If you read one headline about the EU AI Act this year, it was probably some version of “high-risk AI rules delayed.”
That headline is true.
The problem is what many organisations have taken from it.
The delay has quietly created the impression that the EU AI Act itself has been pushed back. It has created the impression that organisations have more time before they need to do anything meaningful. It has created the impression that the pressure is off. It isn't.
The EU AI Act is being implemented in stages. Some of its obligations have already been applied for more than a year. Others became applicable this year. The rules that were actually delayed are primarily the main obligations for high-risk AI systems. Those deadlines were moved for specific implementation reasons.
So the useful question is not whether the EU AI Act was delayed. It is: Which parts were delayed?, Which parts are already applicable? And, what should organisations be doing now?
Two important parts of the EU AI Act have applied since 2 February 2025. They are the prohibition of certain AI practices under Article 5: Prohibited AI practices and the obligation under Article 4: AI literacy.
The prohibited practices cover a defined set of uses considered unacceptable under the Act. These include certain manipulative or exploitative AI systems, some forms of biometric categorisation and social scoring. They also include other practices specified in the legislation. These are not future requirements. They already apply.
Article 4 introduced the requirement for providers and deployers to take measures to support AI literacy among people using AI systems on their behalf. It also was itself amended by the Digital Omnibus in July 2026. Providers and deployers should not assume the underlying obligation has been removed.
The principle remains straightforward. Organisations using AI need to understand what their people are using. They need to understand how they are using it. And they need to understand what those people need to know about the capabilities and limitations of the systems involved.
From 2 August 2025, the obligations covering providers of General-Purpose AI (GPAI) models also became applicable.
These are the foundation models that sit behind many of today's generative AI tools. Providers of GPAI models have obligations including maintaining technical documentation. They must implement a copyright policy. They must also publish a sufficiently detailed summary of the content used to train their models. Additional obligations apply to GPAI models presenting systemic risk.
This does not mean that an organisation using ChatGPT, Claude, Gemini or another foundation model automatically becomes responsible for the GPAI provider's obligations.
But it also does not mean that using a third-party model makes the organisation exempt from the AI Act. If a business builds or deploys an AI system using a third-party model, its own responsibilities depend on what the system does. They also depend on how it is classified and how it is used. The AI Act deliberately creates responsibilities across the AI value chain. It does not put everything on the model provider.
Then there is Article 50: Transparency obligations for providers and deployers of certain AI systems.
The transparency requirements under Article 50 became applicable on 2 August 2026. Among other things, providers of AI systems intended to interact directly with people must ensure that people are informed they are interacting with an AI system. The exception is where that is already obvious in the circumstances.
There are also specific transparency requirements covering AI-generated or manipulated content. These include machine-readable markings of certain synthetic content. They include disclosure of deepfakes. They also include specific requirements for AI-generated or manipulated text published to inform the public on matters of public interest. There are exceptions and conditions. One example is where appropriate human review or editorial control exists.
So if your organisation operates a customer-facing AI chatbot, the transparency requirements are already relevant. If your organisation generates or publishes AI-generated content, the position is more nuanced. It is not accurate to say that every piece of AI-assisted content must simply carry an “AI generated” label. The Act specifies particular categories of content. It also specifies particular circumstances in which disclosure or marking is required.
There is also a limited transition for certain AI systems already placed on the market before 2 August 2026. For those systems, the Article 50(2) marking and detection requirements apply from 2 December 2026.
In July 2026, the European Union adopted the Digital Omnibus on AI. Its formal name is Regulation (EU) 2026/1744.
This did not postpone the AI Act as a whole. Instead, it changed the timetable for the main requirements applying to certain high-risk AI systems.
For high-risk AI systems classified under Article 6 (2): Classification rules for high-risk AI systemsand Annex III, the main requirements in Chapter III, Sections 1, 2 and 3 now apply from 2 December 2027.
These are the high-risk AI use cases in sensitive areas. They include employment, education, certain biometric uses, critical infrastructure and access to essential services. They also include other areas covered by Annex III.
For high-risk AI systems covered by Article 6(1) and Annex I, the corresponding date is 2 August 2028. These are AI systems embedded in certain regulated products such as medical devices and machinery.
So, yes, a significant part of the high-risk compliance timetable has moved. But that is very different from saying the EU AI Act has been delayed. The reason for the change was largely implementation readiness.
The EU identified delays in the availability of standards, common specifications and alternative guidance. It also identified delays in establishing the national competent authorities needed to implement and supervise the rules. The legislation concluded that keeping the original August 2026 deadline could create significant implementation problems and unnecessary costs.
In other words, the EU has bought more time to put the supporting infrastructure in place. It has not abandoned the underlying requirements.
Another date worth putting in the diary is 2 December 2026.
From that date, new prohibitions introduced through the Digital Omnibus will apply to AI systems used to generate or manipulate realistic intimate material involving an identifiable person without that person's explicit consent.
For organisations already dealing with generative AI, this is another reminder that the regulatory landscape is still changing. That is true even while the wider high-risk timetable has been pushed out.
And there is another date that is easy to overlook. Providers of GPAI models that were already on the market before 2 August 2025 have until 2 August 2027 to comply with the relevant GPAI obligations.
The fact that some of these deadlines extend into 2027 does not mean that the GPAI regime itself has been delayed.
The AI Act is therefore not one deadline. It is a series of obligations arriving at different times.
It is tempting to look at the move from August 2026 to December 2027 and see sixteen months of breathing room. A better way to look at it is sixteen months of implementation time.
The standards, guidance and assessment infrastructure being developed during this period will shape how organisations demonstrate and operationalise compliance when the high-risk requirements take effect.
That matters because the work required to comply is not something most organisations can build in a few weeks.
You need to know where AI is being used. You need to understand which systems are being used, by whom and for what purpose. You need to assess risk. You need appropriate governance, policies and controls. You need documentation. You need to understand how third-party AI models and systems fit into your technology and supplier landscape. And where relevant, you need processes covering human oversight, monitoring and logging. You also need data and model governance.
The standards work is already under way.
In July 2026 the European standards bodies CEN and CENELEC published EN 18286. It is the first European standard developed to support the AI Act.
It sets out a quality management system for organisations that provide AI systems. It is aimed mainly at providers of high-risk AI systems.
The European Commission is expected to publish a reference to it in the Official Journal later in 2026. Once a standard is cited there, following it gives organisations a presumption of conformity with the requirements it covers.
Further standards are being finalised. The Commission's request for them runs until 28 February 2027.
That gives organisations something concrete to build towards now.
The legal deadline is therefore not necessarily the sensible starting point. The organisations that wait until December 2027 to begin may find themselves trying to build these capabilities at exactly the point when the requirements are already applicable. Expectations from regulators, customers, partners and other stakeholders will also be higher.
The AI Act's penalty structure is significant. Violations of the prohibited AI practices can attract administrative fines of up to €35 million or 7% of worldwide annual turnover, whichever is higher. Certain other infringements can attract fines of up to €15 million or 3% of worldwide annual turnover. Supplying incorrect, incomplete or misleading information to notified bodies or national competent authorities can attract fines of up to €7.5 million or 1% of worldwide annual turnover. These are maximum statutory penalties. They are not automatic fines for every breach. The Act provides for proportionality and different treatment depending on the nature of the infringement and the organisation involved.
But the numbers make one thing clear: the EU AI Act is not simply a voluntary governance framework.
None of this is abstract if your business sits in payments. The Act speaks directly to two things payments businesses do every day: credit scoring and fraud detection.
Start with fraud. Annex III is the list of use cases the Act treats as high-risk. A card fraud model does not automatically appear on that list. The relevant entry covers AI systems used to evaluate the creditworthiness of individuals or to establish their credit score. Fraud detection is carved out of that entry. The Commission's draft guidance says the carve out applies where fraud detection is the main intended use. It must come ahead of any other purpose. In practice that means pattern recognition and anomaly detection. It does not mean assessing someone's ability to pay. The draft guidance goes further. A system mainly used for pattern recognition and anomaly detection may still benefit from the carve out. That can be true even where its output is also used in credit decisions. That is good news for the fraud engines most payments businesses already run.
But the carve out is narrower than it sounds. It does not cover a model that is itself intended to assess whether an individual can or will pay. Take a model built to set a credit limit or to decide whether to extend credit, which also flags fraud. That function is a creditworthiness assessment. It may fall into the high-risk category even though fraud detection is part of what the model does. The intended purpose of the system is what counts, not the label on the model. Using a model for a purpose it was not intended for can change its classification. It can also change who is treated as its provider.
Blocking a transaction or restricting an account for suspected fraud is different. On its own, that is not a creditworthiness assessment. So there are two questions to ask. What is each model intended to do? And what is its output actually used for? If either answer involves an individual's ability to pay, it needs a proper classification assessment. That is better done deliberately than assumed.
Lending style decisions sit closer to the high-risk side. Annex III explicitly lists AI systems used to evaluate the creditworthiness of individuals or establish their credit score. Buy now pay later underwriting is the clearest example in payments. The same can apply to AI used to assess the credit risk of an individual merchant, such as a sole trader. It does not matter whether the model is built in house or licensed from a third party. Annex III is about individuals. Assessing a company as a legal entity is not covered by that wording. So it is worth checking how your own merchant base is made up.
The European Commission published draft guidance in May 2026 on how these classifications should be applied in practice. A final version is expected by the end of the year. Treat current classifications as a strong steer rather than the last word.
Article 50 transparency is worth a direct look at your own estate right now, not later. If your organisation runs a customer-facing chatbot for chargeback queries, dispute resolution or merchant onboarding, that obligation has applied since 2 August 2026.
The same goes for GPAI. Payments businesses building fraud analyst copilots, dispute summarisation tools or merchant support assistants on top of a third-party foundation model do not inherit that provider's obligations. But they do not escape their own either. Responsibility for how the system is actually used stays with the deployer. So does responsibility for what it is allowed to decide.
None of this sits in isolation. Payments organisations already operate inside PCI DSS, card scheme rules and, increasingly, DORA where it applies. The practical challenge with the AI Act is rarely a single new rule in isolation. It is mapping another layer of obligations onto governance structures that, in most cases, already exist in some form. That is a considerably easier starting point than building from nothing.
The honest question for a payments business is not whether you have an AI policy. It is whether you actually know where AI is being used across the business.
That includes the obvious AI projects. But it also includes the tools adopted informally by individual teams. It includes AI functionality embedded inside third-party software. It includes models accessed through APIs. And it includes systems that may never have been recorded in a central technology or risk register.
Without that inventory, it is difficult to know which obligations already apply. It is also difficult to know which will apply from December 2027 or August 2028. And it is difficult to know where gaps may already exist in governance and control.
The deadline moved. The need to understand your AI environment did not.
The organisations that use this additional time to identify their AI systems, classify their risks, establish governance, build documentation and put appropriate oversight in place will be in a very different position from those that simply wait for the next deadline to arrive.