In July, six days before Europe’s toughest AI rules were due to take effect, the EU pushed them back sixteen months. The delay is real and what it postponed is substantial — but the obligations that moved are precisely the ones whose cost is set at build time. Data provenance, audit logging, where human review sits, and knowing what systems you run cannot be added to a working system later at any sensible price.
The reason for the delay was mundane. The technical standards companies were supposed to comply with had not been finished, and most member states had not appointed the regulators meant to enforce them. Brussels moved the date rather than enforce a rule nobody could yet follow.
Most coverage read this as breathing room. That reading is understandable and expensive. A company that treats the delay as permission to wait will spend next year retrofitting under deadline pressure. A company that absorbed the requirements into its design decisions this year will spend next year producing documents it already has.
What did the EU actually postpone?
Some of the heaviest requirements in the Act, and it is worth being precise about which, because it was narrower than the headlines suggested.
The postponed obligations cover high-risk systems: a working risk management system, data governance, record-keeping, human oversight, accuracy and security standards, a conformity assessment, and registration in an EU database. That is a genuine reprieve, and it now runs to the end of 2027.
Everything governing what you may actually do with AI stayed where it was. A short list of outright banned uses has been in force since early 2025. Rules for the companies that build large models have applied since the middle of that year. And as of this August, transparency rules apply: in most cases, if a customer is dealing with an AI system, you have to say so, and AI-generated or manipulated content has to be marked as such. The precise duty varies depending on whether you built the system or are simply running it, but this one is live today and it reaches ordinary businesses, not just AI vendors.
The delay applies to high-risk system requirements only. Prohibited uses, general-purpose model rules, AI transparency duties and the GDPR all remain in force right now.
Does data protection law give you the same reprieve?
No, and for most companies it was always the tighter constraint. European regulators have made clear that a model trained on personal data is not automatically anonymous just because data went in and predictions came out, and their draft guidance on web scraping takes the same line: publicly visible does not mean exempt. Much of what that guidance expects is evidence you can produce — why the data was collected, what legal basis you relied on, how that judgment was reached, and where the data came from.
It is worth noting how unsettled the enforcement side remains. One of Europe’s highest-profile actions against a generative AI provider, Italy’s case against OpenAI, was annulled by a Rome court in March on a jurisdictional point, leaving the substantive questions untouched. The case law is genuinely open. The documentation expectation is not, and it is the half you control.
The American picture is unsettled in a different way but points the same direction. Colorado passed the first comprehensive state AI law, delayed it twice, then repealed and replaced it with something narrower. California’s rules on automated decision-making take effect in stages through 2028. A federal executive order directs litigation against state AI laws, but no federal statute has passed and executive orders do not override state law by themselves.
The dates keep moving. The direction has not changed in three years. Every regime that has survived contact with a legislature converges on the same four questions: what AI systems are you running, what data do they touch, who is accountable for the outputs, and can you show your work.
Which decisions can’t be added later?
Four, and they all get made in the first week of building an AI workflow, usually without anyone noticing a decision is being made. This is where compliance stops being a legal exercise and becomes an engineering one.
Data provenance. If you fine-tune a model or build a search system across a body of internal documents and do not record where each source came from and on what basis you held it, that lineage is gone. It cannot be reconstructed. When a customer exercises a deletion right, or an enterprise buyer asks what your system learned from, the honest answer is that nobody knows. The remedy at that point is retraining, which is a budget line rather than a fix.
The audit trail. Logging what went in, what came out, which version of the model produced it, and who reviewed it is a few days of work while a system is being built. Added afterward it means instrumenting something already in production, and even then you only get history going forward. A log started this quarter carries more than a year of evidence by the time the deferred obligations arrive. A log started in 2027 carries none, and there is no way to manufacture it.
Where the human sits. Both the California and Colorado frameworks turn on whether automation has replaced human judgment on decisions that matter to people: hiring, credit, housing, healthcare. Where a person can genuinely interpret, question and override the output, the obligations are lighter. That is a design decision about where the approval step goes and whether the reviewer has enough context to actually disagree. Made at the start, it is a manageable design constraint. Made after the reviewer has been automated out of the process, it means rebuilding the workflow and renegotiating the return you promised the board. This is the same boundary that decides when an experiment has quietly become production software.
Knowing what you have. A list of the AI systems in use, what data each touches, and which sit near consequential decisions. It sounds trivial. It is also the step organisations routinely skip, even though nearly every framework assumes some version of it already exists.
| Decision | Cost if built in | Cost if retrofitted |
|---|---|---|
| Data provenance | A field in the ingestion pipeline | Retraining, or an unanswerable question |
| Audit trail | A few days of logging work | Instrumenting production, with no back history |
| Human oversight | Where the approval step goes | Rebuilding the workflow and its business case |
| System inventory | A spreadsheet, maintained | A discovery exercise across every team |
Why does this matter before any regulator shows up?
Because the commercial deadline arrives first, and it has already arrived.
Enterprise security questionnaires now routinely include a section on AI governance. Buyers are asking suppliers to describe what AI they run, how training and inference data are handled, what human oversight exists, and what happens when something goes wrong. ISO/IEC 42001 certification, the international standard for AI management systems, is appearing more often in those conversations, particularly in regulated industries and European markets.
The consequence of a blank answer is not a fine. It is a stalled deal, a longer sales cycle, and a competitor whose documentation was ready. For a mid-market company selling into larger enterprises, that arithmetic bites well before any regulatory deadline does.
When is this the wrong thing to worry about?
Often, and it is worth saying so plainly. If you are using an off-the-shelf assistant for drafting, summarising or research, and it touches no personal data and makes no decision about anyone, none of this applies to you. Building a governance programme around that is theatre, and it is the most common way companies waste money on AI compliance.
The four decisions above matter when a system is doing one of two things: learning from data about people, or influencing a decision that affects someone’s employment, credit, housing, healthcare or access to a service. Everything else is ordinary software, and it should be governed like ordinary software.
The same logic applies to timing. There is no advantage in building audit infrastructure for a prototype you may abandon in a month. The question is where the line sits between an experiment and production, and the answer is usually the moment the output stops being reviewed by the person who built it.
What should a leader do about this now?
Ask a narrower question than the one most boards are asking. The useful reframe is not “are we compliant.” Compliance against a regime that keeps being amended is a moving target, and chasing it produces anxiety rather than progress.
Which of our AI workflows touch decisions that matter to people, and can we currently show how those decisions got made?
Most organisations cannot answer that today. For most, it is a contained problem now, answerable from an inventory and a handful of design choices. It becomes a far larger one once the systems are entrenched, the provenance is gone, and someone external is the one asking.
The delay bought time. It is worth spending on the part that cannot be bought back.
Key regulatory dates
- 2 December 2027 — EU AI Act high-risk obligations for standalone systems, deferred from 2 August 2026 by Regulation (EU) 2026/1744, in force 27 July 2026. Embedded systems in regulated products follow on 2 August 2028.
- Already in force — EU prohibited practices (February 2025), general-purpose AI model obligations (August 2025), and Article 50 transparency and content-labelling duties (August 2026).
- 2 December 2026 — labelling requirements extend to systems already on the market, and a new prohibition on AI-generated non-consensual intimate imagery takes effect.
- 1 January 2027 — California’s automated decision-making obligations under the CCPA regulations, and Colorado’s replacement AI framework (SB 26-189). California risk assessment submissions follow in April 2028.
- Ongoing — GDPR, including EDPB Opinion 28/2024 on AI models. Draft Guidelines 02/2026 on anonymisation and 03/2026 on web scraping were adopted in July 2026 and are open for public consultation until 30 October 2026; final versions are not expected before year end.
This article describes the general regulatory landscape and is not legal advice. Obligations depend on your circumstances; consult qualified counsel. Positions stated are accurate as of 9 September 2026.
Where this lands in practice is a question about your own systems rather than about the law. Our engineering and integration work starts from the same four questions.