Brussels has provisionally deferred the EU AI Act's high-risk obligations to December 2027. Irish boards treating that as a reprieve are reading the wrong signal.
In early May, EU legislators reached a provisional agreement to push the most demanding parts of the AI Act — the obligations attached to high-risk systems — from 2 August 2026 out to 2 December 2027. Member State representatives confirmed the position in Council on 13 May. For AI embedded in regulated products, the new date is 2 August 2028. Many Irish boards read the headline, exhaled, and moved the item down the agenda.
That is the wrong signal to take from it. The deadline that was supposed to concentrate minds this summer is moving. The exposure it was meant to address is not.
What actually changed, and what did not
The deferral comes from the Digital Omnibus, a package the European Commission tabled on 19 November 2025 to simplify a body of digital rules that was visibly running ahead of Member States' capacity to implement it. The most consequential element is a delay to the high-risk obligations under Annex III — the risk-management systems, data governance, technical documentation, logging, human oversight and conformity assessment that apply to AI used in recruitment, credit decisions, access to essential services and similar consequential settings.
Two things are worth being precise about, because the precision is the point.
First, the delay is not yet law. As of late July 2026 the Omnibus has a provisional political agreement but has not been formally adopted or published in the Official Journal. Formal adoption is expected before the original 2 August deadline, but "expected" is not "enacted." An organisation that has stood down its compliance work is betting its regulatory position on a legislative process that has not concluded.
Second, the rest of the Act is untouched. The prohibited-practice bans have applied since February 2025, carrying the heaviest penalty tier — up to €35 million or 7% of global turnover. The obligations on general-purpose AI models came into force in August 2025. And the machinery around all of it — national market surveillance authorities, the Commission's enforcement toolkit, and the penalty regime itself — was never part of the deferral. What slipped is one deadline for one category of system. What remains is the entire enforcement architecture.
The enforcement teeth arrive on schedule
Here is the part that gets lost when a deadline moves. From August, the penalty provisions and the enforcement powers over general-purpose AI become operational, and transparency obligations under Article 50 — the requirement to tell people when they are interacting with AI or looking at AI-generated content — sit with national authorities to enforce. The maximum exposure for those breaches is €15 million or 3% of worldwide turnover.
The European AI Office has already moved from writing guidance to opening inquiries, and national authorities in several Member States have begun formal investigations. Ireland, like every Member State, must designate the authorities that will police this domestically. The direction is unambiguous: the supervisory capacity is being built out, not wound down.
So the practical position for an Irish organisation is this. The one deadline you may have been counting down to has probably moved. Every other obligation is live, the penalty regime is live, and the regulators charged with enforcing it are staffing up. A board that reads "delay" and hears "stand down" has misjudged the risk in both directions.
Why a moving deadline is a governance trap
The deeper problem is that most boards were never really preparing for 2 August. They were preparing for a date. And a date is a poor organising principle for a risk you do not yet understand.
The evidence on this is uncomfortable. In recent disclosure analysis, only around a fifth of large listed companies described any board oversight of AI at all, and a similar proportion disclosed a governance framework or policy. More than half of directors, surveyed candidly, concede their board has a genuine skills gap on the subject. The deadline was doing the work that oversight should have been doing — creating urgency in the absence of understanding. Remove the deadline and, for many boards, the urgency evaporates and nothing structural is left behind.
That is the trap. A slipping compliance date is not the same as receding risk. The director's duty to understand what AI is operating inside the organisation, how it reaches consequential decisions, and what happens when it fails, does not move with the Official Journal. Neither does the directors-and-officers exposure that attaches when an oversight failure produces a financial, operational or reputational loss. Those obligations are anchored to Irish company law and to the board's own duty of care, not to a Brussels timetable.
The organisations that will be in a defensible position in December 2027 are not the ones that restart their preparation in mid-2027. They are the ones treating the extra time as room to do the diagnostic work properly rather than as permission to do nothing.
The Acuity AI position
Use the extension for what it is worth. The right response to a deferred deadline is not to close the file and it is not to rush a documentation exercise you will redo in eighteen months. It is to spend the recovered time on the work that holds its value regardless of when the rules bite.
Concretely, that means three things. Build and maintain an inventory of the AI systems actually in use across the organisation — including the AI features quietly arriving inside software you already licence. Classify each against the Act's risk tiers so you know which obligations are merely delayed and which are already live. And establish the oversight mechanism — who owns AI risk, what the board sees, and how incidents surface — because that structure is what the regulator, and a court, will look for first.
None of this depends on the final adoption date, and none of it favours any particular vendor or platform. It is the difference between an organisation that understands its own AI exposure and one that was only ever tracking a calendar.
Our approach starts with diagnosis, not prescription: establish what is actually in place before recommending what to do about it. If your board treated the May announcement as a reason to pause, that is precisely the moment to look again. Contact us to understand where you genuinely stand.