EU AI Act High-Risk Database Delayed Until Mid-to-Late 2027

The EU's central registry for high-risk AI systems faces a significant setback, raising questions about enforcement timelines and compliance planning for developers and enterprises.

EU AI Act High-Risk Database Delayed Until Mid-to-Late 2027

What the EU AI Act High-Risk Database Delay Actually Means

The European Union's planned public database for high-risk AI systems — a cornerstone transparency mechanism of the landmark EU AI Act — has been pushed back to mid-to-late 2027, according to reporting by Euractiv. The delay is a significant development for developers, compliance officers, IT decision-makers, and policy professionals who have been mapping their AI deployment timelines around the regulation's original schedule. The EU AI Act high-risk database was designed to serve as a centralized, publicly accessible registry where providers of high-risk AI systems would be required to register their systems before placing them on the EU market.

For organizations building or deploying AI systems in sectors like healthcare, education, critical infrastructure, employment, and law enforcement — all categories flagged as high-risk under the AI Act — this database was meant to be both a transparency tool and an enforcement mechanism. Its delay does not mean compliance obligations disappear, but it does shift the practical enforcement landscape in ways that demand careful attention from legal and technical teams alike.

AI regulation and digital compliance concept
The EU's AI Act represents one of the most comprehensive AI governance frameworks in the world, with the high-risk database central to its enforcement architecture.

The database was originally intended to be operational well ahead of the AI Act's phased enforcement schedule. The Act itself was formally adopted and entered into force, with different provisions activating at staggered intervals — prohibited AI practices faced the earliest deadlines, while high-risk AI system requirements follow on a longer runway. The registry was meant to coincide with those high-risk obligations, giving regulators and the public visibility into what systems are being deployed and by whom. Pushing it to mid-to-late 2027 means a meaningful gap in that transparency infrastructure.

Why the High-Risk AI Registry Is Central to EU AI Governance

To understand why this delay matters, it helps to understand what the database was supposed to do. Under the EU AI Act, providers of high-risk AI systems are required to register their systems in an EU-wide database managed by the European Commission before those systems go to market. The registry would include details about the system's intended purpose, the conformity assessment process it underwent, and the provider's contact information. Essentially, it is designed to work similarly to how the GDPR's data processing records function — creating an auditable trail that regulators can use to hold organizations accountable.

According to analysis from the Future of Life Institute, which has closely tracked the AI Act's legislative progress, this kind of public registry is a rare example of the EU building meaningful "ex ante" (before-the-fact) transparency into AI governance rather than relying solely on after-the-fact investigations. That makes its delay more than just an administrative hiccup — it weakens the proactive oversight architecture that civil society groups and AI safety researchers argued was essential to the law's effectiveness.

2027Revised target for EU high-risk AI database launch
85+High-risk AI use cases identified in the AI Act annexes
27EU member states subject to AI Act obligations
€30MMaximum fine for non-compliance with high-risk AI obligations

For IT decision-makers at enterprises deploying AI systems in regulated sectors, the database delay is a double-edged development. On one hand, it reduces the immediate pressure of having public registration requirements enforced. On the other hand, it creates planning uncertainty — organizations that had aligned their internal governance timelines to the database's expected launch now face an extended ambiguous period where internal compliance processes are mature but the external verification infrastructure is not yet in place. This kind of regulatory lag can actually breed complacency, a risk that compliance professionals have flagged repeatedly during the GDPR's own rocky rollout years.

How the EU AI Act's Phased Timeline Is Evolving

The EU AI Act operates on a tiered implementation schedule that has always been complex to navigate. The regulation became law with a clear phased structure: the earliest obligations targeted outright prohibited AI practices, followed by requirements for general-purpose AI (GPAI) models, then high-risk AI systems, and finally a broader set of transparency and minimal-risk obligations. The high-risk AI system registration database sits within the third major wave of implementation, which is now landing in a more compressed and delayed window than originally anticipated.

AI Act Obligation Category Timeline Status Key Requirement
Prohibited AI Practices First wave (already active) Full ban on social scoring, real-time biometric surveillance in public, and other prohibited systems
GPAI Model Obligations Second wave Transparency, copyright compliance, and systemic risk assessments for large foundation models
High-Risk AI Systems Third wave (enforcement ongoing) Conformity assessments, technical documentation, human oversight, and registry registration
High-Risk AI Database Delayed to mid-to-late 2027 Public EU-wide registry of registered high-risk AI systems
Minimal/Transparency Risk AI Final wave Voluntary codes of conduct and limited disclosure requirements

The delay in the high-risk AI database is not occurring in a political vacuum. The European Commission, which is responsible for building and operating the database infrastructure, has been navigating significant institutional and resource pressures. The Commission's AI Office — established to coordinate AI Act implementation — is a relatively new body still building its operational capacity. According to reporting by Politico Europe, the AI Office has faced staffing challenges and a heavy workload as it simultaneously develops technical standards, coordinates with national supervisory authorities across all 27 member states, and manages the GPAI model obligations that came into force earlier in the timeline.

"The EU AI Act is an ambitious piece of legislation, and the database is not a simple registry — it requires significant backend infrastructure, standardized data formats, and integration with national enforcement bodies. Delays of this kind are not surprising, but they do underscore the gap between legislative ambition and administrative execution."

— EU AI policy analyst, commenting on implementation challenges

What Developers and Compliance Teams Should Do Now

For developers building high-risk AI systems and compliance officers managing AI governance programs, the database delay should not be interpreted as a green light to pause internal preparation. The substantive obligations of the EU AI Act for high-risk AI systems — conducting conformity assessments, maintaining technical documentation, implementing human oversight mechanisms, and ensuring data governance — remain in place regardless of when the public registry goes live. The database is the external transparency layer; the internal compliance requirements are a separate track that continues on its own timeline.

Privacy and AI governance consultancy IAPP (International Association of Privacy Professionals) has consistently advised organizations to treat AI Act compliance as a multi-year program rather than a point-in-time project. That advice becomes even more relevant when implementation timelines shift. Organizations that treat the database delay as a reason to slow down internal readiness risk finding themselves scrambling when the registry does launch and enforcement attention intensifies simultaneously.

Developer working on AI compliance documentation and governance frameworks
Technical teams building high-risk AI systems must maintain compliance readiness regardless of the database delay — substantive obligations remain on their original timeline.

Practically speaking, compliance teams should be using this extended window to accomplish several things. First, conducting or completing AI system classification exercises to determine which of their deployed or in-development systems fall under the high-risk categories defined in Annex III of the AI Act. Second, building the technical documentation and conformity assessment records that will ultimately need to be submitted to the registry. Third, establishing human oversight protocols and audit log mechanisms that demonstrate meaningful human control over high-risk decision-making. And fourth, aligning with the harmonized standards being developed by European standardization bodies CEN and CENELEC, which will provide the technical specifications organizations need to demonstrate conformity.

For small and medium-sized enterprises and startups, the delay may provide some practical breathing room, but it also means less clarity on exactly what registration will entail in practice. The European Commission's AI Office has committed to providing guidance and templates ahead of the database launch, but those materials are still in development. Organizations operating in this space would benefit from engaging with industry associations and national digital innovation hubs that are tracking the regulatory development in real time.

The Delay in Context: EU AI Regulation Under Pressure

The high-risk AI database delay is part of a broader pattern that observers of EU digital regulation will recognize. The GDPR, which became enforceable in 2018, saw years of inconsistent enforcement across member states, underfunded data protection authorities, and significant delays in landmark rulings. As Reuters and others have documented, there are legitimate concerns that the EU AI Act could face similar growing pains — strong on paper, slow to execute in practice.

The comparison to GDPR is instructive for another reason: despite enforcement delays, GDPR fundamentally reshaped how organizations globally approach data governance. Companies outside the EU changed their privacy practices, US tech giants restructured data flows, and "GDPR compliance" became a standard component of enterprise software procurement. The EU AI Act is widely expected to have a similar "Brussels Effect" — even if the high-risk database takes until mid-to-late 2027 to become operational, the anticipation of it has already driven governance changes in organizations building or deploying AI in Europe and beyond.

US AI governance
Fragmented
China AI governance
Originally reported by EU Digital Policy (Google News). Summarised and curated by European Purpose.