
EU Plans to Push Key High-Risk AI Rules Into 2027 After Pressure From Big Tech
The European Union has delayed the application of its most demanding high-risk AI rules until December 2027, giving companies an extra 16 months to prepare. The change forms part of the Digital Omnibus on AI package, which entered into force in late July 2026 after months of negotiation and sustained industry pressure.
Originally scheduled for 2 August 2026, the obligations for standalone high-risk AI systems listed in Annex III of the AI Act—covering areas such as biometrics, employment, education, critical infrastructure, law enforcement, and border control—will now apply from 2 December 2027. Systems embedded in regulated products under Annex I, including medical devices and machinery, receive an even longer extension until 2 August 2028.
The delay was driven by a combination of practical and political factors. European standardisation bodies have been slower than expected in delivering the harmonised technical standards needed for conformity assessment. At the same time, major technology companies and several Member States, notably Germany, argued that the original timetable risked putting European industry at a competitive disadvantage. US officials also publicly criticised elements of the EU’s digital rulebook, linking regulatory approaches to broader trade discussions.
Supporters of the postponement describe it as a pragmatic adjustment that preserves the substance of the rules while allowing time for workable standards and guidance. Critics, including some MEPs and civil-society groups, see it as a significant dilution of the original ambition, arguing that lobbying by large technology firms successfully softened the timeline.
Importantly, the delay does not freeze the rest of the AI Act. Transparency obligations and enforcement powers for general-purpose AI models took effect in August 2026 as planned. New prohibitions on AI systems that generate non-consensual intimate imagery or child sexual abuse material will apply from December 2026. National AI regulatory sandboxes must still be operational by August 2027.
For companies, the practical message is mixed. The extra time reduces immediate compliance pressure on high-risk use cases, but it does not remove the need to inventory systems, assess risk classifications, or prepare technical documentation. Organisations that treat the delay as an opportunity to pause work may find themselves underprepared when the new deadlines arrive.
The episode also illustrates the tension at the heart of European AI policy: the desire to set global standards for trustworthy AI while remaining competitive with the United States and China. Whether the revised timetable ultimately strengthens or weakens that ambition will depend on how rigorously the rules are enforced once they do take effect.
