EU AI Act High-Risk Rules Delayed to December 2027

EU postpones AI Act high-risk rules to Dec 2027, easing pressure on TMS buyers. See exactly what still applies from August 2026.

EU AI Act High-Risk Rules Delayed to December 2027

On 29 June 2026, the Council of the EU gave final approval to the Digital Omnibus on AI, and with it, the EU AI Act high-risk delay that shippers running AI-driven TMS pilots have been waiting on for months. The package locks in a 16-month deferral for standalone high-risk AI systems and a 12-month deferral for AI embedded in regulated products. If you had 2 August 2026 circled as the day high-risk obligations under Annex III of the AI Act became enforceable, that date no longer applies to those systems. But before you close the compliance folder, read the table below. Not everything moved.

The process moved fast once it got going. Council and Parliament negotiators reached provisional political agreement on May 7, 2026, the European Parliament had already endorsed the package on June 16, 2026, by a 423-57 vote with 174 abstentions, and the Council closed it out on 29 June. That's less than eight weeks from provisional deal to final sign-off, which tells you the political appetite for delay was strong on both sides of the table.

The new compliance calendar for AI Act TMS deadlines

Here's the full picture, because treating this as a single blanket delay is the mistake several compliance teams have already made:

DateWhat applies
2 August 2026Article 50 transparency obligations apply, except the Article 50(2) watermarking rule for systems already on the market
2 December 2026Article 50(2) watermarking catches up for legacy systems, and the new Article 5 prohibition on non-consensual intimate imagery takes effect
2 December 2027High-risk obligations apply to Annex III (stand-alone) AI systems
2 August 2028High-risk obligations apply to Annex I (embedded) AI systems in regulated products

The Digital Omnibus postpones the high-risk obligations for Annex III AI systems from 2 August 2026 to 2 December 2027, and the obligations for high-risk AI in regulated products to 2 August 2028, but it leaves the Article 50 transparency rules and the Article 4 AI literacy duty exactly where they were. That distinction is the whole story for anyone buying or running a TMS with AI features.

The Act classifies AI systems used in employment-related decisions, including task allocation and worker monitoring, as high-risk under Annex III. That description sits uncomfortably close to what several "agentic TMS" vendors have been building: AI dispatch engines that assign loads to drivers, flag underperformance, or auto-schedule shifts. Vendors were already telling customers to treat AI governance in transport software as a live compliance issue ahead of the original August 2026 date, per Neurored's TMS feature guidance. That pressure hasn't disappeared, it's been rescheduled to December 2027.

What hasn't moved is Article 50. If your TMS runs a customer-facing chatbot for shipment status, generates AI-written exception reports, or uses a synthetic voice agent for carrier confirmations, disclosure obligations still apply from 2 August 2026, with the watermarking carve-out for legacy systems running to 2 December 2026.

What to actually change this quarter

  • Don't cancel AI governance work. Re-scope it from an August 2026 scramble to a December 2027 build-out, and use the extra runway to classify AI features properly instead of rushing a checklist.
  • Keep chatbot, voice-agent, and AI-content disclosure work on schedule. That deadline is unchanged.
  • Redirect freed-up compliance budget toward deadlines that didn't move this year, including ICS2 and tachograph rollouts.
  • Ask your TMS vendor, in writing, which of their AI features they classify as Annex III candidates, and request an updated roadmap that reflects the December 2027 date rather than the old one.

Why the EU delayed it

The short version: the infrastructure to enforce the original deadline wasn't ready. The second political trilogue on 28 April 2026 ended without agreement, and if the Omnibus hadn't been formally adopted before 2 August 2026, the original high-risk obligations would have applied as written. National competent authorities and harmonised technical standards for conformity assessment simply weren't in place, and Brussels chose fixed calendar dates over an open-ended standstill.

Where this leaves TMS vendor comparisons

AI governance dashboards and audit trails are becoming a real point of comparison across TMS platforms, not a checkbox feature. Whether you're evaluating MercuryGate, Descartes, Blue Yonder, Manhattan Active, Oracle TM, SAP TM, or multi-carrier platforms like Cargoson or Sendcloud, the question worth asking now is which AI-driven features each vendor considers Annex III candidates, and how they plan to document risk classification before December 2027 rather than scrambling in Q3 of that year.

Bottom line

The deadline moved from August 2026 to December 2027 for standalone high-risk AI systems, and to August 2028 for embedded ones. The work behind that deadline, classification, documentation, vendor due diligence, doesn't get to pause. Gibson Dunn's read on the agreement and DLA Piper's tracking of the trilogue both point the same direction: shippers who keep governance work alive through the extended runway will be ready regardless of whatever further adjustments Brussels makes between now and 2027.