December 2027: The Clock Is Ticking for High-Risk AI
The EU AI Act's requirements for high-risk AI systems become applicable on 2 December 2027, after the EU's 2026 Digital Omnibus postponed the original 2 August 2026 date. If your enterprise deploys AI in healthcare, financial services, HR, education, law enforcement, or critical infrastructure, you likely have high-risk systems that need to comply.
This guide provides the practical steps to get there — not the legal theory, but the engineering and governance work that actually needs to happen.
Step 1: AI System Inventory (Weeks 1-3)
Find All Your AI
Most enterprises don't know how many AI systems they have. Start with discovery:
- Formal AI/ML projects — Data science team models, production ML pipelines
- Embedded AI — AI features in SaaS tools (CRM lead scoring, HR screening, fraud detection)
- Generative AI — ChatGPT Enterprise, Copilot, internal LLM deployments
- Rule-based systems — Some automated decision-making may fall under the AI Act's broad definition
- Third-party AI — API-based AI services (translation, vision, NLP) embedded in your products
For each system, document: Purpose, input data, output decisions, affected persons, deployment context, and vendor (if third-party).
Step 2: Risk Classification (Weeks 3-5)
Classify Each AI System
Map each system to the AI Act's risk categories:
- Prohibited (Art. 5): Social scoring, real-time biometric ID in public spaces (with exceptions), emotion recognition in workplace/education, subliminal manipulation
- High-risk (Annex III): Biometrics, critical infrastructure, education, employment, essential services (credit, insurance), law enforcement, migration, justice
- High-risk (Annex I): AI as safety component of regulated products (medical devices, machinery, vehicles, aviation)
- Limited risk: Chatbots, deepfakes, emotion recognition (transparency obligations only)
- Minimal risk: AI-enabled games, spam filters, search engines (no obligations beyond voluntary codes)
Grey areas: When classification is unclear, document your reasoning. The AI Office will provide guidance, but conservative classification is safer.
Kubernetes Recipes
A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).
Watch on Skillshare →Step 3: High-Risk AI Compliance Requirements (Weeks 5-16)
Art. 9 — Risk Management System
Continuous risk management throughout the AI lifecycle:
- Identify known and foreseeable risks to health, safety, and fundamental rights
- Estimate and evaluate risks using quantitative metrics where possible
- Design risk mitigation measures (guardrails, thresholds, human escalation points)
- Test for residual risk acceptability
- Document everything — this forms the basis for conformity assessment
Art. 10 — Data Governance
Training, validation, and testing datasets must meet quality criteria:
- Relevance and representativeness — Data must reflect the population the AI will serve
- Error-free — Systematic effort to identify and correct errors in training data
- Bias examination — Proactive testing for bias across protected characteristics
- Data provenance — Document where training data came from, how it was collected, and what preprocessing was applied
Art. 11-12 — Technical Documentation
The AI Act requires comprehensive technical documentation including:
- General description and intended purpose
- Detailed description of AI system elements and development process
- Monitoring, functioning, and control mechanisms
- Risk management system description
- Changes and updates throughout lifecycle
- Performance metrics and testing results
- Cybersecurity measures
Art. 14 — Human Oversight
Design human oversight appropriate to the risk:
- Human-in-the-loop: Human approves every AI decision before action (highest risk)
- Human-on-the-loop: Human monitors AI decisions and can intervene (moderate risk)
- Human-in-command: Human can override AI and has a "stop button" (all high-risk)
- Infrastructure requirement: Build dashboards, alert systems, and intervention mechanisms into the AI serving infrastructure
Step 4: Conformity Assessment (Weeks 12-20)
Two paths depending on your AI category:
- Self-assessment (most Annex III high-risk): Internal conformity assessment following Annex VI. You assess yourself against the requirements and sign a declaration of conformity.
- Notified body assessment (some high-risk): Biometric identification systems and AI in regulated products (medical devices, vehicles) need third-party assessment. Engage notified bodies early — they're going to be overwhelmed.
Terraform for Beginners
Master Terraform to build scalable infrastructure using IaC principles.
Start on Udemy →Step 5: EU Database Registration and Post-Market Monitoring
- Register high-risk AI in the EU database (Art. 71) before placing on market or putting into service
- Post-market monitoring plan (Art. 72) — Continuous monitoring of AI performance in production, including user feedback and incident tracking
- Serious incident reporting (Art. 73) — Report serious incidents to market surveillance authorities without delay
Timeline for December 2027 Compliance
- Now: AI inventory + risk classification (if you haven't started, start today)
- Through mid-2027: Risk management, data governance, and technical documentation complete
- Q3 2027: Conformity assessment, internal audit, remediation
- 2 December 2027: Compliance required — declaration of conformity, EU database registration
- Ongoing: Post-market monitoring, incident reporting, periodic review
AI Platform Assessment
Get a 2-3 week infrastructure audit with a concrete roadmap. No big-consultancy overhead.
Book Your Free Assessment →Related Solution
Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 2-3 weeks.
Explore AI Readiness for Regulated Enterprises →
Luca Berton
