
Brussels delayed its high-risk AI rules by 16 months
The European Union has pushed its compliance deadline for high-risk AI systems back by 16 months, to 2 December 2027. The change was published in the Official Journal on 24 July and took effect three days later, a week before the rules it postpones were due to apply.
Regulation (EU) 2026/1744, the Digital Omnibus on AI, amends the bloc’s AI Act. Providers of high-risk systems had faced a 2 August deadline for risk management, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity, followed by conformity assessment and a CE mark. Those obligations now fall on 2 December 2027 for standalone systems under Annex III, which covers employment screening, credit scoring, biometrics, critical infrastructure and access to essential services. Systems embedded in products already governed by EU product law have until 2 August 2028.
The rest of the act is unchanged. Bans on unacceptable-risk practices and the AI-literacy duty have applied since February 2025, and rules for general-purpose models since August 2025. The penalty tiers behind them stand as well.
Procurement teams already ask vendors about AI, prompted by risk committees, insurers and their own regulators, and those reviews recur annually, at renewal, or whenever a new subprocessor is added. A bank subject to DORA maintains its register of critical providers whatever Brussels does with the AI Act.
Contract terms are also unaffected. Clauses on model training, prompt retention and notice before an AI subprocessor is added were signed over the past two years and bind vendors now. So does the act’s territorial scope, which covers providers placing systems on the EU market and, in defined cases, providers established outside the bloc whose system output is used inside it.
The questions themselves are consistent from one questionnaire to the next: where AI touches customer data, which models are in use and whether customer content trains them, what a person reviews before an output reaches a customer, how long prompts and outputs are kept and in which jurisdiction, and whether the vendor holds ISO/IEC 42001 or is working towards it.
Firms already assembling that documentation are unaffected by the new dates. For the others, the regulation will eventually require an AI system inventory, a description of human oversight, data-flow records and a register of models and providers, and buyers ask for the same material today.
Sources
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal · Publications Office of the European Union
- Artificial intelligence: Council gives final green light to simplify and streamline rules · Council of the European Union
- AI Act: Parliament approves simplification measures · European Parliament
- Timeline for the implementation of the EU AI Act · European Commission
- Regulation (EU) 2024/1689 (the AI Act), consolidated text · Publications Office of the European Union