DEV Community

Cover image for What the EU AI Act actually requires of a two-person studio in 2026 — and the database problem nobody mentions
Pennyforge
Pennyforge

Posted on

What the EU AI Act actually requires of a two-person studio in 2026 — and the database problem nobody mentions

Dated: 2026-10-01. Every date below verified against primary or first-tier sources that day; sources at the end.

If you build or deploy a high-risk AI system in the EU in 2026, you are caught in a gap that has a date on every edge of it. This post lays out the gap end-to-end, because the pieces are spread across a regulation, two Commission documents, a service-desk message and a press report.

The cliff in one paragraph

A small studio that ships an AI system falling under Annex III (e.g. AI-assisted CV screening, point 4(b)) can escape the full high-risk regime if it qualifies for the Article 6(3) filter — but using that filter requires a written four-part self-assessment before launch and registration in a central EU database that, by the Commission's own words, is not yet open.

The dated chain

  1. 2026-02-02 — statutory deadline for the Commission's Article 6(5) guidelines on classifying high-risk systems.
  2. 2026-05-19 — the guidelines are published. As draft. ~3.5 months late.
  3. 2026-07-23 — the draft's last update (the EC library page still marks it draft; a targeted consultation is running).
  4. 2026-07-09 — the Commission's own AI Act service desk tells inquirers: "This database is not yet open and operational." (the Article 71 EU database, via a Rapporteur/Euractiv report of 2026-07-27; launch expected Q3 2027.)
  5. December 2027 — when, per the service desk, the registration duty actually starts applying, aligned with the Digital Omnibus "adjusted timeline" for high-risk systems.
  6. …or 2026-08-02 — because the Omnibus did not move the standalone article that creates the registration duty, a 2026 start date is legally plausible. The Commission declined to confirm.

So a studio following the draft guidelines (step 3) is told to register a system (step 4's database) before the database exists (steps 4–6) — with the duty-start date genuinely ambiguous between "next week" and "15 months from now".

What the draft guidelines actually say (the part people skip)

From the draft's Annex III section (148 pages, §2.7, ¶84–117):

  • The Article 6(3) filter is a self-assessment by the provider — there is no independent check, and the four conditions (narrow procedural task; improving a previously completed human activity; detecting decision-making patterns without replacing human assessment; preparatory task) are exhaustive, alternative, and "must be interpreted narrowly".
  • But using the filter triggers Article 6(4): you must (i) document the assessment before the system is placed on the market and (ii) register the system in the Article 71 EU database.
  • The documentation must contain four things: the intended purpose; why the system would be high-risk under 6(2); which 6(3) condition(s) apply and why; and why the system does not perform profiling (profiling kills the filter).
  • It must be producible at any time on a market-surveillance authority's request — and Article 80 gives those authorities power to re-evaluate the classification and, on misclassification, to impose Article 99 penalties.

That is the practical shape of the cliff: not 40 pages of new obligations, but four paragraphs of legal self-assessment plus a registration in a database that doesn't exist yet, enforceable from day one.

What this means if you are a two-person studio

  • If you're outside Annex III (most B2B SaaS, content tools): nothing high-risk applies to you in 2026 beyond the already-in-force Article 50 transparency duties (mark AI-generated text, disclose chatbots).
  • If you're inside Annex III and can document a 6(3) condition: write the four-part assessment now (it's a day of work, not a project), and track the database — your registration is a line item that must exist before launch, wherever "launch" is dated.
  • If you're inside Annex III and can't (you do profile people, you make the decision): the full Chapter III regime is the plan, and the Omnibus timeline (not the old 2026-08-02 date) is what your compliance calendar should follow — but the registration-article ambiguity is an exception to that comfort.

Honest caveats

  • The guidelines are a draft; the final version can move the filter's conditions or documentation requirements.
  • The "2026-08-02 vs December 2027" conflict rests on the Omnibus not amending one standalone article; the Commission has not ruled, and a small clarifying act could close it either way.
  • I am one studio reading the documents, not a law firm; this is a dated map, not advice.

Sources (all checked 2026-10-01)

  • EC draft guidelines, Annex III section (PDF, 148 pp) — digital-strategy.ec.europa.eu library page, published 2026-05-19, last update 2026-07-23 (¶84–117 = the filter section).
  • Rapporteur (Euractiv) 2026-07-27: "EU's high-risk AI database pushed back to mid-to-late 2027" — service desk message of 2026-07-09, Q3-2027 launch, Dec-2027 duty start, un-moved registration article.
  • AI Act Service Desk, Article 71 explainer (ai-act-service-desk.ec.europa.eu) — database design per the regulation.
  • EUR-Lex, Regulation (EU) 2024/1689, Art. 6 + Annex III (text checked in an earlier pass of this series).

This work was done by Pennyforge, a one-person studio: the analysis was AI-assisted with human editorial review, as we practice it across all our research posts.

Top comments (0)