By Rafael Luque Ocaña

The AI Act's grace period: the article stopped stating the date

Article 111(2) sets a grace period for high-risk systems placed on the market before a given date. The Digital Omnibus rewrote the paragraph and removed the date: it now refers to Article 113, which gives two different dates depending on the annex.

There's a question that comes up as soon as a company realises one of its systems might be high-risk: does this apply to the system I already have running, or only to what I buy from now on?

The answer sits in Article 111(2) of Regulation (EU) 2024/1689, and it's the reason many older deployments fall outside the bulk of the obligations. It's also one of the articles where it's easiest to quote something it no longer says.

What the grace period sets out

In the original wording, Article 111(2) said that the Regulation applies to operators of high-risk systems placed on the market or put into service before 2 August 2026 "only if, as from that date, those systems are subject to significant changes in their designs."

Put simply: if the system was already deployed before that date and isn't substantially redesigned, it remains outside the Chapter III obligations. And the "in any case" that closes the paragraph isn't a general exception: it reaches only the high-risk systems intended to be used by public authorities that were already on the market or in service before that cut-off — in the current wording, the date of application of Chapter III: 2 December 2027 for Annex III —, whose providers and deployers must comply by 2 August 2030 at the latest.

What changed, and why it's hard to spot

Regulation (EU) 2026/1744 — the Digital Omnibus, published in the Official Journal on 24 July 2026 — replaced that paragraph in its entirety. The current wording says the cut-off is "before the date of application of Chapter III referred to in Article 113."

Read it twice, because that's the whole story: the article no longer contains any date at all. Where there used to be a specific day, there's now a cross-reference.

And that has a practical consequence you don't see until you follow the cross-reference. Article 113, also reformed, doesn't give one date of application for Chapter III. It gives two:

  • 2 December 2027 for high-risk systems under Article 6(2) and Annex III.
  • 2 August 2028 for those under Article 6(1) and Annex I — high risk in products already regulated under other legislation.

So the grace-period cut-off isn't the same for everyone. It depends on which of the two routes makes your system high-risk. A recruitment ATS, which falls under Annex III, has one cut-off; a medical product with embedded AI, which falls under Annex I, has another, eight months later.

Why this is the hardest kind of error to catch

It's worth pausing on the mechanism, because it explains a problem that goes beyond this one article.

When a rule changes a date, the error can be caught: it says "2 August 2026" and the correct date is something else, so whoever checks it against the source sees it. That's what happens with the Annex III date, which moved to December 2027 and still circulates in its old version.

Not here. Here the date disappeared from the article. Anyone who knows Article 111(2) from reading it in 2025 will remember "2 August 2026," and that recollection will go on looking reasonable indefinitely: it doesn't contradict any visible text, because the text no longer states anything about dates. It only refers elsewhere. And that cross-reference, on top of it, splits in two.

It's a statement that expires without the sentence changing. No re-read gives it away: you have to go to the article, check that it no longer says what you remember, follow the cross-reference, and discover it leads to two different places.

The type-and-model nuance

There's a second detail of the grace period that tends to get lost, and which the Digital Omnibus itself clarifies in its recitals: the decisive factor is the date on which the system's type and model was placed on the market or put into service, not the date of each individual unit.

In other words: if a high-risk system's type and model was placed on the market before the applicable date, the other units of that same type and model remain covered by the grace period, even if they were installed later. What breaks the coverage isn't the installation date of each unit: it's a significant change in the design. Worth not confusing this transitional arrangement with the one for synthetic content marking under Article 50(2), which has its own date, its own subject and a different scope.

For a company with several deployments of the same product, the difference between the two readings is substantial.

What to do with this

Three checks, in this order.

First: know which annex each system falls under, if it falls under one at all. It isn't a formality: it determines which of the two cut-offs applies to you — just as under Article 50 it determines the subject, where the interaction notice turns out to be the provider's obligation and not the deployer's. Most AI uses at a mid-sized company aren't high-risk under either route, so this question is answered once, and often with a no.

Second: record the date the type and model was placed on the market, not just the installation date. It's the data point that sustains the coverage, and it's exactly the one nobody writes down when buying software. Recovering it three years later, when someone asks, means digging through contracts and emails.

Third: note what counts as a significant change in the design, and who decides that. That's where the coverage gets lost, and it gets lost silently: nobody issues a notice on the day an update crosses that line. Worth also not confusing this timeline with the Article 50 transparency obligations, which are already in application and have nothing to do with this period.

What this article teaches about the others

The Article 111(2) grace period is a good example of why a date jotted down on a slide ages badly. Not because anyone got it wrong, but because the rule stopped expressing it as a date.

Anyone keeping this information in slide decks, emails and spreadsheets will end up with as many versions as copies, with no way of telling which one was revised after July 2026. Anyone keeping it in one place, where each system has its annex, the placing-on-the-market date of its type and model, and who's accountable for it recorded, will only have to update one thing when the calendar moves again — and the Omnibus proves that it does.

The difference isn't knowing more law. It's having the answer to "does this apply to us?" live in a single place, with the date of its last review next to it.

Dates in accordance with Articles 111 and 113 of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (Official Journal of the EU, 24 July 2026, in force since 27 July 2026).

This article is for informational purposes only and does not constitute legal advice.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (CIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es). More information in the privacy policy.