
If you've been keeping an eye on the EU AI Act, you'll know there's been plenty of speculation over the past few months. Would implementation be delayed? Would the rules be softened? Would the legislation change altogether?
The latest update gives us some answers.
While the direction of travel hasn't changed, businesses now have more time in certain areas to prepare for EU AI Act compliance, alongside some important clarifications around enforcement and a handful of new obligations.
For companies building AI products, integrating AI into existing platforms, or thinking about their wider AI governance framework, this isn't a reason to pause your compliance plans. It's an opportunity to use the extra time wisely.
Here's what has changed, and more importantly, what it means for your business.
One of the biggest changes is the revised implementation timetable for different parts of the legislation.
The updated application deadlines are:
For many businesses, particularly those developing or deploying high-risk AI systems, these revised dates provide some welcome breathing room.
That said, the delay shouldn't be mistaken for a pause button.
Strong AI governance takes time to build. Understanding where AI is being used across your organisation, documenting decision-making, assessing risk and putting internal policies in place isn't something you'll want to leave until the last minute.
Increasingly, customers, investors and enterprise clients are asking businesses to demonstrate responsible AI use. Good AI compliance is becoming just as much a commercial advantage as a legal requirement.
The update also expands the list of prohibited AI practices.
From December 2026, AI systems that generate non-consensual intimate images, create child sexual abuse material (CSAM), or edit genuine photographs to reveal intimate body parts without consent will be prohibited.
While most technology companies won't be developing these kinds of systems, the change highlights an important trend.
The EU continues to take a firm stance on harmful uses of AI and is prepared to evolve the legislation as new technologies emerge.
For businesses developing AI products, it's another reminder that AI risk management should be considered throughout product development rather than treated as a final compliance exercise.
One practical challenge since the legislation was introduced has been understanding which regulator is responsible for supervising different AI systems.
The latest amendments provide greater clarity around the role of the AI Office, particularly where the same organisation develops both a general-purpose AI model and the AI systems built on top of it.
The update also confirms that national authorities will continue overseeing AI systems in specific sectors, including law enforcement, border management, judicial authorities and financial services.
For businesses operating across multiple jurisdictions or regulated industries, this clarification should make navigating AI regulation a little more straightforward.
One of the more practical changes relates to businesses already operating in highly regulated sectors.
For high-risk AI systems covered by Annex I, such as medical devices, toys, machinery, watercraft and other regulated products, the AI Act will no longer duplicate requirements where existing sector-specific legislation already imposes similar AI obligations.
That's good news for businesses already managing multiple compliance frameworks, helping to reduce unnecessary duplication while maintaining appropriate safeguards.
Products covered by the Machinery Regulation have also been given a more tailored approach.
Rather than applying the AI Act directly, the European Commission will be able to introduce additional health and safety requirements through machinery legislation where appropriate.
For manufacturers and industrial technology businesses, this should provide a more consistent regulatory approach without overlapping legal requirements.
Another welcome addition is a commitment from the European Commission to publish guidance aimed at making compliance easier.
The Commission has been tasked with helping businesses understand how to meet the requirements for high-risk AI systems while minimising unnecessary administrative burden, particularly where organisations are already complying with sector-specific legislation.
As further guidance is published over the coming months, businesses should gain a much clearer picture of how the legislation will work in practice.
Although some deadlines have moved, the overall message hasn't changed.
Businesses using or developing AI should use this additional time to strengthen their AI governance framework, understand where AI is being used across the organisation and prepare for future compliance obligations.
A good place to start is by:
For many growing businesses, AI legal compliance is no longer simply about avoiding regulatory risk. Enterprise customers, investors and procurement teams increasingly want confidence that AI is being used responsibly, securely and transparently.
Getting ahead now can save a significant amount of time and complexity later.
Whether you're building AI products, embedding AI into your business or trying to understand what the latest EU AI Act update means for your organisation, having the right AI legal advice early can make all the difference.
At Founders Law, our Emerging Technologies team works with startups, scaleups and ambitious technology businesses to navigate AI regulation, build practical AI governance frameworks and prepare for EU AI Act compliance without slowing innovation.
If you'd like to discuss how the latest changes affect your business, we'd be happy to help.