Cookie Consent

I use cookies to understand how my website is used. This data is collected and processed directly by me, not shared with any third parties, and helps us improve our services. See my privacy and cookie policies for more details.

The Deadline Moved: What the EU AI Act Deferral Reveals About Boards

Published in Board | 10 minute read |    
A vast split-flap departures board mounted on the marble wall of a grand institutional concourse, its four rows announcing the EU AI Act's provisions as though they were flights: high-risk systems delayed to December 2027, transparency departed on schedule in August 2026, prohibitions boarding for December 2026, and embedded systems told to wait in the lounge until August 2028, while a lone director in a dark suit stands small beneath the board with a briefcase, reading a timetable that has just changed around him, a visual rendering of the article's argument that the deferral moved some departures and not others, and that the traveller's obligations did not move at all (Image generated by ChatGPT 5.6)

The EU AI Act was written to govern the artificial intelligence systems that make consequential decisions about people: the software that screens job applications, scores loan applications, and selects students for university places. Its rules for those high-risk systems were due to apply from 2 August 2026. Just six days before that deadline, the EU deferred it, pushing the postponement through “as a matter of urgency” for a simple reason: the EU had not produced the standards businesses needed in order to comply, and had not set up the authorities meant to supervise them. Many organisations had spent two years building governance to meet a date the EU itself could not meet. The alternative was always available: deliver the standards and the supervisors first, then set a compliance date that holds. A deadline set before the machinery to meet it exists is a deadline that can move, and a deadline that can move once can move again.

The new date is 2 December 2027, sixteen months later than planned. Most commentary will spend those months asking what the deferral means for compliance programmes. The more useful question for directors is what it reveals about any Board whose AI governance was built around a regulatory date, because the past fortnight has just tested that foundation in public.

What actually changed, and why

The December 2027 date does not cover everything, and the detail matters. The deferral applies to standalone high-risk systems, the hiring, credit, and education uses this article opened with. High-risk AI embedded in regulated products, machinery, medical devices, and vehicles among them, moves instead to 2 August 2028.

The same amendment also tightened the law. Two new prohibitions, on AI systems that generate or manipulate non-consensual intimate material or child sexual abuse material, apply from 2 December 2026. The duty to build AI literacy among staff operating AI systems remains in force, as it has been since February 2025, in a softened form. No Board should need that date to arrive before it can say its organisation does not deploy systems capable of generating such material. Where the statute has been slower than basic ethics, the statute was never the standard.

And some obligations did not move at all. From 2 August 2026, people must be told when they are interacting directly with AI, and deployers of emotion-recognition and deepfake systems carry their own disclosure duties. The deferral is a reprieve on part of the timetable, not a repeal of it. Anyone in your organisation saying that the AI Act has been delayed is describing a law that does not exist.

The instability is global

The same instability appears outside Europe. On 14 July 2026, Nobel Laureate Sir Demis Hassabis, chief executive of Google DeepMind, proposed a standards body for frontier AI in the United States: industry-funded, government-backed, staffed by technical experts, initially reviewing frontier models voluntarily before release, with mandatory assessment envisaged once the protocol matures. The design borrows deliberately from the self-regulatory structure used in American finance.

The proposal deserves to be taken seriously, and its limits deserve equal attention. The financial model works because access to a regulated market passes through identifiable member firms. However, model weights, once published, are replicated and retrained beyond any membership gate, so the body’s practical purchase on open-weight models is far less clear than its stated coverage. And the proposal concerns the makers of frontier models, where the readers of this article sit on the deploying side, choosing among frontier models, open-weight models, and retrained variants of both.

Look further afield and the picture widens without settling. The United Kingdom has chosen, for now, not to legislate at all, asking existing regulators to govern AI at the point of use while a promised bill for the most powerful models slips from one parliamentary session to the next. China is moving in the opposite style, issuing a steady stream of targeted rules, on labelling, on deepfakes, on interactive AI services, while a comprehensive AI law is still being drafted. Four major jurisdictions, four different answers to the same question, none of them finished.

That is the point, and it is not a story about any one jurisdiction. Everywhere, governments and industry are still working out how AI should be governed, and every scheme so far governs a slice. Statutory regimes slip their dates; self-regulatory proposals stop at the laboratory door. A Board waiting for complete coverage before governing will wait indefinitely, because nothing on any legislator’s table provides it. No regime on offer, statutory or self-regulatory, covers all of what a Board might deploy.

What the deferral reveals

Every regulatory shift of the past month, the deferral among them, is a test of whether a Board has mistaken regulatory milestones for governance maturity. Strip the chronology away and each one becomes an unusually useful diagnostic: it measures what your AI governance was actually anchored to. An AI governance programme that exists because 2 August 2026 was coming is a compliance project, not governance. It may be a competently run compliance project, but when the date moved, the discipline moved with it, and that is the tell. Workstreams paused, budgets re-phased into 2027, attention released back to other matters. None of that is irrational as project management. All of it is revealing as governance, because it means oversight of a live, deployed, risk-bearing technology was calibrated to a statutory calendar rather than to the technology the organisation is actually running.

The deferral treats everyone the same. Organisations that spent two years preparing received the same sixteen months as organisations that did nothing. That looks unfair, and it is not, because the two groups are not in the same position. The AI systems themselves did not stop: they are still screening candidates, scoring credit, and shaping decisions today, under data protection, equality, and consumer protection law that applies today. The prepared organisation knows what it runs, has the controls in place, and can prove both. The unprepared organisation has none of that, and sixteen more months of exposure. Nothing about early preparation was wasted, because the preparation was never really for Brussels.

A compliance deadline is a constraint on the business, not a reason to govern it. A constraint is something you plan around, resource for, and meet. A reason to govern does not appear in any official journal.

So ask the question at your next Board meeting: what changed in our AI oversight when the deadline moved? If the answer is anything beyond your filing dates, your governance was anchored to the wrong thing. If nothing changed but the calendar, it was anchored correctly. Every director is capable of asking it, and the answer arrives in minutes.

What does not move

A director’s accountability for AI risk does not come from the AI Act, so it did not defer with it. In the UK, the Companies Act 2006 requires directors to promote the success of the company, exercise independent judgement, and apply reasonable care, skill, and diligence. Those duties say nothing about technology and everything about it. They predate the AI Act by nearly two decades, and they read exactly the same the day after the deferral as they did the day before. The same holds beyond the UK, though the instruments differ by jurisdiction.

Precision cuts both ways here. The AI Act did not create Board accountability for AI, and not every AI error lands as personal liability for each director. The accurate claim is narrower and stronger: directors were already accountable for care, risk, data, discrimination, and the quality of corporate decision-making, and none of that defers because a European timetable slipped. The oversight labour those duties require is a live operating cost today, one I priced in The Balancing Item, and it did not defer either.

This is where Minimum Lovable Governance earns its keep. Governance proportionate to the risk of what the organisation actually deploys, owned by the Board, is stable under any regulatory timetable because it is anchored to the deployment, not the statute. A Board governing on that principle experiences a moving deadline as administration: the dates are noted, the schedule is redrawn, and the oversight of the systems in production continues unchanged. Regulatory obligations become a floor the organisation clears in passing rather than a target it builds towards.

That is also how innovation keeps flowing while the goalposts move. The answer is not less governance; it is governance anchored to something that does not move. Boards governing to their own accountability can adopt with confidence while the timetable churns, because nothing in the churn changes what they were already doing. The principle these articles have carried from the start holds without amendment: agency for the work can transfer to the machine, and accountability for the outcome cannot, and no regulation in any jurisdiction has ever moved that.

In practice

Three questions belong on the next Board agenda, and none of them requires a lawyer to ask. The first is which of the organisation’s AI deployments would count as high-risk, and what written, defensible determination exists for each. Classification is where organisations are furthest behind, and it is the evidence base for every regulatory regime that will eventually apply, in Europe and elsewhere. The sixteen months are an opportunity to do that work properly, not permission to stop it.

The second is where the organisation’s ethical bar sits, and who set it. No regime on offer covers everything a Board might deploy, so the gap between what regulation requires and what the organisation stands for is governed by the Board or by nobody. A Board that cannot state its own answer is inheriting one from its model providers, whether it knows it or not.

The third is which obligations remain live regardless of the deferral. The transparency duties apply now, the duty to build AI literacy among staff continues, and the new prohibitions arrive in December 2026. The deferral is a change to part of one statute’s timetable. It is not a holiday, and a management team briefing the Board as though it were one has misread the instrument.

December 2027 will arrive

The image worth keeping is the legislator racing to beat its own deadline in order to move it. December 2027 will arrive in its turn, the standards will eventually exist, and the obligations will apply, in Europe and everywhere else still writing its answer. The Boards that meet those dates without drama will be the ones for whom no date was ever the reason to govern. Regulations arrive when legislators are ready. Accountability begins when an organisation deploys the system. Accountability is a condition of deployment, not a product of regulation.

Let's Continue the Conversation

Thank you for reading about what the EU AI Act deferral reveals about Board governance. I'd welcome hearing how the moving deadline landed in your boardroom - whether your oversight activity continued unchanged because it was anchored to your deployments rather than the statute, you're using the sixteen months to complete the classification work the deferral has made less urgent but no less necessary, or you're wrestling with how to keep governance momentum when the regulatory timetable that justified the budget has just moved by more than a year. I'd particularly value hearing which obligations your Board identified as remaining live from 2 August, and whether the deferral prompted the diagnostic question this article proposes: what actually changed in your AI oversight when the date moved?