The EU AI Act's Big Deadline Just Moved, That's Not the Same as a Pause

Written by Martin Hulbert, Chief Technology Officer, Ignite Technology

If you were bracing for the EU AI Act’s high-risk AI obligations to land this month, they didn’t. The Digital Omnibus on AI pushed the deadline for high-risk AI systems under Annex III back from August 2026 to December 2027. That covers most of what an enterprise deploying AI agents in employment decisions, credit, and insurance assessments, or critical infrastructure would actually fall under.

While this deadline move is genuinely useful to know, it isn’t is a reason to slow anything down.

What Actually Changed

The Digital Omnibus deferred the obligations under Annex III, things like risk management systems, bias-checked data governance, automatic logging, human oversight capability, and fundamental rights impact assessments. The requirements themselves haven’t changed, only the date they become enforceable has moved, and it moved because the harmonised technical standards regulators need weren’t ready in time, not because the obligations themselves were reconsidered.

What Still Applies From August 2026 – Article 50

One part of the Act wasn’t touched by the delay at all. Article 50 transparency duties took effect on 2 August 2026 and apply regardless of whether a system counts as high-risk. Anyone deploying an AI agent that interacts with customers or staff has to disclose that it’s AI, unless that’s already obvious from context. Any AI-generated content needs a machine-readable marker showing its artificial origin. Deepfakes and manipulated media require disclosure. Systems using emotion recognition or inferring sensitive biometric attributes have to inform the people exposed to them.

For any organisation running a customer-facing or employee-facing AI agent, that’s a live obligation today, not a 2027 planning item.

Why the Extra Time Isn’t Licence to Wait

December 2027 sounds distant enough to shelve, it isn’t, for one simple reason. The controls the Act eventually requires, tested risk management processes, real audit trails, human oversight that actually functions under load, take months to build properly and longer to prove out under real operating conditions. An organisation that starts now arrives at the new deadline with governance that’s been running long enough to trust. An organisation that waits arrives with the same sixteen months compressed into a scramble.

It’s also worth remembering the deferral only touched Annex III and Annex I. Prohibited practices have been enforceable since February 2025. General-purpose AI model obligations, the rules covering the underlying models most AI agents are built on, took effect in August 2025 and were never part of this delay.

Where Broadcom Automic Already Does This Work

Broadcom redefined its Automic platform this year specifically to act as an intelligent control plane for enterprise AI. Several of Automic Version 26‘s features map directly onto what the EU AI Act is asking for.

Automic v26 introduces a dedicated agentic AI job type that wraps AI decision-making in rigorous, audit-ready object definitions, enforcing role-based access control, logging, and security protocols on every autonomous action from the start, not added afterwards. That’s the audit trail and access control layer the Act’s high-risk obligations will require by December 2027, already built into the platform doing the automation.

Its bring-your-own-model architecture lets organisations route routine automation to public models while keeping sensitive operational workloads inside self-hosted, private models, a real control for anything touching the categories the Act treats as high-risk. And its policy-bounded framework for agentic execution reflects the same guardrails-before-autonomy principle behind the Act’s human-oversight requirement, whatever language Broadcom itself uses for it.

Broadcom didn’t build or market v26 as EU AI Act compliance software. But the underlying architecture, audit-ready objects, role-based access control, model isolation, policy boundaries, is exactly what regulatory-grade agentic AI governance requires in practice. Ignite has spent 20-plus years implementing this platform inside the regulated industries the Act’s high-risk categories describe, which is a different starting point than approaching this compliance work with no platform history at all.

Your Next Steps

If your organisation runs Agentic AI agents that talk to customers or staff, check today whether they disclose that they’re AI and whether generated content carries the right markers. That’s a live legal requirement now, not a future one.

Get in touch through the form below and we’ll walk through exactly where you stand.

Frequently Asked Questions for the EU AI Act Deadline Change

The high-risk AI system obligations under Annex III (covering employment, credit and insurance, critical infrastructure, education, and public sector use cases) moved from 2 August 2026 to 2 December 2027. Annex I obligations, covering AI embedded in regulated products like medical devices, moved from August 2027 to August 2028.

Prohibited practices since February 2025, general-purpose AI model obligations since August 2025, and Article 50 transparency duties since August 2026. None of these were affected by the Digital Omnibus deferral.

No. General-purpose AI model obligations already took effect on 2 August 2025 and weren’t part of this deferral.

No single platform does that on its own. V26 gives you the audit-ready job structures, access controls, and policy boundaries that regulatory-grade governance depends on, but configuring those correctly for your specific use cases and regulatory obligations is implementation work, not a setting you switch on.

No. The obligations that were deferred still have to be met eventually, and building real governance, not just a compliance checklist, takes longer than most organisations expect. Starting now is what makes the December 2027 deadline manageable rather than a scramble.