Earlier this month the part of the EU AI Act that most people notice came into effect. From 2 August, a chatbot has to tell you it is a machine, and synthetic images and video have to be labelled as generated. Those are the transparency rules. They are useful, and they are also the easy part.

The hard part of the AI Act was always the high-risk rules. These govern the systems that make decisions about people: software that screens job applicants, scores someone for credit, sorts patients, runs biometric identification or sits inside critical infrastructure. For those systems the Act demands risk assessments, human oversight, documentation and quality controls. That is where the law has teeth, and that is the part that just slipped.

What actually changed

On 27 July a regulation known as the Digital Omnibus on AI entered into force. It does not repeal anything. It moves the dates.

The high-risk obligations for standalone systems, the ones listed in Annex III of the Act, were due to apply from 2 August 2026. They now apply from 2 December 2027. For AI built into regulated physical products, covered by Annex I, the deadline moves to 2 August 2028. So the clauses that decide whether a hiring model or a diagnostic tool is allowed on the European market have been pushed back by well over a year, in the same summer that the softer transparency clauses switched on.

The Commission is direct about why. Its own notice says the Omnibus “delivers a targeted simplification of the AI rulebook while preserving strong safeguards for people’s safety and fundamental rights,” and frames the change as easing compliance for smaller companies and buying everyone more time. You can read the Commission’s framing in full. The legal text is Regulation (EU) 2026/1744.

The honest reading

There are two ways to see this, and both are true at once.

The generous reading is that the standards were not ready. A high-risk obligation is only as real as the technical standard that tells a company how to meet it, and those harmonised standards were running late. Enforcing a deadline against rules nobody had finished writing would have produced compliance theatre, not safety. Extending the timeline and expanding the testing sandboxes is a reasonable response to that.

The blunter reading is that this is what happens to ambitious regulation when it meets industry pressure and a competitiveness panic. Europe spent years building the first comprehensive AI law in the world and made a great deal of noise about it. When the moment came to switch on the expensive obligations, it switched on the cheap ones instead and moved the expensive ones over the horizon.

Neither reading should be a surprise. This is how most technology regulation actually behaves. The announcement is loud, the principles are firm and the binding deadlines drift as the practical difficulty of enforcement becomes clear. The AI Act is not being abandoned. It is being paced, and the pacing tells you which clauses were ready and which were not.

The thing worth watching is not the December 2027 date on its own. It is whether, when that date arrives, the standards exist, the enforcement bodies are staffed and the deadline holds. A postponed rule is still a rule. A rule postponed twice is a suggestion.

Photograph: Sebastian Wallroth, CC BY 4.0.