# EU AI Act: Prepare for 2027 Deadline on High-Risk AI Systems

> The EU AI Act introduces major regulations for high-risk AI systems, with a critical compliance deadline in June 2027 for systems embedded in products under specific EU laws.

Source: https://loopbackup.com/blog/eu-ai-act-prepare-for-2027-deadline-on-high-risk-ai-systems-mpzg1ra6
Publisher: Loop Backup
Content language: en

---

## At a Glance

**Deadline:** June 9, 2027

Providers of AI systems intended for use in specific regulated products (e.g., medical devices, machinery) must ensure their systems comply with the EU AI Act's requirements by June 2027. This marks the 36-month milestone from the Act's entry into force.

## The EU AI Act: A New Era of AI Governance

The European Union's AI Act is a landmark piece of legislation that establishes a comprehensive legal framework for artificial intelligence. Its primary goal is to ensure that AI systems placed on the European market are safe and respect fundamental rights. The Act follows a risk-based approach, imposing stricter obligations on AI systems that pose a higher risk to safety or fundamental rights.

While some provisions of the Act have already come into effect, several key deadlines are staggered over a multi-year period. Understanding this timeline is crucial for any organization developing, deploying, or distributing AI systems within the EU. A critical part of compliance is robust data management; ensuring the integrity and availability of your data with a solution like [Loop Backup](/), is foundational to building trustworthy AI.

## What Changes with the June 2027 Deadline?

This specific deadline primarily concerns providers of high-risk AI systems that are components of products covered by existing New Legislative Framework (NLF) legislation, as listed in Annex II of the Act. This includes a wide range of product categories, such as:

*   Machinery
*   Toys
*   Lifts
*   Medical devices
*   In vitro diagnostic medical devices
*   Personal protective equipment

By June 9, 2027 (36 months after the Act's entry into force), providers of these embedded high-risk AI systems must have completed the necessary conformity assessments. Unlike other high-risk systems which had a 24-month transition period (June 2026), these specific systems were given an extra year to align with the product safety legislation they fall under.

Compliance involves meeting a stringent set of requirements, including:

*   **Risk Management:** Establishing a continuous risk management system throughout the AI system’s lifecycle.
*   **Data Governance:** Ensuring that training, validation, and testing data sets are relevant, representative, and of high quality.
*   **Technical Documentation:** Drawing up detailed documentation that explains the system’s purpose, capabilities, and limitations.
*   **Record-Keeping:** Enabling the automatic recording of events (“logs”) while the high-risk AI system is operating.
*   **Transparency & Human Oversight:** Designing systems to be sufficiently transparent to allow users to interpret the output and enabling effective human oversight.

## Who is Affected?

The obligations primarily fall on "providers" (those who develop an AI system and place it on the market or put it into service under their own name or trademark). However, the ripple effects are significant, impacting:

*   **Product Manufacturers:** Companies that integrate these high-risk AI components into their final products (e.g., a medical device manufacturer using an AI-powered diagnostic tool).
*   **Deployers:** Organizations that use high-risk AI systems in a professional capacity. They have obligations to use the system in accordance with its instructions and to monitor its operation.
*   **Importers and Distributors:** Entities that make AI systems from outside the EU available on the EU market.

For all affected parties, data is the common denominator. Your ability to demonstrate compliance, whether through technical documentation, risk assessments, or post-market monitoring, relies on well-managed, auditable data. This underscores the need for a comprehensive [cloud backup](/microsoft-365-backup) and data protection strategy, as regulators may require access to datasets and logs to verify compliance.

## What to Do Now: Preparing for the Deadline

With the deadline approaching, organizations cannot afford to wait. The process of bringing a high-risk AI system into compliance is complex and time-consuming. Loop Backup recommends the following steps:

1.  **Identify and Classify:** Conduct a thorough inventory of all AI systems you develop, deploy, or use. Classify them according to the AI Act's risk framework to determine if they fall into the high-risk category, particularly those covered by the Annex II list.

2.  **Conduct a Gap Analysis:** For systems identified as high-risk, perform a detailed gap analysis against the Act's requirements. This will highlight areas where your current processes for development, data handling, and risk management fall short.

3.  **Prioritize Data Quality:** Scrutinize your data governance practices. The AI Act places enormous emphasis on the quality and integrity of the datasets used to train and test AI. Ensure your data is unbiased, representative, and fit for purpose.

4.  **Update Technical Documentation:** Begin the process of creating or updating the extensive technical documentation required for conformity assessment. This documentation is not just a formality; it is a critical component of demonstrating compliance.

5.  **Engage with Notified Bodies:** For many high-risk systems, a third-party conformity assessment by a designated "Notified Body" will be required. Begin identifying and engaging with these bodies early, as their capacity will be limited.

The EU AI Act represents a paradigm shift in technology regulation. The June 2027 deadline for high-risk systems in regulated products is a critical milestone. By taking proactive steps now, you can ensure your organization not only complies with the law but also builds more trustworthy and robust AI.
