10. July 2026
Back in 2024, the AI Act was adopted in Brussels with the aim of creating common rules for the development and use of AI. The regulation is built on a risk-based approach, where the requirements for companies depend on how much risk an AI system poses to people, society, and fundamental rights.
However, in the autumn of 2025, a need arose to postpone some parts of the AI Act through a Digital Omnibus. The reasoning behind the postponement includes a wish to ensure that companies have access to the necessary standards, common specifications, and guidelines before the requirements for high-risk AI systems come into force. The standards are meant to make it easier to translate the legal requirements into concrete processes and workflows in practice.
The political agreement has now been formally approved by both the European Parliament and the Council of Ministers, and the new deadlines will be 2 December 2027 for standalone high-risk AI systems and 2 August 2028 for high-risk AI systems embedded in products. The next step is publication in the Official Journal of the EU, after which the changes will take effect.
Even though parts of the AI Act's requirements have been postponed, work on the European AI standards is continuing at a fast pace.
Several of the standards have been out for public consultation during the spring, while others are going through the final approval processes. The standards are intended to help companies and organizations work systematically with, among other things, risk management, cybersecurity, datasets, transparency, and quality management of AI systems, and can be used by all types of companies regardless of their risk level.
The first standard expected to be published is the standard for quality management of AI systems. The standard has already been approved by the European member states in the formal vote and is expected to be published during the summer. Once the standards are published, the European Commission must harmonize them so they can serve as a tool for demonstrating that an AI system meets the applicable requirements.
Standards in public consultation
Standards under further processing
Standards sent to the European Commission
Both standards are expected to be sent out for public consultation in September.
Minimal or no risk
AI systems with very low risk are not subject to specific requirements. This can include, for example, spell checkers, recommendation features, or navigation tools.
Limited risk
These systems are subject to transparency requirements. Users must, for example, be informed that they are interacting with an AI system.
High risk
AI systems that can affect people's safety, health, or fundamental rights. This can include, for example, AI used for credit assessment, recruitment, education, or critical infrastructure. These systems are subject to extensive requirements regarding documentation, risk management, and control.
Unacceptable risk
AI systems deemed to pose an unacceptable risk to society are prohibited. This includes certain forms of social scoring and other applications that conflict with the EU's fundamental values.