Commentary. Europe’s decision to postpone major parts of its high-risk artificial-intelligence regime is understandable. Companies say they need more time, standards remain incomplete, and smaller developers face compliance costs that can consume resources better spent on improving their products. But the delay also exposes a larger problem: regulation that arrives late, changes often and leaves the public unsure about which protections actually apply.

The European Union’s AI Omnibus, which entered into force in July, moved deadlines for obligations covering high-risk systems to December 2027 and August 2028, depending on the category of system.[1] The changes were presented as simplification and as a way to give companies more room to prepare. That is a legitimate goal. Rules that cannot be understood or implemented are not effective rules.

Our view is that Europe should use this extra time to make the law more workable—not to make it weaker. The distinction matters. A delay can be responsible if it produces clear technical standards, practical guidance and credible enforcement. It becomes an evasion if lawmakers treat business uncertainty as a reason to postpone public safeguards indefinitely.

The case for delay

Businesses have a reasonable argument. The AI Act creates obligations across a rapidly changing technology sector, while many companies still struggle to determine whether their systems fall into regulated categories. Legal and compliance advisers have warned that implementation depends partly on standards and tools that are still developing.[2] Smaller firms, in particular, may lack the staff to document datasets, assess risks and monitor systems in the same way as large technology companies.

A rushed regime could also produce defensive innovation. Companies might avoid useful applications in health, education or public services because the legal consequences are unclear. The Omnibus package aims to streamline requirements, expand testing opportunities and improve consistency with other EU rules.[3] Those are sensible objectives, especially if they help regulators focus on systems that can materially affect people’s safety, rights or access to essential services.

Why the public should remain sceptical

Yet the people exposed to automated decisions do not receive a delay in the consequences of error. A flawed hiring tool can exclude applicants now. An unreliable medical system can influence care now. A synthetic image or deceptive chatbot can mislead audiences before a formal high-risk obligation takes effect.

That is why the EU should preserve the provisions that have not been postponed. Transparency requirements for chatbots, generated content and deepfakes began applying in August 2026, while enforcement powers over general-purpose AI models also became more significant.[4] These measures are not a substitute for high-risk oversight, but they establish a basic principle: people should know when technology is generating or shaping what they see.

The counterargument is that transparency labels can be imperfect, easily ignored or technically difficult to apply. That criticism deserves attention. A label alone cannot correct discrimination, prevent fraud or explain a complex automated decision. But imperfect disclosure is still preferable to deliberate ambiguity. It gives users, journalists, researchers and regulators a starting point for scrutiny.

What should happen next

Europe’s next phase should focus on three commitments. First, regulators should publish plain-language guidance and stable technical standards early enough for companies to build compliance into products rather than retrofit it. Second, enforcement should be proportionate: penalties should deter serious negligence, while good-faith smaller firms should receive support and predictable transition rules. Third, companies should be required to document meaningful testing, incident reporting and human oversight—not merely produce paperwork designed to satisfy an audit.

Europe should also resist the temptation to turn regulatory competition into a race to the bottom. The United States remains fragmented, with states adopting different rules on disclosure, training data and consumer protection.[5] That fragmentation may encourage experimentation, but it can also leave citizens’ rights dependent on geography. Europe’s advantage will not come from having the longest rulebook. It will come from demonstrating that innovation and accountability can coexist.

More time can be useful. It is not, by itself, a policy. The test of the AI delay is whether it produces clearer obligations and stronger public protection by the new deadlines. If it does, Europe will have chosen prudence. If it merely postpones difficult decisions, the cost will be paid by the people least able to challenge automated systems.

Sources