Skip to content

Europe delays high-risk system deadlines and expands the AI Office’s authority

Europe’s package simplifying AI rules has entered into force with later deadlines for high-risk systems and wider testing spaces, without abandoning oversight or bans on harmful uses.

Share
European flags outside a government building

Listen to this article

Read by Anchor

Europe’s compliance map no longer follows the dates on which companies based their plans months ago. On July 27, the European package simplifying AI rules, known as the AI Omnibus, entered into force. It moved the application of requirements for high-risk systems to later dates, while also expanding some testing tools and supervisory authority. The change does not remove the regulatory path, but redistributes time, burden and responsibility between developers and the bodies using the systems.

The delay is room to work, not an exemption from the work.According to the European Commission, the rules for high-risk systems listed in Annex III will apply from December 2, 2027. The rules for high-risk systems embedded in physical products, such as machinery, toys and lifts, will apply from August 2, 2028. This gives organisations more time to build conformity files and test systems, but it does not change the nature of the risks that led these uses to face greater scrutiny in the first place.

The package also extends some simplified arrangements previously reserved for small and medium-sized enterprises to small mid-cap companies. It widens access to regulatory sandboxes, meaning spaces in which AI systems can be tested under the supervision of the competent authorities. It also creates an EU-wide sandbox. For a startup, the practical difference may be the ability to test a regulated product before exhausting its funds on a launch that does not comply with the rules.

Administrative simplification is matched by tighter rules in sensitive areas.The Commission says the package simplifies the registration requirements in the European database for some exempt systems. It also recasts AI literacy requirements so that the Commission and member states take a greater role in promoting them. In return, the package prohibits systems that produce explicit sexual or intimate content without consent, as well as child sexual abuse material. It allows the processing of special categories of data to detect and correct bias, within the legal framework governing that processing.

The broader institutional effect appears in governance. The European AI Office has received extended supervisory powers over specified systems, including those built on general-purpose models and integrated into large platforms and search engines. The Commission says the amendment clarifies the relationship between the AI Act and other European laws, and simplifies procedures for conformity assessment bodies. The point is that a delay in timing does not amount to a retreat from oversight. Some deadlines have moved as part of an effort to make lines of responsibility clearer.

This is a moment of European regulatory sovereignty.The Union is competing not only through models and data centres, but by setting the conditions under which technology must operate in its market. According to the official description, the package seeks to reduce costs for growing companies without abandoning the protection of safety and fundamental rights. The success of that balance will not be measured only by the number of months added, but by the ability of companies and authorities to turn the extra time into auditable testing and documentation processes.

For the Arab region, the stakes are direct for companies developing or deploying systems in Europe and for manufacturers embedding AI in products intended for the European market. They need to update their compliance maps by system type, not treat the news as a general extension that covers everything. Regulators in the region can also read the European experience as a practical test: how can innovation be supported through sandboxes while maintaining a clear prohibition on harmful uses and a central authority capable of follow-up?

The new deadline should produce better evidence.Boards and risk teams should now ask: which systems fall under Annex III? Which products belong to Annex I? What data and tests will be required to demonstrate conformity? The honest answer is not that Europe has simply relaxed its law. What happened is a resetting of the clock, alongside wider routes for experimentation, an adjustment of the administrative burden and preservation of the core oversight.

The package ultimately offers genuine breathing room, particularly for smaller companies, but puts the value of that space to the test. Those that use the time to build a risk record and clear tests will reach the new deadlines in a stronger position. Those that read the delay as an invitation to wait may find that supervisory authority has expanded while their readiness has not moved.

Don't miss the next story

Subscribe for updates