Expertise hub / Compliance
Compliance 10 min read

The EU AI Act: what does it mean for your organisation?

In mid-2026, the deadline for high-risk AI systems shifted by sixteen months. Many organisations immediately concluded that the AI Act had been postponed again. That's only half the story. The obligations aren't disappearing, and several already apply today.

If you've followed AI Act news over the past months, you know the feeling: just when you'd pencilled in a deadline, it shifts again. On 29 June 2026, the Council of the EU gave the definitive green light for a delay to the obligations for high-risk AI systems. The question that inevitably follows is always the same: does this mean we can wait?

The short answer: no. The long answer, we explain below.

Four risk levels, one decisive question

The AI Act doesn't impose the same obligations on everyone. Everything starts with one question: which risk category does your AI system fall into?

// The four risk levels
Unacceptable riskbanned since Feb '25
High risk (Annex III / Annex I)obligations delayed
Limited risktransparency obligation
Minimal riskno specific obligation

Systems for social scoring, manipulative techniques or untargeted facial recognition are banned. Systems in HR, credit scoring, education, critical infrastructure and other Annex III domains are high-risk. Chatbots and generative AI that creates synthetic content fall under transparency obligations. And systems with no meaningful impact on people (an internal spam filter, for example) fall outside the heavy obligations.

The deadline has shifted, but hasn't disappeared

The obligations for Annex III systems move sixteen months, to December 2027. For AI that is part of regulated products, a later deadline applies, to August 2028. The transparency obligation for AI-generated content (making synthetic content recognisable) gets four extra months, to 2 December 2026.

16
months delay Annex III
2 Dec '27
new high-risk deadline
€15M
max. fine for non-compliance

Two obligations are already in force and remain so: the ban on unacceptable AI practices (since February 2025) and the obligations for providers of general-purpose AI models (since August 2025). The AI literacy obligation under Article 4 (your staff must have sufficient knowledge of the AI systems it uses) has also applied since February 2025.

The obligations for Annex III systems move sixteen months, to December 2027. For AI that is part of regulated products, a later deadline applies, to August 2028.

What this concretely means for your organisation

You use AI in an Annex III domain

HR, credit scoring, education, critical infrastructure: the deadline is 2 December 2027, but risk management, data governance, technical documentation and logging aren't built in a weekend. Start classifying now, not in 2027.

You deploy generative AI that generates content

The transparency obligation (Article 50(2)) applies from 2 December 2026 for systems already on the market before August 2026. New systems must comply with it immediately.

You use AI as a tool, without impact on people

Lighter obligations, but not zero: the AI literacy obligation (Article 4) has applied since February 2025 to every organisation that uses AI systems, regardless of risk level.

Why start now if the deadline has moved

The delay largely came about because the European standardisation bodies are running behind. The technical standards organisations are meant to rely on aren't expected until late 2026. That explains why the deadlines shifted, but it's no reason to delay preparation. Classification, risk management, documentation and testing take time. Those who start now will have a solid base once the definitive standards become available.

Also bear in mind that a political agreement isn't the same as a legal amendment. At the time of writing, the delay hasn't yet been formally published in the Official Journal of the European Union. Until that publication, the original statutory timeline formally remains in force. A well-considered compliance approach therefore accounts for both the announced changes and the legislation currently in effect.

Independent validation helps with this. A test partner that validates AI systems rather than building them can carry out classification, test documentation and validation objectively. That way you not only demonstrate that your AI system does what it's supposed to do, but you also have the evidence a regulator can request.

An example from practice: two systems, two outcomes

Two clients asked us for a classification in the same week. Both use a language model, and yet they land in completely different categories.

// Two classifications side by side
Internal chatbot for IT supportminimal risk
CV screening for external candidateshigh risk (Annex III)

The chatbot has no meaningful impact on an individual: it answers questions about a password reset. The CV-screening system helps decide who gets invited for an interview, with direct consequences for someone's job prospects: exactly the kind of decision Annex III classifies as high-risk. Same underlying technology, completely different obligations.

A practical starting checklist

// Know where you stand

Curious where your AI systems sit on the risk ladder?

We go through your AI systems, classify them under the AI Act, and show you concretely what still needs to happen.

Book a call
// Read also