July 15, 2026

EU AI Act: What the Delay Does (and Doesn’t) Mean

The EU AI Act delay doesn't apply to every requirement. Discover what has changed, what hasn't, and what UK businesses need to do before August 2026.

By
Mark Edgeworth
5 min read
July 15, 2026
QBS Software and Hicomply partnership announcement graphic with Earth at night from space

When the EU AI Act deadline for high-risk AI systems was postponed in May 2026, many organisations assumed they had gained valuable breathing space.

The headline requirements for high-risk AI systems, originally due to take effect on 2nd August 2026, have now been deferred until 2nd December 2027. On the surface, that gives organisations another sixteen months to prepare.

It is good news - but only for part of the legislation.

Buried within the same agreement is a crucial detail that many businesses have overlooked. The EU AI Act's Article 50 transparency obligations covering AI chatbots, AI-generated content and deepfakes, have not been delayed. They still come into force on 2 August 2026, making them an immediate priority for organisations using AI today.

Two different timelines

The EU AI Act has been introduced in phases since centering into force in August 2024.

Restrictions on the most harmful AI practices have applied since February 2025, while obligations for providers of general-purpose AI models have been in place since August 2025.

The May announcement only changed the timetable for high-risk AI systems. Requirements around risk management, technical documentation, human oversight and conformity assessments for AI used in areas such as recruitment, credit scoring, education and critical infrastructure. Those obligations now move to December 2027 for most organisations.

Article 50 is different.

It requires organisations to:

  • Tell people when they are interacting with an AI system
  • Make AI-generated content identifiable, including deepfakes
  • Ensure generative outputs include machine-readable marking

None of those obligations have changed. The only concession is a grace period until December 2026 for machine-readable marking on tools already on the market.

That means that from August 2026, any UK business using customer-facing AI chatbots, generating marketing content with AI or producing synthetic media for an EU audience will have legal obligations to meet - even if none of its AI systems are classified as high risk.

What this means for UK businesses

It's easy to view the EU AI Act as legislation that only affects organisations operating within the European Union.

We heard similar assumptions when GDPR was introduced. Businesses quickly discovered that regulations follow customers across borders, not company headquarters.

The EU AI Act works in much the same way.

If your AI system is used by people in the EU, or its outputs reach an EU market, you are likely to fall within scope regardless of where your organisation is based.

For many UK businesses, that could include:

  • AI-powered customer service chatbots
  • AI-generated marketing content
  • AI-assisted product descriptions
  • Synthetic media product for European audiences

If your organisation sells into the EU or supports customers there, AI governance is no longer just a future consideration. It's a current compliance requirement.

The EU AI Act is exposing the AI governance gap

One of the biggest challenges I see is that AI adoption has often happened organically.

Individual teams have experimented with new tools to improve productivity, but governance hasn't always kept pace. As a result, many organisations simply don't have a complete picture of which AI systems are being used, who owns them or how they're being managed.

This is where organisations with mature governance programmes already have an advantage.

Frameworks such as ISO 27001 require businesses to establish clear ownership, documented controls and visibility over the technologies they use. Those same foundations make extending governance into AI significantly easier than starting from scratch.

The organisations best prepared for the EU AI Act won't necessarily be those using the least AI. They'll be the ones with the strongest AI governance.

Why ISO 42001 supports EU AI Act compliance

This is also why ISO 42001, the international standard for AI management systems, will become increasingly important.

For organisations already certified against ISO 27001 or SOC2, ISO 42001 follows a familiar management system approach. Rather than creating an entirely new governance model, it builds on processes many organisations already have in place - with around 50% control overlap with ISO 27001. Half the work is already done.

It provides the governance framework organisations need to understand where AI is being used, assign ownership, manage risk and demonstrate accountability. All principles that align closely with the expectations set out in the EU AI Act.

Businesses that adopted AI rapidly without embedding governance are likely to be the most exposed as the August deadline approaches.

The delay is only valuable if organisations use it wisely

There is a real risk that the postponement of the high-risk requirements leads organisations to de-prioritise AI governance altogether.

That would be a mistake for two reasons.

Firstly, the Article 50 obligations taking effect this August are far from insignificant. They carry their own enforcement requirements, and regulators have already demonstrated a willingness to act on AI-related issues using existing legislation before the AI Act's full enforcement framework is established.

Secondly, it's around the work required to prepare. Understanding which AI systems are in use, who owns them, how they process data and how decisions are documented isn't work that becomes redundant if a deadline changes.

It's good governance.

And good governance strengthens an organisation's overall security and compliance posture, regardless of regulation.

How to prepare

The first priority is visibility.

Many leadership teams would struggle to produce a complete inventory of the AI tools currently being used across their organisation, let alone identify which systems interact directly with customers or generate content for EU audiences.

That inventory is the logical place to start.

From there, the same disciplines that underpin effective information security practice also apply to AI governance:

Establish clear ownership.

Document controls.

Maintain evidence that can be produced when required.

Review how AI is being used across the organisation, and regularly.

Build governance processes that can evolve alongside changing regulations.

These aren't new principles. They're the same foundations that support resilient, audit-ready compliance programmes.

Final thoughts

The EU AI Act was never designed to arrive all at once, and delaying part of the legislation is undoubtedly helpful for organisations preparing for high-risk AI obligations.

But it's important not to mistake that delay for a pause on AI governance altogether.

For UK businesses with customers, users or operations connected to the EU, August 2026 remains a significant milestone. Organisations that use this time to strengthen governance, improve visibility and establish clear accountability won't just be better prepared for Article 50—they'll also be in a far stronger position for the wider requirements still to come.

AI governance shouldn't begin when a deadline arrives. It should become part of how your organisation manages risk, builds trust and operates day-to-day.

Take Your Learning Further

Discover research, playbooks, checklists, and other resources on

ISO 42001

compliance.

Decorative
Getting Started
Enterprise
Growth
Computer Software
Construction
Financial Services
Health care
IT and Services
Legal Services