Compliance & Risk

The EU AI Act Deadline Moved to December 2027. The Work It Required Did Not Get Easier

High-risk obligations for AI used in hiring and workforce management slipped from August 2026 to December 2027. Enterprises that had not started now have sixteen more months to solve a classification problem that 40% of systems still fail.

September 4, 2026 · Compliance & Risk
A laptop open beside a stack of books and a pot of pencils in front of a bookshelf

Key Takeaways

  • Following the Digital Omnibus, high-risk AI obligations for employment uses moved from 2 August 2026 to 2 December 2027, covering hiring, performance evaluation, workforce monitoring and termination decisions.
  • Obligations for AI systems treated as regulated products or safety components were extended further, to 2 August 2028.
  • AI-generated content watermarking and a new prohibition covering child abuse material and non-consensual intimate imagery both land on 2 December 2026.
  • An appliedAI analysis of 106 enterprise AI systems, cited by the Cloud Security Alliance, found 40% could not be clearly classified under the Act's risk tiers.

Compliance deadlines rarely move, which is why the ones that do reset behaviour so thoroughly. High-risk obligations under the EU AI Act for systems used in employment were due on 2 August 2026. Following the Digital Omnibus, they now fall on 2 December 2027, covering AI used in hiring, performance evaluation, workforce monitoring and termination. Obligations for AI systems treated as regulated products or safety components moved further still, to 2 August 2028.

Two things did not move. Watermarking of AI-generated content is due on 2 December 2026, as is a new prohibition covering child abuse material and non-consensual intimate imagery. So the year ahead still contains real obligations; what receded is specifically the largest and most expensive one, and it receded for the organisations least likely to have started.

Sixteen Months Is Not a Reprieve If the Blocker Is Classification

The reason the extra time may not help is visible in the readiness data. An appliedAI analysis of 106 enterprise AI systems, cited in a Cloud Security Alliance research note, found that 40% could not be clearly classified under the Act's risk tiers. Not "were found to be high risk" and not "failed the requirements": could not be categorised at all. Every downstream obligation, from conformity assessment to human oversight design to record keeping, depends on knowing which tier a system sits in.

That is a definitional problem rather than an engineering one, and definitional problems do not resolve by waiting. The Commission may issue guidance that narrows the ambiguity, and organisations that spend the deferral lobbying for it are making a rational bet. But the same CSA note observes that over half of organisations lack systematic AI inventories, and no amount of regulatory clarification tells a company which models it is running. A clearer rule applied to an unknown estate produces the same answer as an unclear one.

The sequence matters for anyone judging how firm the new date is. A provisional agreement was reached on 7 May 2026, the Omnibus followed, and the effect was to move the single most expensive tier of obligations by sixteen months while leaving the Act's architecture intact. A deadline that has already moved once invites the assumption that it will move again, and that assumption is the main risk to any programme planned around December 2027.

The Cost Estimates Are Why This Was Deferred

The CSA note puts initial conformity investment for large enterprises at $8 million to $15 million, with ongoing annual costs of $1 million to $5 million, and mid-size organisations at $2 million to $5 million initially. Those are estimates rather than observations, and they should be read as such, but they indicate the order of magnitude that made an August 2026 deadline politically unsustainable.

They also indicate why the deferral is not simply good news for buyers of AI. Most of that cost sits with providers, and providers who were building toward August 2026 have now had their compliance roadmap moved by sixteen months. Deployers relying on a vendor to supply conformity documentation should assume that documentation slipped by the same interval.

There is also a division of labour that the deferral does not change. Providers carry the conformity assessment, technical documentation and quality management obligations; deployers carry human oversight, monitoring, and the duty to use a system in line with its instructions. Most enterprises are deployers of purchased tools and providers of anything they built themselves or materially modified, which means a single organisation frequently sits on both sides for different systems. Working out which role applies to which system is part of the inventory, not a separate legal exercise.

What the Deferral Is Actually Useful For

The honest answer is inventory. An AI inventory is unglamorous, needs no legal interpretation, and is the prerequisite for everything the Act asks. It is also the piece that takes longest, because shadow adoption means the register cannot be assembled by asking department heads what they use. As this publication found in reporting on AI agent incidents, 82% of organisations discovered agents they did not know were running, while 68% believed they already had good visibility.

That gap is the compliance risk, not the regulation. An organisation that reaches December 2027 with a complete register of its AI systems, their purposes, their data and their vendors will find conformity work tractable. One that reaches it with a clearer rulebook and no register will be exactly where it was in August 2026.

The Act's hardest requirement was never the paperwork. It was asking organisations to state, in writing, which AI systems they operate, and that question has been the same since 2024 and remains unanswered by most.

Share

More in Compliance & Risk

All Resources →