The deadline moved. The work didn’t.
Europe has given companies more time. The Digital Omnibus on AI, in force since 27 July, moves the AI Act’s high-risk obligations from August 2026 to 2 December 2027 for stand-alone systems, and to 2 August 2028 for AI built into regulated products such as medical devices.
For executives, the temptation is to treat the extension as a reprieve. The obligations themselves are unchanged: risk management, data governance, technical documentation, logging, human oversight and, in some cases, a fundamental rights impact assessment before a system goes live. None of that is a form to fill in the month before the deadline. It is architecture.
The work breaks in the gaps between teams. Legal reads the Act, engineering builds the product, procurement buys the model, and nobody owns the evidence trail that connects them. Retrofitting that trail onto a system already in production is expensive; designing it in costs a fraction.
Economists will recognise a familiar choice between doing something once, properly, inside the firm, and paying repeatedly to patch it later. The practical answer is to treat compliance as a product requirement: an inventory of AI systems and their risk class, logging and documentation built into the delivery pipeline, and a named owner for each system.
It must be said that waiting has some value. Harmonised standards are still being finalised, and building to a moving target carries its own cost. But the direction is clear, and the architecture holds whatever the detail.
Companies that use the extra sixteen months will reach December 2027 with systems they can sell to regulated buyers across the EU. Those that do not will discover that compliance, like a building’s wiring, is cheapest before the walls go up.
The open question is which of the two most AI programmes resemble today.
AX’s Diagnostic Lab shows where AI adds value in your workflows and where the risks sit. Talk to us →