The EU Just Delayed Its Own AI Rules. Is Regulating AI Getting Harder — and What Should Businesses Do?
The EU's Digital Omnibus pushed the AI Act's high-risk rules to December 2027 — but most obligations already apply. What changed, how the US, China, Korea and India compare, why regulating AI is getting harder, and a practical playbook for businesses and policymakers.
By Pavan Kumar Verma · · 9 min read

When the European Union's AI Act came into force in August 2024, it was celebrated as the world's first comprehensive law for artificial intelligence. Supporters hoped it would do for AI what the GDPR did for data protection: set a global standard that everyone else would follow.
Two years later, the EU has hit the brakes on its own rules.
The Digital Omnibus on AI — now Regulation (EU) 2026/1744, in force since 27 July 2026 — pushes back the Act's toughest obligations, the rules for "high-risk" AI systems, by more than a year. The official reason is simple: the technical standards and guidance companies need in order to comply weren't ready.
So here's the question this post tries to answer: if the EU, with all its regulatory experience, can't regulate AI on schedule, is regulating AI getting harder rather than easier? And what should businesses and governments actually do about it?
What changed — and what didn't
The most important thing to understand is that the delay is narrower than the headlines suggest.
| Obligation | Original date | After the Omnibus |
|---|---|---|
| Prohibited AI practices (e.g. social scoring, manipulative AI) | 2 February 2025 | Unchanged — already in force |
| AI literacy for staff using AI | 2 February 2025 | Unchanged — already in force |
| General-purpose AI (foundation model) obligations | 2 August 2025 | Unchanged — already in force |
| Transparency duties (e.g. telling people they're talking to a chatbot) | 2 August 2026 | Unchanged — now in force |
| Marking / watermarking AI-generated content | 2 August 2026 | 2 December 2026 |
| New bans on AI that generates non-consensual intimate imagery or child sexual abuse material | — | 2 December 2026 |
| Stand-alone high-risk systems (Annex III: hiring, credit scoring, insurance pricing, education, biometrics, critical infrastructure, public services) | 2 August 2026 | 2 December 2027 |
| High-risk AI embedded in regulated products (Annex I: medical devices, machinery, toys, lifts) | 2 August 2027 | 2 August 2028 |
The Omnibus also:
- extended simplified documentation and proportionate penalties beyond traditional SMEs to larger "small mid-cap" companies;
- kept the requirement for high-risk systems to be registered in the EU database, even where some exemptions apply;
- gave the European Commission more power to remove overlapping requirements between the AI Act and sector-specific laws;
- strengthened the AI Office's role in supervising general-purpose AI models;
- extended the deadline for national regulatory sandboxes to 2 August 2027.
Penalties remain serious: up to 7% of global annual turnover for the most serious breaches.
Why the EU blinked
Three reasons stand out.
- The standards weren't ready. High-risk obligations depend on detailed technical standards — for risk management, data quality, accuracy, robustness and human oversight. European standards bodies didn't finish them in time, and companies can't comply with rules whose technical details don't yet exist.
- The technology moved faster than the law. The Act was largely drafted before generative AI exploded into public use. Lawmakers had to bolt on rules for general-purpose models late in the process, and the technology has kept changing since.
- Competitiveness pressure. Europe has spent the past two years worrying that it is falling behind the United States and China in AI. The Omnibus is part of a broader push to simplify EU digital rules and reduce the compliance burden on European companies.
Meanwhile, the rest of the world is going in different directions
The EU's delay matters partly because there is no global consensus to fall back on. Every major economy is taking a different path:
| Jurisdiction | Approach | Where it stands (2026) |
|---|---|---|
| European Union | One comprehensive, risk-based law | Bans, AI literacy, foundation-model and transparency rules in force; high-risk rules delayed to Dec 2027 / Aug 2028 |
| United States | No federal AI law; deregulatory federal stance | A December 2025 executive order set up a federal task force to challenge state AI laws, but state laws in California, Texas, Illinois and Utah are in force; Colorado's replacement framework starts in January 2027 |
| China | Targeted, fast-moving rules | Generative AI measures since 2023; mandatory labels and embedded metadata on AI-generated content since September 2025 |
| South Korea | Comprehensive "AI Basic Act" | In force since January 2026, with risk assessments and a local representative required for high-impact and generative AI |
| India | Guidelines, not a new law | AI Governance Guidelines (November 2025) rely on existing laws — including the new data protection rules being phased in from November 2026 |
| Emerging economies | Strategies and draft policies | Kenya published a draft AI and Emerging Technologies Policy in July 2026; only 22 of 54 African countries have a national AI strategy |
For a company that builds or uses AI across borders, the result is a patchwork: a comprehensive law in Europe that keeps moving, a federal–state tug-of-war in the US, strict content-labelling rules in China, a new framework in Korea, and principles-based guidance in India.
So, is regulating AI getting harder?
Yes — and it's worth being honest about why.
- AI is a general-purpose technology. The same model can write marketing copy, screen job candidates and assess credit risk. Regulating the technology itself is almost impossible; regulating its uses is more realistic but far more complex.
- "High-risk" is hard to define. Drawing clear lines between harmless and dangerous uses — in a way that works for both a start-up and a global bank — has proven much harder than expected.
- Standards take years; models change in months. Formal standard-setting processes simply can't keep pace with releases that change what AI can do every few months.
- Countries are competing, not coordinating. AI is now seen as a matter of national competitiveness and security, which makes governments reluctant to tie their own hands while others move ahead.
- Regulators lack capacity. Enforcing AI rules requires technical expertise that most regulators — in Europe and everywhere else — are still building.
But there's another side to this. In practice, much of AI's real-world regulation is happening through existing laws: data protection, consumer protection, anti-discrimination, financial-services rules and product liability. A bank using AI to decide who gets a loan was already regulated before the AI Act existed. That's an important point for businesses tempted to treat a delay as a holiday.
The trap: treating a delay as a holiday
The worst response to the Omnibus would be to put AI governance on hold until December 2027. Here's why:
- Most obligations are already in force. Prohibited practices, AI literacy, transparency and foundation-model rules all apply today, and watermarking arrives in December 2026.
- Fifteen months is not long. Building an AI inventory, classifying risks, documenting systems, testing for bias and setting up human oversight across a large organisation can easily take a year or more.
- Your customers won't wait. Large enterprises — especially banks and insurers — are already asking their technology suppliers for evidence of responsible AI practices in contracts and procurement.
- The deadlines could move again — in either direction. Planning around the latest date is a gamble.
A practical playbook for businesses
Whether you're a global enterprise, a technology vendor or a fast-growing company, these steps make sense regardless of where the deadlines land:
- Build an AI inventory. List every AI system you build, buy or use — including AI features inside the software you already pay for.
- Classify by risk and by geography. For each system, ask: is it used in hiring, credit, insurance, education, health, biometrics or critical services? Which countries' users does it affect?
- Design to the strictest common baseline. For most global companies, that means the EU AI Act. It's easier to build one strong governance framework than five different ones.
- Get transparency right now. Tell people when they're interacting with AI, and prepare to label AI-generated content — required in the EU, China and parts of the US.
- Adopt a recognised framework. International standards such as ISO/IEC 42001 (AI management systems) and the NIST AI Risk Management Framework give you a structured approach that regulators everywhere recognise.
- Fix your contracts. Add clear clauses on AI use, data, testing, transparency and liability with both your suppliers and your customers.
- Train your people. AI literacy is already a legal obligation in the EU — and a practical necessity everywhere.
- Assign ownership. Make a named executive accountable for AI risk, with a cross-functional group covering technology, legal, compliance, risk and business teams.
A special note for banks, insurers and their technology partners
Financial services sit squarely in the high-risk zone. Under the AI Act, creditworthiness assessment and credit scoring, and risk assessment and pricing for life and health insurance, are listed as high-risk uses. These are exactly the areas where AI adoption — including newer "agentic" AI — is growing fastest.
The extra time is a gift if it's used well: to test models for bias, document decisions, build human review into workflows and prepare evidence for regulators and auditors.
And for offshore vendors and GCCs
The AI Act applies to AI systems placed on the EU market or whose outputs are used in the EU — wherever the developer is based. Technology firms and capability centres in India, Africa, the Middle East and elsewhere that build AI for European clients need to understand these rules as well as their clients do. Done well, that's not a burden but a competitive advantage: "we build AI that's compliant by design" is a powerful message.
Lessons for policymakers still writing their AI rules
For countries such as India, Kenya and many others now shaping their own approach, the EU's experience offers useful lessons:
- Have the standards ready before the deadlines. Rules without technical guidance create uncertainty, not safety.
- Regulate uses, not the technology. Focus on high-impact decisions — credit, jobs, health, justice — rather than trying to define "AI" itself.
- Empower existing regulators. Financial, health, consumer and data protection authorities already understand their sectors; give them AI expertise and clear mandates.
- Use sandboxes generously. Let companies test innovative AI under supervision before rules are final.
- Stay interoperable. Align with international standards and major trading partners so that local companies can sell globally without rebuilding everything.
- Build enforcement capacity early. A law that regulators can't enforce helps no one.
Final thought
The EU's delay isn't a sign that AI regulation has failed. It's a sign that regulating a fast-moving, general-purpose technology is genuinely hard — and that even the world's most experienced regulator is learning as it goes.
For businesses, the message is clear: don't wait for regulators to finish their homework. The companies that build trustworthy, transparent and well-governed AI now will spend less on compliance later, win more customer trust today, and be ready whichever way the deadlines move next.
How is your organisation approaching AI governance — waiting for the rules to settle, or building now? I'd like to hear your view in the comments.
Sources: Regulation (EU) 2024/1689 (AI Act) and the Digital Omnibus on AI, Regulation (EU) 2026/1744, as analysed by Travers Smith, Orrick, Jones Walker, DLA Piper and Plesner; the White House executive order "Ensuring a National Policy Framework for Artificial Intelligence" (December 2025) and analysis by Baker Botts, Ropes & Gray and Latham & Watkins; China's Measures for Labeling AI-Generated Synthetic Content (2025) and Interim Measures for Generative AI Services (2023); South Korea's AI Basic Act (OECD.AI and US International Trade Administration summaries); India's AI Governance Guidelines (MeitY, November 2025) and DPDP Rules 2025; Kenya's draft AI and Emerging Technologies Policy (2026); Africa AI Governance Index 2026; ISO/IEC 42001:2023; NIST AI Risk Management Framework.