Brussels delays high-risk AI rules, not the rulebook itself

AI

Brussels has bought companies more time on its toughest AI rules, but firms hoping for a reprieve from compliance work are likely to be disappointed.

According to AscentAI, the EU’s Digital Omnibus on AI has pushed the high-risk deadline from August 2026 to December 2027, while AI embedded in regulated products under Annex I, covering items such as medical devices, machinery and vehicles, now has until August 2028 to comply.

The postponement, however, does not touch the AI Act’s core obligations. Firms still need to inventory their AI systems, classify use cases, identify which rules apply, assign ownership and track guidance as it evolves.

AscentAI recently discussed how the EU AI is not delayed, and instead, just one provision is.

The Act’s reach extends well beyond the EU’s borders. Any business shipping an AI feature to EU end users becomes a provider placing a system on the EU market. An EU subsidiary using a US-built internal tool counts as a deployer located in the Union. Even firms with no EU sales can be caught if their AI’s output is consumed there.

High-risk status applies to systems used as safety components of regulated products, or those themselves classed as products requiring third-party conformity assessment. It also captures systems falling under Annex III’s eight sensitive areas, including biometrics, critical infrastructure, employment, law enforcement and access to essential services, though narrow procedural tasks and certain human-reviewed activities are exempted.

Two deadlines are drawing closer regardless of the wider delay. From December 2026, new Article 5 prohibitions kick in banning AI systems that generate non-consensual intimate imagery or CSAM. The prohibition is broad, catching any system where such generation is a “reasonably foreseeable and reproducible outcome” without significant technical modification, where adequate safeguards are absent, meaning providers of general-purpose image and video tools must assess misuse risk at the design stage. [Note: this quoted passage is sourced from footnote citation [1] in the original text; no company or named spokesperson attribution was provided, so it could not be formatted per the standard quote style.]

The same December date brings machine-readable watermarking requirements under Article 50(2), though other Article 50 transparency obligations, covering chatbot disclosure, emotion recognition notices and deepfake labelling on public interest matters, already took effect in August 2026.

For RegTech providers and compliance teams, the message is that a later deadline is not a lighter workload. Tracking legislative change across multiple jurisdictions and connecting it to specific obligations, entities and use cases remains a live operational challenge, one that will only grow as more AI Act provisions come into force through 2030.

Read the full AscentAI post here. 

Stay ahead of the regulatory curve. Subscribe to FinTech Global’s newsletter for the strategic intelligence and early insight decision-makers need to navigate AI regulation before it reshapes the market.

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoying the stories?

Subscribe to our daily FinTech newsletter and get the latest industry news & research

Investors

The following investor(s) were tagged in this article.