-risk classification | Governed by the Machinery Regulation |
| Process model controlling a manufacturing critical quality attribute | Neither annex | Not high-risk under the AI Act. Fully in scope for GMP. |
| Pharmacovigilance case intake triage or duplicate detection | Neither annex | Not high-risk under the AI Act. Fully in scope for GVP. |
| Generative assistant drafting regulatory or medical content | Neither annex, but Article 50 transparency may apply | Article 50 applied 2 August 2026 |
| Drug discovery or target identification model | Neither annex | Not high-risk under the AI Act |
The provider and deployer question sits underneath all of it
Classification tells you whether obligations exist. Your role tells you which ones land on you. A provider develops a system or has it developed and places it on the market or puts it into service under its own name or trademark. A deployer uses a system under its own authority. Most pharma organizations are deployers for the vast majority of their AI, and providers for a small number of internally built systems and anything they supply externally.
The trap is the middle ground. Fine-tuning a vendor model on your own data, rebranding a vendor system, or materially changing the intended purpose of a system can move you from deployer to provider, and the provider obligations are an order of magnitude heavier. Every scoping exercise should record the role alongside the classification, because getting the role wrong invalidates the whole assessment.
Running the Scoping Exercise
Most organizations cannot answer the scoping question today because they cannot answer a more basic one: what AI systems do we actually have? Shadow deployment through SaaS features is the norm. A vendor adds an AI capability to a system you validated three years ago and no one raises a change control because, from the vendor’s perspective, it is a feature release.
Here is an approach that works, sized for a real organization rather than an ideal one.
Build the inventory from procurement, not from IT
Start with the contract and vendor list rather than the application register. Every AI capability entered the organization through a purchase order, a SaaS renewal, or a cloud account. Cross-check against your validated systems list and your data processing records under GDPR. Expect the first pass to find between two and five times as many systems as anyone predicted.
Record intended purpose in the vendor’s words
Classification under the AI Act turns on intended purpose, and intended purpose is what the provider states, not what your users happen to do. Capture the vendor’s own description verbatim from the documentation or the contract. Where your actual use differs from the stated purpose, flag it, because that gap is where deployers become providers.
Apply the three routes in order
Annex I product route first, because it is the most objective test: is the system a regulated product or a safety component of one. Then Annex III, testing the use case against the eight areas. Then the residual category. Record the reasoning for each, not just the answer. The reasoning is what you will be asked for.
Assign provider or deployer for each system
Name the legal entity, not the department. In a multinational group, the entity that places the system into service in the Union is the one carrying the obligation, and that is frequently not the entity that bought the software.
Cross-map to the GxP register in the same pass
For every system, record whether it touches a GxP process, and if so which one. You are already gathering the information. Doing it once and using it twice is the difference between a compliance exercise and a piece of infrastructure you keep.
Set a re-run cadence and a change trigger
The inventory is stale the day it is finished. Tie it to procurement approval and to your change control process so new AI capabilities are classified at the point of entry. A scoping exercise that is not maintained will have to be repeated from scratch in 2027.
A group with a moderately complex portfolio should be able to complete steps 1 through 4 in six to ten weeks with a small cross-functional team drawn from quality, IT, legal, procurement and HR. HR belongs in that group from the start, because the most likely Annex III systems in the organization sit in their function and they are rarely part of regulatory compliance conversations.
The Classification Filter and the Registration Duty
Article 6(3) contains a filter that many organizations will want to use. A system that falls within an Annex III area is not high-risk if it does not pose a significant risk of harm to health, safety or fundamental rights, and one of four conditions applies: it performs a narrow procedural task, it improves the result of a previously completed human activity, it detects decision patterns or deviations without replacing or influencing the human assessment without proper review, or it performs a preparatory task for an assessment.
There is one hard exception. A system that performs profiling of natural persons is always high-risk, whatever else is true.
Two traps in Article 6(3). First, the profiling exception is broad. A recruitment tool that scores candidates is profiling. A performance monitoring tool that builds a picture of an individual employee is profiling. The filter is not available for either. Second, using the filter is not free. A provider that concludes an Annex III system is not high-risk must document that assessment before the system is placed on the market, and must still register it in the EU database.16 The final Omnibus text kept that registration duty while simplifying the procedure.6
The practical effect is that Article 6(3) is not an exit. It is a documented, registered, defensible position that you have to build and be prepared to hand to an authority on request. That is less work than a full high-risk conformity assessment, but it is not nothing, and it needs to be produced before the system goes into service rather than reconstructed afterward.
The Commission has been working on guidelines for classifying high-risk systems, which are intended to reduce exactly this uncertainty.17 Those guidelines are part of the “alternative guidance” whose delayed availability recital 40 cites as a reason for the deferral. Watch for them, but do not wait for them to start the inventory.
The grandfathering provision and why it is unreliable for AI
Article 111(2) provides that high-risk systems placed on the market or put into service before the application date only need to comply if they undergo significant changes in their design. Public authority deployments are treated differently and must comply by 2 August 2030.18 The final Omnibus text clarified that this protection operates at the type and model level, so materially unchanged units can continue.5
Do not build a strategy on this. The phrase “significant changes in their designs” is a poor fit for systems that are retrained, updated by a vendor on a monthly release cycle, or fine-tuned on new data. A model that learns is a model that changes. Any organization planning to rely on grandfathering needs a defensible, documented definition of what constitutes a significant design change for each system, agreed with quality, and a monitoring process that detects when the line is crossed. That is arguably more work than compliance.
What Did Not Move at All
The deferral covered the high-risk regime. Several obligations that people conflate with it were untouched, and at least one of them is live right now.
Article 50 transparency
Article 50 applied from 2 August 2026 and was not deferred.2 It covers four situations. Providers must ensure people are told when they are interacting directly with an AI system, unless that is obvious. Providers of generative systems must mark synthetic audio, image, video and text in a machine-readable format so it can be detected as artificially generated. Deployers of emotion recognition or biometric categorization systems must inform the people exposed to them. And deployers must disclose deepfakes, and AI-generated text published to inform the public on matters of public interest where there has been no human review.
Article 50 is not limited to high-risk systems. It attaches to the situation, not the classification, which means it reaches a great deal more of a pharma organization’s AI than the high-risk rules ever will. Patient-facing chatbots, medical information line assistants, AI-generated marketing and social content, and AI-drafted public communications all sit inside its perimeter. Enforcement runs through national market surveillance authorities, with fines up to 15 million euros or 3 percent of worldwide turnover.2 Systems already on the market before 2 August 2026 have until 2 December 2026 for the machine-readable marking requirement specifically.5
Article 4 AI literacy
The AI literacy duty has applied since 2 February 2025 and was not deferred. The Omnibus did soften the wording, from an obligation to ensure a sufficient level of AI literacy to a duty to take measures that support its development, taking account of knowledge, experience, education, context of use, and the people affected.19 The softening is real but modest. Providers and deployers still need a training approach, and still need to be able to show it exists.
Prohibitions and general-purpose AI
The Article 5 prohibitions have applied since 2 February 2025. The general-purpose AI model obligations have applied since 2 August 2025. Neither moved. A new prohibition covering AI systems that generate non-consensual intimate imagery and child sexual abuse material was added by the Omnibus with a transitional period ending 2 December 2026.6
Governance and enforcement
The governance chapter, the penalties chapter, and the provisions on notifying authorities all applied from 2 August 2025, a full year before the original high-risk date. The AI Office and the national competent authorities are not new arrivals of August 2026.12 What August 2026 brought was the first substantive obligation those authorities have to supervise across the general population of AI systems, which is Article 50.
The GxP Obligations the Deferral Does Not Touch
This is the section to read if you take only one thing from this article into your next governance meeting. The AI Act deferral changes nothing about your GxP obligations, and for most pharma and biotech organizations the GxP obligations are the binding constraint anyway.
A system can be entirely out of scope for the AI Act and still be fully in scope for EU GMP Annex 11, the draft Annex 22, and 21 CFR Part 11. That is the ordinary case, not the exception. Every example in the “neither annex” row of the scoping table above falls into it: the process model, the pharmacovigilance triage tool, the manufacturing analytics platform. None of them is high-risk under the AI Act. All of them are computerized systems supporting regulated activities, and all of them carry validation, data integrity, audit trail, access control and record retention obligations that are already in force.
The framing that works with a board. The AI Act is a product-safety and fundamental-rights regime. GxP is a product-quality and patient-safety regime. They ask different questions about the same system. The AI Act asks whether the system is safe to place on the European market. GMP asks whether you can prove the medicine it helped make meets its specification. A deferral in the first regime tells you nothing about the second.
Annex 11 and Annex 22 are moving on their own schedule
The Commission and PIC/S released draft revisions of Annex 11 on computerized systems, a new Annex 22 on artificial intelligence, and a revised Chapter 4 on documentation on 7 July 2025, with consultation closing on 7 October 2025.20 The Annex 11 revision expands the annex substantially and addresses cloud and AI-based systems explicitly for the first time. Annex 22 sets expectations for intended use, risk assessment before deployment, validation using independent test data, model versioning, performance monitoring and drift detection, explainability, and human oversight of AI-driven decisions that affect product quality.21
Annex 22 is still in draft. EMA held a multistakeholder workshop on 30 June and 1 July 2026 to gather expert contributions on control and mitigation measures, with the drafting group reviewing input in a closed session.22 That is an active process on a European timeline that runs independently of the AI Act. The two regimes are not synchronized, they will not converge, and planning for one on the assumption that it covers the other is a mistake.
The overlap is real and it is an opportunity
The good news is that the evidence the two regimes want overlaps heavily. Both want a documented intended use. Both want a risk assessment proportionate to the consequences of the system being wrong. Both want dataset provenance and quality controls. Both want human oversight defined, assigned to a competent person, and evidenced. Both want the system monitored after go-live and changes controlled.
An organization that builds its AI governance around those shared elements produces one body of evidence that satisfies GMP inspectors now and supports an AI Act technical file later. An organization that runs two separate programs produces two sets of documents, two sets of approvals, and two sets of arguments about which one applies. The AI Act’s Article 10 data governance requirements deserve their own treatment and get it elsewhere in this series; the point here is simply that the data work is shared, and it is the long pole in both regimes.
A useful test. Take any AI system in your portfolio and ask: if a GMP inspector asked tomorrow how you know this model still performs as qualified, could you answer from records that already exist? If the answer is no, the AI Act deferral has bought you nothing, because the obligation you are failing is already in force.
Using the Runway: A Plan Through December 2027
The deferral gives you time to sequence work that would otherwise have been done badly under pressure. Here is a way to spend it that produces value whatever the final standards say.
The rest of 2026: know what you have and close the Article 50 gap
Two things are genuinely urgent. First, Article 50 is live now and applies to systems most organizations have not looked at through that lens. Identify every AI system that interacts directly with people, generates synthetic content, or publishes text to the public, and confirm the disclosure and marking are in place. Systems already on the market have until 2 December 2026 for machine-readable marking. Second, complete the inventory and the first-pass classification. Neither depends on a standard.
Also in this window: fix your internal communications. If your organization circulated material in 2025 or early 2026 stating that high-risk obligations start on 2 August 2026, correct it. Stale internal guidance is how teams end up defending decisions against a rule that no longer exists.
2027 first half: build the governance layer
Establish the operating model. Who classifies a new AI system, and at what point in the procurement or development process. Who signs off on an Article 6(3) determination. Who owns human oversight for a given system, and what competence that person needs. How AI-specific risk assessment fits into your existing quality risk management under ICH Q9 rather than sitting beside it. What your change control process does when a vendor updates a model.
Build this once and use it for both regimes. A single AI governance framework that produces GxP-acceptable evidence and AI Act-acceptable documentation is achievable. Two frameworks are not maintainable.
2027 second half: close the gap on in-scope systems
By now the standards position should be clearer. Finalize the technical documentation approach, complete evidence packages for the systems you identified as high-risk, secure notified body engagement early if any of your systems need third-party assessment, and register what needs registering. Reserve capacity for the systems that reveal problems late, because some will.
What to put on the risk register now.
- Harmonized standards cited later than expected, compressing the evidence build into under six months.
- Notified body capacity constrained across Europe in the same window, particularly for organizations with device products facing the August 2028 date.
- HR-owned recruitment and workforce tools classified late because they sit outside the regulatory compliance perimeter.
- Vendor AI features added to validated systems without change control, invalidating both the AI inventory and the GxP qualification.
- Reliance on Article 111 grandfathering defeated by routine model retraining.
Conclusion
The deferral is real, the new dates are law, and the table in this article is the version to work from. But the story the dates tell is not the story most organizations are hearing. The obligations moved because the infrastructure for meeting them was not built: no harmonized standards cited, guidance incomplete, competent authorities designated unevenly, notified bodies barely started. The regulation says as much in recital 40. That is not a reprieve. It is a warning that the demonstration model for these requirements is still being written, and that the organizations which wait for it to be finished will have a matter of months to act on it.
The work that is not blocked is the work that matters most, and it is the work almost nobody has finished: a complete inventory of AI systems, an honest classification against Annex III and Annex I, a clear record of who is provider and who is deployer, and a governance layer that produces one body of evidence for both the AI Act and the GxP framework that already binds you. None of that depends on a standard. All of it takes longer than people expect. And the GxP obligations under Annex 11, the emerging Annex 22, and 21 CFR Part 11 were never deferred at all, which means for most pharma and biotech systems the binding deadline was always today, not December 2027.
Sakara Digital works with pharma and biotech organizations building AI governance that satisfies both the regulatory framework they already live under and the one arriving in 2027. If you are working through AI Act scoping, or trying to decide how much to build before the standards land, we are happy to have that conversation.
For Further Reading
For Further Reading
- Navigating the EU AI Act: A Compliance Roadmap for Life Sciences Quality and Regulatory Teams
- The EU AI Act Hits Enforcement: What Life Sciences Companies Must Do Now
- Annex 11 and Annex 22 Revisions: Preparing GxP Systems for EMA’s New AI and Data Integrity Rules
- AI Governance Framework for Pharma QA Teams
- Risk-Based AI Validation in GxP Environments: A Practical Guide
- EMA’s Annex 22 Implementation Timeline: Where Pharma Sponsors Stand in May 2026
References & Sources
- European Parliament and Council. “Regulation (EU) 2026/1744 of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI).” Official Journal of the European Union, 24 July 2026. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng
- European Commission. “Transparency obligations under Article 50 of the AI Act.” Shaping Europe’s Digital Future, frequently asked questions. https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act
- European Parliamentary Research Service. “Digital Omnibus on AI.” Briefing EPRS_BRI(2026)782651, European Parliament Think Tank, 2026. https://www.europarl.europa.eu/thinktank/en/document/EPRS_BRI(2026)782651
- Bird & Bird. “Digital Omnibus on AI: Provisional Agreement Reached at the May Trilogue.” 2026. https://www.twobirds.com/en/insights/2026/digital-omnibus-on-ai-provisional-agreement-reached-at-the-may-trilogue
- Freshfields. “EU AI Act unpacked #34: The final Digital Omnibus on AI. Key amendments to the AI Act and their impact on businesses active in the EU.” Technology Quotient, 2026. https://www.freshfields.com/en/our-thinking/blogs/technology-quotient/eu-ai-act-unpacked-34-the-final-digital-omnibus-on-ai-key-amendments-to-the-a-102nber
- Cooley LLP. “Digital AI Omnibus Delays Key Deadlines, Introduces New Rules.” Cyber/Data/Privacy Insights, 2026. https://cdp.cooley.com/digital-ai-omnibus-delays-key-deadlines-introduces-new-rules/
- Osborne Clarke. “Medical devices, diagnostics and pharma win concessions in EU Digital Omnibus proposal.” https://www.osborneclarke.com/insights/medical-devices-diagnostics-and-pharma-win-concessions-eu-digital-omnibus-proposal
- “Article 40: Harmonised Standards and Standardisation Deliverables.” EU Artificial Intelligence Act, Regulation (EU) 2024/1689. https://artificialintelligenceact.eu/article/40/
- Smith, Adam Leon. “Is AI harder than cement? Is the EU AI Act being delayed?” Analysis of the CEN-CENELEC JTC 21 standards timetable. https://adamleonsmith.substack.com/p/is-ai-harder-than-cement-is-the-eu
- CEN-CENELEC. “Artificial Intelligence.” Areas of Work, CEN-CENELEC topics, covering the JTC 21 work program in support of the AI Act. https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/
- Leyden, Andrew. “Standards and the EU AI act: legitimacy, state of play, and future challenges.” Information & Communications Technology Law, 9 October 2025. https://www.tandfonline.com/doi/full/10.1080/13600834.2025.2570966
- European Commission. “Governance and enforcement of the AI Act.” Shaping Europe’s Digital Future. https://digital-strategy.ec.europa.eu/en/policies/ai-act-governance-and-enforcement
- “Annex I: List of Union Harmonisation Legislation.” EU Artificial Intelligence Act, Regulation (EU) 2024/1689. https://artificialintelligenceact.eu/annex/1/
- Medical Device Coordination Group. “MDCG 2025-6: Interplay between the Medical Devices Regulations and the Artificial Intelligence Act.” European Commission, 2025. https://health.ec.europa.eu/document/download/b78a17d7-e3cd-4943-851d-e02a2f22bbb4_en?filename=mdcg_2025-6_en.pdf
- European Parliament and Council. “Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), Annex III.” Official Journal, 12 July 2024. https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
- “Article 49: Registration.” EU Artificial Intelligence Act, Regulation (EU) 2024/1689. https://artificialintelligenceact.eu/article/49/
- Regulatory Affairs Professionals Society. “EU Commission drafts guidelines on classifying high-risk systems under the AI Act.” RAPS Regulatory Focus. https://www.raps.org/resource/eu-commission-drafts-guidelines-on-classifying-high-risk-systems-under-the-ai-act.html
- “Article 111: AI Systems Already Placed on the Market or Put into Service.” EU Artificial Intelligence Act, Regulation (EU) 2024/1689. https://artificialintelligenceact.eu/article/111/
- “Article 4: AI Literacy.” EU Artificial Intelligence Act, Regulation (EU) 2024/1689. https://artificialintelligenceact.eu/article/4/
- ECA Academy. “EU GMP Annex 11 (Draft 2025): Computerised Systems.” GMP Guideline reference. https://www.gmp-compliance.org/guidelines/gmp-guideline/eu-gmp-annex-11-draft-2025-computerised-systems
- “Bridging Guidance and Regulation: Interpreting the Draft Annex 22 on Artificial Intelligence in GMP Manufacturing.” PDA Journal of Pharmaceutical Science and Technology, February 2026. https://journal.pda.org/content/early/2026/02/14/pdajpst.2025-000076.1
- European Medicines Agency. “Good manufacturing practice: Multistakeholder workshop on expert contributions to artificial intelligence guidance development (Annex 22).” 30 June and 1 July 2026. https://www.ema.europa.eu/en/events/good-manufacturing-practice-multistakeholder-workshop-expert-contributions-artificial-intelligence-guidance-development-annex-22
- “Article 113: Entry into Force and Application.” EU Artificial Intelligence Act, Regulation (EU) 2024/1689. https://artificialintelligenceact.eu/article/113/
- European Parliament. “Digital Omnibus on AI.” Legislative Train Schedule, Digital Package. https://www.europarl.europa.eu/legislative-train/package-digital-package/file-digital-omnibus-on-ai








Your perspective matters—join the conversation.