Regulation
The EU AI Act delay is not a reprieve
The EU has postponed its rules for high-risk AI systems to December 2027. However, the transparency rules took effect as planned in August 2026, and the rules for general-purpose AI already apply. Organisations that pause their preparations now will find it harder later.
- Lorendix research team
- Security and engineering practice
- 9 September 2026
- 6 min read
The main news from Brussels this summer was a delay. The details tell a different story. Some obligations moved, others did not, and a new prohibition was added. The extra time is only valuable to organisations that use it.
What changed
In June 2026, the European Parliament and the Council adopted the Digital Omnibus on AI, which postponed the obligations for high-risk AI systems.
Stand-alone high-risk systems listed in Annex III of the Act, such as those used in recruitment, credit decisions and access to essential services, must now comply from 2 December 2027 instead of 2 August 2026. AI built into regulated products under Annex I has until 2 August 2028.
2 Aug 2026
Transparency rules under Article 50 apply
2 Dec 2026
Labelling deadline for generative AI already on the market
2 Dec 2027
Rules for stand-alone high-risk systems apply
2 Aug 2028
Rules for high-risk AI in regulated products apply
What did not change
- Transparency
- Since 2 August 2026, people must be told when they are dealing with an AI system, and AI-generated or manipulated content must be disclosed and labelled. Generative AI systems that were already on the market have until 2 December 2026 to add machine-readable labels.
- General-purpose AI
- The obligations on providers of general-purpose AI models have applied since August 2025. They also affect organisations that build on those models, through the documentation and usage terms that providers pass on.
- Prohibitions
- Practices that were already banned remain banned. The omnibus also added a new ban on AI systems that generate non-consensual intimate images or child sexual abuse material.
The deadline has moved, but the work required to meet it has not changed.
Why the rules were delayed
The postponement reflects a lack of readiness rather than a change of direction. The technical standards that organisations need were behind schedule, and many member states had not yet appointed the authorities responsible for enforcement.
Once those are in place, regulators’ expectations will be shaped by the organisations that prepared, not by those that waited.
How to use the extra time
Find out what AI you use
Build an inventory of the AI systems in use across the organisation, including AI features inside software you have bought, and give each one an owner.
Classify each system honestly
Decide which systems could fall under the Annex III categories, and record your reasoning for the ones you conclude do not.
Meet the transparency rules now
Chatbot notices, disclosure of AI-generated content and labelling are already required, and they are the easiest obligations to evidence.
Build the evidence into your systems
Risk management, logging, human oversight and data governance are engineering work. Building them in now will cost less than adding them in 2027.
Sources
- Gibson Dunn: EU AI Act omnibus agreement, postponed high-risk deadlines and other key changes, May 2026
- Certivo: EU AI Act August 2026, what applies after the Digital Omnibus
- Cloud Security Alliance: EU AI Act high-risk deadline, deferred but not cancelled, 2026
In short
- High-risk obligations now apply from December 2027 for stand-alone systems, and from August 2028 for regulated products
- The transparency rules have applied since August 2026, and the general-purpose AI rules since August 2025
- Use the time to list your AI systems, classify them, and build the required evidence into them
More from the practice

AI agents act on what they read
AI agents are now connected to code repositories, inboxes and business tools. The security incidents so far share a common cause: an agent treated text it read as an instruction, and it had the permissions to act on it.

Your help desk is now your security perimeter
One of the most damaging UK retail breaches of the past two years started with a phone call to an outsourced IT service desk. It is now easier for attackers to talk their way through account recovery than to break the systems it protects, and most organisations have not tightened that process.
Bring us a question your team has not been able to answer
If this article raised a question about your own systems, describe the situation rather than the solution you have in mind, and we will tell you what we would look at first.
