Opinions

The Next EU AI Act Milestone – What It Is And What’s Missing

Outside of regulation, trust, safety and accountability matter from both a moral and commercial perspective.

Share this article

Share this article

Outside of regulation, trust, safety and accountability matter from both a moral and commercial perspective.

Opinions

The Next EU AI Act Milestone – What It Is And What’s Missing

Outside of regulation, trust, safety and accountability matter from both a moral and commercial perspective.

Share this article

Since 2 August 2026, organizations are fully subject to Article 50 transparency requirements. In simple terms, that means users must be told when they are interacting with an AI system, and certain AI-generated or AI-manipulated content must be labelled as such. The principle is important; if people are engaging with AI, or consuming content created or altered by it, they should know. And, since transparency is the basis of trust, it is a significant and necessary step for the future of AI.

But while Europe can point to 2 August as a milestone, arguably the more important obligations are the ones that have been pushed back.

As part of the EU AI Omnibus, mandatory compliance for high-risk systems has been postponed. The new application dates are 2 December 2027 for stand-alone high-risk AI systems, and 2 August 2028 for high-risk AI systems embedded in products. Those delays matter because they tell us that however strong the rhetoric around AI regulation has been, the reality is that when rules become commercially and operationally difficult, they can slip, with troubling, unintended consequences.

Why deadlines might shift again and why shifts are problematic

The EU AI Act is widely regarded as the world’s first comprehensive legal framework specifically regulating artificial intelligence, and that is something to be celebrated. AI regulation is long overdue, and we are playing catch-up with a technology that is developing at pace.

Nevertheless, the postponement of the high-risk deadlines shows how hard the AI regulation challenge really is. Europe has often been positioned as the global leader in AI regulation, and it has unquestionably moved faster than many jurisdictions in turning AI governance into a legal framework. Nevertheless, I suspect the EU AI Act timelines may shift again. This might be because of more commercial pressures from ‘big tech’ or evolution to the rules through additional guidance, practical exemptions and implementation compromises.

Some of these changes might be unavoidable, but changing timelines come with the risk of building indifference. Put simply, organizations mistakenly believe that since legislation is delayed, so are their obligations.

It is often these organizations that think compliance alone is the answer and believe the rules governing AI to be a conventional regulatory exercise. They want to know the rule, implement the control, tick the box and move on. That may work in areas where the risk profile stays reasonably stable over time, but it doesn’t work for AI.

Firstly, AI is developing at an extraordinary pace. The models and capabilities that we are regulating for now will be obsolete in the coming years, if not months. Not only that, but AI systems also change in production; models drift, contexts shift, inputs change, and outputs evolve.

A system that appeared safe and well-governed at launch can become a source of bias, error, reputational harm or regulatory exposure later on. That is why point-in-time compliance is not enough. It may satisfy an audit process or a procurement checklist, but it tells you very little about how an AI system is behaving after deployment.

The question is not simply whether your model met a requirement on a particular day. It’s whether you can prove, on an ongoing basis, that it is behaving as intended, that deviations are detected quickly, and that risk is being managed continuously rather than retrospectively.

This why continuous monitoring is an important aspect of AI governance. It is the difference between assuming your controls are working and being able to prove they are. It allows enterprises using AI to detect deviations, identify emerging risk and respond before issues escalate into customer harm, reputational damage or regulatory scrutiny. In doing so, it aligns governance with how AI actually behaves: dynamically, not statically.

Getting ahead of compliance is key

For enterprises deploying AI and the developers designing it, the lesson is that while legal deadlines may move, the underlying risks do not. We regularly see stories of businesses that have lost data, been sued and had their reputations damaged as a result of their AI acting in unintended ways. For developers and vendors, this leads to an important commercial imperative. Enterprises are moving from AI experimentation to deliberate deployment, and many procurement teams now require assurance that AI can be deployed safely.

Continuous monitoring is the missing piece of the puzzle. The practical reality is that once AI is live, what matters most is whether you can see what it is doing and respond when it starts doing something it should not. Transparency is part of that, but telling someone they are interacting with AI is not the same as ensuring that the AI is robust, accountable and behaving safely over time.

2 August 2026 is an important transparency deadline, and one that organizations should take seriously. It is the next milestone in significant regulation, which should be celebrated as the first comprehensive legal framework for AI. Regulation is fundamental because it sets the standard and defines very clearly what is expected of those building and deploying AI and puts the guardrails in place to protect people.

But the bigger lesson for businesses is to avoid the trap of viewing regulation as the only standard. Instead, it’s a baseline, the very minimum that they should be doing. Outside of regulation, trust, safety and accountability matter from both a moral and commercial perspective. Waiting for perfect regulatory certainty is an impossible strategy. By the time it arrives, if it ever does, the systems, the risks and the market will already have moved on.

Nik Kairinos is CEO and Co-founder, RAIDS AI

Related Articles
Get news to your inbox
Trending articles on Opinions

The Next EU AI Act Milestone – What It Is And What’s Missing

Share this article