In July, Brussels handed every AI team in Europe a sixteen-month reprieve. The compliance calendar moved. The failure calendar – the one your models actually run on – didn’t move a day.
Series – this is part 2 of 2 on running AI in production. Part 1: Your AI Is Quietly Rotting and You Can’t See It.
The exhale was audible. The Digital Omnibus – Regulation (EU) 2026/1744, in force since 27 July – deferred the EU AI Act’s high-risk obligations from August 2026 to 2 December 2027, and to August 2028 for AI embedded in already-regulated products. Conformity assessments, evidence duties, post-market monitoring: the whole high-risk package shifted right.
The relief is partly earned. The high-risk regime is heavy, guidance arrived late, and plenty of organisations were heading for a deadline they couldn’t credibly meet. Sixteen extra months to do the work properly is genuinely useful.
But a wrong conclusion is spreading in the slipstream of the announcement: that AI assurance itself can now wait. It can’t, and the reason has nothing to do with Brussels.
What Actually Moved – and What Didn’t
The deferral covers the high-risk obligations for stand-alone systems in Annex III – credit scoring, hiring, access to essential services – and, later still, high-risk AI inside regulated products. What did not move: the transparency duties that took effect on 2 August 2026 (chatbot disclosure, AI-content marking, deepfake labelling), the general-purpose model obligations, the Act’s outright prohibitions, and the AI Office’s enforcement powers, which are live now.

The deferral changed when you must prove your systems still behave. It changed nothing about whether they do. Reading it as permission to stand down the assurance work confuses the regulator’s calendar with the model’s.
Drift Doesn’t Read Regulations
Models degrade on their own schedule. The long-run evidence hasn’t changed since we wrote about the mechanics of silent model failure: a Scientific Reports study that tracked 32 model-dataset pairs over time found temporal degradation in 91% of them, and infrastructure monitoring can’t see any of it, because it watches the servers – the layer that doesn’t rot.
The 2026 numbers say the bill is already being paid. Gartner’s April survey of 782 infrastructure and operations leaders found only 28% of AI projects fully delivering their promised return, with 20% failing outright – and Gartner separately expects 60% of AI projects to be abandoned through 2026 for want of AI-ready data. None of those numbers cite a compliance deadline. Your models started degrading the day they shipped, and no regulation defers that.
Evidence Has a Start Date
There’s a second, sharper reason the deferral is not a pause button. When December 2027 arrives, the organisations that look ready will be the ones holding a monitoring trail: logged predictions, reference datasets, drift reports, evaluation history, model cards. That trail has one awkward property – it can only be produced forwards.

The evidence you will need in December 2027 starts existing on the day you switch the monitoring on – and not a day before. Started now, it’s routine engineering absorbed into normal budgets. Started in autumn 2027, it’s a retrofit under deadline pressure, competing for the same specialists as everyone else who waited, at prices set accordingly.
What to Do With Sixteen Months
Not a programme – a layer, built one model at a time. Log inputs and predictions. Keep a known-good reference window. Run drift detection against it. Track accuracy wherever ground truth eventually arrives. Watch cost per prediction as deliberately as cloud spend, because the inference bill creeps while nobody owns it. For LLM systems, put evaluation and guardrail checks on a cadence. Lineage and model cards then fall out as by-products rather than deliverables.
Do that for one production model this quarter and the December 2027 question stops being frightening. The monitoring is the compliance – everything else is paperwork around it.
Q&A: The AI Act Delay and What It Means
Did the EU AI Act’s high-risk obligations get delayed?
Yes. The Digital Omnibus (Regulation (EU) 2026/1744, in force 27 July 2026) deferred the high-risk obligations for stand-alone Annex III systems – credit scoring, hiring, essential services – from August 2026 to 2 December 2027, and to August 2028 for AI embedded in regulated products. Transparency obligations and general-purpose model rules were not deferred and have been enforced since August 2026.
Does the delay mean AI monitoring can wait until 2027?
No. Models degrade on their own schedule – one long-run study found 91% of model-dataset pairs degraded over time – and the cost of undetected drift accrues whether or not a regulator is watching. There’s also a practical trap: the monitoring evidence you’ll need in December 2027 can’t be backdated, so a trail that starts now is the cheap version of compliance.
What should we do with the extra sixteen months?
Build the post-market monitoring layer while it’s routine engineering rather than a deadline retrofit: log predictions, keep reference datasets, run drift detection, track accuracy where ground truth arrives, watch cost per prediction, and put evaluation on a cadence for LLM systems. Start with one production model and expand.
What does the EU AI Act still require right now?
Since 2 August 2026: transparency duties (chatbot disclosure, AI-content marking, deepfake labelling), the general-purpose AI model obligations, and the Act’s prohibitions – all under an AI Office with live enforcement powers. The high-risk package, including Article 72’s post-market monitoring, follows from 2 December 2027.
The series began with part 1, Your AI Is Quietly Rotting and You Can’t See It – why model degradation stays invisible while every dashboard stays green.
Working Through This With Vertex Agility
Our Managed ModelOps service is the layer this article describes, run as a service: monitoring deployed in your own environment, drift and cost watched on an agreed cadence, and the evidence trail produced as a by-product of normal operation – so December 2027 arrives as a formality rather than a fire drill.
If you’re running models in production and can’t yet prove, on demand, that they’re still behaving, start with the smallest possible step: a free AI Health Scan on one model. Two data extracts, no labels, a straight red, amber, or green in days – and the first entry in a monitoring trail that, from now on, only grows.