EU AI Act Duties Already Binding Now

Deferred Is Not Cancelled: What the EU AI Act Already Requires While Everyone Waits for 2027

Introduction

A political agreement pushing the EU AI Act’s high-risk obligations out to December 2027 has led a lot of organisations to file the whole regulation under “next year’s problem.” That reading is wrong, and it is wrong in a way that creates real exposure. The deferral covers one specific chapter of the Act. Several other obligations were never touched by it, and some of them are already in force.

Confusing a targeted delay with a general reprieve is an easy mistake to make when headlines simplify “AI Act rules delayed” without the qualifier attached. The practical risk is an organisation that quietly stops preparing altogether, only to discover that the provisions still binding it, transparency duties, prohibited practices, and obligations on general-purpose AI providers, were never part of the postponement. This article sets out what the deferral actually covers, what it leaves untouched, and what that means for AI governance work that should already be underway.

Takeaway 1: Only Chapter III high-risk system obligations were deferred, not the whole Act. Annex III standalone high-risk systems move to December 2027 and Annex I embedded systems to August 2028, while other chapters proceed on their original timeline.

Takeaway 2: Transparency obligations under Article 50 were not delayed and are already active. Disclosing AI interaction and labelling AI-generated content are current obligations, not future ones.

Takeaway 3: Obligations on general-purpose AI model providers were untouched by the deferral. Documentation, transparency and safety duties for these providers have applied since before the high-risk delay was even proposed.

Takeaway 4: Prohibited AI practices remain banned regardless of the high-risk timeline. The deferral affects when high-risk systems need conformity assessment, not whether unacceptable-risk practices are permitted.

Takeaway 5: Governance infrastructure built now for transparency and documentation carries forward into high-risk readiness later. Waiting for the 2027 deadline to start means rebuilding the same capability twice, under more pressure the second time.

Executive Summary

The Digital Omnibus amendment to the EU AI Act deferred the application of high-risk system obligations, currently to December 2027 for standalone systems and August 2028 for systems embedded in regulated products, in response to unfinished technical standards and guidance. That deferral is real and specific: it applies to Chapter III. It does not touch the Act’s prohibited-practice bans, its obligations on providers of general-purpose AI models, or its transparency requirements around AI-generated content and AI interaction disclosure, several of which are already binding. For organisations building AI governance programmes, the practical implication is that the 2027 date is the wrong deadline to plan around if the goal is treating every AI Act obligation as still-pending. Some of it already applies now.

What the Digital Omnibus Actually Deferred

The deferral mechanism was introduced specifically because the technical standards and conformity assessment tools needed to operationalise high-risk system obligations were not ready in time for the original schedule, not because the underlying policy goals changed.

A Targeted Delay to Chapter III, Not a Reset of the Act

The postponement applies to the specific obligations that fall on high-risk AI systems under Chapter III: conformity assessment, technical documentation, and the fuller compliance regime that Annex III and Annex I systems are subject to. Everything outside that chapter, prohibitions, general-purpose model obligations, transparency duties, proceeds on the timeline the Act originally set, unaffected by the political agreement that moved the high-risk dates.

Backstop Dates Exist Precisely Because Standards Are Still Catching Up

The new dates function as backstops: high-risk obligations apply once the necessary standards and guidance are confirmed as ready, with December 2027 and August 2028 as the outer limits regardless. This framing matters, because it signals regulators expect organisations to keep preparing during the extension rather than treat it as an open-ended pause.

What Is Already in Force, Deferral or Not

Several obligations sit outside Chapter III entirely and have applied, or begun applying, on their original schedule.

Prohibited Practices Have Been Banned From the Start

The Act’s ban on unacceptable-risk AI practices took effect on its own early timeline and was never part of the high-risk deferral discussion. An organisation using or building a prohibited AI application is not waiting for 2027 to be out of compliance. It already is.

General-Purpose AI Model Obligations Predate the Deferral Entirely

Providers of general-purpose AI models have been subject to documentation, transparency and safety obligations since before the Digital Omnibus was even proposed. These obligations continue unmodified, meaning any organisation relying on general-purpose models, which by now is most organisations using AI in some form, sits under requirements that were never on the table for delay.

Transparency and Disclosure Duties Are Live Now

Requirements that people be told when they are interacting with an AI system, and that AI-generated audio, image, video or text carry a machine-readable indication of its origin, applied on the Act’s original schedule and were not moved by the Omnibus. An organisation deploying a customer-facing AI system without addressing these duties is not in a grace period.

Why Treating the Delay as a Pause Costs More Later

An organisation that stops all AI governance work because “the deadline moved to 2027” is making two mistakes at once: ignoring the obligations that never moved, and discarding groundwork that would have made the eventual high-risk deadline easier to meet.

Documentation and Logging Built Now Are Not Wasted Work

The record-keeping, access control and audit capability that high-risk systems will eventually need under Chapter III overlaps substantially with what transparency and general-purpose model obligations already require. Building that capability now, in response to obligations already active, means the eventual high-risk compliance work starts from an existing foundation rather than from nothing.

The 16-Month Extension Is a Planning Window, Not a Holiday

Regulators granted the delay because implementation tools were not ready, not because they concluded organisations needed less preparation time overall. Treating the extension as time to relax invites exactly the compressed, last-minute scramble the deferral was meant to prevent.

Building AI Governance Around What Actually Applies Today

The practical starting point is separating the AI Act obligation calendar into what is live now, prohibited practices, general-purpose model duties, and transparency and labelling requirements, and what is on a backstop timeline extending into 2027 and 2028. Governance work should be prioritised against the first list immediately and designed so it extends naturally into the second, rather than waiting for a deadline that, for most organisations already using AI in some form, is not actually the one that matters most right now.

How a Data Control Plane Supports AI Governance Obligations Already in Force

Meeting the transparency, documentation and access-governance obligations that already apply, and building toward the ones still to come, both depend on the same underlying capability: knowing exactly what data an AI system or agent touched, under whose authorisation, and being able to produce that record on demand.

The Kiteworks Data Control Plane applies data-aware, zero-trust controls to every action any user or AI agent takes across every channel, including email, file sharing, APIs and AI agents themselves, and captures each one in a tamper-proof, unthrottled audit log that feeds directly into SIEM tooling. Because logging is complete and never sampled, organisations can produce the detailed, queryable record of AI-related data access and activity that current transparency and documentation obligations expect, and that eventual high-risk system requirements will expect in more detail still. Governance built on this foundation now does not need to be rebuilt when the 2027 and 2028 backstop dates arrive.

Organisations that want to see how continuous, cross-channel evidence supports their current AI governance obligations can schedule a custom demo to walk through how it applies to their own AI deployments.

Frequently Asked Questions

Only the high-risk system obligations under Chapter III were deferred, moving to December 2027 for standalone Annex III systems and August 2028 for Annex I embedded systems. All other chapters and obligations remain on their original timelines.

Prohibited AI practices remain banned, general-purpose AI model providers must meet documentation and transparency duties, and Article 50 transparency requirements for disclosing AI interactions and labeling generated content are already active.

Organizations must inform users when they are interacting with an AI system and ensure AI-generated audio, images, video, or text carries machine-readable labeling, as these duties were never postponed and are currently binding.

Many obligations are already active, and the documentation, logging, and access controls developed for transparency and general-purpose model requirements overlap with future high-risk needs, avoiding duplicated effort and last-minute compliance pressure.

Get started.

It’s easy to start ensuring regulatory compliance and effectively managing risk with Kiteworks. Join the thousands of organizations who are confident in how they exchange private data between people, machines, and systems. Get started today.

Share
Tweet
Share
Explore Kiteworks