Public Services & Administration · European Union · AI & Automated Decisions

Public Algorithms Under the EU AI Act: The Deadline Just Moved to 2027

Systems that decide who gets benefits, flags a job applicant, or screens someone at the border were supposed to face strict new EU obligations this past August. A last-minute political deal pushed that deadline back by 16 months.

Which public systems count as "high-risk"

Under Annex III of the EU AI Act (Regulation (EU) 2024/1689), several categories of public-sector AI use are classified as high-risk, including systems used to evaluate eligibility for public benefits and services, systems used in employment and worker management (including public sector recruitment), and systems used in migration, asylum, and border control management. High-risk classification triggers the Act's strictest obligations: technical documentation, risk management, human oversight, accuracy and bias testing, and registration in a public EU database before deployment.

The deadline that just moved

The original deadline for these high-risk obligations was 2 August 2026. On 7 May 2026, EU negotiators reached a political agreement — the "Digital Omnibus on AI" — to push the Annex III high-risk compliance deadline, including EU database registration, from 2 August 2026 to 2 December 2027. This is a genuine, substantial delay of 16 months, not a minor technical adjustment, and it followed a November 2025 Commission proposal that had initially not been enacted into binding law until this May 2026 agreement.

What this delay does and doesn't change

The delay applies specifically to the high-risk regime — conformity assessment, EU database registration, risk management, data governance, logging, and human oversight obligations under Articles 9 through 17 and Article 26. It does not affect other parts of the AI Act that were already in force on their original schedule: the ban on prohibited AI practices took effect 2 February 2025, and general-purpose AI model provider obligations and Article 50 transparency duties (covering chatbots and synthetic content generally) took effect 2 August 2025 and remain in force regardless of the Annex III delay.

Why this still matters if you're affected by a public algorithm now

A delayed compliance deadline for the provider or deployer doesn't mean an automated decision affecting you today has no legal constraints at all. General principles under the EU's data protection framework — including the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects — continue to apply independently of the AI Act's own timeline. If you're affected by an automated benefits or employment decision now, your existing rights to request human review under data protection law remain unaffected by this specific AI Act delay.

What to check if you suspect a high-risk system is involved

  1. Ask the public body directly whether an automated or AI-assisted system was used in the decision affecting you, and if so, what it's called.
  2. Ask specifically whether the system has been registered, or is planned to be registered, in the EU's public high-risk AI database — registration remains open now even though the deadline moved, so some providers register early.
  3. Request a human review of any automated decision, citing your data protection rights independently of the AI Act's compliance timeline.
  4. Note the specific date of the decision affecting you — this matters for understanding which set of obligations were technically in force at that time.

What this means practically

Sources

Related Kibbo Tools