Slow our EU AI Act prep now the deadline's moved to 2027?
High-risk AI obligations are delayed to December 2, 2027, but transparency and watermarking requirements still apply this August, leaving deployers exposed if they slow their compliance programs.
The question
The EU AI Act's high-risk deployer obligations (Article 26) look set to move from August 2026 to December 2027, but the deferral is not yet formally enacted and the transparency obligations still apply from August 2, 2026. Do we slow our compliance program to the new timeline, hold the original schedule to stay safe, or take a middle path?
Counsel's position
Adopt a middle path, prioritizing immediate transparency and watermarking compliance while building foundational high-risk capabilities and deferring resource-intensive, specific high-risk implementations.
Verdict
The verdict: Adopt a middle path, prioritizing immediate transparency and watermarking compliance while building foundational high-risk capabilities and deferring resource-intensive, specific high-risk implementations.
How the criteria decide
3 of 3 criteria resolved on cited evidence.
| Criterion | Favours | Evidence |
|---|---|---|
| EU AI Act deployer compliance scope and timelines | Take a middle path | High-risk AI obligations are delayed to December 2, 2027 Mandatory marking or watermarking of AI-generated output is also moving forward Transparency and watermarking requirements must still comply by this August Systems subject to transparency and watermarking requirements must still comply by this August, though those already on the market will be granted additional leeway until December 2 High-risk classification now excludes tools that merely assist users Only AI systems whose failure would create genuine health or safety risks face the heaviest obligations. Tools that assist users or optimise performance no longer automatically trigger the full regime |
| AI inventory and risk-tier classification workflows | Take a middle path | High-risk classification now excludes tools that merely assist users Only AI systems whose failure would create genuine health or safety risks face the heaviest obligations. Tools that assist users or optimise performance no longer automatically trigger the full regime artifical intelligence via Google News Developers view verification requirements as box-ticking unless tied to quality Practitioners prioritize requirements that serve end-users or their own development needs, but view verification-oriented requirements as box-ticking exercises. |
| AI compliance as enterprise sales enablement | Take a middle path | Developers view verification requirements as box-ticking unless tied to quality Practitioners prioritize requirements that serve end-users or their own development needs, but view verification-oriented requirements as box-ticking exercises. |
High-risk AI obligations are delayed to December 2, 2027
Given your decision on whether to slow your compliance program, this delay provides a longer runway for high-risk systems, though transparency and watermarking requirements continue to advance.
Transparency and watermarking requirements must still comply by this August
While high-risk obligations are deferred, your compliance program must still meet the original timeline for transparency rules, with a brief grace period for systems already on the market.
High-risk classification now excludes tools that merely assist users
As you adjust your compliance roadmap, note that the scope of what triggers the December 2027 high-risk obligations has been narrowed, potentially reducing your regulatory burden.
Developers view verification requirements as box-ticking unless tied to quality
As you pace your compliance program, be aware that simply handing down regulatory checklists often fails; compliance must be integrated into actual development priorities.
High-risk deployers must keep logs of AI outputs for six months
Whether you target 2026 or 2027, your middle-path compliance program must build the technical infrastructure to support mandatory logging and human oversight.
Read another verdict
- Which process should we point AI at first?
- Put one person in charge of AI — or is a Head of AI premature for us?
- Buy a tool for this process, or build around our own knowledge?
- Centralize AI strategy under CEO or distribute ownership?
- Adopt new AI ROI tools or refine existing methods?
- Invest in pre-build costing or post-deployment ROI tracking?
- Our documents are a mess. Clean them up before AI, or after?
- How do we measure the return on an AI workflow — and what baseline is honest?