AI & Agentic Solutions

Production AI and agents on AWS and Azure

Agentic AI & AI Agents

Build AI agents that act on your systems, with guardrails built in.

Generative AI on Amazon Bedrock

Secure generative AI applications inside your AWS environment.

AI Solutions on Microsoft Foundry

Enterprise AI on Microsoft Foundry and Azure OpenAI.

RAG & Enterprise Knowledge Assistants

Accurate, cited answers from your own documents and data.

AI Platform Foundations & LLMOps

Run AI in production with DevOps discipline.

Data & ML Platform Engineering

Design and build scalable data and ML platforms for analytics and AI workloads

Cloud Architecture & Data Platform Engineering

Design scalable cloud and data platforms that last

Cloud Platform Foundations

Establish secure, scalable cloud landing zones and core platform services

Cloud Strategy & Architecture Reviews

Assess cloud architectures to improve scalability, security, and cost efficiency

Cloud-Native Application Architecture

Design modern, resilient application architectures for cloud-native environments

Hybrid Cloud & Migration

Design, modernise, and operate hybrid and on-prem infrastructure

Hybrid Cloud & Migration

Enterprise-ready hybrid infrastructure, built for scale

DevOps, CI/CD & Infrastructure Automation

Automate infrastructure and delivery pipelines with confidence

DevOps, CI/CD & Infrastructure Automation

Automate delivery. Reduce risk. Scale with confidence.

Cloud Cost Optimisation & FinOps

Control cloud spend with clear visibility and governance

Cloud Cost Optimisation & FinOps

Engineering-led cost optimisation with real, measurable savings

Back to Blogs

EU AI Act: High-Risk Deadlines Move to December 2027. What to Do With the Time

The EU has pushed back the date on which its rules for high-risk AI systems begin to apply. For teams building AI that will be used in the EU, including teams outside it, the extra time is welcome. It is worth spending well.

What changed

The AI Omnibus entered into force on 27 July 2026. Under it, the rules for high-risk AI systems listed in Annex III now apply from 2 December 2027, and the rules for high-risk AI built into regulated products (Annex I) apply from 2 August 2028. The Omnibus also extends simplified compliance measures to small mid-cap companies, widens access to regulatory sandboxes and adds a prohibition on generating non-consensual intimate content. Obligations for general-purpose AI models, which have applied since 2 August 2025, are not changed by the delay.

Why the delay is not a pause

Delay does not mean the work goes away. High-risk obligations are about how AI systems are built and run: documented risk management, data governance, logging, human oversight, accuracy and robustness. Those are engineering properties that are far cheaper to design in than to retrofit.

Is your system in scope?

Annex III of the Act lists eight areas where AI systems are treated as high-risk: biometrics; critical infrastructure; education and vocational training; employment, workers’ management and access to self-employment; access to essential private and public services and benefits; law enforcement; migration, asylum and border control management; and the administration of justice and democratic processes. Whether a particular system falls into one of them depends on what it is intended to do, so check the text of the Act or take legal advice for your own case.

For systems that are in scope, Articles 9 to 15 set out the requirements: a risk management system, data and data governance, technical documentation, record-keeping, transparency and information for deployers, human oversight, and accuracy, robustness and cybersecurity. These are the areas the practical steps below are meant to prepare for.

Five practical steps

  1. Inventory your AI systems. List every model, agent and AI feature in use, who owns it, and what decisions it influences.
  2. Classify by risk. Work out which systems might fall under the high-risk categories, and involve legal advisers early.
  3. Make systems traceable. Versioned prompts and models, audit logs and monitoring give you the evidence that regulators and customers will ask for.
  4. Evaluate continuously. Automated tests for quality, bias and safety, run in your delivery pipeline, turn compliance from a one-off project into a routine.
  5. Design for human oversight. Decide where a person reviews or approves an AI-driven action, and build that step into the workflow.

Where we can help

Much of this is platform work: AI-ready landing zones, evaluation pipelines, observability and governance controls. Our AI Platform Foundations & LLMOps service builds exactly those foundations as code.

This article is general information, not legal advice. Check the final text of the regulation and take advice for your own situation.

Sources: European Commission, “AI Omnibus enters into force”; Gibson Dunn analysis of the EU AI Act Omnibus agreement. Also: EU AI Act, Annex III; EU AI Act, Chapter III Section 2 (Articles 8 to 15).

Leave a Comment

Your email address will not be published. Required fields are marked *

Share

LinkedIn icon