- The Annex III deferral is sixteen months, from 2 August 2026 to 2 December 2027. Annex I moved from 2 August 2027 to 2 August 2028. Just over fifteen months remain from this article's publication date.
- Readiness evidence splits into two kinds. Documentary evidence can be written at any time. Operational evidence, meaning logs, change history, incident registers, monitoring observations and oversight records, can only be accumulated forward.
- That asymmetry is the whole argument. A programme paused for a year can write its policies in 2027. It cannot write its 2026 logs in 2027, and 2026 is inside the period a supervisor will look at.
- Two obligations land before the deferred date and neither moved: the Article 50(2) machine-readable marking transitional period ends 2 December 2026, and the revised Product Liability Directive must be applied by Member States from 9 December 2026.
- Sequence structural work early and interpretive work late. Standards and guidance will continue to arrive before December 2027, and classification work done against a guessed reading is the work most likely to need redoing.
- A majority of Member States had not completed formal designation of their supervisors as at 17 August 2026. Build evidence that answers the obligation, not evidence tuned to an authority that may not exist yet.
The asymmetry nobody priced in
Compliance programmes are usually modelled as a volume of work against a date. Move the date, and the same volume of work fits into a later window at lower intensity. For most of what the EU AI Act asks of a deployer, that model holds. For a specific and important part of it, the model fails, because the work in question is not a volume at all. It is an elapsed period.
Consider what a supervisor, an auditor, a customer's vendor risk team or an insurer actually asks a deployer of a consequential AI system. Not only what your policy says, but what your system did. Over what period. With what interventions. Producing what incidents. Changing in what ways and on whose authority. Those questions are answered by records that accumulate, and records that accumulate have exactly one property that cannot be bought later: they must have been running at the time.
A policy written in a rush in October 2027 is a policy. A monitoring record started in October 2027 is a two-month monitoring record, and it will be two months old on the day the obligation activates, describing a period in which the organisation already knew it was being watched. The distinction is obvious once stated and it is almost never in the plan.
Which evidence is which
The split is clean enough to plan against.
| Can be produced at any time | Can only be built forward |
|---|---|
| AI policy and governance framework documents | Interaction and decision logs |
| System classification memos and their reasoning | Change history for prompts, model versions, parameters, tool permissions, retrieval sources and thresholds |
| Technical documentation assembled from provider material | Incident register, including the small entries |
| Role and responsibility mapping | Post-market monitoring observations over time |
| Supplier contract and data processing terms | Human oversight intervention records: who stopped what, when, and why |
| Training curriculum design | Competence demonstrated at a point in time, and complaint and escalation data |
Everything in the right-hand column maps to an obligation the Act already contemplates. Record-keeping under Article 12 exists so operation can be reconstructed after the fact. Human oversight under Article 14 is only demonstrable through records of oversight actually occurring. Post-market monitoring under Article 72 is a longitudinal duty by construction: a monitoring system with no history has monitored nothing. Serious incident reporting under Article 73 presumes an internal register that catches incidents before they become reportable ones. The detail of each is on our existing pages, including Article 12 logging and record-keeping, Article 14 human oversight and Article 72 post-market monitoring.
There is a second reason the right-hand column deserves priority, and it has nothing to do with regulators. It is the column an underwriter reads. AI liability cover is written on a claims-made basis, which means the period before a policy incepts is the period an insurer cannot see and therefore prices conservatively or excludes. Records covering that period are what change the terms. The mechanics are set out on agentinsured.eu, on retroactive dates and prior acts, and the change history specifically is treated as certification evidence on agentcertified.eu.
What did not move, including two dates this year
The deferral is narrower than the headlines suggested, and two obligations land before the end of 2026.
Article 5 prohibited practices have applied since 2 February 2025. General-purpose AI model obligations have applied since 2 August 2025. Article 50 transparency duties applied from 2 August 2026 and were not deferred by the Omnibus; the one relief is a transitional period for the machine-readable marking obligation in Article 50(2), applying to systems already on the market before 2 August 2026, which runs to 2 December 2026. The Article 4 AI literacy duty was amended rather than repealed, with the mandating of a specific level removed and the obligation retained, and supervision commenced on 2 August 2026. Since that date the transparency and governance rules apply and the AI Office together with the Member State authorities hold responsibility for implementing, supervising and enforcing the Act.
Separately from the AI Act entirely, the revised Product Liability Directive, Directive 2024/2853, must be applied by Member States from 9 December 2026. That instrument was never part of the Omnibus and its date has not moved. For a deployer, the December 2026 cluster is therefore real, close, and frequently absent from plans that were rebuilt around December 2027. Our reading of what lands then is at what lands on 2 December 2026, and the double-exposure analysis is at the AI Act and Product Liability Directive together.
A sequence for the fifteen months remaining
What follows assumes an organisation that had a programme running before August and has now slowed it. The ordering principle is simple: structural and forward-only work first, interpretive work last, because interpretation is the part most likely to be revised by guidance and standards arriving between now and December 2027.
Phase 0, now to end of October 2026. Switch on the recorders. Interaction logging with retention set deliberately rather than by default. A dated change history covering prompts, system instructions, model versions, inference parameters, tool permissions, retrieval sources, guardrail configuration and escalation thresholds. An incident register with a low enough bar that small entries actually get made. One routine monitoring observation per system, however simple, recorded on a schedule. This phase is days of engineering work, not quarters, and it is the only phase whose value degrades every week it is delayed.
Phase 1, November 2026 to January 2027. The December cluster. Article 50 disclosure and marking, including the end of the Article 50(2) transitional period on 2 December 2026 for systems already on the market. Product Liability Directive readiness ahead of 9 December 2026, which for most deployers means understanding where in the chain they sit and what their supplier contracts say about defect and recourse rather than building anything new. Our Article 50 guidance is at Article 50 transparency and labelling.
Phase 2, first quarter 2027. Inventory, classification and the supplier conversation. A complete inventory of AI systems with named owners comes before classification, because classifying an incomplete inventory produces confident conclusions about the wrong set of systems. Then classification against Annex III, documented with its reasoning so it can be revisited when guidance moves. In parallel, open the supplier conversation, because your Article 26 file rests substantially on provider technical documentation and contract renegotiation windows are measured in quarters. See the Annex III sector guide and Article 25 value chain responsibilities.
Phase 3, second quarter 2027. The operator file. Article 26 deployer obligations assembled as a single producible file. A fundamental rights impact assessment where Article 27 applies. Human oversight design under Article 14 documented as a design rather than as a policy statement, naming who intervenes, in what window, with what authority. See the Article 26 guide and the Article 27 guide.
Phase 4, third quarter 2027. Test what you built. Validate that logging captures what Article 12 contemplates rather than what was convenient to instrument. Rehearse the serious incident reporting path under Article 73 against a hypothetical, including who decides and how fast. Confirm that the monitoring record produced by Phase 0 actually supports a conclusion rather than merely existing.
Phase 5, October to November 2027. Dry run. Have someone outside the programme request the file as a supervisor or a customer would, with a deadline, and see what comes back. The gaps found in a dry run are almost always retrieval and coherence problems rather than missing work, and they are cheap to fix in November 2027 and expensive to discover in January 2028.
A note on who will be asking
One structural fact should shape how the evidence is written. As at the position re-read at national sources on 17 August 2026, a majority of Member States had not completed formal designation of their market surveillance authorities, and that group included several of the largest economies. Some have designated by statute, some by government decision, some have named an interim lead with a limited mandate, and some have a bill in committee. Our running position is in the Member State implementation tracker, and the enforcement architecture is described at the AI Office and national supervisors.
The practical consequence is that tuning an evidence pack to the anticipated style of a particular authority is not available as a strategy, because in many jurisdictions the authority is not yet in final form and its published expectations do not exist. That is not a problem. It points at the right approach anyway, which is to build evidence that answers the obligation on its own terms. Evidence that satisfies the text satisfies whichever body eventually reads it, and it also satisfies the customer, the auditor and the underwriter who will ask the same questions sooner and without waiting for a designation.
The argument to take to a budget meeting
Programmes are not usually stood down by a decision. They are stood down by a deadline moving and nobody arguing for the budget. The argument, compressed to what fits in a meeting, is three sentences.
The deferral moved the date by sixteen months and did not reduce the work. Most of the work can move with the date, and one part cannot, because it is a record that has to have been running rather than a document that has to be written. Keeping the recorders on costs a fraction of the programme and is the only part of it that becomes impossible to buy later.
Everything else in a readiness programme is genuinely a candidate for deferral, and deferring it is a reasonable use of sixteen months. The distinction between those two categories is the entire content of a good 2027 plan, and it is why a programme that keeps a small amount running through the quiet period arrives at December 2027 in a materially stronger position than one that restarts at full budget in the spring.
Questions
How long is the Annex III deferral and when does it end?
Sixteen months. The Digital Omnibus on AI entered into force on 27 July 2026 and moved the Annex III high-risk obligations from 2 August 2026 to 2 December 2027. Annex I obligations, covering AI embedded in products already regulated under Union harmonisation legislation, moved from 2 August 2027 to 2 August 2028. Measured from 21 August 2026, just over fifteen months remain. Nothing else in the Act's calendar moved backwards, and two obligations land before then, in December 2026.
Is it safe to pause an EU AI Act readiness programme until 2027?
Partly, and the distinction matters more than the decision. Documentary evidence such as policies, classification memos, technical documentation and role mapping can be produced at any point, so deferring it costs only the risk of a rush at the end. Operational evidence such as logs, change history, incident registers, monitoring observations and oversight records can only be built forward. Every month those recorders are not running is a month permanently missing from the record a supervisor will eventually look at. Pause the paper if you must. Do not pause the recorders.
What obligations still apply before December 2027?
Article 5 prohibited practices since 2 February 2025. General-purpose AI model obligations since 2 August 2025. Article 50 transparency duties from 2 August 2026, not deferred, with the machine-readable marking transitional period under Article 50(2) ending 2 December 2026 for systems already on the market. The Article 4 AI literacy duty was amended rather than repealed and supervision commenced 2 August 2026. Separately from the AI Act, the revised Product Liability Directive must be applied by Member States from 9 December 2026.
Which single thing should a deployer do first?
Switch on the recorders this quarter, before any policy work. Interaction logging, a dated change history for prompts, model versions, tool permissions and thresholds, an incident register that accepts small entries, and a routine monitoring observation. These are inexpensive, take days rather than quarters, and are the only artefacts whose value depends entirely on when they were started. Everything else can be written in 2027. None of these can be written in 2027 about 2026.
Does it matter that many Member States have still not designated their supervisor?
It matters for planning rather than for exposure. As at the position re-read at national sources on 17 August 2026, a majority of Member States had not completed formal designation of their market surveillance authorities, including several of the largest economies. For a deployer this argues against tuning an evidence pack to the expected preferences of a specific authority, because in many jurisdictions that authority does not yet exist in final form. Build evidence that answers the obligation, and the designation question resolves itself.
Will the December 2027 date move again?
This desk does not forecast legislative outcomes and will not state a probability. What can be said is what the plan should assume, and the answer follows from the same asymmetry the article is built on. Operational evidence is worth building regardless, because it serves customers, auditors and insurers on their own timetables, none of which is set in Brussels. Interpretive and documentary work is the part exposed to a further change of date, which is a further reason to sequence it late rather than early.
Related analysis
- The Digital Omnibus in force: what changed for deployers. The master brief on what moved and what did not.
- What lands on 2 December 2026. The date cluster inside the deferral window.
- Member State implementation tracker. Where each of the 27 stands, verified at national sources.
- Prompt change control as certification evidence. agentcertified.eu. What a defensible change history contains.
- The deadline moved. Do I still need cover? insureyouragent.com. The same question in the SME register.
Sources
- Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force 27 July 2026. Annex III obligations from 2 December 2027, Annex I from 2 August 2028; transparency and governance rules apply from 2 August 2026. European Commission, AI Omnibus enters into force, checked 17 August 2026.
- European Commission, AI Act Service Desk. Timeline for implementation of the EU AI Act, checked 17 August 2026. Source for the 2 February 2025, 2 August 2025, 2 August 2026, 2 December 2026, 2 August 2027, 2 December 2027 and 2 August 2028 dates.
- Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence, OJ L, 12.7.2024. Articles 4, 5, 12, 14, 25, 26, 27, 50, 72 and 73.
- European Commission. AI literacy: questions and answers, checked 17 August 2026. Source for the amendment to Article 4, the removal of a mandated level, the continuing obligation, and the commencement of supervision on 2 August 2026.
- European Commission. Regulatory framework for AI, checked 17 August 2026. Source for the statement that from 2 August 2026 the transparency and governance rules apply and the AI Office and Member State authorities are responsible for implementation, supervision and enforcement.
- Directive (EU) 2024/2853 on liability for defective products, OJ L, 18.11.2024. National transposition deadline 9 December 2026. Not amended by the Digital Omnibus.
- Member State designation status as re-read at national sources on 17 August 2026 and recorded in the Member State implementation tracker. Entries not carrying a verification date in that tracker rest on the earlier April 2026 position and should be treated as a lead rather than a finding.