AI Act Deferral: What Executive Teams Need to Know Now
Understand the implications of the AI Act's delay and the ongoing regulatory requirements for AI systems. Prepare your organization for compliance now.
Most executive teams heard "the AI Act has been delayed" in July and moved on. That was the wrong half of the news.
The deferral was real, but narrow. What it postponed is not what most organisations are actually exposed to — and the enforcement machinery it left untouched started work on 2 August.

What Actually Changed — And What Did Not
The Digital Omnibus on AI was published in the Official Journal on 24 July 2026 and entered into force three days later, six days before the deadline it amends. It defers the obligations for standalone high-risk systems under Annex III from August 2026 to December 2027, and pushes AI embedded in regulated products out to August 2028. National regulatory sandboxes slip by a year.
Everything else held. The transparency obligations under Article 50 apply from 2 August 2026. The general-purpose AI provider obligations have been live since August 2025. The prohibited-practices regime has been enforceable since February 2025. And national enforcement — the authorities, the penalties, the market surveillance powers — commenced on schedule.
In other words: the burden that was lifted falls mainly on providers of systems used in recruitment, credit scoring, biometrics, education and critical infrastructure. The burden that landed falls on almost everyone else.
Where the Exposure Sits Now
Article 50 is deceptively quiet. It requires that people be told when they are interacting with an AI system rather than a person, and that synthetic content — text, image, audio, video — be machine-readable as such. Deepfakes and AI-generated text published to inform the public on matters of public interest must be clearly disclosed.
Read that against your own estate. The customer service chatbot on the website. The AI-drafted content flowing through marketing. The synthetic voice in the IVR. The candidate-facing assistant sitting in front of the ATS. None of these were designed as regulated systems. Most were procured by a function, not by IT, and are governed by a supplier's terms nobody in the executive team has read.
The reach is extra-territorial in the same way GDPR is. If the output touches the EU market meaningfully — through sales, access, or downstream integration — the organisation is in scope regardless of where the model runs or the company is domiciled. Penalties run to €15 million or 3% of global turnover for most breaches, and materially higher for prohibited practices.
The Sixteen Months Are a Build Window, Not a Reprieve
For organisations genuinely deploying Annex III systems, the deferral to December 2027 is useful. It is not a reason to stop. Conformity assessment, technical documentation, quality management systems and human-oversight design are twelve-month programmes at best, and every one of them improves the system independently of the regulator. Teams that stood down in July will restart in mid-2027 against a harder deadline with a thinner market for the specialists they will need.
There is also a governance problem hiding underneath the compliance one. Most organisations still cannot produce a defensible inventory of where AI is deployed, who owns each system, and which supplier holds which obligation. That inventory is the precondition for every other requirement in the Regulation, and it is not a legal deliverable. It is an operating-model deliverable.
What Boards Should Be Asking
Four questions separate organisations that are genuinely prepared from those with a policy document and a RACI chart.
Who owns AI risk at executive level, and is it a named individual with budget? Can we produce a complete system inventory in a week, including tools procured outside IT? Where are we the provider, and where merely the deployer — because the obligations differ sharply? And has anyone tested whether our supplier contracts actually transfer the obligations we assume they transfer?
If the answers take more than a fortnight to assemble, the gap is structural rather than technical, and no amount of legal review will close it.
What to do next
- Inventory every AI-touching system, including shadow deployments in marketing, HR and service
- Classify each as provider or deployer — the obligations are not the same
- Audit customer-facing disclosure against Article 50 now, not at the next review cycle
- Keep Annex III programmes running to the original scope; treat December 2027 as margin, not permission
- Name a single accountable executive with authority over procurement, not just policy
Grant & Graham works with boards and executive teams on AI governance, operating-model design and enterprise transformation. If your organisation needs senior capacity to run an AI inventory, restructure accountability, or hold a transformation programme together while the regulatory picture settles, we can deploy in days. Explore our AI consultancy and interim management practices, or book a discovery call.
More from the team.
One email a month. Worth opening.
Senior-practitioner thinking. Cancel in a click.
Tell us in 25 minutes what you're navigating.
Senior practitioners on tap — interim, GaaS, or consultancy depending on what fits.