18 June 2026 · EU AI Act · 5 min read

The EU just delayed the AI Act's hardest rules. Don't slow down.

On 16 June 2026 the European Parliament adopted the Digital Omnibus on AI by 423 votes to 57. It moves the obligations for high-risk AI systems from August 2026 to 2 December 2027. If you read that as permission to slow down, you have read it wrong.

What actually changed

High-risk obligations for stand-alone Annex III systems now apply from 2 December 2027, and for AI built into regulated products from 2 August 2028. The duty to watermark AI-generated content moves to 2 December 2026. In the same vote, the EU tightened the rules in one direction: it banned so-called nudifier apps and AI-generated child sexual abuse material outright, and those prohibitions are not on the slow track.

A delay is not a reprieve from risk

Brussels did not decide that high-risk AI is less risky. It decided that the standards, the notified bodies and the AI Office capacity needed to enforce the rules were not ready in time. That is an enforcement gap, not a reduction in risk. The EU AI Act defines trustworthy AI as the combination of three things: lawful, technically robust, and ethically sound. Only the first has a moving date.

What does not move

The classification work does not move. You still need an inventory of every AI system you build or buy, and a risk level against each one. The control framework does not move either: risk management, data governance, technical documentation, record-keeping, transparency, human oversight and robustness map almost one to one onto controls a well-run business already applies elsewhere. And the evidence does not move. Principles you cannot demonstrate are not governance; a model card, a monitoring log and a completed conformity assessment are the assets a regulator, a customer or your board will accept.

What to do with the eighteen months

Ask three questions at your next board meeting. Which of our AI systems are high-risk, and who decided? Which of the controls are missing today? And who owns the evidence trail when someone asks to see it? Then run one real conformity assessment, end to end, on a single high-risk system rather than a policy document covering all of them. Do it once, properly, and you have a template you can reuse.

The deadline moved. The risk did not. The eighteen months are a gift to the organisations that were already going to do the work, and a trap for the ones looking for a reason not to.

Not sure which of your systems are high-risk?

A fixed-price Triage returns a Risk and Confidence Score in days, so you know exactly where you stand.

Book a free scoping call