The EU AI Act's postponement rewards those who never started

The disparity driven by AI is also reflected in how it's currently regulated. This is Part 2 of a three-post series, and this one covers the EU AI Act's postponed deadline for high-risk AI — and why the winners look a lot like the companies that never bothered to start.

The analogy that started this

Picture studying for a professional license while your classmates skipped every class. You got your license on time. They get a multi-year extension, and are allowed to keep operating unlicensed in the meantime. That's roughly the position early-compliant health AI companies now find themselves in.

The AI Act, briefly

The EU AI Act was designed to be the world's first comprehensive cross-sector AI law. It covers any "provider" (maker) or "deployer" (B2B user) of AI tools, and sets requirements based on risk category. From the chatbot you use daily to your email spam filter, all of it is technically in scope. Health use cases land almost entirely in the "high-risk" bucket, which sets compliance requirements comparable to Class II medical devices — regardless of how the product is actually classified under MDR.

For AI/ML-enabled healthtech, that means relatively little extra burden if you're already a Class II+ SaMD, since you already have the QMS and Notified Body infrastructure to build on. It means disproportionately more if you're navigating the wellness-medical borderline, where the blanket "high-risk" classification can bump a consumer product up to something resembling a full medical device — an unfair jump for what would otherwise be considered genuinely low-risk.

What happened with the deadline

Here's the update since this question was first live: the high-risk obligations, originally due August 2, 2026, have now been formally postponed. The European Parliament and Council reached political agreement on May 7, 2026, the Parliament voted it through on June 16, 2026, and the Council gave final approval on June 29, 2026. The amended regulation was published in the Official Journal on July 24, 2026 and entered into force three days later.

The actual deferral: 16 months, not the two years initially floated — standalone high-risk (Annex III) systems now have until December 2, 2027, and AI embedded in already-regulated products (Annex I, which covers most medical devices) until August 2, 2028. Shorter than originally feared, but the core problem this series raised doesn't go away with a shorter number.

The grandfather clause that makes this unfair

Under Article 111 of the AI Act, the rules are not retroactive. High-risk AI systems already placed on the market before the new deadline don't need to comply at all, unless they undergo a significant design change afterward. It's a genuine grandfather clause, not a temporary reprieve — a system that's simply left alone can, in principle, stay outside the framework indefinitely.

The consequence is exactly the asymmetry the classroom analogy points at. Companies that did nothing so far may get a durable free pass. Companies that prioritised compliance properly did the upfront investment — industry estimates for a single high-risk AI provider's initial QMS and conformity work commonly run from roughly €200,000 into the mid-six-figures, with recurring annual costs layered on top; the specific €450,000/year figure some in the industry (including sources Giulia has cited previously) put on ongoing provider compliance sits toward the higher end of that range, but is broadly consistent with what a full QMS-plus-conformity-assessment programme costs to run — will carry that infrastructure while competitors who waited run with essentially zero overhead, and will still need to re-adjust to whatever rules eventually stick.

Why this is a disgrace, not just an inconvenience

In a space moving faster and more competitively than anything seen before, this isn't a minor timing quirk — it's a structural penalty on the companies that took the law seriously. One of regulation's core jobs is ensuring a level playing field for competition. Consumers and patients urgently need safeguards around AI, and neither of those goals is served by a system where the reward for early, good-faith compliance is a cost disadvantage against companies that simply waited out the deadline.

Europe rushed to be first with comprehensive AI legislation, only to end up with a system where viability, alignment, and timelines were afterthoughts — one that's straining the sector it was meant to protect before full implementation even arrived.

If you're at the borderline or caught in the middle of this, we can help you find a suitable path.

Series navigation

Part 1: LLMs' health advice gets separate treatment
Part 3: FDA's first-ever warning for uncontrolled use of AI in production

References

  • Council of the European Union, Artificial intelligence: Council gives final green light to simplify and streamline rules, 29 June 2026

  • Gibson Dunn, EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes, May 2026

  • Cloud Security Alliance, EU AI Act High-Risk Deadline: Deferred, Not Cancelled, on Regulation (EU) 2026/1744 and Article 111 mechanics

  • Tech Policy Press, EU's AI Act Delays Let High-Risk Systems Dodge Oversight, April 2026

  • Software Seni / ERT-cited industry figures on high-risk AI provider compliance costs, 2026

Methodology note: This article is based on Part 2 of my original three-post LinkedIn series (link), reflecting my professional experience and perspectives on the EU AI Act's postponed high-risk deadline and its impact on health AI companies. AI assisted in elaborating the topic into a broader article by integrating background research, fact-checking of the underlying figures and timeline, and updating the piece to reflect the deadline's final outcome as formally adopted. All analysis and regulatory perspectives are my own, and all content has been reviewed by me for accuracy.

Previous
Previous

Top nominated!

Next
Next

Notes from Scarlet's digital health summit