Deferred.
If you saw a headline in the last fortnight saying the EU has delayed its AI rules, you saw half a story. The half that got delayed is the half most businesses were never going to be caught by. The half that started is the one with your name on it.
Both things happened inside a week.
What actually changed
The high-risk regime is the heavy one: quality management systems, conformity assessments, technical files, registration in an EU database. It is a genuine programme of work, and it is the thing that had everybody's compliance budget earmarked for this summer. That has moved by roughly sixteen months.
Article 50 is the light one, and it is almost embarrassingly simple: if a person is talking to an AI, tell them. If your system generates synthetic text, images, audio or video, mark it as machine-generated. That's the bulk of it.
Simple, and now enforceable, and far more widely applicable than the high-risk rules ever were. Annex III catches recruitment, credit scoring, education, essential services. Article 50 catches anyone who put a chatbot on their website.
The bit people get wrong about being British
"We're UK-only" is not the answer people think it is. The Act reaches third countries — which is what the UK now is — where the output produced by the AI system is used in the Union. Not where your company is registered. Not where your servers are. Where the answers land.
A support chatbot on a public website with no geo-blocking will, sooner or later, answer a question for someone in Dublin or Düsseldorf. That is output used in the Union.
I'm not going to tell you that definitely puts you in scope — that's a question for your own advisers, and the honest answer for a lot of firms is still "probably not, in practice". But it is a much narrower escape route than "we don't sell to Europe", and it is worth ten minutes of thought rather than a shrug.
We failed our own test
Here is the part I could have left out.
When the transparency rules landed, we ran them over our own estate — as you'd hope, given we sell this. Our free AI readiness check is a chatbot. It talks to people. Article 50 says those people must be told they're talking to an AI.
It didn't tell them. Worse: buried in the system prompt was an instruction to the model that read, more or less, never say you're an AI. It was written as a style rule — nobody wants a diagnostic that opens with "As an AI language model, I…" — but a style rule written that way is a prohibition on the exact honesty the law now requires. We had told our chatbot not to admit it was a chatbot.
That's fixed. It says so on screen before you type anything, it will tell you plainly if you ask, the generated report is marked as AI-generated in its metadata, and the score now carries a line saying it came from a model and might be wrong.
I'm writing that down publicly for two reasons. It is the fastest way to make the point that this catches ordinary, well-meaning setups rather than only the reckless ones. And an AI governance practice that quietly fixed its own gap and said nothing would be exactly the sort of firm I'd tell you not to hire.
What to actually do
Not a programme. An afternoon.
- List the places a person meets AI in your business. Website chat, phone triage, an assistant in your app, automated replies. This list is usually shorter than people fear and longer than they expect.
- Check each one says so. Before the first message, not in a privacy policy nobody opens. Plain words.
- Check anything generated is marked as generated. Text, images, audio, video — in the file's metadata where it's technically feasible, not just a footnote.
- Write down who owns it. Because the models change, the vendors change, and the setting someone flipped in March will get flipped back.
Then park the high-risk question until you've done step one. If nothing you run looks like the Annex III list, December 2027 is not your deadline anyway.
The reprieve that isn't
The deferral is real and it is welcome — sixteen extra months on the hardest obligations is a meaningful gift to anyone who is genuinely in scope. But there's a trap in it.
The firms most likely to relax are the ones who read "AI Act delayed" and stopped there. They now feel covered, and a rule they've never heard of started applying to them ten days ago. Meanwhile the firms genuinely caught by the high-risk regime have been handed more runway to do work that takes about that long anyway — and runway spent feeling relieved isn't runway.
Deadlines moving is not the same as obligations going away. It rarely is.
