All insights
Signal·16 August 2026·5 min read

The deadline moved. Your exposure didn’t.

Europe just pushed its biggest AI deadline back by more than a year. Here is what actually changed, what did not, and why waiting is the expensive option.

Daniel ÍndiasDesigns and builds the systems at Innerflect

This piece covers a moving regulatory situation. Next review: 16 November 2026. Corrections are added as dated notes, never silent edits.

The short version

  • Europe pushed its biggest AI deadline back by more than a year. That part is true.
  • The rules that were already live did not move. For most companies, those are the ones that apply.
  • What got pushed back is the part you cannot add at the end. So the extra time is for building, not for waiting.

On 27 July 2026 a new EU law came into force. It moved the AI Act's heaviest deadline from August 2026 to December 2027.

Most of what you can read about this online is now wrong, in one of two ways. Older articles still say the deadline is August 2026. Newer ones say the pressure is off. Neither is right.

Timeline showing EU AI Act duties already live in 2025 and 2026, with Annex III deferred to 2 December 2027 and Annex I deferred to 2 August 2028.
What moved is a subset. The obligations already in force did not shift by a single day.

What moved, and what did not

The ruleBeforeNow
High-risk AI systemsAug 2026Dec 2027
AI built into regulated productsAug 2027Aug 2028
Banned uses of AILive since 2025Unchanged
Rules for the big AI model providersLive since 2025Unchanged
Telling people they are talking to AIAug 2026Applies now
Training your staff to use AILive since 2025Unchanged

Four of those six lines did not move at all.

Does the delayed one even apply to you?

The deadline that moved covers a specific list: hiring, credit scoring, biometrics, education, healthcare, critical infrastructure, policing. Serious stuff, and a short list.

If that is not what your company does, that deadline was never yours in the first place.

Three other rules are yours, and they are live today.

Some uses are simply banned. No phase-in, no small-company discount. The fines here are the big ones.

If it is a machine, say so. A chatbot that pretends to be a person, or AI-written content passed off as human, is a problem now, not in 2027.

Train the people using it. This is the one almost everyone skips, because it does not look like a rule. If your team uses AI on your behalf, they have to know how. That is training and ownership, not a policy document nobody reads.

The part nobody can postpone

Here is the bit that matters.

Look at what the delayed rules actually ask for: keep records of what the AI did. Have a person who can step in. Know where your data came from. Be able to show where an answer originated.

Now ask which of those you could add in the last month before a deadline.

You cannot add a record of the past. Either the system was writing things down while it worked, or that year is simply gone. You cannot add a person into a decision that has no place for one. You cannot trace an answer back to its source if nothing ever recorded the source.

Moving a deadline moves the day you have to show your work. It does not move the day you have to start doing it.

Companies that treat this as free time will spend 2027 rebuilding what they built in 2026. Companies that build it in now will spend 2027 filling in forms.

Diagram mapping six EU AI Act duties to six Innerflect system layers, with Governance receiving risk management and technical documentation.
Every obligation resolves to a layer someone has to own. Compliance is a read of the architecture, not a document produced beside it.

Every rule is really a piece of plumbing

What the rule asksWhat you actually need
Manage the riskA named owner for each system, and a way to raise a problem
Govern the dataOne trusted source, and clarity on where information came from
Document itWritten while building, not reconstructed a year later
Keep recordsThe system logging what it did, as it does it
Keep a human in itA real moment where a person can say stop
Keep it accurate and safeTesting, limits, and no data quietly leaving Europe

Notice what is missing from that list: a compliance department. Every line is a piece of infrastructure.

Most companies cannot answer the basic questions yet

The rules arrive at an awkward moment.

More than half of organizations cannot say for certain which AI tools are running inside their own business. A third of executives admit they could not switch off a misbehaving one today. Gartner expects that by 2027, four in ten companies will have to pull AI systems back out of service because nobody set the ground rules first.

Gartner also names the reason, and it is worth sitting with: companies treat AI as all-or-nothing. Either lock it down, or trust it completely.

Neither survives real work. Lock it all down and people go around you, which is how customer data ends up in an app nobody approved. Trust it all and there is nobody watching when it matters.

The way out is not more restriction. It is deciding, job by job: this gets automated, this gets assisted, this stays with a person. That decision is the actual work. It is also, almost word for word, what the law asks you to be able to show.

Being small helps a little, not a lot

Smaller companies get simpler paperwork, ready-made templates, safe spaces to test, and lighter fines. Regulators have to take your size and resources into account.

That is a lighter load, not a free pass. A forty-person company still has to say what its systems do, who owns them, and where a person decides.

This matters more here than in most places. In Portugal, around one company in nine uses AI at all. Across the EU it is about one in five small and medium companies, against more than half of large ones.

Most of the market has not started. That is not a disadvantage. Starting now means building this in from the first system, instead of retrofitting it into ten years of accumulated tools.

What to do in the next 30 days

Five steps. None of them need a lawyer.

  1. 01List them. Every AI tool touching your work, including the ones nobody approved. The unapproved list is usually the longer one.
  2. 02Give each one an owner. One person who can answer for it. This is the cheapest control there is, and the one most often skipped.
  3. 03Find the human moments. For each tool, where does a person decide? Check they actually can. If there is no such moment, you just found something.
  4. 04Turn on the record. Not a dashboard. A record of what the system did, and on whose say-so.
  5. 05Check what your customers see. Anything that talks or writes. Saying "this is AI" is cheap now and expensive later.

If that list gives you more questions than answers, that is the normal result. That is the point of doing it.

Five-step 30-day control flow from inventory to disclosure, followed by the six system layers touched by each step.
The five moves, in order. Each one is a question a regulator, a client or a board can ask.

The honest summary

The date changed. What you are exposed to did not.

The rules already in force apply to companies far smaller than the ones in the headlines. And the rules that got delayed are exactly the ones you cannot add at the end.

So the delay bought you time to build it properly. It did not buy you time to skip it.

Questions

So the August 2026 deadline is gone?
One deadline moved, to December 2027. It covers a specific list of high-risk uses like hiring, credit scoring and biometrics. The other rules were untouched and still apply today.
What applies to a normal company right now?
Three things. Some uses of AI are simply banned. If your AI talks to customers or writes content, you have to say it is AI. And the people using AI on your behalf have to be trained to use it.
We are small. Are we exempt?
No. Smaller companies get simpler paperwork, templates and lighter fines, and regulators must take your size into account. That is a lighter load, not a free pass.
Should we just wait until 2027?
Waiting costs more. The things that got postponed are the ones you cannot add at the end: records of what the AI did, a person who can stop it, and knowing where its answers came from. Those get built in, or they get rebuilt.

One question

If someone asked you today which AI tools are running inside your company, and who approved each one, could you answer within an hour?

Two to three weeks. We map how work, decisions and AI move through your company, and show you where the gaps are.

Next step

Not sure where your leverage is?

Start with a specific operating layer, scope a custom build, or begin with the assessment.

Let's find out together.