The high-risk deadline moved.
The work did not.
The Digital Omnibus, in force since 27 July 2026, moves the main obligations for stand-alone high-risk AI systems to 2 December 2027. Transparency obligations still apply from 2 August 2026. The extension is not relief. It is the window to build the inventory, documentation, monitoring and governance foundations properly, while there is time to do it well.
Where the obligations now sit
2 Aug 2026
Transparency obligations apply
In force
2 Dec 2026
AI-generated content marking
Upcoming
2 Dec 2027
Stand-alone high-risk systems, Annex III
Upcoming
2 Aug 2028
High-risk systems embedded in regulated products, Annex I
Upcoming
Regulation (EU) 2026/1744, in force 27 July 2026.
Two-Stage AI Act Scanner
Screen the purpose first. Then measure the control gap.
Stage one asks what the system is for, which is what decides classification. Stage two scores your controls. The two results are reported separately.
Stage 1 - Classification screening
Classification follows the intended purpose of the system. Answer for the system you have in mind.
Stage 2 - Control readiness
Separate from classification. This measures how mature your controls are, whatever the classification turns out to be.
Directional indicator, not legal advice. Formal classification is confirmed in a scoped assessment.
AI-Powered Gap Analysis
Describe your AI estate. Get a regulator-aware gap analysis.
0 / 3000
Engagement Model
From Exposure to Audit-Ready.
Most institutions used the original timeline as the reason to start. With Annex III obligations now at December 2027, the firms that move first will have documentation, monitoring and evidence in place before auditors ask for them, rather than assembling it under pressure. We build that foundation as a structured engagement.
Diagnose
- 2-week gap assessment
- Evidence-readiness score
- Executive memo
- Prioritized remediation roadmap
Remediate
- Annex IV documentation
- Model risk controls
- Monitoring framework
- Audit evidence package
- Up to 12 high-risk models
Operate
- Continuous monitoring
- Quarterly re-attestation
- Ongoing compliance operations
- Unlimited model additions
If a regulator formally rejects documentation produced by Syntheon within 12 months, we continue remediation at no additional cost.
Subject to engagement terms. Full guarantee conditions provided in the statement of work.
Why Syntheon
Three delivery models, compared factually.
Readiness Diary
What we're seeing in regulator-facing conversations.
"December 2027 is one budget cycle and one audit cycle away, not four years."
Authority & Alignment
Designed for regulated European enterprises.
EU AI Act aligned
Mapped to high-risk AI obligations and Annex IV evidence requirements.
DORA-aware delivery
Operational resilience and ICT risk controls embedded in our delivery model.
Financial-services specialisation
Credit, AML, underwriting, claims, fraud, and risk-scoring systems.
Website delivery and data residency
This website is delivered through a global content delivery network, so pages may be served from an edge location outside the EU. No client data is processed here. Client systems and client data are a separate matter: production deployments and any client data we process run in EU regions, and data residency is agreed per engagement and recorded in the documentation for that system.
Executive AI Act Briefing
Request a private, regulator-aware consultation.
We respond within one business day with a scoped briefing proposal.
