MICKAI®ArticlesThe EU AI Act deferral buys time,…
Article · 30 July 2026

The EU AI Act deferral buys time, not a pass on auditable AI

Deferred deadlines change when the high-risk obligations bite, not what a regulator will eventually ask your AI to prove.

Author
Micky Irons
Published
30 July 2026
Follow Micky Irons
LinkedInX
eu-ai-actai-regulationsovereign-aiai-audit-trailai-compliance
The EU AI Act deferral buys time, not a pass on auditable AI

The deferral of the EU AI Act's high-risk deadlines gives organisations more time to comply, but it does not change what a regulator will eventually ask of a high-risk system, which is to show its working. On 29 June 2026 the Council of the European Union gave final approval to the Digital Omnibus simplification package. Under the agreed changes, high-risk obligations for standalone systems listed in Annex III are deferred to 2 December 2027, and obligations for AI embedded in regulated products move to 2 August 2028. The core high-risk requirements themselves survive intact. The organisations that treat this as breathing room to build evidence, rather than a reprieve from producing it, will be the ones that pass inspection first time.

What did the Council of the EU approve on 29 June 2026?

The Council gave final approval to the Digital Omnibus, a simplification package that makes targeted adjustments to the EU AI Act. The headline change for regulated buyers is the deferral of the high-risk regime. Standalone Annex III systems, the category covering areas such as employment, credit and access to essential services, now face their compliance date on 2 December 2027, while AI embedded in regulated products, such as medical devices and machinery, follows on 2 August 2028. What the package does not do is soften the core demands on systems that remain high-risk. Risk management, data governance, technical documentation, record keeping, human oversight, accuracy and robustness all remain on the statute book.

Does the deferral change what high-risk AI systems must eventually prove?

No. Every substantive obligation the deferral touches is still coming, and most of them are evidence obligations at heart. Record keeping requires logs of the system's operation. Technical documentation requires an accurate account of how the system was built and how it behaves. Human oversight requires proof that a person could intervene, and did, where it mattered. None of these can be conjured retrospectively in the weeks before a deadline. A log that starts in November 2027 says nothing about the operation that preceded it, and documentation reverse engineered from a live system is exactly the kind of artefact a supervisory authority learns to distrust. The date moved. The burden of proof did not.

A deferral moves the deadline. It does not move the burden of proof. When a supervisor finally asks a high-risk system to show its working, the only good answer is a record that was being written all along.

Mickai

Why is retrofitting auditability harder than building it in?

Because evidence is a property of architecture, not an accessory bolted on later. If an AI capability runs across third party services, the record of what it did is scattered across vendors' logs, retention policies and jurisdictions the deploying organisation does not control. Reconstructing a decision after the fact then depends on requests to suppliers, best effort telemetry and human memory, all assembled under pressure. We took the opposite path. Mickai is a Sovereign Intelligence Operating System, a SIOS, that runs entirely on the customer's own hardware, on premise and air gapped where required. Every action its studios take is written to the Open Audit Record, a cryptographically signed, tamper evident log that is post quantum secure and verifiable offline. The evidence a supervisor will one day ask for exists from the first day of operation, held by the organisation itself, because the operating system cannot act without writing it.

How does a sovereign operating system produce the evidence regulators will ask for?

By making the control the default rather than the policy. In our design, sensitive actions do not execute on the say so of a single model. A cooperative multi model consensus substrate requires our specialist sovereign models to agree before any sensitive action runs, which reduces the chance that one confident but wrong output becomes an operational decision. Sensitive actions are further gated by voice biometrics, so meaningful human oversight is enforced by the system rather than described in a manual. A hardware held root of trust anchors the stack, and because the operating system functions fully offline, the audit trail does not depend on any external service being reachable, honest or still in business. For a high-risk deployment, that turns Annex III record keeping from an aspiration into a byproduct of normal operation.

We build this as one operating system carrying 87 studios, of which ten are production ready at launch and 77 are in development, so the same audit and oversight fabric extends across functions instead of being reimplemented for each new use case. The architecture is covered by 104 filed UK patent applications across 2,340 claims, held by Mickai LTD, though we treat the patents as a moat around the engineering rather than the story itself.

What should regulated organisations do with the extra time?

Use it to make the eventual inspection boring. The deferral is most valuable to organisations that treat 2 December 2027 as the date their evidence must already be mature, not the date they start gathering it. In practical terms, we suggest five moves.

  • Map which of your AI systems will fall under Annex III or the embedded product rules, and record the reasoning behind each classification.
  • Decide where the evidence of AI behaviour will live, and prefer infrastructure you control over logs held in a supplier's cloud.
  • Upgrade logging from best effort text files to signed, tamper evident records that can be verified independently of the system that wrote them.
  • Put human oversight into the control path itself, so sensitive actions require an authenticated person rather than a policy that assumes one.
  • Rehearse the supervisor's question now. Pick a past AI assisted decision and test whether you can reconstruct it end to end from your records.

Organisations that do this will find the 2027 and 2028 deadlines arrive as a formality. Those that wait will discover that the hardest part of the EU AI Act was never the paperwork. It was the months of evidence they did not collect while they had the chance.

Frequently asked questions

When do the deferred EU AI Act high-risk obligations now apply?

Standalone high-risk systems under Annex III must comply from 2 December 2027, and AI embedded in regulated products from 2 August 2028, following the Council of the EU's final approval of the Digital Omnibus package on 29 June 2026.

Does the Digital Omnibus weaken the EU AI Act's high-risk requirements?

Not materially. The package makes targeted adjustments, and narrows which embedded systems count as high-risk, but the core obligations on high-risk systems, risk management, record keeping, technical documentation and human oversight, remain in place. Organisations must still meet them in full, only later.

Why should organisations build auditability before the new deadlines?

Because the obligations are evidence based and evidence cannot be created retrospectively. Logs, documentation and proof of human oversight only exist if they were captured while the system ran, so building auditable AI now means the record is already mature when enforcement begins.

Can an air-gapped AI system still meet EU AI Act record keeping duties?

Yes. Record keeping requires trustworthy logs, not connectivity. Mickai's Open Audit Record is cryptographically signed, tamper evident and verifiable offline, so an air gapped deployment can hand a supervisor a complete, independently checkable history of every AI action.

What is MICKAI?

Mickai is a Sovereign Intelligence Operating System, a SIOS, that runs on the customer's own hardware, on premise and air gapped. Every action is written to the Open Audit Record, a cryptographically signed, post quantum secure, tamper evident log that can be verified offline. It carries 87 studios on one operating system, with ten production ready at launch and 77 in development, and its architecture is covered by 104 filed UK patent applications across 2,340 claims, filed rather than granted.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/eu-ai-act-high-risk-deferral-auditable-ai. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles