Why the Annex I deadline gets overlooked
Almost all the commentary on the EU AI Act’s high-risk timeline has focused on Annex III, the standalone list covering recruitment, credit scoring, education, essential services and biometric identification. The Digital Omnibus on AI, Regulation (EU) 2026/1744, pushed those obligations out to 2 December 2027. Far less attention has gone to a second deadline that matters just as much to a large slice of European industry: 2 August 2028, for AI embedded in products already regulated under EU product-safety law.
If your business builds AI into medical devices, radio equipment, lifts, pressure equipment or personal protective equipment, that is the deadline that applies to you, and the analysis behind it is different from the Annex III one. The Omnibus did more than move the date: it narrowed what counts as a safety component, moved an entire sector out of the AI Act’s high-risk regime altogether, and created a mechanism that may yet limit which requirements apply to the sectors that remain.
What counts as an Annex I product, and why the section matters
Annex I lists EU sectoral safety legislation in two sections, and which one an act sits in now determines almost everything. Section A contains the New Legislative Framework acts: toys, recreational craft, lifts, ATEX equipment, radio equipment, pressure equipment, cableways, personal protective equipment, gas appliances, medical devices and in vitro diagnostic medical devices. Section B contains other acts, largely transport — civil aviation security and safety, agricultural vehicles, two- and three-wheel vehicles, marine equipment, rail interoperability, vehicle type-approval and general vehicle safety — and, following the Digital Omnibus, machinery.
That last point is most likely to catch businesses out. The Omnibus deleted machinery from Section A and added the Machinery Regulation, Regulation (EU) 2023/1230, to Section B. The consequence flows from Article 2(2): for systems classified as high-risk under Article 6(1) in relation to products covered by Section B legislation, only Article 6(1), Article 60a and Articles 102 to 112 apply. The AI Act’s high-risk package — risk management, data governance, technical documentation, logging, human oversight, accuracy and conformity assessment — does not apply to AI in machinery at all. Manufacturers who spent two years building an AI Act programme have not wasted the work, but its legal home has changed.
What the 2 August 2028 deadline actually covers
The two-limb test in Article 6(1)
An AI system is high-risk under Article 6(1) where both of two conditions are met: it is intended to be used as a safety component of a product, or is itself a product, covered by the legislation listed in Annex I; and that product must undergo third-party conformity assessment under that legislation before being placed on the market. This applies irrespective of whether the AI system is placed on the market independently of the product, so a standalone AI component supplied to a manufacturer is caught.
A narrower definition of “safety component”
The Omnibus inserted three new paragraphs into Article 6 that materially narrow the first limb. Article 6(1a) provides that AI systems used solely for non-safety-related aspects of user assistance, performance optimisation, service efficiency, automation or convenience, or quality control, do not qualify as safety components. Article 6(1b) claws back systems whose failure or malfunctioning would endanger health and safety, which qualify notwithstanding that carve-out. The Article 3 definition was tightened in the same direction: a component fulfils a safety function where its intended purpose is to prevent or mitigate risks to health and safety of persons or property.
A business can no longer assume that AI somewhere inside a regulated product automatically triggers high-risk obligations, nor assume the opposite. The test is function by function, and a company that concludes its AI is a mere convenience feature without documenting why has nothing to show an authority that asks.
The second limb, and the radio equipment trap
The second limb is often treated as a formality, and the Omnibus made it anything but. Article 6(1c) provides that a product required to undergo third-party conformity assessment solely because of risks other than those to health and safety — in particular risks relating to radio spectrum or electromagnetic interference that do not affect health and safety — does not satisfy the second limb. That bites hardest on radio equipment, where third-party assessment is frequently triggered on spectrum or electromagnetic compatibility grounds rather than safety ones, so manufacturers of connected products should test it before assuming they are in scope.
One conformity assessment, not two
For products that remain in Section A, the AI Act is layered onto conformity assessment regimes businesses have operated for years. Article 8(2) makes providers responsible for compliance with all applicable Union harmonisation legislation and lets them integrate the necessary testing, reporting and documentation into procedures that already exist under the sectoral act — a choice rather than a mandate, but plainly the right one, because parallel files drift apart. Article 43(3) also allows notified bodies already notified under a Section A act to assess AI Act conformity, provided their compliance was assessed as part of that sectoral notification, and sets a deadline for them to apply for AI Act designation — so talking to your existing notified body early is likely faster than finding a newly designated one.
The requirements that may yet be limited
There is one more moving part, and it is unusually consequential for anyone planning a compliance budget. A new Article 2(13), inserted by the Omnibus, provides that for high-risk systems under Article 6(1) the application of specific requirements in Articles 9 to 15 and 17 to 25 may be limited where, and to the extent that, Section A legislation already provides an equivalent or higher level of protection of health, safety or fundamental rights, and the limitation does not reduce overall protection. The Commission must adopt delegated acts by 2 August 2027 specifying which systems and requirements are concerned, and on what conditions.
That range covers risk management, data governance, technical documentation, logging, human oversight, accuracy, the quality management system and much of the provider obligation set. The substantive content of the Section A package is therefore not yet settled, and the instrument that settles it is due exactly one year before the compliance date. Machinery follows a parallel track: amendments to the Machinery Regulation require delegated acts adding health and safety requirements for AI systems to that Regulation’s own annex by 2 August 2028, with an interim presumption of conformity through AI Act harmonised standards. Note also that the 2028 date applies to the Article 6(1) high-risk obligations only. It does not touch the Article 50 transparency obligations, which applied from 2 August 2026 regardless of classification, so a regulated product with a generative or interactive component that talks to end users already carries disclosure duties.
Practical example
A Swedish medical technology company sells a diagnostic imaging device with two AI functions. The first improves image reconstruction so radiologists see a clearer picture. The second flags suspected findings and drops images it classifies as normal from the priority review queue.
Medical devices remain in Section A, and the device requires third-party conformity assessment under the Medical Devices Regulation, so the second limb is satisfied. The first function is a strong candidate for the Article 6(1a) carve-out: it is performance optimisation, and its failure produces a poorer image rather than a danger. The second is different. If a misclassification can cause a genuine finding never to be reviewed, the function’s failure endangers health, and Article 6(1b) brings it back in as a safety component however the manufacturer would prefer to describe it. Its obligations crystallise on 2 August 2028, assessed alongside the existing conformity assessment.
In Sweden, market surveillance for Article 6(1) systems in medical devices and in vitro diagnostics falls to Läkemedelsverket, which is also the notifying authority for those products, with Swedac as notifying authority for the remaining areas and Post- och telestyrelsen covering Article 6(1) for radio equipment. Worth noting: the June 2026 government decision designates Article 6(1) authorities for those two sectors only. The other Section A sectors have no named Swedish authority under it, and the designations are interim, expiring on 31 December 2026 pending complementary legislation.
Common mistakes companies make
The first is treating 2028 as a reason to deprioritise the work. The quality management system, technical documentation and classification analysis all take time, and must align with a sectoral conformity assessment process that is itself slow, so companies starting in 2028 will be racing a deadline that companies starting in 2026 will meet comfortably.
The second is assuming the narrowed test excludes your AI without the analysis. The Omnibus made the test narrower, not automatic, and Article 6(1b) exists precisely to catch functions a manufacturer has optimistically labelled a convenience.
The third is classifying the product rather than the function: regulated products contain several AI functions with different risk profiles, and one decision covering all of them will be wrong about at least one.
The fourth is machinery manufacturers continuing to build to the AI Act’s high-risk requirements. Since machinery moved to Section B, those requirements do not apply, and the substantive AI obligations will arrive through the Machinery Regulation instead. Building to the wrong instrument costs twice: wasted effort now, and a gap where the real requirements land.
Recommended actions
Start by establishing which section of Annex I your product’s governing legislation now sits in, because that question alone determines whether the AI Act’s high-risk package applies to you. For Section A products, map every AI function separately and apply the narrowed safety-component test to each, recording the reasoning rather than just the conclusion. Then test the second limb honestly: if third-party conformity assessment is required only on spectrum or electromagnetic compatibility grounds that do not affect health and safety, Article 6(1c) may take you out of scope entirely.
For functions that remain in scope, treat the quality management system and technical documentation as work to start now, and integrate them into the sectoral technical file rather than maintaining a parallel one. Raise AI Act designation with your existing notified body early, since bodies already notified under your sectoral act can carry out the assessment and capacity will be the binding constraint closer to the deadline. Diarise 2 August 2027 for the delegated acts, and keep the classification analysis on file — it is the first thing a regulator or a customer’s legal team will ask to see.
Frequently asked questions
Does the 2028 deadline mean my business can wait?
No. The date defers when the obligations take legal effect, not when the work needs to start. Quality management systems, technical documentation and the classification analysis take time, notified body capacity is finite, and the Article 50 transparency obligations already apply regardless.
We make machinery with AI in it. What applies to us now?
The Digital Omnibus moved the Machinery Regulation from Section A to Section B of Annex I, and under Article 2(2) only a narrow set of AI Act provisions applies to Section B products. The AI Act’s high-risk requirements therefore do not apply to AI in machinery; substantive AI-related health and safety requirements are instead to be added to the Machinery Regulation by delegated act, with a deadline of 2 August 2028.
Does this deadline apply to software as a medical device?
Medical devices, including software as a medical device, sit in Annex I Section A where they require third-party conformity assessment under the Medical Devices Regulation or the In Vitro Diagnostic Medical Devices Regulation. Whether a particular AI function within the device is a safety component still depends on the narrowed test in Article 6(1a) and (1b), so the same function-by-function analysis applies.
Conclusion
The 2 August 2028 date is a genuine and welcome extension for manufacturers of regulated products. But it is only one of the changes the Digital Omnibus made here, and the others matter more to scoping than the date does: what counts as a safety component is narrower, one limb of the test turns on why third-party assessment is required at all, machinery has left the regime, and the content of the requirements for the sectors that remain will not be settled until the delegated acts arrive in 2027. Businesses that use the intervening period to work out which of those changes apply to them will be far better placed than those who noted the new date and moved on.
Lawgent helps businesses classify AI functions in regulated products, map AI Act obligations against existing product-safety conformity assessment, and prepare technical documentation ahead of the deadlines that apply to them.