EU AI Act 2026: The high-risk promise is shaky

EU AI Act 2026: The high-risk promise is shaky



Three months before the deadline, the EU Commission is blinking. The high-risk AI rules of the AI ​​Act, marketed as a promise of protection for years, will be postponed by up to 16 months via the Digital Omnibus Package. The official reason sounds technical. The political effect is different: an arbitrage gap of historic dimensions is opening up — and companies have already noticed what that means.

Anyone who reads this as a pragmatic compromise has not understood the mechanics of regulatory protection. The postponement is not a concession to the industry. It is a structural failure that is now written into the text of the law.

What happened

On August 2, 2026, the full requirements of the EU AI Act for high-risk Annex III AI systems should come into force. This includes standalone AI applications in eight explicitly defined areas: employment and personnel decisions, access to education, law enforcement, credit assessment, biometric identification, critical infrastructure, administration of justice, and migration and border protection.

The list of obligations was extensive and expensive: conformity assessments, technical documentation, CE marking, registration in the EU database, ongoing risk management system (Article 9), transparency obligations (Article 13), human supervision (Article 14) and accuracy requirements (Article 15). For a medium-sized company that develops a single high-risk AI system, the EU Commission puts the initial compliance costs at up to 600,000 euros. Fines for non-compliance: up to 35 million euros or 7 percent of global annual turnover.

Now, as part of the Digital Omnibus Package, the Commission is proposing to postpone the deadline for Annex III systems to December 2, 2027 — 16 months later. For Annex I systems, i.e. AI that is embedded in regulated products such as medical devices or machines, the deadline should move from August 2027 to August 2028. The reason: Harmonized standards from the standardization body CEN-CENELEC will not be available until the end of 2026 at the earliest, and many EU member states have not yet set up operational supervisory authorities.

A detail that is often missed in the reporting: If the trilogue negotiations between the Commission, Parliament and Council are not completed before August 2, 2026, the original deadlines apply – without delay. The postponement is not yet a done deal.

What the world says about it

As expected, the reactions fall along lines of interest. Industry associations and management consultants welcome the postponement as a “pragmatic adjustment to reality” — a formulation that raises the question of which reality was ignored when the original deadline was set. Compliance service providers, on the other hand, warn against interpreting the time gained as a license: the technical requirements do not change, only the timing of their implementation.

The real criticism comes from AI ethics organizations and some member states. They identify the structural problem: High-risk systems that are brought onto the market before December 2027 could remain permanently outside the regulatory framework – as long as the provider does not fundamentally change the system after the deadline. This is not a theoretical aside. There is a built-in incentive to deploy AI systems in high-risk areas as quickly as possible before the deadline in order to then operate in the gray zone – provided that the final omnibus formulation does not contain any different transitional regulations for systems that have already been deployed.

In current analyzes (April 30, 2026), legal firms such as DLA Piper explicitly point out the conditional nature of the postponement: Anyone who now implements their compliance roadmap to December 2027 runs the risk that the original August deadline will take effect if the legislative process stalls.

In Germany, according to media reports from February 2026, the Federal Cabinet passed the AI ​​Measures and Innovation Act (KI-MIG), which is intended to regulate national market surveillance and sanction mechanisms. It would be the German implementing law for the AI ​​Act – and would now be in a strange state of limbo: a national implementation law for European requirements, the timing of which is open.

What we think about it

The real problem with the postponement is not the extra time. Companies that are serious about developing or deploying high-risk AI need predictable deadlines — and €600,000 in compliance costs for an SME is not an abstract number, but a real barrier to market entry. Anyone who ignores this is making regulatory policy for large corporations that can diversify away these costs.

The problem is the cause of the shift: the EU has been regulating high-risk AI since 2021, and the harmonized standards needed for an orderly conformity assessment do not yet exist. CEN-CENELEC missed the deadline. The supervisory authorities in the Member States are still being set up. This is not an unforeseeable event — this was foreseeable, and it was ignored because political promises were more important than operational reality.

Now this gap is being written into the regulatory architecture. For DACH companies with a connection to the EU market, this means the following: The postponement does not change the substantive requirements. Risk management systems, technical documentation and proof of compliance will not disappear, they will just come later. Anyone who stops working on compliance now will be in a worse position in 2027 than they are today. And anyone who deploys a high-risk system as quickly as possible before the new deadline in order to remain permanently outside the framework is acting legally – but with a calculation that only makes regulatory tightening more likely.

The internal link to EU AI Act 2026: Overview of high-risk AI obligations helps to understand the catalog of duties specifically. Anyone who wants to understand the technical security architecture behind it can find it here LLM Guardrails and AI Security the appropriate context.

A second effect that receives little attention: the shift does not affect all systems equally. Article 5 bans — social scoring, manipulative AI, certain biometric mass surveillance — have been in effect since February 2025 and remain unchanged. This creates a paradoxical situation: the most serious bans are in place, but the requirements for systems that operate in the gray zone between permitted and prohibited have been postponed. This is exactly where the regulatory competition of the next 18 months will take place.

The verdict

The extension of the deadline through the Digital Omnibus Package is not a concession. It is the admission that the EU made a regulatory promise without creating the technical and institutional infrastructure for it. The result is a gap that will be strategically exploited — and that will be far more difficult to close retrospectively than setting a clean deadline from the start.

For compliance teams and IT project managers in DACH companies, the sober conclusion is: the postponement does not change the direction, only the speed. Anyone who takes a break now will lose time in 2027 that cannot be regained. Anyone who underestimates the risk of a trilogue agreement not being concluded on time could find themselves unprepared for the original deadline in August 2026.

The real measure of the AI ​​Act has never been whether it takes effect on time. It was whether it actually makes systems that affect people in high-risk areas safer. This question is not answered by the postponement – it has only been postponed for 16 months.

🎼
The doctor’s opinion

For years, the EU has marketed August 2026 as a promise of protection – and is giving in three months earlier because the technical infrastructure that it should have ensured itself is missing. This is not a pragmatic adjustment. This is a mistake that turns into an arbitrage incentive. Anyone who deploys high-risk AI before December 2027 and keeps it quiet afterwards may be operating permanently outside the framework – legally, calculatedly, and with full knowledge of the gap.

📚 Sources

The AI ​​verdict appears every Friday – exclusively for members.

Become a member now and never miss a review again.




Leave a Reply

Your email address will not be published. Required fields are marked *