← All episodes
Special · News ·8:30 ·August 7, 2026

The EU Pushed Its AI Act 16 Months — The Deadline Trap Boards Will Miss

The date every board has been racing toward just slid 16 months into the future. The headlines got it wrong in both directions: one tranche moved, the live regime didn't, and the fines are unchanged. An extension kills the urgency without touching the liability.

The Promise

  • The delay exists for a real reason: the technical standards high-risk compliance depends on aren't finished, and the conformity assessment machinery isn't ready. Brussels bought time to build the rails before enforcing the rules.
  • Sixteen months is genuine runway for the organisations that use it — time to inventory high-risk use cases, build the oversight record, and stand up conformity work that nobody retrofits in a quarter.
PROMISE RISK
Balanced

The Risk

  • An extension is the most dangerous moment in any regulation, because it kills urgency without touching liability. If your AI screens résumés or prices insurance today, it carries the same real-world exposure in December 2027 that it carried in August 2026. Only the reporting clock moved.
  • The systems that got the longest leash are the consequential ones — hiring, credit, insurance, medical devices, education admissions, law enforcement, immigration. High-risk is defined by where you point the model, not by how advanced it is.
  • Article 4, the AI literacy obligation, is in limbo — the official releases went quiet on whether it survives in its current form. A duty that's unclear in the statute is still one a plaintiff's lawyer can argue you ignored.

Three obligations, three new dates

On 7 May 2026, negotiators from the Council, Parliament and Commission reached a provisional agreement — the Digital Omnibus on AI, the first major set of amendments since the Act took effect in 2024.

The centrepiece: obligations for high-risk AI systems, the heaviest compliance tier, move from 2 August 2026 to 2 December 2027. National regulatory sandboxes slip to August 2027. The transparency rule for AI-generated content — watermarking and synthetic media labelling — moves to 2 December 2026, only a few months.

Most of the coverage collapsed all of that into one line: the EU delayed the AI Act. It didn’t. It delayed one tranche.

What did not move: the ban on unacceptable-risk systems, in force since February 2025. The rules for general-purpose models, in force since August 2025. Those are live right now, and the fines are unchanged — up to €35 million or 7% of global turnover at the top of the scale.

High-risk is a use case, not a capability

The Act doesn’t regulate AI by how advanced it is. It regulates AI by where you point it.

Four tiers. Unacceptable risk — social scoring, certain biometric surveillance — banned outright already. Minimal risk at the bottom: spam filters, recommendation engines, the AI sorting your inbox, no obligations at all, and that’s most AI in production today. A transparency tier in between for chatbots and synthetic media that simply have to disclose. And high-risk, Annex III, where the heavy compliance lives: risk assessments, technical documentation, human oversight, conformity checks before market.

Here’s the part most executives get wrong. High-risk has nothing to do with model power. A frontier model writing your marketing copy is minimal risk. A dull three-year-old model deciding who gets a mortgage is high-risk. Same law, opposite obligations.

So when the EU pushed high-risk to 2027, it didn’t push frontier AI. It pushed the AI that makes decisions about people’s lives.

What the 16 months are actually for

In 2018, before GDPR took effect, I wrote that its value would be behavioural — that it would force organisations to finally answer three questions they’d been dodging: what data are we collecting, where is it stored, and how is it protected. The companies that treated the date as a finish line spent the next two years catching up.

The work splits three ways. If you’re on the board, this is the window to build the oversight record you’ll wish you had. Inventory where the company already runs high-risk use cases — hiring, credit, insurance, anything that decides something about a person. Most boards don’t have that list. December 2027 is not when you start it; it’s when you’re supposed to be done.

If you run security or sit in the C-suite, the employer obligations and the literacy expectation didn’t move with the high-risk date. In my experience the gap that hurts you is never the system you knew about — it’s the one a team stood up quietly while everyone was watching the deadline.

If you’re general counsel, treat the limbo around Article 4 as a reason to keep the literacy programme running, not to shelve it. We were waiting for Brussels to clarify is not a sentence anyone wants to say under oath.

Three questions before your next leadership meeting. Where do we already run high-risk AI, by use case rather than by model? Did our AI programme quietly slow down when the deadline moved — because if the honest answer is yes, the delay is already working against you. And is our literacy effort still running, given the duty didn’t leave with the date?

The needle lands toward risk. Not because the regulation got harder, but because an extension is exactly the moment discipline walks out the door.