Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
EU AI Act Delays Won't Save You Latergeneral
5 min readFor Compliance Officers

EU AI Act Delays Won't Save You Later

The decision to delay the EU AI Act's high-risk system obligations has brought relief to many compliance teams. However, this relief may be masking several misconceptions about what these delays mean for your risk management and resource planning.

These misconceptions arise because organizations equate "more time" with "less urgency." The reality is more complex. The delays offer specific opportunities for strategic action but also introduce new compliance challenges that weren't present under the original timeline. If you're viewing this as merely a calendar adjustment, you're missing the point.

Myth 1: You Can Postpone AI Risk Assessments Until 2027

The Reality: Your third-party risk register just became a ticking clock.

The provisional agreement sets deadlines of 2 December 2027 for stand-alone high-risk AI systems and 2 August 2028 for embedded systems. But waiting until those dates to assess risk ignores a critical exposure: your vendors and service providers are making AI deployment decisions now.

Consider a team using an HR management platform that introduces AI-powered resume screening before 2027. Under the delayed timeline, that system falls into the Annex III high-risk category when the rules take effect. If your vendor hasn't documented their Article 6(3) exemption analysis or prepared conformity assessment documentation, you inherit that compliance gap when the deadline hits.

Your move: Map every vendor contract that could introduce AI functionality in the next 18 months. Flag any that touch Annex I or Annex III use cases. Require vendors to disclose AI deployment plans and their compliance readiness in writing. The delay gives you time to renegotiate terms, not to ignore the risk.

Myth 2: The Simplified Registration Procedure Means Less Work

The Reality: The reinstatement of registration for Article 6(3) exemptions creates a documentation burden you weren't planning for.

The AI Omnibus originally proposed removing the EU database registration requirement for systems relying on Article 6(3) exemptions. That proposal was dropped. Now, if you claim an exemption, you still register the system through a "simplified" procedure.

Here's the issue: simplified registration still requires you to document why you believe the exemption applies. You need a defensible risk assessment showing the system performs a narrow procedural task. You need evidence that failure or malfunction doesn't create material risk. And you need this documentation ready before you register, because regulators will ask for it during supervision.

The myth assumes "simplified" means "optional" or "light touch." It doesn't. It means you're filing a shorter form, but the substantive analysis behind that form is just as rigorous.

Your move: Draft your Article 6(3) exemption analysis now. Document the specific procedural task, the risk assessment methodology, and the evidence supporting your conclusion. Treat this as an audit artifact, not a checkbox exercise.

Myth 3: AI Literacy Obligations Are Now Someone Else's Problem

The Reality: The shift from "providers and deployers must ensure" to "Commission and Member States support and facilitate" doesn't eliminate your duty to train staff.

The provisional agreement changes the AI literacy obligation from a hard requirement on providers and deployers to a softer obligation where regulators "support and facilitate" literacy initiatives. Some compliance teams are reading this as a green light to deprioritize training.

That's a misreading. If you deploy a high-risk AI system and your staff can't explain how it makes decisions, how they monitor its outputs, or when they should escalate anomalies, you're creating operational risk that no regulator can fix for you. The EU AI Act's transparency obligations (Article 13) and human oversight requirements (Article 14) still apply. Your staff needs to understand the system's capabilities, limitations, and decision logic to meet those obligations.

Your move: Build AI literacy into your existing training programs now. Focus on three areas: how to interpret AI system outputs, how to identify bias or accuracy issues, and when human intervention is required. Don't wait for the Commission to publish guidance. You already know what your teams need to understand.

Myth 4: The Narrowed "Safety Component" Definition Reduces Your Scope

The Reality: The narrowing applies to products where AI "only assists users or optimizes performance." If failure creates health or safety risk, you're still in scope.

The provisional agreement clarifies that products with AI functions that only assist users or optimize performance won't automatically face high-risk obligations if their failure or malfunction doesn't create health or safety risks. This sounds like a broad carve-out. It's not.

The key phrase is "does not create health or safety risks." If your AI-enabled product's failure could lead to physical harm, misdiagnosis, financial loss affecting livelihood, or rights violations, you're still dealing with a high-risk classification. The narrowing eliminates edge cases (think: AI that suggests playlist recommendations in a medical device interface), but it doesn't touch core safety-critical functions.

Your move: Review every AI-enabled product in your portfolio. For each one, document what happens if the AI component fails completely. If the answer includes any safety consequence, assume high-risk classification and plan accordingly. Don't rely on the narrowed definition to exclude systems you haven't rigorously analyzed.

Myth 5: Watermarking Delays Give You Until December 2026 for All Systems

The Reality: The December 2026 delay only applies to systems already on the market before 2 August 2026.

The provisional agreement delays watermarking obligations for AI-generated content until 2 December 2026, but only for providers who placed their systems on the market before 2 August 2026. If you launch a new generative AI system after August 2026, watermarking obligations apply immediately under the original timeline.

This creates a two-tier compliance structure: legacy systems get a grace period, new systems don't. If you're planning a generative AI product launch for late 2026 or early 2027, you need watermarking capability from day one.

Your move: Inventory every generative AI system you operate. Tag each with its market placement date. For systems launched before August 2026, you have until December 2026 to implement watermarking. For anything launched after, assume immediate compliance. If you're building new systems now, watermarking should be in your technical requirements from the start.

What to Do Instead

Stop treating the delays as a pause button. Treat them as a window to build structural compliance capabilities you'll need regardless of the timeline.

First, establish an AI inventory process that captures system purpose, risk classification, and regulatory timeline. You can't comply with obligations you haven't mapped to specific systems.

Second, integrate AI risk assessment into your vendor management and procurement workflows. Every contract that could introduce AI functionality should trigger a compliance review before signature.

Third, document your Article 6(3) exemption analyses now, while you have time to iterate. Waiting until registration deadlines means rushing through risk assessments that regulators will scrutinize later.

Fourth, build AI literacy into your operational training programs. The regulatory obligation may have softened, but your operational need for trained staff hasn't.

The delays aren't a gift. They're a test of whether you can use additional time strategically or whether you'll squander it by treating "later" as "less important." Your regulator will know the difference when 2027 arrives.

EU AI Act official documentation

Topics:general
Promotional banner for the Pentest Readiness checklist download

You Might Also Like