Have any questions? +1 646.844.5712 (US)

  • Facebook
  • LinkedIn
  • Twitter
HiTech ServiceHiTech Service
  • Home
  • About
  • Services
    • Software Development
    • Customer Support
    • Quality Assurance
    • Managed Services
    • Compliance Audit
    • GDPR Compliance
    • Competency Center
    • Emergency IT Support
    • Software as medical device
    • Local AI Agent Development
  • Projects
  • GDPR
  • Articles
  • Case Studies
  • Contact
Menu
  • Home
  • About
  • Services
    • Software Development
    • Customer Support
    • Quality Assurance
    • Managed Services
    • Compliance Audit
    • GDPR Compliance
    • Competency Center
    • Emergency IT Support
    • Software as medical device
    • Local AI Agent Development
  • Projects
  • GDPR
  • Articles
  • Case Studies
  • Contact
Illustration of a clock and hourglass made of circuit-board patterns in EU flag blue and gold, symbolizing the delayed EU AI Act high-risk compliance deadline

The EU Just Gave AI Companies 16 More Months — Here’s What the AI Act Delay Actually Changes

By John

Companies building recruitment algorithms, credit-scoring models, and other high-risk AI systems for the European market had a hard deadline circled on the calendar: August 2, 2026. It’s no longer hard, and it’s no longer August 2026. The European Commission, Council and Parliament have agreed to push it to December 2, 2027 — sixteen months of breathing room that almost nobody in the industry saw coming this late in the process.

That’s the headline. The part worth actually reading past the headline is what didn’t move, because the answer is: the law everyone already has to comply with regardless of what happens to the AI Act.

What Got Pushed, and What Didn’t

The European Commission published its Digital Omnibus on AI on November 19, 2025, proposing to defer the compliance deadline for standalone high-risk systems under Annex III — the category covering recruitment tools, credit scoring, law enforcement applications, education software, and border control systems — from August 2, 2026 to December 2, 2027. AI embedded inside already-regulated products (medical devices, vehicles, industrial machinery, covered under Annex I) gets pushed even further, to August 2, 2028.

The Council and Parliament formally agreed to simplify and streamline the rules on May 7, 2026, following MEPs voting in March to support the postponement. What stayed exactly where it was: the underlying GDPR exposure. If a high-risk AI system processes biometric data or does emotion recognition, GDPR penalties of up to €20 million or 4 percent of global turnover still apply the moment that processing happens — not on some future compliance date, but now, because GDPR was never on the AI Act’s clock to begin with.

Why Brussels Blinked

The delay isn’t a political retreat from AI regulation so much as an admission that the machinery required to enforce it wasn’t ready. The stated reasoning centers on delays in designating national competent authorities in member states, and on the fact that the harmonized technical standards and conformity assessment tools that high-risk providers are supposed to test against don’t fully exist yet. You can’t credibly require a company to pass a conformity assessment against a standard that hasn’t been finalized.

That’s a real, defensible problem. It’s also one the Commission created for itself by setting an ambitious original timeline in 2024 and then discovering, as implementation deadlines approached, that the supporting infrastructure — accredited assessment bodies, published technical standards, functioning national authorities — was running well behind the legal deadline. The Digital Omnibus is, in effect, the EU acknowledging its own regulatory apparatus wasn’t going to be ready in time, and adjusting the law to match reality rather than forcing companies to comply against a system that couldn’t actually process their compliance.

The GDPR Safety Net Underneath

Two interlocking circuit-board gears in EU blue and gold, one frozen with a padlock icon representing the delayed AI Act, the other spinning representing GDPR still fully in force

This is the detail that matters most for anyone tempted to treat the delay as a green light. The AI Act, GDPR, and the Digital Markets Act now converge on the same systems, particularly anything handling customer interactions or sensitive personal data at scale — and only one of those three frameworks just got a schedule extension. A recruitment AI tool that processes candidate biometric data for identity verification, for instance, doesn’t get to wait until December 2027 to worry about data protection law. It was already subject to GDPR the day it started processing that data, delay or no delay.

That distinction gets lost fast in coverage that treats “AI Act delayed” as equivalent to “AI regulation postponed.” It isn’t. Companies that read the Digital Omnibus as permission to deprioritize AI governance work entirely are conflating two different regulatory clocks — one that just moved, and one that never was on the same schedule in the first place.

Who’s Cheering, Who’s Not

A circuit-board balance scale weighing industry relief against regulatory oversight concern, in EU blue and gold

Industry reaction has split along predictable lines. Companies mid-build on high-risk systems get real relief: more runway to finalize technical documentation, complete conformity assessments once standards actually exist, and avoid a compressed scramble against a deadline the supporting bureaucracy couldn’t have met anyway. For a mid-size company building, say, an AI-driven credit scoring tool for the European market, sixteen extra months is the difference between shipping compliant and shipping late.

Critics see it differently. Advocacy and policy groups have argued the delay lets high-risk systems dodge oversight during exactly the window when adoption of those systems — in hiring, lending, and law enforcement — keeps accelerating. Every month between now and December 2027 is a month a recruitment-scoring algorithm or a predictive policing tool operates under whatever governance a company voluntarily chooses to apply, rather than a legally mandated standard.

Both readings are correct at the same time, which is usually how regulatory delays work. The companies get real, defensible extra time to comply with a law whose enforcement infrastructure genuinely wasn’t ready. The systems being regulated keep operating in the meantime under lighter obligation than the original law intended. Neither fact cancels the other out — and neither one touches the GDPR exposure that was never part of this deadline to begin with.

  • On May 1, 2026
  • 0 Comment
Tags: AI, compliance, EU AI Act, GDPR, regulation

Leave Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts
  • Why Load Test Numbers Lie
  • When Config Became Executable: The Twenty-Year Pattern Behind Supply Chain Attacks
  • How Software Became a Medical Device
  • Compliant With What? A Working Map of GDPR, HIPAA, SOC 2 and ISO 27001
  • Local AI vs Cloud AI: The Break-Even Is About Utilization, Not Tokens
Categories
  • ai (7)
  • android (18)
  • apple (36)
  • chart (18)
  • cloud (1)
  • fix (42)
  • games (11)
  • google (31)
  • hardware (73)
  • healthcare (3)
  • how to (231)
  • internet (92)
  • ios (23)
  • macos (3)
  • microsoft (82)
  • mobile (36)
  • news (74)
  • optimization (17)
  • osx (4)
  • outsourcing (8)
  • qa (3)
  • regulation (7)
  • review (120)
  • security (37)
  • software (159)
  • windows (150)
Archives
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • August 2025
  • March 2025
  • February 2025
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • March 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • June 2018
  • May 2018
  • April 2018
  • February 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017
  • June 2017
  • May 2017
  • April 2017
  • March 2017
  • February 2017
  • January 2017
  • December 2016
  • November 2016
  • October 2016
  • September 2016
  • August 2016
  • July 2016
  • June 2016
  • May 2016
  • April 2016
  • March 2016
  • February 2016
  • January 2016
  • December 2015
  • November 2015
  • October 2015
  • September 2015
  • July 2015
  • January 2015
Archives
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • August 2025
  • March 2025
  • February 2025
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • March 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • June 2018
  • May 2018
  • April 2018
  • February 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017
  • June 2017
  • May 2017
  • April 2017
  • March 2017
  • February 2017
  • January 2017
  • December 2016
  • November 2016
  • October 2016
  • September 2016
  • August 2016
  • July 2016
  • June 2016
  • May 2016
  • April 2016
  • March 2016
  • February 2016
  • January 2016
  • December 2015
  • November 2015
  • October 2015
  • September 2015
  • July 2015
  • January 2015

AI recruiting assistant for Smarter, Transparent Hiring

Previous thumb

GDPR Regulators Just Finished Grading Europe on 'The Right to Be Forgotten.' Now They're Grading Honesty.

Next thumb
Scroll

Services

  • Software Development
  • Quality Assurance
  • Customer Support
  • Managed Services
  • 24/7 Emergency IT Support
  • Competency Center
  • Local AI Agent Development
  • Software as a Medical Device

Compliance

  • Compliance Audit
  • GDPR Compliance
  • What is GDPR
  • ISO 9001:2015 Certification

Company

  • About Us
  • All Services
  • Projects
  • Case Studies
  • Articles
  • Contact
About HiTech Service

With 10 year experience of working together, we have reached tangible synergetic effect in performance and productivity, which results in highest quality services and satisfied clients.

Privacy Policy   Cookie Policy

 

  • Facebook
  • X
  • LinkedIn
CONTACT INFO
  • 900 Foulk Rd, Suite 201, Wilmington, DE, USA, 19803
  • Kudryavs’kyi descent 5b, Kyiv, Ukraine, 04053
  • +1 646.844.5712 (US)
ISO 9001:2015 certificate issued to HiTech Service LLC by Veritas
RIPE Atlas logo, the network measurement community HiTech Service takes part in
BrainBasket Foundation logo, IT education initiative HiTech Service supports
HiTech Service LLC membership badge of the Hi-Tech Office Ukraine association Dun & Bradstreet verified business badge for HiTech Service LLC
YouTeam partner badge for HiTech Service LLC
Hitech Service LLC

Copyright 2026