More in
AI at Work Insights
What to Ask Before You Let an AI Agent Touch Company Data
Oct 2, 2026
How to Prepare for AI Regulation When Deadlines Keep Moving
Oct 2, 2026 · Currently reading
How to Choose an AI Model Without Rebuilding Every Time One Launches
Oct 2, 2026
The Coordination Tax: The Hidden Cost That Kills Operational Velocity
Apr 13, 2026
Measuring AI ROI Beyond 'Time Saved'
Mar 17, 2026
The Governance Gap: What Leaders Get Wrong About AI at Work
Mar 5, 2026
AI Agents in the Sales Pipeline: Hype, Reality, and What's Actually Working
Jan 22, 2026
AI Copilots vs. AI Agents: Understanding the Difference Matters
Jan 21, 2026
How to Prepare for AI Regulation When Deadlines Keep Moving
Turn this article into takeaways for your work.
Each assistant summarizes the article only for you and suggests best practices for your work.
If you've stopped trying to memorize the exact date your AI obligations kick in, you're not being careless. You're being realistic. The EU AI Act's high-risk compliance deadline has already moved once, and the agencies writing the technical standards underneath it are still behind schedule. More delays are plausible. Betting your compliance plan on any single date is a losing bet.
So treat the dates as a moving target and build the parts of your compliance posture that don't move. An inventory of where you use AI, who owns each use, and what happens when something goes wrong holds its value whether enforcement starts in 2026, 2027, or later. That groundwork is what this article is about.
Where the Rules Stand (as of October 2026)
The EU AI Act has not gone away. It has gotten more complicated, because the enforcement timeline now has more moving parts than it did a year ago. The EU's Digital Omnibus on AI, finalized and published in the Official Journal of the European Union, entered into force in late July 2026 and rewrote several of the compliance dates companies had been planning around, according to Orrick's analysis of the final text.
The headline change: obligations for standalone high-risk AI systems, the category that covers most B2B tools touching hiring, credit, or performance decisions, no longer take effect on August 2, 2026. Jones Walker's breakdown of the delay and Morgan Lewis's client alert on the amendments both confirm the new date is December 2, 2027. High-risk obligations for AI embedded in regulated products (medical devices, machinery, and similar categories under Annex I) move further out, to August 2, 2028.
Not everything moved, though. The Act's transparency rules, requiring you to tell people when they're interacting with AI, when content is AI-generated, or when a system is scoring them emotionally or biometrically, still apply from August 2026. There's a narrow grace period on one piece: technical watermarking of AI-generated content from systems already on the market before August 2, 2026 gets until December 2, 2026 to comply. Everything else under that transparency umbrella is unaffected by the delay.
Key Facts
- High-risk obligations under Annex III (employment, credit, education, and similar uses) are deferred from August 2, 2026 to December 2, 2027.
- High-risk obligations for product-embedded AI under Annex I are deferred to August 2, 2028.
- Transparency obligations under Article 50 (AI-interaction disclosure, deepfake labeling) still apply from August 2026, with most content unaffected by the delay.
- A narrower grace period pushes technical watermarking compliance, for systems already on the market, to December 2, 2026.
- Morgan Lewis reads the delays as extra time to meet the same obligations, not a reduction in what's ultimately required.
If you sell into the EU, or run AI tools touching EU customers or employees, none of this means the pressure is off. The clock reset, and the next reset isn't guaranteed to be the last one. This is a general overview, not legal advice. Confirm your specific obligations with qualified counsel before you rely on any date here.
The Six Things That Don't Move When the Dates Do
Regulatory deadlines move because they depend on political negotiation and technical standards bodies. Your internal readiness doesn't depend on either. The six building blocks below hold their value under any timeline, including a US state law you haven't heard of yet.
| What to build | Why it holds under any timeline | Who owns it |
|---|---|---|
| AI use inventory: every tool or feature using AI, where it's deployed, what decision it touches | You can't comply with a rule you can't locate. The prerequisite for everything else, EU or otherwise | CIO/IT, with input from every department head |
| Risk tiering: sort each use into customer-facing, HR/hiring, credit/financial, or internal productivity | Nearly every proposed AI law draws its toughest rules around consequential decisions about people | Legal or compliance lead, informed by the inventory owner |
| Transparency practices: disclose when people are talking to AI, seeing AI-generated content, or being scored by it | Already a live EU obligation and a common thread in US proposals, plus good customer trust practice on its own | Product and customer-facing teams |
| Human oversight on consequential decisions | "The AI recommended it" has never been a defensible answer for an employment or credit decision | Department heads whose workflows use AI in decisions |
| Vendor documentation and contract language | You're liable for AI you deploy even if you didn't build it. Getting it in writing now beats chasing it under deadline pressure | Procurement, with legal sign-off |
| A review cadence (quarterly is reasonable) | Rules keep changing. A standing review catches new obligations before they become a surprise | Inventory owner, reporting to the CEO or compliance lead |
Notice what's absent from that list: nothing depends on August 2026, December 2027, or any other specific date. The constants are structural, not calendar-driven, which is why they survive the next round of political horse-trading over timelines. Regulators keep moving the deadline because technical standards aren't ready, not because expectations changed. As Morgan Lewis's analysis puts it, the delays are "an extension of time to complete their AI Act compliance efforts, rather than ... a material relaxation of the underlying obligations." Build for the obligations, not the date.
For a deeper walkthrough of how to turn that into an actual written policy your department will follow, see our guide to creating an AI governance policy for your department, and our AI readiness assessment templates if you need a starting scorecard for the inventory step.
Why "Wait and See" Is the Costlier Option
Executives who put compliance groundwork on hold until a deadline is locked are making a bet: that building the inventory, tiering, and oversight process later, under time pressure, costs less than building it now. That bet rarely pays off. Discovering mid-audit that your ATS has an AI scoring feature you never documented, or that a chatbot never disclosed it was AI, is a scramble either way. The only variable you control is whether it happens on your schedule or a regulator's.
There's also a quieter cost: your teams keep adding AI capability in the meantime. Every new tool a sales team adopts widens the gap between what's actually running in your business and what you've documented, which is also why security teams now flag the access AI systems carry as its own risk category, a topic covered in our look at why AI agents now carry more system access than most companies have secured.
One more point worth being direct about: deregulatory moves in one jurisdiction don't cancel obligations in another. A company watching US federal policy loosen can still carry real exposure in the EU. We covered that dynamic in our analysis of the deregulatory US executive order and why it didn't change binding compliance risk. Build for the strictest jurisdiction that applies to your business.
What to Do in the Next 30 Days
You don't need outside counsel to start the first two steps below. You do need it before you rely on any conclusion you draw from them.
- Build the inventory first, in writing. List every tool your teams use that has an AI feature, including ones bundled into software you didn't buy specifically for AI (CRM, support, HR, even scheduling tools increasingly ship AI scoring features). If you use an AI-assisted CRM or workspace platform, Rework included, note what the feature does and whether it touches a hiring, credit, or performance decision.
- Run each tool through the risk-tier test. Does it make or meaningfully inform a decision about a specific person's employment, credit, or access to a service? If yes, it's high priority regardless of which law eventually governs it.
- Check your transparency gaps now, since this is already live. Does every AI-generated customer communication disclose that it's AI? These obligations are active in the EU today and increasingly expected everywhere.
- Ask your top five AI vendors for compliance documentation in writing. If they can't produce it, that's useful information for procurement, not just a compliance footnote.
- Put a quarterly review on the calendar now, before you need it. The next regulatory shift will come from a direction nobody at your table is currently watching.
If your AI-driven sales or lead-scoring tools touch EU customers, our RevOps compliance checklist for AI lead scoring under the EU AI Act walks through the function-specific version of this inventory. If your technical team is weighing which governance framework to standardize on, our comparison of OpenAI's Frontier Governance Framework against NIST's AI risk framework is a useful companion read.
The deadlines will keep moving. The six building blocks above won't need to.
Frequently Asked Questions about AI Compliance
Does the EU AI Act still apply to companies outside the EU?
Yes. The Act applies based on where your AI systems are used or where their outputs affect people, not where your company is headquartered. A US or Asia-based company selling to EU customers, or processing EU employee data through an AI system, can fall within scope. Confirm your specific exposure with counsel.
If the high-risk deadline moved to December 2027, why start now?
The deferral buys time to prepare, not a reason to skip preparing. Building an accurate AI inventory and oversight process across a real organization takes months, and companies that wait until the deadline nears will compete for the same scarce legal and compliance resources everyone else needs at once.
What's the difference between the delayed obligations and the ones still coming in 2026?
The delayed obligations involve formal risk assessments, technical documentation, and conformity processes for high-risk AI systems. The obligations still on track for 2026 are narrower and center on transparency: telling people when they're interacting with AI or seeing AI-generated content. Those disclosure duties take far less to implement, so get them in place well before any high-risk deadline arrives.
Do I need a lawyer to build the AI use inventory?
No. The inventory is an operational exercise your IT and department leaders can run without outside counsel. You'll want legal input to interpret whether a specific tool crosses into high-risk territory and what documentation that status requires, so build the inventory first and bring counsel in for the classification conversation.
Are US state AI laws moving on the same timeline as the EU?
Not necessarily, and that's part of the challenge. US state-level AI rules are developing on separate timelines with different scope, so a posture built only around the EU AI Act can still leave gaps elsewhere. The six building blocks in this article, inventory, risk tiering, transparency, oversight, vendor documentation, and a review cadence, are designed to generalize across jurisdictions rather than being EU-specific.
Sources: Orrick, "EU AI Act Update: Digital Omnibus Finalizes 8 Compliance Changes" (July 2026) | Jones Walker, "Yes, August 2 Still Matters: The EU Approved a High-Risk AI Delay, but Most Transparency Obligations Remain" (July 2026) | Morgan Lewis, "EU Approves Delays and Other Amendments to Certain EU AI Act Obligations: What Businesses Should Know" (June 2026)
This article is a general business overview, not legal advice. AI regulation is changing quickly and varies by jurisdiction. Confirm your specific obligations with qualified legal counsel before making compliance decisions.
