
The AI Act "Delay" Is Half-True — And It Matters for Programs in Flight
By Mark Sutter
A briefing for transformation delivery leaders · July 2026
The headline everyone heard vs. what actually happened
In May 2026, the EU agreed to push back the AI Act's high-risk obligations. Most delivery teams heard "the deadlines moved to 2027/28" and re-filed AI governance under later. That reading is wrong in both directions — and if your clients are running on it, parts of their compliance calendar (and your programme plans) are now inaccurate.
What actually moved:
| Obligation | Old date | New date |
|---|---|---|
| High-risk AI systems — Annex III (standalone, incl. HR/employment, credit, essential services) | 2 Aug 2026 | 2 Dec 2027 |
| High-risk AI embedded in regulated products — Annex I | 2 Aug 2027 | 2 Aug 2028 |
| Watermarking of AI-generated content (Art. 50(2)) | 2 Aug 2026 | 2 Dec 2026 |
What did not move:
- 2 Aug 2026 — all other transparency obligations apply, including deployer obligations (chatbot disclosure, informing individuals when AI is used on them). This is weeks away.
- 2 Dec 2026 — new prohibited practices take effect, including the ban on AI-generated non-consensual intimate imagery.
- Grandfathering: systems placed on the market before the new deadlines can avoid full high-risk obligations — until substantially modified. A transformation programme that upgrades or retrains a client's AI system can reset that clock. Few programme plans account for this.
Closer to home: MAS is about to make this contractual
Singapore's MAS closed consultation on its AI Risk Management Guidelines on 31 January 2026, with final issuance expected this year and a 12-month transition. They apply to all financial institutions, proportionately — and they explicitly cover third-party AI: FIs cannot delegate governance to vendors and are expected to impose due diligence, contractual protections, and ongoing oversight on them.
Translation for delivery firms: once issued, FI clients will start flowing AI governance requirements down into consulting SOWs, vendor onboarding, and mid-programme change requests. If your engagement touches an AI system at a regulated client, expect the governance workstream to appear whether it was scoped or not.
Why clients keep asking about ISO/IEC 42001
Neither regulator prescribes a certification — but clients need a way to evidence governance to boards, auditors, and procurement. ISO/IEC 42001 (AI management systems) has become the default answer, the same way ISO 27001 became shorthand for "we take security seriously." Expect it in RFP requirements and client-side vendor assessments through 2026–27, ahead of any legal deadline.
Five questions worth asking about programmes in flight
- Does any programme deploy, upgrade, or retrain an AI system for a client — and has anyone checked whether that counts as "substantial modification" under the grandfathering rules?
- Are client-facing AI features (chatbots, gen-AI content) ready for the August 2026 transparency obligations that did not move?
- For FI clients: who owns the response when MAS-driven third-party AI requirements land in the SOW mid-engagement?
- If a client asks the programme to evidence AI governance (42001-aligned or otherwise), is that in anyone's scope — and whose bench does it come from?
- Is anyone tracking which client AI use cases fall under Annex III, so the Dec 2027 runway is a plan rather than a scramble?
Prepared by 3peat.ai — AI governance, ISO/IEC 42001 frameworks, and delivery support for consulting teams across APAC. Questions on any of the above: get in touch.
Ready to use the 3peat AI Framework Builder?
Use the 3peat AI Framework Builder to list your AI systems, classify risk, and generate a practical governance framework your team can implement immediately.
3peat AI Framework Builder