June 11, 2026 3 mins read

EU High-Risk AI Database Delayed to Q3 2027: Technical Infrastructure Realities Catch Up with the AI Act

Last updated: 11 July 2026

Reading Time: 4 min read

As the European Union recalibrates its regulatory timelines following the adoption of the Digital Omnibus package, another critical piece of the compliance puzzle has shifted: the central EU Database for High-Risk AI Systems.

According to internal communications from the European Commission’s AI Act service desk, the centralised database required to log and track high-risk AI deployments will not be open or operational until the third quarter of 2027.

For enterprise compliance officers and product teams, this delay aligns technical infrastructure with the broader deferral of high-risk obligations—providing much-needed operational clarity.

Here is what the delay entails, why it occurred, and how organisations should adapt their compliance roadmaps.

1. The Launch Schedule: From 2026 to Late 2027

Under the original EU AI Act architecture, providers of high-risk AI systems (such as those used in recruitment, credit evaluation, education, and critical infrastructure) were expected to register their systems in a public EU database managed by the newly established EU AI Office before placing them on the market.

Early expectations from the European Council targeted a functional registry launch by mid-2026. However, internal guidance confirms a revised build-out timeline:

  • Current Status: The database infrastructure remains under active development by the EU AI Office and is not yet open to testing or registration.
  • Target Launch: Official operational readiness is now scheduled for Q3 2027 (between July and September 2027).
  • Enforcement Alignment: The operational window opens shortly before mandatory high-risk obligations (Annex III) take effect on 2 December 2027.

The database delay highlights the complex interaction between legislative drafting and technical implementation:

                  ┌─────────────────────────────────────────┐
                  │      Digital Omnibus Adopted (July 2026) │
                  └────────────────────┬────────────────────┘
                                       │
            ┌──────────────────────────┴──────────────────────────┐
            ▼                                                     ▼
 [Annex III Compliance Deferred]                      [Database Article Left Unchanged]
     Pushed to 2 Dec 2027                                  Text implies 2 Aug 2026
            │                                                     │
            └──────────────────────────┬──────────────────────────┘
                                       │
                                       ▼
                   [Technical Reality: Q3 2027 Launch]
              Registration impossible before DB exists

When the EU Digital Omnibus package deferred Annex III high-risk compliance dates from August 2026 to December 2027, it updated the main application cross-references. However, the standalone clause mandating the database establishment itself was left textually unchanged, creating a minor legal discrepancy on paper.

In practice, this discrepancy is academic: organisations cannot register in a database that does not yet exist. The Commission’s service desk has confirmed that the registration timeline naturally tracks the omnibus package’s adjusted application date of December 2027.

3. The Role of the Central AI Registry

Digital rights advocates and regulatory bodies emphasize that the central database remains a vital pillar of the AI Act’s oversight framework.

Once live, the public-facing registry will serve three primary functions:

  1. Public Transparency: Allowing citizens, researchers, and civil society to inspect which high-risk AI applications are deployed across the EU.
  2. Regulatory Oversight: Giving national market surveillance authorities a single pane of glass to monitor market access, system architecture, and conformity assessments.
  3. Lifecycle Tracking: Ensuring system modifications, major incidents, and vendor changes are formally logged throughout an AI system’s operational lifecycle.

4. Strategic Implications for Compliance Teams

While the database delay prevents immediate registration, it does not pause the necessity of internal governance preparations.

What You Should Do Now:

  • Maintain Internal Registries: Do not wait for the EU database to start cataloguing systems. Build internal AI Model Inventories to map system architecture, training data sources, and risk classifications today.
  • Prepare Conformity Documentation: High-risk systems will still require technical documentation, Quality Management Systems (QMS), and risk assessments before they can be entered into the EU database in late 2027.
  • Focus on Active Deadlines: Divert immediate resources toward obligations taking effect now—specifically Article 50 transparency notices (effective August 2026) and upcoming machine-readable watermarking mandates.

The Bottom Line

The Q3 2027 database launch date provides a realistic alignment between software development cycles and European regulatory infrastructure. Organisations should view this extended runway as an opportunity to build robust, audit-ready documentation well ahead of the registration portal going live.