Skip to main content
Praxikon
All obligations
Applicablev1.0.0

Article 111(2): legacy high-risk systems and the 2 August 2030 date

High-risk AI systems placed on the market or put into service before the date of application of Chapter III, since the Digital Omnibus 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, come under the high-risk requirements of that Chapter only once their design is significantly changed as from that date. This is not an exemption from the whole Regulation: Article 4 and Article 50 keep running. For systems intended to be used by public authorities the carve out falls away entirely: their providers and deployers must in any case comply with the requirements and obligations by 2 August 2030.

Without prejudice to the application of Article 5 as referred to in Article 113, third paragraph, point (a), this Regulation shall apply to operators of high-risk AI systems, other than the systems referred to in paragraph 1 of this Article, that have been placed on the market or put into service before the date of application of Chapter III referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs.

Praxikon tracks Article 111(2): legacy high-risk systems and the 2 August 2030 date under the EU AI Act, checked against the official source on 14 August 2026, citing the source for every statement.

Status
Applicable
Application date
2 August 2030
Version
1.0.0
Last reviewed
14 August 2026

Review status: placed against the official source (14 August 2026). Next check due by 10 February 2027. The check date is the knowledge date of this version; no later recheck has been recorded.

From source to evidence

Why this obligation applies, what it asks of you, and what you show for it.

Applies

Applicable · 2 August 2030

For whom

  • Authorised representative
  • Deployer
  • Distributor
  • and 2 more

What you do

  • Assess for every design change whether it is significant
  • Plan compliance for legacy public sector systems by 2 August 2030

What you record

Transition register of legacy high-risk systems

Official source

Amended Article 111(2)

Who this is relevant to

When this applies

  • Authorised representative

    The authorised representative is the party located in the Union that, on the basis of a written mandate, performs and carries out the obligations and procedures of the Regulation on behalf of a provider established outside the EU. The definition in Article 3(5) already applies today, so the role can be determined now. The appointment duty itself starts on 2 December 2027 for the standalone Annex III route and on 2 August 2028 for the embedded Annex I route. From those dates, a third-country provider may not place a high-risk AI system on the Union market without an appointed representative.

  • Deployer

    An organisation using an AI system under its authority, excluding personal non-professional use.

  • Distributor

    You are a distributor if you make an AI system available on the Union market without being the provider or the importer. This catches resellers, systems integrators and managed service providers that pass on someone else's AI.

  • Importer

    You are an importer as soon as you, from within the EU, first place an AI system on the Union market that bears the name or trade mark of a party established outside the EU. What counts is not your purchasing role but whose brand is on the system and who first brings it to market.

  • Provider of an AI system

    A party that develops or has an AI system developed and places it on the market under its own name.

  1. 1The transitional rule is without prejudice to the application of Article 5, as referred to in Article 113, third paragraph, point (a). A prohibited practice remains prohibited, regardless of when the system was placed on the market or put into service and regardless of whether the design has changed.
  2. 2The transitional rule concerns the high-risk requirements of Chapter III and is not an exemption from the whole Regulation. Article 4 has applied since 2 February 2025 irrespective of when a system reached the market, and Article 50 has applied to all systems in scope since 2 August 2026. The paragraph 4 added by the Digital Omnibus confirms this: it gives legacy generative systems a short extra period for Article 50(2), which would make no sense if Article 50 did not reach them.
  3. 3Applies to operators of high-risk AI systems placed on the market or put into service before the date of application of Chapter III referred to in Article 113, other than the systems referred to in paragraph 1 that are components of the large-scale IT systems listed in Annex X. That date is 2 December 2027 for systems that are high-risk under Article 6(2) and Annex III, and 2 August 2028 for systems that are high-risk under Article 6(1) and Annex I. For that group the high-risk requirements bite only once the systems are subject to significant changes in their designs as from that date.
  4. 4The grace period runs per type and model, not per unit. If at least one individual unit of the type and model was lawfully placed on the market or put into service before the cut off date, other units of the same type and model are covered too and may be offered without additional obligations, requirements or additional certification, as long as the design remains unchanged. The decisive date is the one on which the first unit of that type and model was placed on the market or put into service in the Union.
  5. 5Applies independently to providers and deployers of high-risk AI systems intended to be used by public authorities. They must in any case take the necessary steps to comply with the requirements and obligations of the Regulation by 2 August 2030, even where the design remains unchanged.

What the official source establishes

Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5), applies from 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and from 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I.

Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026.

The grace period in paragraph 2 applies where the type and model of an AI system has already been placed on the market. If at least one individual unit was lawfully placed on the market or put into service before the cut off date, the grace period also covers other units of the same type and model, which may be offered without additional obligations, requirements or mandatory additional certification, as long as the design remains unchanged. On a significant change to the design after the cut off date the provider must fully comply with all relevant provisions applicable to high-risk AI systems, including the conformity assessment requirements.

Our interpretation

The official source remains authoritative. This general interpretation is not legal advice.

In practice this provision is read exactly the wrong way round. Executives hear that existing systems are left alone and conclude that nothing is needed until well into the 2030s. That is wrong in two ways. For a public sector organisation the second sentence gives no escape but a deadline, and it applies whether or not you change anything about the system. And for everyone the transitional rule concerns only the high-risk requirements: Article 4 has been running since February 2025 and Article 50 since August 2026, with legacy generative systems having only until 2 December 2026 to get the machine-readable marking of Article 50(2) in order. The first sentence, moreover, is not a resting place but a switch. As soon as the design is significantly changed you must comply fully with what applies to high-risk systems, the conformity assessment first of all; those duties do follow the shifted calendar of 2 December 2027 and 2 August 2028. That switching moment rarely arises at a time you choose: it arises on a supplier update, a migration or a new data source. Two things therefore matter more than the date itself. You need to know when the first unit of each type and model reached the market, because that is the decisive date and without it you cannot later show which track a system was on. And you need a moment in your change process at which someone assesses whether a change is significant, before it goes live.

What you can do now

Determine per type and model of your high-risk AI systems when the first unit was placed on the market or put into service, and whether the system is intended to be used by public authorities. Record that determination with a date and a reasoning, and note which route applies, because that decides whether your cut off is 2 December 2027 or 2 August 2028. For the systems intended for public authority use, set a plan towards 2 August 2030 that counts back from the conformity assessment and the registration, not from the end date. Also build into your change and release process a review moment at which someone records whether an intended design change is significant, before the change goes into production. Separately, check whether Article 111(4) catches you: if so you have until 2 December 2026 for the marking under Article 50(2).

  1. 01

    Assess for every design change whether it is significant

    Fix a moment in your change and release process at which someone assesses and records whether an intended change to a legacy high-risk system is a significant change in its design, before the change goes into production.

  2. 02

    Plan compliance for legacy public sector systems by 2 August 2030

    Determine which high-risk systems are intended to be used by public authorities and were already running before the cut off date for their route, and count back from the conformity assessment and the registration to a plan that finishes before 2 August 2030.

What to retain

Transition register of legacy high-risk systems

Per type and model: the date the first unit was placed on the market or put into service, the route and therefore the cut off date, whether it is intended to be used by public authorities, which design changes have been made since that cut off, and per change the judgement whether it was significant with the reasoning and the date. This is the file that shows which track a system was on and why.

Control and reassessment

  • Review gate on a design change

    The control that ensures no change to a legacy high-risk system reaches production without a recorded judgement on whether it is significant, with an identifiable assessor and a demonstrable link to the release.

Public tools

  • Full text of Article 111

    The legal text on EUR-Lex: the base text in Regulation (EU) 2024/1689 and the replacement of paragraph 2 and the addition of paragraph 4 in Regulation (EU) 2026/1744. Reading only the base text means reading the 2024 version.

Conditions and exceptions

  • Systems that are components of the large-scale IT systems established by the legal acts listed in Annex X fall not under paragraph 2 but under paragraph 1. Paragraph 1 was not amended by the Digital Omnibus and keeps its own cut off: placed on the market or put into service before 2 August 2027, with compliance by 31 December 2030.

Official sources and locators

  • Digital Omnibus on AI 2026/1744

    European Parliament and Council | official-journal-2026-07-24

    Source locator: Amended Article 111(2)

  • Digital Omnibus on AI 2026/1744

    European Parliament and Council | official-journal-2026-07-24

    Source locator: Amended Article 113 application dates

  • Digital Omnibus on AI 2026/1744

    European Parliament and Council | official-journal-2026-07-24

    Source locator: New Article 111(4)

  • Digital Omnibus on AI 2026/1744

    European Parliament and Council | official-journal-2026-07-24

    Source locator: Recital 39 of Regulation (EU) 2026/1744

Referring to this object

Citation block

Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.

Reference

Praxikon, "Article 111(2): legacy high-risk systems and the 2 August 2030 date",
praxikon:eu:ai-act:obligation:article-111-legacy-public-systems@1.0.0,
dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0 (schema 1.5.0),
effective_at 2026-07-27T00:00:00.000Z, known_at 2026-08-14T00:00:00.000Z,
sha256 f6d9b4b81b0a9ef37eec8fdd812d98a712cc1688491f8db5c61b8a857ee419e4,
https://www.praxikon.com/en/verplichtingen/article-111-legacy-public-systems
(https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-111-legacy-public-systems&effective_at=2026-07-27&known_at=2026-08-14&lang=en, accessed 2026-09-15)

Short form

praxikon:eu:ai-act:obligation:article-111-legacy-public-systems@1.0.0 (sha256 f6d9b4b8)

BibTeX

@misc{praxikon-eu-ai-act-obligation-article-111-legacy-public-systems-1-0-0,
  author       = {{Praxikon}},
  title        = {Article 111(2): legacy high-risk systems and the 2 August 2030 date},
  year         = {2026},
  version      = {1.0.0},
  number       = {praxikon:eu:ai-act:obligation:article-111-legacy-public-systems},
  howpublished = {AI Act Change \& Evidence Graph, dataset 2.2.0, schema 1.5.0},
  note         = {effective_at 2026-07-27T00:00:00.000Z; known_at 2026-08-14T00:00:00.000Z; sha256 f6d9b4b81b0a9ef37eec8fdd812d98a712cc1688491f8db5c61b8a857ee419e4},
  url          = {https://www.praxikon.com/en/verplichtingen/article-111-legacy-public-systems},
  urldate      = {2026-09-15},
  language     = {en}
}

CSL JSON

[
  {
    "id": "praxikon:eu:ai-act:obligation:article-111-legacy-public-systems@1.0.0",
    "type": "dataset",
    "title": "Article 111(2): legacy high-risk systems and the 2 August 2030 date",
    "container-title": "AI Act Change & Evidence Graph",
    "publisher": "Praxikon",
    "version": "1.0.0",
    "number": "praxikon:eu:ai-act:obligation:article-111-legacy-public-systems",
    "URL": "https://www.praxikon.com/en/verplichtingen/article-111-legacy-public-systems",
    "language": "en",
    "issued": {
      "date-parts": [
        [
          2026,
          8,
          14
        ]
      ]
    },
    "accessed": {
      "date-parts": [
        [
          2026,
          9,
          15
        ]
      ]
    },
    "note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0; schema 1.5.0; effective_at 2026-07-27T00:00:00.000Z; known_at 2026-08-14T00:00:00.000Z; sha256 f6d9b4b81b0a9ef37eec8fdd812d98a712cc1688491f8db5c61b8a857ee419e4; retrieved_from https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-111-legacy-public-systems&effective_at=2026-07-27&known_at=2026-08-14&lang=en; licence https://www.praxikon.com/nl/legal/terms"
  }
]

How to verify a reference later is set out in the methodology. Terms

Version history

  1. v1.0.0

    27 July 2026

    Article 111(2): legacy high-risk systems and the 2 August 2030 date

    High-risk AI systems placed on the market or put into service before the date of application of Chapter III, since the Digital Omnibus 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, come under the high-risk requirements of that Chapter only once their design is significantly changed as from that date. This is not an exemption from the whole Regulation: Article 4 and Article 50 keep running. For systems intended to be used by public authorities the carve out falls away entirely: their providers and deployers must in any case comply with the requirements and obligations by 2 August 2030.

Corrections to this obligation

No substantive correction to this object has been recorded.

Open the correction log
Zahed Ashkara, jurist and freelance AI & Privacy Consultant

Behind this page

Zahed Ashkara

Freelance AI & Privacy Consultant, jurist

Help with implementation

Zahed Ashkara, jurist and freelance AI & Privacy Consultant, supports implementation with your team through Embed AI.

View AI governance at Embed AI

For AI agents and integrations

This page and the machine output derive from the same versioned object. Use the API for deterministic filters by role, topic and time.