The European Parliament amended the AI Act on 16 June and the enforcement clock for high-risk systems slipped by up to sixteen months. What matters now is how organisations respond to being handed more time, because that response reveals more about a company’s operating model than any compliance document ever will.
On 16 June the European Parliament voted to amend the EU AI Act. 423 in favour, 57 against, 174 abstentions. The headline that spread fastest was the delay. Enforcement of the high-risk rules now moves to December 2027 for the systems listed in Annex III, and to August 2028 for AI built into regulated products. That is up to sixteen months of extra time.
That sounds like relief. The detail of the text says otherwise.
The dates are now fixed
The new dates no longer depend on the technical standards and guidelines being ready first, which was the soft deadline most organisations were quietly counting on. For anyone who had privately decided to start once the standards landed, that escape route has closed.
The structure of the Act survives the edit almost untouched. The risk tiers, the obligations and the underlying logic all remain. Parliament even widened the rules in places, adding a ban on AI systems that generate non-consensual intimate imagery and child sexual abuse material. So the vote leaves the rules intact and makes the timeline firmer. The compliance clock is now real, and the “we were waiting for the standards” excuse expires with it.
And the clock has real money behind it. The Act’s penalties reach €35 million, or 7% of global annual turnover, whichever is higher, at the top of the range. For many companies a figure like that is a full year of profit, or the budget of an entire function.
Why the delay is the dangerous part
Here is the trap, and it is a matter of psychology more than law. A far-off fixed date feels safer than a near soft one, so it draws less attention, which is precisely backwards. The budget gets reallocated, the governance hire gets postponed, and the AI inventory stays a spreadsheet nobody owns. Then 2027 arrives on a date that will not move, with no extension left to hope for.
This is where the delay becomes personal. Moving a deadline is a quiet test, and most organisations will fail it. Give a disciplined company sixteen more months and it starts building: an owner named for each system, a written record of how each was tested, a decision about who watches them once they are live. Give an undisciplined company the same sixteen months and nothing moves until month fifteen. The regulation is identical for both, and so are the sixteen months. The difference lies in whether the organisation already runs on ownership and evidence, or on good intentions and a slide deck.
The map still holds
Last year I wrote a full guide to the AI Act, built to clear the fog for founders and teams trying to work out what actually applied to them. That map still holds. The four risk tiers, the obligations that sit on each, and the advice to default to the stricter category and work backward, because it is cheaper to build with compliance than to retrofit it. The only thing this vote changed is the clock. You can read the full guide here: https://renebohnsack.substack.com/p/eu-ai-act-for-startups-a-guide-to
The single most useful thing you can do this month is smaller than most compliance programmes assume. Take every AI system your organisation actually runs and answer three questions for each one:
Who owns it
Which risk tier it falls into
How you would show, in writing, that it was tested before people started relying on it.
Most leaders cannot answer all three today, and every other obligation in the Act sits on top of that list.
The argument underneath
There is a larger argument beneath the vote. The amendment is part of a competitiveness drive, the premise being that lighter rules will help Europe close its innovation gap with the US and China. That gap is genuine, though whether regulation was ever its main cause is far less certain. Europe still defines what trustworthy AI looks like, and reading this vote as “AI governance no longer matters” draws the wrong lesson from a decision that was only ever about timing.
If your AI Act deadline were this quarter instead of December 2027, how much of your organisation would actually pass?
Join us live
The guide linked above laid out the map. On Tuesday 21 July I am hosting a live session with Luís Barreto Xavier of Abreu Advogados to walk your own use cases through it. The focus is practical throughout: what the amendment actually lets you do, and under what conditions.
We start from the questions leaders keep asking. Can I upload our CVs and let AI screen the candidates? Can I pool our customer data to build marketing personas? Can I feed AI our annual report and invoices to read the company’s position?
For each one the honest answer is a version of “yes, under these conditions”, “yes, once you have done X and Y”, or “no”. Knowing which one applies is what separates using AI with confidence from guessing.
It is built for leaders of mid-sized companies, including those in regulated sectors, and for anyone whose data touches European ground even from outside Europe. No prior knowledge of the Act is assumed - we spend a few minutes on what changed, then the rest on what to do about it.
Virtual, about an hour, Tuesday 21 July at 17:00 London time.

