Copy article

EU AI Act delays are a reality check: rushed compliance creates paperwork, not safer systems

ended 31. March 2026

The European Parliament voting to delay key EU AI Act deadlines is being framed as a win for innovation. It is better read as an admission: compressed timelines produce compliance theatre.

High-risk AI obligations are not a form to complete. They are an operating model. If the calendar forces organisations to focus on templates and documentation, the result is predictable. Systems ship, risk controls are generic, and the hardest work is postponed until after the first incident.

At the same time, the move to ban specific harmful applications, such as ‘nudify’ tools, points to the other end of the spectrum: there are cases where the right answer is a line in the sand, not a maturity journey.

The uncomfortable tension is that the EU is trying to do both at once: slow down where implementation is complex, but accelerate where harms are immediate. That is a sensible instinct. It will fail if deadlines become a substitute for evidence. The real question is whether the EU can make ‘high risk’ mean something measurable.

We’d like your views:

  • When does delay improve safety, and when does it simply defer accountability?
  • Which AI risks are best handled by bans versus operating standards?
  • What would count as proof that a high-risk system is controlled, beyond documentation?
  • How should smaller firms comply without creating a market advantage for incumbents?
  • Who should be liable when a high-risk AI product is safe on paper but harmful in practice? The test is whether these rules change behaviour in real deployments, not just in compliance packs.

2 responses from the Newspage community

Copy all

Star Quote
Copy

Delaying the EU AI Act can improve safety, but only if it buys time for real control, not prettier paperwork. Deadlines create panic; panic creates templates; templates create the illusion of governance while the model ships unchanged.

In audits, the difference between ‘compliant’ and ‘controlled’ is operational detail: who can stop a model, who reviews drift, what is logged, what is tested in production, and what happens when it fails. If none of that exists, a risk register is theatre.

Some harms do need bright lines. ‘Nudify’ tools are one: the intent is abuse, so a ban is proportionate. But most ‘high risk’ systems should be regulated like safety-critical operations: measurable performance, traceable decisions, and clear accountability for operators and vendors.

Proof should look like outcomes: fewer incidents, faster containment, and the ability to explain decisions to affected people. If we cannot show that, we have delayed accountability.
Copy

The delay changes the enforcement date. but not what happens when a poorly governed AI system makes a bad call about someone's credit application, hiring outcome, or benefits claim.

The regulators aren't ready either. Even the handful of countries that formed enforcement bodies are behind on the guidance organisations actually need to understand what "high risk" requires in practice. All that's happened is a moving target that got slightly less mobile.

The organisations treating the delay as a reprieve are already accumulating liability. The models are running. The decisions are landing on real people. The enforcement clock being paused doesn't pause the fact that there's a real person on the other end of every high-risk AI decision right now. The customer's risky outcome is certain whether the pen-pushing exercise completes in time or not.