Our engineers set up and run your first chatbot / LLM security scan. Get in touch

The High-Risk Deferral Is Law. The August Date Landed Anyway.

The Digital Omnibus on AI entered into force on 27 July 2026, moving the EU AI Act high-risk deadline to December 2027. What most summaries miss is that 2 August 2026 still arrived for everything the deferral did not touch, and that a longer runway does not extend the record you have to show at the end of it.

eu-ai-actcompliancehigh-riskaudit-evidence

In June we wrote that the high-risk deadline looked set to move, and ended on an open question: the change was politically agreed but not yet law, so plan against the new dates and keep the old one in view.

That question closed last week. The Digital Omnibus on AI was published in the Official Journal on 24 July 2026 and entered into force on 27 July. The high-risk deadline is now December 2027, as a matter of law rather than expectation.

Then, six days later, 2 August 2026 arrived and took effect for everything the Omnibus did not move.

That second sentence is the one worth your morning. The coverage has been about sixteen extra months. The part that reaches an engineering team is narrower and more awkward: the conformity clock moved, the transparency clock did not, and neither of them extends the record an assessor reads at the end.

What moved, precisely

  • Stand-alone high-risk systems in Annex III: from 2 August 2026 to

2 December 2027. Annex III covers areas such as recruitment and worker management, education, credit scoring, insurance pricing and access to essential services. Check the annex against your own systems rather than against that shortlist.

  • High-risk systems embedded in regulated products under Annex I: to

2 August 2028.

  • National regulatory sandboxes: member states now have until

2 August 2027 to establish at least one.

What did not move

Article 50 transparency continues to apply from 2 August 2026. The deferral is scoped to the high-risk chapters and the sandbox deadline. It is not a general postponement of the Act, and reading it as one is the mistake that will cost somebody a quarter.

There is one near-term date inside that which is easy to lose. Labelling of synthetic content carries a grace period for systems already on the market before 2 August 2026: those have until 2 December 2026. Anything placed on the market after 2 August 2026 owes it on arrival. That is four months away, not sixteen, and it applies to a much wider set of systems than the high-risk list does.

So the honest summary for a planning meeting is two lines, not one:

Product conformity work has until December 2027. Disclosure and labelling work is live now, with one grace window closing in December.

The trap in a deferral

Here is the part that does not show up in a timeline graphic.

The obligations did not change. The same risk management process, the same logging for the life of the system, the same human oversight on consequential actions, the same accuracy and robustness and cybersecurity that have to hold up under adversarial pressure, the same quality management system around all of it. The bar is where it was. The regulator moved the date, not the bar.

And most of what satisfies that bar is not a document. It is a record.

An assessor reading Article 12 in December 2027 is not asking whether you have logging. They are asking to see the logs. An assessor reading Article 15 is not asking whether you tested for robustness. They are asking what you tested, when, against what, and what you did about the results. Those questions have an answer only if something was running the whole time.

This is why a deferral is less generous than it looks. A team that stands down now and restarts in mid-2027 does not arrive with sixteen extra months of preparation. It arrives with a sixteen-month hole in the middle of its record, during a period when it was shipping model changes, and it cannot fill that hole honestly. You cannot go back and test a version you already replaced.

The teams that come out of this well will treat December 2027 as the date the record is read, not the date the record starts.

What that means for the next sixteen months

Nothing exotic. Four things, in the order they pay off.

Get the inventory to the point where it is boring. Every model, every retrieval corpus, every tool an agent can call, every endpoint, and for each one: who declared it, when, and who confirmed it. Half of what an assessor wants under technical documentation is a truthful list with provenance on it. Most organisations discover in the first week that they cannot produce that list, which is exactly why it is the first task and not the fourth.

Make testing a schedule, not an event. A robustness claim backed by one exercise is a claim about one afternoon. A robustness claim backed by a recurring suite is a claim about a system. The difference is invisible in a slide and decisive in an audit. Run it against production configurations, and record the runs that found nothing as carefully as the ones that found something, because a clean result you cannot produce is the same as a test you never ran.

Record what you did not cover. Coverage gaps are not a failing to hide; they are a normal property of any test programme and an assessor knows it. A report that says which checks ran, which timed out, and which were skipped is more credible than one that quietly reports only what succeeded. The second kind invites the question you least want asked.

Wire the disclosure work now, because that part is already due. Interaction disclosure and synthetic content labelling do not wait for 2027, and the December grace window is short enough that it should be on this quarter's plan rather than next year's.

Where we sit

We built Penaxtra around the assumption that the evidence is the hard part. Adversarial test suites run on a schedule against live endpoints, findings map to control identifiers across the frameworks that ask for them, coverage gaps are recorded rather than rounded away, and the whole thing leaves an audit trail with the asset inventory attached. That was the right shape when the deadline was August 2026, and the deferral does not change it, because none of it is about the date. It is about having something to show when the date arrives.

If the last week landed on your desk as sixteen months of breathing room, the useful correction is that you got sixteen months of runway. Runway is only worth something to an aircraft that is moving.

On sources and scope. Dates and obligations above are drawn from the Digital Omnibus on AI as published in the Official Journal on 24 July 2026 and from the European Commission's own summary of it. This is an engineering reading written for planning purposes, not legal advice. How the Act applies to a particular system depends on facts we cannot see from here, so take the classification question, and anything turning on it, to your own counsel.

Sources: European Commission, AI Omnibus enters into force - Navigating the AI Act (European Commission FAQ)

Related: The EU AI Act High-Risk Deadline Is Moving to 2027. The Work Did Not.


Continue in the wiki

All articles Request architecture review