Skip to content

Life. Adventure. Consulting. Technology.

Technology

The Deadline Moved. So Why Is Your Programme Slowing Down?

The AI Act's high-risk obligations were deferred by sixteen months, six days before they were due to apply. Rather less moved than the headlines suggest, and an organisation that stopped when the date changed has learned something about its own programme.

Chris Cooper 4 min read
The steel frame of a partly built structure standing against a bright open sky

The Digital Omnibus entered into force on the twenty-seventh of July. That was six days before the AI Act’s high-risk obligations were due to apply, and they now arrive in December 2027.

Sixteen months is a substantial deferral. It is also being read, in a good many organisations, as considerably more than it is.

1. The Deferral Is Real and It Is Large

There is no point being sniffy about it. Standalone high-risk systems under Annex III move from this month to December 2027. Systems built into products already covered by product safety law move to August 2028.

For anyone who spent the first half of this year assembling technical documentation, arranging conformity assessment and building risk management processes — that is genuine breathing room.

The architecture of the Act is untouched — only the dates have changed, and they have changed by a lot.

2. It Moved Because the Standards Were Late

The reason is worth dwelling on, because it is not the reason most people assume.

Nobody concluded the requirements were wrong. The standards and guidance needed to make the obligations workable had not arrived — and a deadline nobody can comply with is not much of a deadline.

The application dates have now been cut loose from the completion of those standards and fixed outright, which is a quiet improvement. An open-ended dependency has become a date.

3. Rather Less Moved Than the Headline Suggests

The deferral is narrower than the coverage implies, and this is where organisations are getting caught.

The Article 50 transparency duties apply from this month. Telling people they are dealing with an AI system, marking synthetic output, disclosing deepfake content — none of it was postponed. It also reaches far more software than the high-risk regime does.

Nor did anything else move. Obligations on general-purpose models have applied since last August — and the prohibited practices, along with the AI literacy duty, since February 2025.

4. A Date Is Not a Reason

Which brings the difficulty into focus. A programme built around a deadline responds to that deadline moving by slowing down — because the deadline was the thing driving it.

The date moved because the standards were late. Nothing about the systems running in your organisation changed on the twenty-seventh of July.

They make the same decisions about the same people, on the same data, with the same oversight they had a month ago.

5. What the Slowdown Tells You

An organisation whose governance work paused this summer has been handed a precise piece of information about itself, free of charge.

It has learned that the work was compliance work rather than operating work. There is nothing wrong with that in principle, and plenty of necessary things get done only because somebody insists on them.

But compliance work stops when the compliance date stops, and it has to be started again from cold. Work that exists because the organisation needs it does not behave that way.

6. Some Organisations Should Slow Down

This is not an argument that everybody should carry on at the same pace regardless. That would be simple to write and wrong.

Sixteen months of extra time is a perfectly legitimate reason to move people onto something more pressing — particularly where a conformity assessment was going to be built against standards that did not yet exist.

Slowing deliberately, having decided the work can wait, is a different act from slowing because the pressure came off. The first is a plan — the second is drift.

7. What Stays on the Calendar

The result is several separate tracks rather than one date. Four are worth keeping in front of people:

  • Article 50 transparency, applying from this month
  • the watermarking duty for systems already on the market, from December
  • general-purpose model obligations, in force since last August
  • the high-risk regime, December 2027 and August 2028 respectively

Presenting these as a single AI compliance deadline is how organisations end up missing the ones that did not move.

8. The Same Crunch, Sixteen Months Later

The systems that will be high-risk in December 2027 are largely the systems being deployed right now.

Documentation, risk management, oversight arrangements and registration are slow work, and none of it gets faster for being started later. The volume did not fall when the date did.

An organisation treating the extension as permission to stop is arranging to have precisely the same difficulty in 2027 that the legislators have just deferred.

Final Thought

Regulators move deadlines from time to time. They very rarely move the reason a deadline existed in the first place.

Knowing what AI is running in your organisation, what it decides and who is answerable for it was never really a European requirement. It was a management one that a European requirement happened to make urgent for a while.

Stay in touch

Occasional writing, straight to your inbox

A short note when I publish something worth reading. No noise, and easy to leave whenever you like.