Pillaraxis Cyber law, privacy & security — read plainly
Vol. 2 · 2026
Kochi, India
Brief No. 019
Law & Policy

The EU AI Act's High-Risk Deadline, and the Fight to Delay It

August 2026 was supposed to be the date the AI Act's toughest obligations landed. A year of negotiation over the Digital Omnibus has left that date in genuine doubt.

Regulatory deadlines are usually treated as fixed points that compliance teams build backward from. The EU AI Act's high-risk system obligations have spent much of 2026 as something closer to a moving target, and the reason is a single piece of draft legislation: the Digital Omnibus on AI, published by the European Commission on 19 November 2025.

As originally written, the AI Act required systems classified as high-risk under Annex III — including tools used in recruitment, credit scoring, and biometric categorisation — to comply from 2 August 2026. The Digital Omnibus proposed pushing that back to 2 December 2027, a deferral of sixteen months, on the argument that the technical standards and support tools organisations need to actually comply were not going to be ready in time. A second political trilogue between Parliament, the Council, and the Commission on 28 April 2026 ended without agreement. The Omnibus eventually entered into force on 27 July 2026, days before the original deadline — but the high-risk deferral specifically remained genuinely contested through much of that process.

The safer advice throughout 2026 was consistent: plan around a deferral that has not been enacted, and you have created your own compliance risk.

For any organisation with an August 2026 compliance programme underway, this created a real strategic bind: build to the original deadline and risk having invested heavily in a timeline that gets extended anyway, or wait for clarity and risk having no time left if the extension fails to materialise. The safer institutional advice throughout 2026 was consistent — treat the original date as operative until an extension is actually law, because planning around a deferral that has not been enacted is itself a compliance risk.

Separately from the high-risk timeline fight, the Act's other phases have landed as scheduled: prohibited practices took effect in February 2025, and general-purpose AI model governance obligations applied from August 2025, with the Commission and AI Board approving the GPAI Code of Practice that July. The lesson from watching this play out in real time is less about AI regulation specifically and more general: a phased compliance deadline in an actively contested piece of legislation is a moving estimate, not a fixed date, right up until the point it actually passes.

← OlderScattered Spider, DragonForce, and the Rise of Ransomware-as-a-Service