AI Act delayed by 16 months - analysis from the perspective of a founder building compliance tools in Poland
21 July 2026 · Reading time: approx. 18 minutes
Sixteen months that change the market dynamics
The EU Council approved a package simplifying AI Act implementation at the end of June. The key change: obligations for high-risk systems - those used in recruitment, credit scoring, education, biometric identification - will take effect not on 2 August 2026 as planned, but on 2 December 2027. Sixteen additional months beyond the original timeline.
The European Commission proposed this delay in autumn 2025 as part of the Digital Omnibus package. Parliament and the Council finalized details this spring after several months of trilogue. 569 votes in favour, 45 against, 23 abstentions. The result leaves no doubt about the political consensus.
Before anyone reads this as regulatory loosening or a concession to the tech lobby - it is not. This delay applies exclusively to elements requiring the most implementation work on the business side, for which the regulatory ecosystem simply failed to deliver tools on time. The level of citizen protection does not decrease. Regulatory ambition does not diminish. Only the pace changes.
What stays on schedule, as originally planned
Basic transparency requirements operate according to the original timeline. The obligation to inform users about AI interaction comes into effect this August. Synthetic content labeling - in December. The ban on AI-generated sexual content without consent (including deepfakes) has been in force since 2 December 2026. Brussels accelerated this specific deadline after the scandal involving fake images of Italian Prime Minister Giorgia Meloni, which demonstrated the problem was not theoretical.
This is an important distinction worth emphasizing. Transparency and abuse protection proceed at full speed. Only obligations concerning high-risk systems were postponed - because there were simply no ready standards, certification procedures, or designated supervisory bodies for them. You cannot require compliance with norms that do not yet exist.
Additionally, Parliament accelerated one deadline: providers of generative systems already on the market must implement watermarking (marking AI-generated content) by 2 November 2026 - three months earlier than the Commission wanted. AI content transparency is a topic that, according to European legislators, cannot wait even one additional quarter.
Why the delay was inevitable
Anyone who has tried to actually implement compliance with EU regulation understands this reason immediately. The issue is not that provisions were poorly drafted. The problem is that the entire apparatus meant to enable their application simply did not exist when it was supposed to start functioning.
Let us start with facts. CEN-CENELEC Joint Technical Committee 21 - the body responsible for developing technical standards - was supposed to deliver harmonized norms by 30 April 2025. The chair admitted back in 2024 they would not make the deadline but promised readiness by end of 2025 or early 2026. In October 2025 the deadline was pushed again to end of 2026. This was already the third postponement. Companies do not know against which standards they should demonstrate compliance because nobody has told them yet.
The European Commission itself missed its own deadline. By 2 February 2026 it was supposed to publish guidelines on Article 6 - classification of high-risk systems. It did not. It acknowledged it was "integrating months of feedback" and planned to publish the final draft "by the end of the month". The final version? Perhaps March, perhaps April. Companies only learned in spring whether their systems even fell under the high-risk category.
Many member states have not designated AI supervisory authorities. Conformity assessment bodies (those meant to certify AI systems) have not been established in most countries. The entire chain - from standards through supervisory bodies to certification procedures - had gaps at every level.
Imagine someone telling you: pass an exam in 6 months. But they do not give you a textbook. They do not tell you what the questions will be. The examiner has not been hired yet. And the institution organizing the exam admits it has not managed to prepare the materials itself. That was exactly the situation for companies supposed to meet AI Act requirements by August 2026.
Hence the Digital Omnibus on AI - published by the Commission on 19 November 2025 as part of the broader "Simpler and Faster Europe" programme. European business had been complaining for months that bureaucracy was hindering competition with US and Asian firms operating in a much more liberal regulatory environment. The package attempts to simplify digital law without sacrificing safety. Crucially: companies get more time, but dates are fixed and automatic. The Commission gets no switch, no discretion. Parliament explicitly rejected that.
Systems under sectoral law - an even longer delay
It is worth noting that the delay is not uniform. High-risk AI systems from Annex III (biometric identification, critical infrastructure, employment, migration, justice system) must meet requirements by 2 December 2027. But systems subject to EU sectoral law - machinery, toys, medical devices, civil aviation - have until 2 August 2028.
This makes sense. Sectoral systems are subject to additional industry regulations that are themselves changing and adapting to the new AI reality. Requiring simultaneous compliance with the AI Act and, say, the Medical Devices Regulation when both regulatory ecosystems are mid-transformation would be a recipe for chaos.
Regulatory sandboxes - the first real mechanism for practical testing
During this transitional period, the key tool will be regulatory sandboxes. They allow testing AI solutions under regulator supervision, in controlled conditions, before rules take full effect. An entrepreneur can enter a sandbox, run their system on live data, identify risks - without facing legal consequences even if the system does not yet meet all requirements.
From my perspective - someone building a product at the intersection of AI and regulation - this is exactly the mechanism that was missing. It allows identifying problems before they become violations. It simultaneously educates the regulator on real use cases rather than paper scenarios written by lawyers who have never seen a production AI system from the inside.
In theory, sandboxes have existed in the AI Act from the beginning. In practice, their real implementation at the national level is only starting now. In Poland they will be managed by the newly established Commission for the Development and Security of Artificial Intelligence (KRiBSI). This is not a distant prospect - it is happening now, this quarter.
Poland's AI Systems Act - what actually happened
The Polish parliament (Sejm) adopted the majority of Senate amendments to the AI Systems Act in early July. The law is now on the President's desk. Poland is among the first EU countries with finished national legislation implementing the AI Act - which itself is a significant market signal.
The act establishes KRiBSI - the Commission for the Development and Security of Artificial Intelligence. This will be the central supervisory body for the AI market in Poland. It will handle citizen complaints, manage regulatory sandboxes, and issue guidelines for companies. This is not another advisory council without competencies - KRiBSI receives real supervisory powers.
In parallel, the government is developing infrastructure projects. PLLuM - a Polish large language model - is one of them. The state is investing in AI infrastructure and building its position as a customer for domestic technology solutions. For companies building AI products in Poland this is a good signal - the administration is beginning to understand that smart oversight means not just enforcement and inspections but active ecosystem support.
Pamela Krzypkowska from the GovTech department at the Ministry of Digital Affairs wrote something I agree with completely: the deferral of AI Act obligations is an opportunity, but the time bought is not a gift. It is a loan, and loans are repaid together or not at all. That is the essence of the matter. Sixteen months that change nothing in a company's preparations are sixteen wasted months. And wasted time costs double when deadlines finally arrive.
What this actually means for companies - without generalities
I know every article about regulations ends with a list of "what companies should do". Let me try to frame this differently - from the perspective of someone who sees how companies approach this topic in practice, not in conference presentations.
First thing is inventory. Sounds trivial, but most companies do not know how many AI systems they actually use. Marketing bought one tool, HR another, the legal department a third, someone in IT connected an API to a fourth. Nobody inventoried this, nobody knows which of these systems fall under the high-risk category. Before you start building compliance you need to know what you are dealing with. This is not a one-week task - in a mid-size company it can take a month or two to map the entire landscape.
Second thing is documenting decision processes. The AI Act requires transparency - who decided to deploy an AI system, on what basis, what is the scope of human oversight over the machine. Most companies do not document this. Decisions happen in meetings, in emails, on Slack - and there is no audit trail. When an auditor arrives and asks "show me how you reached the decision to use this system in recruitment" - a PowerPoint from 2024 will not suffice.
Third thing is oversight culture. This is the hardest because you cannot buy it as a service. You must build organizational awareness that AI systems require continuous monitoring, that results need validation, that data bias will not fix itself. This is a mental shift that requires time - and that is why these sixteen months are so valuable. You cannot build an oversight culture in the quarter before a deadline.
A company that starts these preparations now will only be fine-tuning processes in eighteen months. Those who postpone will hit time pressure. I saw this with GDPR - companies that started preparations a year before the regulation took effect passed through smoothly. Those that started three months before spent three times more and still had gaps. The pattern repeats with every major regulation.
The public administration perspective
On the other side - public administration has its own tasks and they are worth mentioning because they directly affect how companies will be able to operate. Making open data available for model training. Developing national computing infrastructure. Building supervisory competencies (people at KRiBSI need to understand how AI systems work to oversee them sensibly). And finally, the courage to buy Polish technology solutions instead of defaulting to foreign vendors.
This last point is crucial for the ecosystem. If public administration buys compliance solutions exclusively from large international firms, Polish startups building governance tools will have no references. And without public sector references it is hard to sell to the private sector in the regulatory space - because companies look for solutions "verified by the regulator". This is a closed circle that sandboxes can help break.
Why we are building Evidion for exactly this time window
Here I shift to the perspective closest to me. We are building Evidion as the evidence and governance layer for organizations implementing AI. Three pillars the product rests on: continuous oversight of AI systems in the organization (not a one-time audit but real-time monitoring), documenting accountability in a verifiable manner (cryptographic evidence integrity, timestamps, chain of custody), and centralized audit-ready compliance evidence in one place instead of scattered across dozens of systems.
Put simply - we turn regulatory compliance from a statement of intent into something you can show an auditor. Concrete evidence, not a PowerPoint full of promises. Evidence-based compliance instead of trust-me compliance.
The deadline shift to December 2027 does not mean less work for us. Quite the opposite. It means sixteen months during which companies should be building documentation and oversight processes - and we have time to deliver them a tool that makes this possible. This is the window in which a platform like Evidion can become the market standard before time pressure forces everyone into rushed implementations and choosing whatever is at hand.
In July we closed our pre-seed round: 850 thousand dollars from DGE3 Investment VC. Growth Score 94 and Heat Score 92 on Crunchbase confirm the market sees potential. I am not saying this to boast - I am saying it to show that the thesis about a time window for AI compliance tools is not my private opinion. Investors are putting money on it.
Regulatory sandboxes built by KRiBSI could become a natural partner for platforms like ours. The administration will need tools to verify compliance of companies testing AI in controlled environments. Someone needs to provide the evidence layer for these sandboxes. Someone needs to collect and store test artifacts in an audit-ready manner. That is our specialization.
What we do not know - risks and unknowns
I would be dishonest if I did not mention risks. The trilogue could drag on and deadlines could change again. CEN-CENELEC standards may prove inadequate to market realities when they finally appear. KRiBSI as a new institution may need more time to build operational capabilities than optimistic timelines assume. Companies may ignore the delay and do nothing until the last moment - because this happens with every regulation.
There is also a risk that Europe overshoots in the other direction and creates such a complicated compliance framework that only large corporations can afford conformity. That would kill innovation rather than protect it. For now the direction is good - sandboxes, SME support, gradual implementation - but the devil is in the details of national implementation.
And finally - the AI compliance tools market is still forming. In a year it may look completely different from today. Large players (ServiceNow, OneTrust, IBM) may decide that AI governance is their natural extension and flood the market with enterprise solutions. For startups like ours this means the window is real but not infinite. Sixteen months is our deadline too for building a position.
What follows from all of this
I observe this from the position of someone who integrates AI models in production environments and must continuously track changing legal requirements. This delay is a classic example of regulation catching up with technology - but in a thoughtful manner. The EU is not abandoning regulatory ambition. It is giving itself and companies time to do it properly rather than poorly.
Companies that prepare compliance infrastructure now gain an advantage. Not just legal (avoiding fines) but operational (better understanding of their own AI systems, better oversight, lower risk of reputational incidents). Compliance does not have to be a cost. It can be an investment in process quality.
The time loan must be repaid with concrete work. System inventories. Process documentation. Building oversight culture. Choosing tools. Testing in sandboxes. All of this requires time and resources - but it also requires a conscious decision to start now rather than in a year.
Sixteen months is a lot of time. But only for those who use it.
