Legal 12 min read

Legacy AI Systems and 'Grandfathering': What Article 111 Really Protects — and What It Doesn't

Many organizations assume AI systems already on the market before August 2026 are exempt. Article 111 is far narrower than that. Here is what grandfathering really covers, the 'significant change' trigger that ends it, the 2030 public-authority deadline, and how to document your baseline.

By Elena Rossi, Legal Tech Analyst · Published

The Dangerous Comfort of "It's Already Deployed"

A widespread misconception about the EU AI Act is that systems already in use before the deadlines are simply exempt — "grandfathered in." The transitional rules in Article 111 do provide some relief for legacy systems, but it is much narrower and more conditional than most assume. Misreading it is one of the easiest ways to end up unexpectedly non-compliant on August 2, 2026.

What Article 111 Actually Says

GPAI models placed on the market before August 2, 2025 must achieve compliance by August 2, 2027. High-risk (Annex III) systems placed on the market before August 2, 2026 are only caught by the Act if their design is significantly changed after that date. And high-risk systems used by public authorities must be brought into compliance by August 2, 2030 regardless of any significant change. So a private-sector Annex III system placed on the market before August 2, 2026 is not automatically required to meet Articles 9–15 — until it undergoes a significant change in design.

The "Significant Change" Trigger

Grandfathering ends the moment a legacy high-risk system is subject to significant changes in its design. The Act's definition of "substantial modification" in Article 3(23) is instructive: a change not foreseen in the original conformity assessment that affects compliance or alters the intended purpose. In practice, watch for model retraining or replacement that changes performance, new or materially different training data, an expanded intended purpose, or architectural changes beyond what the original design anticipated. Routine maintenance and security patches generally do not count, but continuously-learning systems are especially exposed.

The 2030 Deadline for Public Authorities

Public bodies get no free pass. Even without any significant change, high-risk AI systems operated by public authorities that were placed on the market or put into service before August 2, 2026 must be brought into full compliance by August 2, 2030. Given the pace of public-sector procurement and budgeting, four years is not as generous as it sounds — remediation planning should begin now.

Documenting Your Baseline

Because grandfathering hinges on whether a system has "significantly changed" since a baseline date, you must be able to prove what the baseline was. Freeze and record the baseline version (model version, weights reference, configuration, intended purpose); document the original conformity basis; establish a change-control log capturing every subsequent modification and whether it is significant; and set a significant-change decision gate that flags when a change would end grandfathering and trigger full compliance.

The Bottom Line

Article 111 is a narrow, conditional bridge — not a permanent exemption. Any organization relying on it must confirm the system truly predates the cut-off, remember that public-sector systems face the 2030 deadline anyway, and rigorously document the baseline and control change so it can defend the grandfathered status.

Unsure whether a legacy system is still grandfathered? Browse our directory of AI Act legal specialists who can assess your transitional status.