The EU AI Act's Loophole With No Expiry Date
Article 111(2) of the EU AI Act decides which high-risk AI systems will never have to comply.
I was at a conference two weeks ago, listening to a presentation on the EU AI Act and its connection to GDPR, when the speaker put Article 111(2) on the screen.
I had read it before. If you’ve read the AI Act cover to cover (condolences), so have you. It lives in Chapter XIII Final Provisions, the part of a regulation where the highlighter runs dry. Entry into force. Amendments to other regulations. Transitional arrangements. Article 111(2) reads like exactly what it appears to be: a transition rule for AI systems that were already on the market before the new obligations apply.
Then he walked the room through what it does.
I sat there realizing I had filed one of the most consequential provisions in the EU AI Act under administrative. Judging by the quality of the silence around me, I wasn’t the only one.
Article 111(2) doesn’t give older AI systems more time to comply.
It decides which AI systems never have to.
What the Provision Says
The text, from the Official Journal version:
“...this Regulation shall apply to operators of high-risk AI systems... that have been placed on the market or put into service before 2 August 2026, only if, as from that date, those systems are subject to significant changes in their designs. In any case, the providers and deployers of high-risk AI systems intended to be used by public authorities shall take the necessary steps to comply with the requirements and obligations of this Regulation by 2 August 2030.”
Transitional provisions normally come in two parts. Old systems get relief, and then a date arrives when the relief ends. Article 111(2) has the first part. For private-sector systems, the second part doesn’t exist.
A high-risk AI system placed on the EU market before the deadline, and never significantly redesigned afterwards, is exempt. There is no date at which that changes. The risk management system, the data governance requirements, the technical documentation, the human oversight design, the accuracy and robustness standards: none of it applies. Not late. Never.
Though, I must mention two exceptions. The Article 5 prohibitions apply to everything, old or new (a pre-deadline social scoring system is still illegal). And systems intended for use by public authorities must comply by August 2, 2030, modified or not.
The Dates Just Moved and the Difference Grew
The original cut-off was August 2, 2026. The Digital Omnibus on AI, provisionally agreed on May 7, 2026, moves the high-risk AI obligations to December 2, 2027 for stand-alone Annex III systems (hiring tools, credit scoring, education, life and health insurance pricing), and to August 2, 2028 for AI embedded in regulated products. The Article 111(2) cut-off moves with them.
Laura Caroli, who led the Parliament’s technical negotiations on the AI Act, put it plainly: a high-risk hiring system placed on the market before December 2, 2027 “may remain outside the AI Act indefinitely, unless it is substantially altered after that date”.
At the time of writing this article, the Digital Omnibus on AI isn't in the Official Journal yet. The European Parliament approved the final text on June 16, 2026; the Council's formal adoption and publication follow, before August 2. Everything here reflects the text Parliament approved in June. I'll flag anything that changes in the official version once it's published.
The Digital Omnibus on AI does one more thing to this provision, and it got a fraction of the attention the delay got. The Commission’s proposal clarifies that the exemption attaches to the type of system, not to each individual unit. If at least one unit of a high-risk AI system was lawfully placed on the EU market before the deadline, identical units can continue to be placed on the market afterwards, with no conformity assessment, as long as the design stays unchanged. (This clarification originated in the November 2025 proposal, and it survived: the adopted text keeps the grace period attached to the type of system, not each individual unit.)
The pool of exempt AI systems doesn’t just persist after December 2027.
It keeps growing.
What This Means if You’re the One Buying
If your company is procuring AI systems in the next 18 months, the system you sign for may never be subject to the AI Act’s requirements. Not because of a loophole your vendor found. Because of the EU AI Act’s own architecture.
Which changes what the compliance conversation in procurement is even about. “We’ll be AI Act ready” on the sales slide is not a compliance status. The question is no longer whether the vendor is compliant. The question is whether their system will ever be legally required to be.
And you cannot check the answer yourself. There is no public registry of when an AI system was “placed on the market”. The EU database for high-risk systems covers systems that register and comply, which exempt legacy systems, by definition, don’t. A vendor’s claim about their system’s legacy status is unverifiable from the outside. That moves it from due-diligence question to contractual warranty (more on that below).
What Your Vendor Is Thinking
Every month between now and December 2027 is a strategic shipping window. Place a high-risk AI system on the EU market before the deadline and you’ve acquired an indefinite exemption. Keep the design frozen and you keep it. Under the type-based clarification, you can keep selling new copies of it too.
This is not a fringe reading. MEP Sergey Lagodinsky calls the provision “a loophole” and “a weak spot” in the law. Bram Vranken of Corporate Europe Observatory warns that companies “might abuse this timeline and quickly push risky AI systems onto the market” before the deadline, saving the compliance costs entirely. The people who built and watched over this regulation are saying, on the record, that the rational vendor strategy is to race to market and then stand very still.
None of this requires bad faith. It requires a vendor who reads the regulation and responds to incentives.
On “Significant Change”
The exemption holds only while the system avoids “significant changes in its design”. So the entire question of whether a legacy system ever enters the EU AI Act collapses into one undefined phrase.
What we know: Recital 177 says significant change should be understood as equivalent to “substantial modification” under Article 3(23). That definition covers a change not foreseen or planned in the provider’s initial conformity assessment which either affects compliance with the high-risk requirements or changes the system’s intended purpose.
Notice the problem. The test’s reference point is the initial conformity assessment. Legacy systems never had one. That’s what makes them legacy systems. The yardstick the regulation points to doesn’t exist for exactly the systems this provision governs. I think that in practice the reference point will have to be the provider’s own design documentation, which the provider writes, controls, and can draft as broadly as their lawyers dare.
The open questions are the ones your vendor will answer in their own favor. Is retraining on new data a design change? A new model version behind the same interface? Swapping the underlying foundation model while the product name stays the same? No guidance exists yet. Until it does, expect every vendor changelog to be written by someone who has read Article 111(2) very carefully.
The Trap on Your Side of the Contract
The exemption protects the system as the vendor shipped it. It does not protect what you do to it afterwards.
If you substantially modify a high-risk AI system yourself, or change its intended purpose, Article 25(1) can make you the provider. Not provider-ish. The provider: conformity assessment, technical documentation, CE marking, registration, all of it, for an AI system you didn’t build, possibly without the documentation you’d need to do any of it.
Buying an exempt legacy system and customizing it heavily is how a company wakes up one morning as an AI provider.
Six Questions Before You Sign
The practical part. These belong in your procurement process for any AI system that is or could be high-risk, starting now.
“When was this system first placed on the EU market?”
The single most consequential question in the deal, and the sales team likely won’t know why you’re asking. Don’t accept the answer on a call. Make it a contractual warranty, with the date stated. If the vendor won’t warrant the date, that tells you something too.
“Which types of updates do you classify as design changes?”
Their update policy decides whether the exemption survives contact with their own roadmap. Get their classification approach in writing, with an obligation to notify you before any update they consider significant, and before any update you might.
“If an update brings the system into scope, who carries the compliance?”
Allocate it in the contract: who performs the conformity assessment, who pays, what happens to the system in production while that takes months. Contract silence defaults to a dispute, and the dispute happens while you’re running an uncertified high-risk system live.
“Will you hand over the technical documentation if the roles shift?”
If you ever become the provider under Article 25, you need the technical file to have any chance of complying. The EU AI Act foresees cooperation from the original provider, but you don’t want to be litigating the AI Act when you could be enforcing a clause. Documentation escrow or a hard contractual handover duty.
Does your AI inventory record legacy status?
Internal question. Every high-risk system in your inventory should carry three fields: its placing-on-market date, its Article 111(2) status, and a modification log. If your inventory doesn’t have those columns, this article is your reason to add them.
Are you, or do you sell to, a public authority?
Then the indefinite exemption isn’t yours. August 2, 2030 applies regardless of modifications. Different planning, different timeline, same provision.
The EU AI Act was written to make high-risk AI systems demonstrably safe: documented, overseen, accountable. For systems shipped before December 2027, it will do something else entirely. It will make them permanent.
From that date, the EU market carries two kinds of high-risk AI, identical on the demo call, separated only by a date. One is governed. One never will be but it will keep selling.
The date won’t be on the box. It will be in your contract, if you ask.






This is the part that will actually matter: two AI systems can look identical on the demo but live under totally different rules just because of when they shipped, and that's going to shape vendor behavior for years. Really useful piece, thanks for laying it out this clearly.