All articles
Colourful hand-drawn AI GOVERNANCE title with a friendly smiling robot

The AI Act "Delay" Is Half-True — And It Matters for Programs in Flight

By Mark Sutter

A briefing for transformation delivery leaders · July 2026

The headline everyone heard vs. what actually happened

In May 2026, the EU agreed to push back the AI Act's high-risk obligations. Most delivery teams heard "the deadlines moved to 2027/28" and re-filed AI governance under later. That reading is wrong in both directions — and if your clients are running on it, parts of their compliance calendar (and your programme plans) are now inaccurate.

What actually moved:

ObligationOld dateNew date
High-risk AI systems — Annex III (standalone, incl. HR/employment, credit, essential services)2 Aug 20262 Dec 2027
High-risk AI embedded in regulated products — Annex I2 Aug 20272 Aug 2028
Watermarking of AI-generated content (Art. 50(2))2 Aug 20262 Dec 2026

What did not move:

  • 2 Aug 2026 — all other transparency obligations apply, including deployer obligations (chatbot disclosure, informing individuals when AI is used on them). This is weeks away.
  • 2 Dec 2026 — new prohibited practices take effect, including the ban on AI-generated non-consensual intimate imagery.
  • Grandfathering: systems placed on the market before the new deadlines can avoid full high-risk obligations — until substantially modified. A transformation programme that upgrades or retrains a client's AI system can reset that clock. Few programme plans account for this.

Closer to home: MAS is about to make this contractual

Singapore's MAS closed consultation on its AI Risk Management Guidelines on 31 January 2026, with final issuance expected this year and a 12-month transition. They apply to all financial institutions, proportionately — and they explicitly cover third-party AI: FIs cannot delegate governance to vendors and are expected to impose due diligence, contractual protections, and ongoing oversight on them.

Translation for delivery firms: once issued, FI clients will start flowing AI governance requirements down into consulting SOWs, vendor onboarding, and mid-programme change requests. If your engagement touches an AI system at a regulated client, expect the governance workstream to appear whether it was scoped or not.

Why clients keep asking about ISO/IEC 42001

Neither regulator prescribes a certification — but clients need a way to evidence governance to boards, auditors, and procurement. ISO/IEC 42001 (AI management systems) has become the default answer, the same way ISO 27001 became shorthand for "we take security seriously." Expect it in RFP requirements and client-side vendor assessments through 2026–27, ahead of any legal deadline.

Five questions worth asking about programmes in flight

  1. Does any programme deploy, upgrade, or retrain an AI system for a client — and has anyone checked whether that counts as "substantial modification" under the grandfathering rules?
  2. Are client-facing AI features (chatbots, gen-AI content) ready for the August 2026 transparency obligations that did not move?
  3. For FI clients: who owns the response when MAS-driven third-party AI requirements land in the SOW mid-engagement?
  4. If a client asks the programme to evidence AI governance (42001-aligned or otherwise), is that in anyone's scope — and whose bench does it come from?
  5. Is anyone tracking which client AI use cases fall under Annex III, so the Dec 2027 runway is a plan rather than a scramble?

Prepared by 3peat.ai — AI governance, ISO/IEC 42001 frameworks, and delivery support for consulting teams across APAC. Questions on any of the above: get in touch.

Ready to use the 3peat AI Framework Builder?

Use the 3peat AI Framework Builder to list your AI systems, classify risk, and generate a practical governance framework your team can implement immediately.

3peat AI Framework Builder