The EU AI Act Delay Is Not the Reprieve Your Board Thinks It Is

The Deadline Moved. The Liability Did Not. Quote From Thomas Anglero, Strategic Ai Advisor.
Thomas Anglero on why the EU AI Act delay is not a reprieve for boards.

 

The EU has pushed its high-risk AI deadline from August 2026 to December 2027, and most boards have read that as breathing room and handed the file back to legal. That is the wrong read. The deadline moved. The liability did not, and the systems that got the delay are the ones deciding who your company hires and lets go.

What actually changed, and what did not

Under the Digital Omnibus, agreed in May and given the Council’s final green light at the end of June 2026, the high-risk obligations for standalone systems under Annex III move from 2 August 2026 to 2 December 2027, and for AI embedded in regulated products to 2 August 2028. Three things did not move. The Article 50 transparency obligations still apply from 2 August 2026. The fine ceilings are unchanged, at up to 35 million euros or 7 per cent of global turnover for the worst breaches and up to 15 million euros or 3 per cent for most other violations. And the whole architecture, the risk classification and the list of prohibited practices, stays exactly as written. This is a deferral, not a dismantling, and a board that treats it as a reprieve has confused a later deadline with a smaller problem.

The delay landed on precisely the systems a board should worry about

Here is the part that should stop a board. The high-risk category that moved covers AI used in employment decisions: recruitment, candidate selection, performance evaluation, task allocation, monitoring, promotion and termination. That is not niche. Most companies already run some of it. Many HR teams now rely on software that uses AI to filter and rank CVs, and several recruiters will tell you they rarely look at a candidate who did not clear the machine first. That is the exact activity these rules govern, and the reason they exist is that the filtering carries bias a company may not even know it has built in. Handing that to legal as a paperwork exercise misses what it is: a governance question about how your company treats people, sitting on a deadline with a fine attached. It is the sort of thing a board should be asking about directly, which is the argument in Why Boards Are the Furthest Behind on AI.

Even opting out is now visible

One detail almost nobody has clocked. If your company decides its HR or credit tool is not high-risk, that decision no longer sits in an internal memo. Under the retained registration rule, a self-assessment that a system is exempt has to be filed in a public EU database. Regulators, journalists and competitors get a searchable list of every borderline call a company has made. The quiet exemption is now a public statement.

Why the runway is the opposite of a reason to wait

The hard part of AI Act compliance was never the documentation template. It is finding every AI system in the organisation, deciding which category each falls into, and keeping that inventory current as new tools ship. None of that gets easier with time. Start now and there is room to do it properly. Start in late 2027 and there are weeks, not months. Meanwhile other law bites regardless: GDPR, product liability and sectoral rules all apply today. This is exactly the runway I argued you should spend, not bank, in AI Budgets Are Being Cut. This Is the Moment to Move, and exactly the moment not to lean on the partners who sell hours, which I set out in Your Traditional Partners Are Failing You in the Age of AI.

A board that hands this to the lawyers and moves on has misread the whole situation. Use the time. Inventory the systems, own the classification, and treat it as governance, because that is what it is, and the exposure sits with the leadership, as I described in Why a CEO Will Be Fired Over a Failed AI Implementation.

If you are leading your organisation through this, I work with a limited number of senior leaders each quarter. Get in touch at Anglero.com.


Thomas Anglero is a Strategic AI Advisor, keynote speaker and author of Intro to Artificial Intelligence. He has delivered over 450 keynotes across 30 countries for organisations including IBM, the WHO, the World Government Summit and the European Commission. He founded the IBM Watson AI Lab for Cancer at the Oslo Cancer Cluster and closed over $500 million in enterprise transformation deals as CTO and Chief Innovation Officer at Cognizant.

Frequently asked questions

Did the EU AI Act get cancelled or weakened?

No. The Digital Omnibus deferred the high-risk deadlines, standalone systems to 2 December 2027 and embedded systems to 2 August 2028, but left the architecture, the prohibited practices, the transparency obligations from August 2026 and the fine ceilings unchanged. It is a delay, not a dismantling.

What are the EU AI Act fines?

Up to 35 million euros or 7 per cent of global turnover, whichever is higher, for the most serious breaches, and up to 15 million euros or 3 per cent for most other violations. The Omnibus did not change these.

Why should a board not treat this as a compliance checkbox?

Because the delayed high-risk rules cover AI used in hiring, promotion and termination decisions. That is a governance question about how the company treats people, not a paperwork task, and delegating it to legal misses what it actually governs.

What should a board do with the extra time?

Inventory every AI system, decide which high-risk category each falls into, and keep that list current. That work does not get easier with time, and other law such as GDPR still applies now.

Thomas Anglero
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.