The EU's AI Act Deadline Arrived. Brussels Moved the Goalposts First
The EU AI Act's high-risk rules for school and university AI were due 2 August 2026, but a last-minute Digital Omnibus pushed them to December 2027 — leaving only disclosure duties in force now.
A deadline that arrived and immediately dissolved
For over a year, compliance teams at universities and international schools across Europe had 2 August 2026 circled on the calendar. That was the date the EU AI Act's toughest rules for "high-risk" AI systems — including tools used for admissions decisions, automated grading, exam proctoring and student monitoring — were due to become enforceable.
They didn't. Six days before the deadline, on 27 July, the EU's Digital Omnibus on AI entered into force, pushing the application date for these Annex III high-risk systems from 2 August 2026 to 2 December 2027. Some categories of embedded high-risk AI now have until 2028. The deferral was agreed so close to the wire that several compliance advisories published in the spring had to be rewritten in the space of a week.
The underlying obligations have not changed. Only the date on which non-compliance starts to bite has moved.
That distinction matters more than it sounds. The Act's requirements for education AI — documented risk assessments, human oversight, bias testing, technical logging — still exist in law. What changed is when regulators can actually penalise an institution for not having them in place.
What still applies from this month
Not everything was deferred. Article 50's transparency duties came into force on schedule on 2 August 2026, and they apply regardless of whether a system counts as high-risk. Schools and universities using AI tools now have to ensure:
- Students and staff are told clearly when they are interacting with an AI system rather than a human.
- AI-generated or AI-manipulated content, including deepfakes used in teaching materials, is labelled as such.
- Any use of emotion-recognition or biometric categorisation — a feature creeping into some proctoring and engagement-monitoring products — triggers a notification obligation.
So a university using an AI-driven exam proctoring tool that flags "suspicious" facial expressions is caught by the disclosure rules now, in 2026, even though the deeper high-risk obligations for that same tool don't bite until December 2027.
Why this matters beyond Brussels
UK schools and universities are not directly bound by the EU AI Act. But the deferral matters to them in three ways. First, many UK institutions buy assessment and proctoring software from vendors — Turnitin, Gradescope-style grading tools, exam-integrity platforms — that serve the EU market and will build compliance timelines around the new December 2027 date, meaning UK customers effectively inherit that vendor roadmap. Second, transnational education partnerships and dual-degree programmes with EU universities will need to track both regimes. Third, the deferral is a live case study in how fast AI regulation can move: a headline deadline that education leaders had been planning around for eighteen months evaporated in a single week, which is exactly the kind of whiplash that makes school leaders wary of building policy around any single external deadline.
The deferral itself was not uncontroversial. Digital rights groups have criticised the Digital Omnibus as a rollback driven by industry lobbying rather than a genuine technical readiness gap, arguing that pushing back oversight of AI used in admissions and grading removes protection for students precisely while adoption of these tools is accelerating.
What to do
- If your institution procures AI tools from EU-facing vendors (proctoring, automated grading, admissions screening), ask the vendor directly what changed in their compliance timeline after 27 July, rather than assuming their marketing material is current.
- Treat the Article 50 disclosure duty as a floor, not a ceiling: telling students when they are interacting with an AI system is good practice regardless of jurisdiction, and costs little to implement now.
- Do not treat the December 2027 deferral as permission to wait. Risk assessment and human-oversight documentation take months to build properly; starting now avoids a repeat scramble when the new deadline approaches.
What to watch
Watch for whether the December 2027 date holds, given that the August 2026 date didn't. Also watch how UK regulators and the Department for Education respond — the UK has its own emerging AI governance track, and divergence from the EU timeline could leave English schools and universities navigating two separate sets of expectations for the same imported tools.
Sources:
- EU AI Act's High-Risk Deadline: Deferred, Not Cancelled
- EU AI Act education deadline arrives, most rules deferred
- What Actually Comes Due on August 2, 2026: Article 50 Transparency and the Digital Omnibus Reset
- The EU AI Act and assessment: December 2027 is not a snooze button
- EU Digital Omnibus on AI Enters Into Force