EU AI Act
December 2027: what the delay changes, and what it does not
Zenatia Insights · July 2026 · 4 min
What moved
The Digital Omnibus package moved the entry into force of the AI Act high-risk obligations to December 2027. Sixteen months more than the original calendar. Many organizations read the news as a reprieve. That is a misreading. The delay moves a deadline. It does not suspend the law.
What already applies
Three blocks are in force today, without waiting for 2027. Prohibited practices: social scoring, manipulation that exploits vulnerability, certain biometric uses. AI literacy: the teams that deploy or use AI systems must be trained on their risks, and you must be able to demonstrate it. Transparency: a user has to know when they are talking to a machine, and generated content has to be identifiable as such. None of these three blocks was delayed.
Who stays exposed
First, whoever is selling. Large European buyers are not waiting for the regulatory deadline: they are writing their AI requirements into contracts now, questionnaires and audit rights included. A vendor who answers “we will look at it in 2027” drops out of the shortlist. Second, whoever is building today the systems that will be high risk tomorrow: a system designed without documentation, without traceability, without risk management will cost far more to bring into line than a system born clean.
What to do this week
One thing, and it takes a few days: the inventory. Which AI systems are running inside your organization, including the ones nobody declared. What risk classification each one carries. What gap sits between what they are and what they will have to prove. Sixteen months is comfortable for whoever starts now. It is short for whoever starts in 2027.
And for you?
One hour of conversation is enough to place your case. It commits you to nothing, beyond knowing where you stand.
Start the conversation