The EU AI Act entered into force on August 1, 2024. The implementation timeline is staggered: prohibited AI practices became enforceable in February 2025. General-purpose AI model obligations (GPAI) took effect in August 2025. The most substantive chapter, obligations for high-risk AI systems under Annex III, now applies 2 December 2027, deferred from 2 August 2026 by the Digital Omnibus on AI (agreement 7 May 2026, endorsed by the European Parliament 16 June 2026; formal Council adoption pending), with preparatory obligations remaining active. Note that Article 50 transparency obligations stay on the original schedule of 2 August 2026.
Annex III high-risk systems include AI used in: critical infrastructure, education, employment and workforce management, access to essential private services (credit, insurance), law enforcement, migration, and administration of justice. The obligations are substantial: conformity assessments, technical documentation, human oversight measures, accuracy and robustness standards, and registration in the EU AI system database before deployment.
The extraterritorial reach of the Act is unambiguous: any provider or deployer whose AI system's output is used within the EU is subject, regardless of where the provider is established. Canadian financial institutions, insurers, and SaaS companies serving EU-based businesses or individuals are within scope if their systems fall into Annex III categories. This is not theoretical, it is already active for several Canadian organizations.
What this means for your organization
This is not a comfortable deadline for a cold start, even at 2 December 2027. A conformity assessment for a high-risk AI system, including technical documentation, a fundamental rights impact assessment, and a human oversight design, takes several months to complete properly. Organizations that start now stay within a viable timeline. Those who wait will be compressing a European compliance sprint on top of the work Law 25 and OSFI E-23 already require.