Request a demo
Industry Insights

The EU AI Act Just Slipped to 2027 — Here's Why You Shouldn't Slow Down

Manuel Jenni

CPO of PEDCO

July 27, 2026
10 min read
The EU AI Act Just Slipped to 2027 — Here's Why You Shouldn't Slow Down

For two years, every AI governance roadmap in Europe pointed at the same date: 2 August 2026. That was when the EU AI Act's high-risk obligations — the provider requirements in Articles 9 to 17 and the deployer requirements in Article 26 — were due to bite. Risk management systems, data governance, technical documentation, logging, human oversight, accuracy and robustness, conformity assessment. The substantive core of the regulation.

That date has moved. Following political agreement in May 2026, the European Parliament's endorsement in June and the Council's final green light on 29 June 2026, the simplification package defers the high-risk obligations well into 2027. Depending on the category of system, organisations have gained somewhere between twelve and sixteen additional months.

The immediate reaction inside a lot of companies has been predictable: reallocate the budget, move the programme manager onto something with a nearer deadline, revisit it next year. We think that is the wrong read, and this post is the argument for why.

First, be precise about what actually moved

A deferral of part of a regulation is not a pause of the regulation. Three things are worth keeping straight.

What moved: the high-risk system obligations. This is the expensive, documentation-heavy tier — the one covering AI in employment, credit, biometrics, education, essential services, and AI embedded as a safety component in regulated products.

What did not move: the prohibitions on unacceptable-risk practices and the AI literacy obligation have applied since February 2025. The general-purpose AI model obligations have applied since August 2025. If your organisation deploys AI at all, you are already inside the scope of an in-force regulation — the AI literacy requirement in particular applies to providers and deployers regardless of risk tier, and it is the one most organisations have quietly ignored.

What did not change at all: the penalties. Up to €35 million or seven per cent of global turnover for prohibited practices; up to €15 million or three per cent for high-risk non-compliance. These exceed GDPR's ceilings, and the deferral did not touch them.

One practical caution: the final dates take effect on publication in the Official Journal, and the deferral is tiered rather than a single uniform shift. Before you rebuild a plan around a specific month, confirm the date that applies to your specific systems and role — provider or deployer — against the published text.

Four reasons the extra time is not free

1. Your customers' procurement teams did not get an extension

This is the reason that will reach you first, and it has nothing to do with regulators. AI governance questions are now standard in enterprise vendor questionnaires, and the organisations asking them are not waiting for an enforcement date to decide who they buy from. If you sell into regulated industries — automotive, medical devices, aerospace, financial services, public sector — the request for your AI governance documentation arrives on your customer's procurement cycle, not the Commission's.

We have watched this shift happen over the last eighteen months in our own sales conversations. The question moved from does your product use AI to show us your AI management system, your model inventory, your data governance and your human oversight design. A deferral in Brussels does not make that question go away. It makes it the only deadline that still has teeth.

2. ISO 42001 is now the near-term deadline

ISO/IEC 42001, the first certifiable AI management system standard, has been adopted across Europe as EN ISO/IEC 42001:2026, with national adoption due in September 2026. That is the deadline that did not move — and for most organisations it is the more consequential one, for a simple reason: implementing an AI management system to ISO 42001 covers a substantial share of what the AI Act's high-risk regime demands in the way of documentation, risk management and lifecycle governance.

This is the arbitrage the deferral creates. The compliance work you would have done under duress by August 2026 is largely the same work that earns you a certificate customers actually recognise. Doing it now, on your own schedule, converts a regulatory cost into a commercial asset. Doing it in late 2027, under deadline pressure, converts it back into a cost.

3. The work is inventory and evidence, and both take longer than anyone plans

Every organisation that has run an AI Act readiness assessment reports the same first finding: nobody knows how many AI systems they have. Not the CIO, not the CISO, not the quality function. Models arrive embedded in purchased software, in SaaS features that were switched on by a vendor update, in scripts written by an analyst, in a chatbot that a department procured on a corporate card.

Building an accurate inventory across a mid-sized organisation takes months, and it is the precondition for literally everything else — classification, risk assessment, data governance, human oversight design, logging, post-market monitoring. You cannot compress it at the end, because the constraint is not effort, it is the number of people you have to find and interview.

The same is true of the evidence trail. Article 12's logging requirements and the post-market monitoring expectations are retrospective by nature: the records that demonstrate compliance in 2028 are the ones your systems either did or did not generate starting now. There is no way to backfill them.

4. The sector regulations did not pause

If you build products, the AI Act was never your only clock. The Cyber Resilience Act's vulnerability and incident reporting obligations start on 11 September 2026, with a twenty-four hour early warning and seventy-two hour full notification for actively exploited vulnerabilities. In medical devices, the FDA's Quality Management System Regulation took effect in February 2026 and EUDAMED registration became mandatory in May 2026. ISO 9001:2026 publishes in September. IATF's revision work begins in October.

The overall regulatory load on a quality and compliance function in 2026 did not decrease. One item on a long list moved. Teams that treat the deferral as slack rather than as reallocation will find the slack was already spoken for.

What to do with the time you just gained

The honest answer is: the same work, at a saner pace, in a better order.

Build the inventory properly. Every AI system, including embedded and vendor-supplied ones. Owner, purpose, data inputs, decision impact, whether a human reviews the output, whether there is a log. Do it once, do it thoroughly, and put it under change control — an inventory that is not maintained is worth roughly nothing.

Classify by role and risk tier. Provider or deployer changes your obligations fundamentally, and most organisations are both, for different systems. Get this wrong and every downstream assessment is wrong.

Design human oversight before you need to document it. Article 14's oversight requirement is easy to satisfy on paper and hard to satisfy in reality. Oversight means a person who can understand the output, has the authority to override it and the time to actually look. If your process assumes a reviewer approves two hundred AI-generated items an hour, you do not have oversight; you have a rubber stamp with an audit trail.

Fix data governance now. It is the longest-lead item in the entire regime and the one with the most dependencies on systems you do not control.

Then go for ISO 42001. With the inventory, classification, oversight design and data governance in place, certification is a structuring and audit exercise rather than a discovery one.

The QMS advantage most organisations overlook

Here is the part that quality functions consistently undersell to their own leadership: if you already run a certified management system, you are not starting from zero. You are starting from most of the way there.

ISO 42001 follows the same harmonised structure as ISO 9001 and ISO 27001. Context of the organisation, leadership, planning, support, operation, performance evaluation, improvement. You already have management review. You already have internal audit. You already have corrective action, document control, competence management, nonconformity handling and a mechanism for tracking objectives. An AI management system is a delta on that machinery, not a parallel structure — and the organisations that treat it as a greenfield build are the ones that spend two years and a seven-figure budget rediscovering processes they already own.

The delta is real and specific: an AI system inventory, impact assessment covering individuals and society rather than only the organisation, data governance across the model lifecycle, human oversight design, and monitoring that continues after release. But the scaffolding — the audit rhythm, the evidence discipline, the escalation route — is the same scaffolding, and it is already load-bearing.

This is also where PEDCO AuditPro fits into an AI governance programme. The platform reads a management system as it exists and assesses it against a reference model, which means an existing ISO 9001 or ISO 27001 system can be assessed against ISO 42001's requirements to show exactly what already conforms, what conforms partially, and what genuinely has to be built — each finding traced back to the document that supports it. For most organisations the useful output is not a long list of gaps. It is the much shorter list that remains after you subtract everything your QMS already does.

The uncomfortable summary

Deadlines that move once can move again, and the temptation to bet on that is real. But the bet only pays off if the deadline is the only reason you are doing the work — and for AI governance in 2026, it is not. Customers are asking now. ISO 42001 lands in national adoption this September. The inventory takes months regardless of when it is due. The evidence trail has to start before you need it.

The deferral did not remove any work. It gave you the chance to do it deliberately instead of frantically. That is worth quite a lot, and it is worth exactly nothing if you spend it waiting.

Written by

Manuel Jenni

CPO of PEDCO

Ready to Transform Your Compliance?

See how PEDCO AuditPro's knowledge graph technology can help your organization.

Book a Demo
PEDCO

© 2026 PEDCO AG. All rights reserved.