The EU AI Act’s high-risk deadline just got moved six days before it was due to kick in. Regulation (EU) 2026/1744 came into force on 27 July, pushing the Annex III obligations from 2 August 2026 out to 2 December 2027, and the embedded ones under Annex I to August 2028.
Why did the dates get bumped?
Member states hadn’t designated their competent authorities, and the harmonised standards that conformity assessment depends on were still unwritten. In a nutshell: the EU was about to start enforcing compliance against benchmarks that didn’t exist yet, so it bought itself time rather than softening the rules. Risk management, data governance, technical documentation, logging, human oversight, conformity assessment, registration. All of it is still coming and the penalties haven’t been changed.
What still lands on 2 August?
The transparency obligations under Article 50 will still land on 2 August, so if you have anything EU-facing that talks to people or generates content, that work is due this week regardless.
In the EU none of this was ever a hypothetical exercise. GDPR already requires firms to explain automated decisions made solely by machine where they significantly affect people. The implementation of this AI Act is the braces for the belt, effectively.
Regulatory runway is not commercial runway
Sixteen months of regulatory runway doesn’t translate into 16 months of commercial runway. Banks, insurers and energy retailers are already writing these controls into procurement as they did with GDPR. If you’re selling agentic systems into regulated industries, the governance layer isn’t a compliance cost you can defer until the deadline.
What does this mean for ANZ?
Our read is that New Zealand is unlikely to move first. The current regulatory posture favours waiting for international frameworks to mature, then adapting what has worked elsewhere. Australia is further along. APRA told the industry in April that AI governance is not keeping pace with adoption, and it does not need a change to the National AI Plan (which shelved the proposed mandatory guardrails) to act. It has said it is not writing a standalone AI standard, but that position rests on firms lifting their game. If its April 2026 observations on the implementation of CPS 230, CPS 234, CPG 235 and CPS 510 do not improve, turning them into an AI-specific prudential standard is a short step.