Skip to main content
Should You Delay High-Risk AI Compliance?EU AI Act & GPAI
5 min readFor Legal & Compliance Officers

Should You Delay High-Risk AI Compliance?

The European Commission's November 19 omnibus package suggests delaying regulation of high-risk AI systems under the EU AI Act. For compliance officers, this isn't just a legislative update, it's a strategic decision point. Do you continue with full compliance preparations, or wait to see how the delay reshapes your obligations?

This decision affects resource allocation, vendor contracts, documentation timelines, and your organization's risk exposure. Here's how to approach it.

The Decision You're Facing

You're managing AI systems that would fall under the EU AI Act's high-risk classification, like credit scoring models, hiring algorithms, or medical diagnostic tools. The proposed delay creates three possible paths:

  1. Continue building toward full compliance as if the delay won't happen.
  2. Pause compliance work until the regulatory timeline clarifies.
  3. Pursue a hybrid approach that maintains momentum on foundational controls while deferring system-specific work.

Each path carries distinct risks and resource implications.

Key Factors That Affect Your Choice

Your deployment timeline matters most. If you're planning to deploy or significantly update high-risk systems in the next 12-18 months, regulatory uncertainty doesn't eliminate your exposure, it amplifies it. A delay that gets reversed mid-implementation leaves you scrambling.

Your current documentation baseline is critical. Organizations that already maintain Technical Documentation (Annex IV) equivalents for other frameworks, like SR 11-7 model Validation Evidence or ISO/IEC 42001 documentation, face lower switching costs. If you're starting from scratch, the delay might seem like a reprieve. It's not, it's a window to build foundations before hard deadlines hit.

Your market positioning determines strategic value. Early compliance signals assurance to enterprise customers and regulators. If your competitors are treating the delay as permission to slow down, your readiness becomes a differentiator.

Regulatory trajectory in your sector. Financial services and healthcare face overlapping requirements from sector-specific regulators. A delay in the AI Act doesn't pause your obligations under existing frameworks. Your decision tree needs to account for the tightest constraint, not the most lenient one.

Path A: Full Speed Ahead

Choose this if:

  • You're deploying high-risk systems within 18 months.
  • You operate in regulated sectors (finance, healthcare, critical infrastructure) where model risk management is already mandatory.
  • You serve enterprise customers who conduct vendor AI audits.
  • You've already allocated budget for compliance infrastructure.

What this looks like in practice:

Build your risk management system now. Implement conformity assessment processes even if the formal requirement date shifts. Document your training data provenance, establish human oversight protocols, and create audit trails for model updates.

You're not just checking boxes, you're building operational resilience. When a credit model fails in production, your incident response doesn't wait for regulatory clarity. Your Data Protection Impact Assessment process doesn't pause because Brussels is negotiating timelines.

The upside: You're audit-ready regardless of when enforcement begins. You can respond to customer due diligence requests with evidence, not promises. If the delay gets reversed or shortened, you're not caught in a compliance sprint.

The risk: You invest resources in controls that might face revised requirements. The omnibus package could reshape specific obligations, making some of your early work obsolete.

Path B: Strategic Pause

Choose this if:

  • Your high-risk systems won't deploy until late 2026 or beyond.
  • You're a small or mid-sized provider without existing model risk infrastructure.
  • Your budget for compliance is constrained and needs to be deployed tactically.
  • You operate outside sectors with parallel regulatory requirements.

What this looks like:

Freeze system-specific compliance work. Don't commission Technical Documentation (Annex IV) for systems still in development. Don't finalize conformity assessment contracts with notified bodies. Don't build post-market monitoring infrastructure for products that won't launch soon.

But don't go dark entirely. Monitor the omnibus negotiations. Track how member states respond to the proposed delay. Maintain relationships with legal counsel who can alert you when the regulatory timeline solidifies.

The upside: You preserve resources and avoid building to a moving target. If the delay extends or requirements change substantially, you haven't locked yourself into outdated approaches.

The risk: If the delay doesn't materialize or gets shortened, you face compressed timelines. Vendor capacity for conformity assessments could become constrained as everyone rushes to comply simultaneously. Your competitors who kept building might have market advantages.

Path C: Foundations Now, Systems Later

Choose this if:

  • You have a mixed portfolio of high-risk systems with staggered deployment dates.
  • You need to balance resource constraints with strategic positioning.
  • You're building AI capabilities that will eventually require compliance, but aren't deployment-ready yet.
  • You want optionality as the regulatory landscape clarifies.

What this looks like:

Invest in the infrastructure that's valuable regardless of regulatory timing. Build your AI Management System framework. Establish data governance processes that improve model quality independent of compliance. Create model inventory and risk tiering processes. Train your teams on risk assessment methodologies.

Defer the system-specific work that's purely compliance-driven: detailed Technical Documentation (Annex IV) for systems not yet deployed, formal conformity assessment procedures, CE marking preparations.

This path treats compliance as a byproduct of good AI risk management, not as a separate workstream. You're building capabilities that serve operational excellence first and regulatory readiness second.

The upside: You maintain momentum without overcommitting resources. Your foundational work transfers across regulatory changes. You can accelerate system-specific compliance when timelines clarify.

The risk: You might underestimate the effort required to scale from foundations to full compliance. The gap between "good practices" and "documented, auditable controls" is wider than it appears.

Summary Matrix

Factor Path A: Full Speed Path B: Pause Path C: Foundations
Best for Imminent deployments, regulated sectors Distant timelines, constrained budgets Mixed portfolios, strategic positioning
Resource intensity High upfront Low near-term Moderate sustained
Regulatory risk Low High if delay shortens Moderate
Market advantage Immediate None Building
Flexibility Low, committed to current requirements High, can pivot to final rules Moderate, foundations set, details flexible

The proposed delay doesn't eliminate your need for AI governance, it tests whether you're building compliance theater or operational resilience. Choose the path that aligns your regulatory obligations with your actual risk exposure, not the one that feels easiest in the moment.

You Might Also Like