
Image AI-generated. All text human -written.
Many companies rushed AI into production long before they built any governance around it. That approach was tolerable in 2023, when enforcement was theoretical. It is a much riskier bet now that the EU AI Act’s obligations are becoming real, enforceable law.
The Legal Framework, in Brief
The EU AI Act (Regulation (EU) 2024/1689) is the world’s first comprehensive, horizontal AI law. It entered into force on August 1, 2024, and takes a tiered, risk-based approach: AI systems are classified as unacceptable risk (banned), high-risk, limited risk, or minimal risk, with obligations scaling to the potential harm a system could cause.
High-risk systems — those used in areas like hiring, credit scoring, critical infrastructure, biometric identification, law enforcement, and education — face the heaviest obligations. Under Chapter III of the Act, providers and deployers of these systems must generally demonstrate:
- Risk management — a continuous, lifecycle risk management system (Article 9)
- Data governance — quality controls over training, validation, and testing data (Article 10)
- Technical documentation — complete records of how the system was built and functions (Article 11)
- Traceability and logging — automatic event logging sufficient to reconstruct the system’s operation and catch malfunctions or drift (Article 12)
- Transparency to deployers — clear instructions for use (Article 13)
- Human oversight — the ability for a qualified person to understand, monitor, and intervene in the system’s operation (Article 14)
- Cybersecurity and accuracy/robustness (Article 15)
- Quality management systems at the organizational level (Article 17)
- Conformity assessment, CE marking, and registration in the EU’s public database before the system can be placed on the market
A system that lacks this infrastructure isn’t just poorly managed — it fails the legal bar for operating in the EU.
An Important Timeline Correction
Here’s where accuracy matters: earlier guidance (including much content still circulating online) points to August 2, 2026 as the hard deadline for full high-risk obligations. That was true until recently.
On May 7, 2026, EU negotiators reached a provisional agreement on a “Digital Omnibus” package amending the AI Act — the first substantive amendment since the Act’s adoption. That package entered into force on July 27, 2026, and it pushes back the compliance timeline:
- Obligations for Annex III (use-case-based) high-risk systems — the category covering most enterprise AI, including hiring, credit, and similar applications — are now due December 2, 2027, not August 2026.
- Obligations for Annex I (product-related) high-risk systems, such as AI embedded in machinery or medical devices, move to August 2, 2028.
- The requirement for EU member states to stand up national regulatory sandboxes shifts from August 2026 to August 2, 2027.
The delay was driven largely by the fact that the technical standards bodies (CEN-CENELEC) tasked with translating the Act’s requirements into concrete technical standards were not able to finish that work on the original schedule, leaving companies without a clear rulebook to build against.
Two things stay true despite this extension, though:
- Prohibited AI practices (e.g., social scoring, certain manipulative or biometric-categorization systems) have been banned since February 2, 2025, along with AI literacy obligations for organizations deploying AI in the EU.
- Transparency obligations for general-purpose AI (GPAI) model providers — including documentation and disclosures about training data — have applied since August 2, 2025.
So the extension applies specifically to the high-risk system obligations under Chapter III — not to the Act as a whole, and not to obligations that are already in force.
Why “We’ll Deal With It Later” Is Still a Bad Strategy
An extended deadline is not the same as no deadline, and it’s not a reason to stay unprepared:
- December 2027 is closer than it looks. Conformity assessments, technical documentation, data governance controls, and logging infrastructure take months to build properly — retrofitting them under deadline pressure is far more expensive and error-prone than designing them in from the start.
- Penalties remain severe. Under Article 99 of the Act, non-compliance can trigger administrative fines of up to €35 million or 7% of global annual turnover for prohibited practices, up to €15 million or 3% for other high-risk infringements, and up to €7.5 million or 1% for supplying incorrect or misleading information to regulators — whichever figure is higher in each tier. These apply to non-EU companies serving the EU market too, though SMEs and startups get the benefit of the lower of the two figures rather than the higher one.
- Misclassification carries its own risk. Treating a system as lower-risk than it actually is can lead to mandatory recalls, forced suspension of deployment, or market access restrictions once the correct classification is identified.
- Standards may still shift. Because the delay exists partly to give standards bodies more time, the technical specifics of “how” to comply may still be refined between now and the new deadlines. Building governance now, on the current text and best available guidance, keeps you ahead rather than scrambling later.
The Practical Takeaway
Deploying AI without governance was never really “innovation” — it was exposure that hadn’t been priced in yet. The EU’s own timeline has moved, but the destination hasn’t changed: organizations operating high-risk AI systems in or affecting the EU will need lifecycle risk management, real data governance, traceability, human oversight, and conformity assessment on file. The extension is breathing room, not a reprieve — and the companies that use it to build real governance infrastructure will be in a very different position by December 2027 than those that use it to keep waiting.
EU AI Act Compliance Disclaimer
This article is provided for general informational and educational purposes only and should not be considered legal, regulatory, or compliance advice. The EU AI Act is evolving, and its requirements can vary depending on the organisation, AI system, role, and specific use case. For professional advice and guidance on EU AI Act compliance, visit www.exclevelai.eu