IA 360
Regulatory Framework

Brussels did not suspend the AI Act: it proposed two high-risk clocks

The Commission proposed linking some high-risk obligations to the availability of standards and guidance, with different backstop dates. Reading the proposal requires separating legislative status, category, role, and trigger.

5 min read AI-generated Leer en español
Brussels did not suspend the AI Act: it proposed two high-risk clocks

On November 19, 2025, the European Commission did not itself postpone the Artificial Intelligence Act or set one new date for every high-risk system. It presented a legislative proposal to change the timeline and several implementation rules. The text distinguished systems tied to Annex III uses from systems embedded in Annex I products, with different triggers and backstop dates.

The distinction matters to a person applying for employment, credit, or education and to an organization buying or developing those systems. “Delayed until 2027” mixes a proposal with binding law and hides which obligation, actor, and category is involved. The useful capability is to read any regulatory change through four questions: what is its status, which article does it amend, who does it cover, and what event starts the clock?

A proposal does not yet change an obligation

The Commission’s communication presented the Digital Omnibus as a simplification package covering AI, cybersecurity, and data. But the document’s legal form is “Proposal for a Regulation,” identified as COM(2025) 836 and placed under the ordinary legislative procedure. The European Parliament and the Council therefore had to examine, negotiate, and adopt a text before it could become law.

The first check on regulatory news is the legal verb. “Proposes,” “adopts,” “enters into force,” and “starts to apply” describe different moments. A press conference can announce political intent; proposed articles show the mechanism; publication in the Official Journal establishes the adopted text; and an application date states when an obligation operates. Substituting one stage for another creates mistaken business decisions and public expectations.

The original Act already had more than one timeline

The EU Artificial Intelligence Act classifies two broad groups as high risk. Article 6(1) covers systems that are safety components of certain regulated products, or are those products themselves, when third-party conformity assessment is required. Article 6(2) points to uses listed in Annex III.

Annex III includes areas such as biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice. It does not make every program used in a school or workplace high risk. Intended purpose, influence on a decision, and the Article 6(3) exceptions for narrow, preparatory, or auxiliary tasks that do not pose significant risk all matter. If the system profiles people, the exception does not apply.

The original Act set August 2, 2026 as its general application date, while Article 6(1) and corresponding obligations were to apply from August 2, 2027. Even before the Omnibus, there was no single day for everything called high risk. A compliance table must begin with the precise legal basis, not a commercial label.

The proposed mechanism had both a trigger and a deadline

Article 1(31) of the proposal sought to amend Article 113 of the Act. The Commission would adopt a decision confirming that adequate compliance support was available, such as harmonized standards, common specifications, or Commission guidance. After that decision, the sections on high-risk classification, requirements, and obligations would begin to apply after a transition period.

For Article 6(2) and Annex III systems, that period would be six months from the decision. For Article 6(1) and Annex I systems, it would be twelve months. The text also set backstops: without a decision, or if the calculation ran later, the rules would apply no later than December 2, 2027 for Annex III and August 2, 2028 for Annex I.

That is not the same as saying that everything moves to December 2027. The first group could start earlier if the Commission confirmed the support tools promptly and six months elapsed. The second had a different transition and backstop. The durable lesson is that a regulatory deadline can depend on an event and also contain a final limit; both belong in the record.

Which obligations sat inside the clock

The proposal cited Sections 1, 2, and 3 of Chapter III. Section 1 contains classification. Section 2 requires, among other elements, continuous risk management, data governance, technical documentation, logging, transparency to deployers, human oversight, accuracy, robustness, and cybersecurity. Section 3 allocates duties among providers, authorized representatives, importers, distributors, and deployers.

Those roles are not interchangeable. A provider develops a system or places it on the market under its name. A deployer uses it under its authority. A company can buy a recruitment tool and still hold duties concerning instructions, oversight, input data, logs, or impact assessment where applicable. A provider’s deadline does not automatically settle the duties of the customer operating the system.

The proposal did not erase the substantive content of all those requirements. Its explanatory memorandum said the aim was to link application to available support without reducing protection for health, safety, and fundamental rights. It also proposed other changes, including more flexibility for post-market monitoring plans and reduced registration for some systems assessed as non-high-risk. “Simplification” must therefore be translated article by article; calling the package regulation or deregulation is not enough.

Why standards were late and why standards are not enough

The Commission justified the mechanism by pointing to delays in harmonized standards, guidance, national authorities, and conformity-assessment bodies. A harmonized standard can turn an abstract requirement into testable controls and provide a presumption of conformity when properly applied. Without those tools, two companies or supervisors may interpret the same requirement differently.

A standard cannot decide whether a particular use harms a person, and it does not replace system evidence. The Act defines risk management as a continuous lifecycle process. It requires identification of known and foreseeable risks, assessment of intended use and reasonably foreseeable misuse, testing of measures, and review after deployment. Waiting for a template does not prevent an organization from preserving versions, data, incidents, and decisions now.

What an organization should do while the calendar moves

First, inventory each system’s intended purpose and the decisions it influences. Second, document why it falls under Article 6(1), Article 6(2), or an Article 6(3) exception. Third, assign the real roles: provider, importer, distributor, or deployer. Fourth, build a matrix linking each obligation to its article, evidence, internal owner, current date, proposed change, and activation condition.

The minimum file preserves model and software version, data provenance and controls, tests across affected groups, instructions, logs, incidents, human oversight, and changes in purpose. If a date moves, that work still helps procure responsibly, detect harm, and demonstrate what was known. If a system stops being auxiliary and begins materially influencing a decision, classification must be revisited.

For the person affected by a decision, a delay does not erase the GDPR or employment, consumer, equality, and product-safety law. The AI Act itself says it complements those frameworks. The proposed postponement should not be presented as a period without rights or a general authorization to deploy any system.

A method for reading the next regulatory headline

The worksheet fits on one page. Record the document and its status; the existing text it seeks to amend; the exact article; affected categories; obligated actor; event that starts the clock; transition period; backstop date; and outstanding legislative steps. Link every fact to the official text. One column separates fact from interpretation, while another records the last verification.

Applied on November 19, 2025, the result was precise: the Commission had proposed two conditional clocks for parts of the high-risk regime; it had not unilaterally suspended the AI Act. Reading this way guards against both alarm and complacency. A date may change, but classifying the use, assigning responsibility, and preserving evidence begin much earlier.

This article was produced with artificial intelligence under human editorial oversight.

Share this article

This website uses cookies to improve the browsing experience. Cookie policy.

↑↓ navigate ↵ open esc close