Like the GDPR, the EU AI Act applies to anyone doing business in Europe, not just firms based there. Its high-risk deadlines just moved to 2027. The obligations that matter most to fund managers and fintechs did not.
The EU AI Act is the world's first comprehensive AI regulation, and like the GDPR its reach is extraterritorial: it applies wherever an AI system's output is used in the EU. A UK or US firm with European clients, investors or distribution is in scope without ever opening a European office. The Act has been rolling out in phases since early 2025, with the heaviest obligations, for so-called high-risk systems, originally due this month.
That deadline is what just moved. On 24 July 2026 the EU published Regulation (EU) 2026/1744, known as the Digital Omnibus, in the Official Journal, and it entered into force three days later. The headline in every board pack is that the Act's high-risk obligations have been deferred to December 2027, and the conclusion many will draw is that the industry has bought sixteen months. Whichever side of the table you sit on, that conclusion costs money.
If you run a fund manager, or allocate capital to one, you are almost certainly a deployer of AI rather than a builder of it, and the obligations that were not deferred land on your desk, alongside a UK accountability regime that never depended on Brussels. If you build or sell AI into those firms, the deferral is not a pause in your compliance clock but the opening of a sixteen-month commercial window in which your buyers' diligence sharpens.
The deferral is real but narrow. Obligations for standalone high-risk systems under Annex III, the category covering AI used in recruitment, employee management and creditworthiness assessment, move from August 2026 to 2 December 2027. High-risk AI embedded in regulated products under Annex I moves to August 2028. That is the whole of the relief.
Everything else stays on its original timetable. The Article 50 transparency obligations took effect on 2 August 2026, two weeks ago as I write: client-facing chatbots must disclose what they are, and synthetic content must carry machine-readable marking. The Article 4 AI literacy duty has applied since February 2025, and it binds deployers as well as providers, any firm using AI tools, not only the firms building them. The prohibitions have been live since early 2025, and the Omnibus added a new one rather than softening any. The general-purpose AI rules for model providers took effect in August 2025. None of this was deferred.
The relief is real but narrow. Two high-risk deadlines moved. Every other obligation, including the transparency duties that took effect this month, stayed exactly where it was.
The Act sorts AI by what it is used for, not by how clever the technology is, and the same model can sit in different tiers depending on the job you give it. Four tiers matter, and for most readers the question is which of the middle two they are in.
Prohibited is the short list of banned practices: social scoring, manipulative techniques exploiting vulnerable groups, untargeted facial scraping and the like. If you are reading this, you are almost certainly not here, but it is worth knowing the list exists because the penalties at this tier are the headline ones, up to 35 million euros or 7% of global turnover.
High-risk is the tier the deferral is about, and it is defined by use case. For financial services readers the ones that bite are AI used in recruitment or employee management, creditworthiness and eligibility decisions, and biometric identification. A model scoring loan applicants is high-risk. The same underlying technology summarising research notes is not. High-risk systems carry the heavy machinery: conformity assessment, technical documentation, registration, logging, human oversight designed in, and for deployers the obligations I set out below. This is what now lands in December 2027 rather than this month.
Limited risk is where much of the everyday estate sits, and its obligation is transparency rather than conformity: people must be told they are dealing with AI. A client-facing chatbot must disclose that it is one. AI-generated content must be identifiable as such, with machine-readable marking. Emotion recognition and similar systems must inform the people exposed to them. These duties went live on 2 August 2026 and were not deferred, which is why a firm can be entirely outside the high-risk tier and still be non-compliant today.
Minimal risk is everything else, spam filters, spell-checkers, most internal productivity tools, and carries no new obligations, though the Article 4 literacy duty still applies to the people using them.
Two notes on the boundaries, because the boundaries are where firms get caught. Human involvement is not a get-out-of-tier card: routing a high-risk system's output through a person only changes the analysis if that person has real authority, competence and time to change the outcome. A reviewer who rubber-stamps the model's decision leaves you exactly where you were. And the tier attaches to the use, so the moment a limited-risk tool is repurposed into a consequential decision about a person, hiring, credit, eligibility, it changes tier, whether or not anyone told compliance.
Managers and allocators rarely build foundation models. They buy, license and fine-tune them, for research summarisation, client communications, onboarding, screening and portfolio analytics. Under the Act that makes the firm a deployer, and the deployer seat carries its own obligations: operating systems in line with the provider's instructions, assigning competent human oversight, monitoring performance, keeping logs, and informing the provider and the authorities when something goes wrong.
Two traps sit inside that seat. The first is the role shift. A firm that substantially modifies a system, rebrands it, or deploys it beyond its intended purpose can become the provider in law, inheriting the full compliance stack it thought it had bought its way out of. Fine-tuning a licensed model on proprietary data is exactly the activity that demands this analysis before it happens, not after. The second is the value chain. When a regulator or an investor asks who verified the training data and who answers for an error, the licence agreement is where the answer lives, and most were written before anyone had thought about the question.
For a UK manager the sharper point is that the binding accountability regime owes nothing to Brussels. The FCA has chosen not to write an AI rulebook; it expects firms to govern AI through the frameworks that already exist, and under the Senior Managers and Certification Regime a named individual is personally accountable today for the outcomes an AI system produces. If a screening model quietly disadvantages a class of clients, the question will not be whether Annex III applied yet. It will be which senior manager owned the control environment. The Consumer Duty asks the same question from the customer's side. Neither waits for December 2027.
If you sell AI-enabled products into fund managers, the deferral does not slow your compliance clock, it accelerates your commercial one. Your buyers are regulated firms whose due diligence is about to get sharper, because every one of them now has to answer the deployer questions above, and they will answer them by asking you. Expect procurement to probe training data provenance, conformity readiness, documentation, logging support, and who carries liability when the model errs. The vendors who can answer cleanly will move through diligence in weeks. The vendors who cannot will watch deals stall in legal review, and in my experience the deal that stalls in diligence rarely closes at the original price.
There is a positioning prize here as well. Between now and December 2027, conformity readiness is a differentiator; after it, a licence to operate. The providers who arrive at buyers' doors with the technical documentation, the transparency mechanics and the value-chain answers already built will spend the next sixteen months taking market share from those who treated the deferral as a pause. I spent eighteen years on the buying side of this table building the vendor frameworks a large institution uses to make exactly these decisions, and I can tell you the shortlist conversations are already changing.
For managers: know every AI system in use across the firm, classify each against the Act with the role-shift question asked wherever a model has been tuned or repurposed, check this month's transparency obligations are actually met, put a literacy programme in front of the people using the tools, and renegotiate vendor agreements while the firm still holds negotiating strength. For providers: build the conformity evidence now, make the value-chain answers part of the sales motion rather than an objection to be handled, and treat every diligence questionnaire as the sales document it has quietly become.
Deferred is not cancelled. December 2027 will arrive as a deadline, and on both sides of the table, the firms that treated it as a start date will meet it as one.
Primary source: Regulation (EU) 2026/1744 (the Digital Omnibus on AI), Official Journal of the European Union, 24 July 2026. Regulation (EU) 2024/1689 (the EU AI Act).