The short version
- Europe pushed its biggest AI deadline back by more than a year. That part is true.
- The rules that were already live did not move. For most companies, those are the ones that apply.
- What got pushed back is the part you cannot add at the end. So the extra time is for building, not for waiting.
On 27 July 2026 a new EU law came into force. It moved the AI Act's heaviest deadline from August 2026 to December 2027.
Most of what you can read about this online is now wrong, in one of two ways. Older articles still say the deadline is August 2026. Newer ones say the pressure is off. Neither is right.
What moved, and what did not
| The rule | Before | Now |
|---|---|---|
| High-risk AI systems | Aug 2026 | Dec 2027 |
| AI built into regulated products | Aug 2027 | Aug 2028 |
| Banned uses of AI | Live since 2025 | Unchanged |
| Rules for the big AI model providers | Live since 2025 | Unchanged |
| Telling people they are talking to AI | Aug 2026 | Applies now |
| Training your staff to use AI | Live since 2025 | Unchanged |
Four of those six lines did not move at all.
Does the delayed one even apply to you?
The deadline that moved covers a specific list: hiring, credit scoring, biometrics, education, healthcare, critical infrastructure, policing. Serious stuff, and a short list.
If that is not what your company does, that deadline was never yours in the first place.
Three other rules are yours, and they are live today.
Some uses are simply banned. No phase-in, no small-company discount. The fines here are the big ones.
If it is a machine, say so. A chatbot that pretends to be a person, or AI-written content passed off as human, is a problem now, not in 2027.
Train the people using it. This is the one almost everyone skips, because it does not look like a rule. If your team uses AI on your behalf, they have to know how. That is training and ownership, not a policy document nobody reads.
The part nobody can postpone
Here is the bit that matters.
Look at what the delayed rules actually ask for: keep records of what the AI did. Have a person who can step in. Know where your data came from. Be able to show where an answer originated.
Now ask which of those you could add in the last month before a deadline.
You cannot add a record of the past. Either the system was writing things down while it worked, or that year is simply gone. You cannot add a person into a decision that has no place for one. You cannot trace an answer back to its source if nothing ever recorded the source.
Moving a deadline moves the day you have to show your work. It does not move the day you have to start doing it.
Companies that treat this as free time will spend 2027 rebuilding what they built in 2026. Companies that build it in now will spend 2027 filling in forms.
Every rule is really a piece of plumbing
| What the rule asks | What you actually need |
|---|---|
| Manage the risk | A named owner for each system, and a way to raise a problem |
| Govern the data | One trusted source, and clarity on where information came from |
| Document it | Written while building, not reconstructed a year later |
| Keep records | The system logging what it did, as it does it |
| Keep a human in it | A real moment where a person can say stop |
| Keep it accurate and safe | Testing, limits, and no data quietly leaving Europe |
Notice what is missing from that list: a compliance department. Every line is a piece of infrastructure.
Most companies cannot answer the basic questions yet
The rules arrive at an awkward moment.
More than half of organizations cannot say for certain which AI tools are running inside their own business. A third of executives admit they could not switch off a misbehaving one today. Gartner expects that by 2027, four in ten companies will have to pull AI systems back out of service because nobody set the ground rules first.
Gartner also names the reason, and it is worth sitting with: companies treat AI as all-or-nothing. Either lock it down, or trust it completely.
Neither survives real work. Lock it all down and people go around you, which is how customer data ends up in an app nobody approved. Trust it all and there is nobody watching when it matters.
The way out is not more restriction. It is deciding, job by job: this gets automated, this gets assisted, this stays with a person. That decision is the actual work. It is also, almost word for word, what the law asks you to be able to show.
Being small helps a little, not a lot
Smaller companies get simpler paperwork, ready-made templates, safe spaces to test, and lighter fines. Regulators have to take your size and resources into account.
That is a lighter load, not a free pass. A forty-person company still has to say what its systems do, who owns them, and where a person decides.
This matters more here than in most places. In Portugal, around one company in nine uses AI at all. Across the EU it is about one in five small and medium companies, against more than half of large ones.
Most of the market has not started. That is not a disadvantage. Starting now means building this in from the first system, instead of retrofitting it into ten years of accumulated tools.
What to do in the next 30 days
Five steps. None of them need a lawyer.
- 01List them. Every AI tool touching your work, including the ones nobody approved. The unapproved list is usually the longer one.
- 02Give each one an owner. One person who can answer for it. This is the cheapest control there is, and the one most often skipped.
- 03Find the human moments. For each tool, where does a person decide? Check they actually can. If there is no such moment, you just found something.
- 04Turn on the record. Not a dashboard. A record of what the system did, and on whose say-so.
- 05Check what your customers see. Anything that talks or writes. Saying "this is AI" is cheap now and expensive later.
If that list gives you more questions than answers, that is the normal result. That is the point of doing it.
The honest summary
The date changed. What you are exposed to did not.
The rules already in force apply to companies far smaller than the ones in the headlines. And the rules that got delayed are exactly the ones you cannot add at the end.
So the delay bought you time to build it properly. It did not buy you time to skip it.