← Back to Perspectives

On 16 June 2026, the European Parliament approved amendments delaying most of the EU AI Act's high-risk system obligations, originally due to bind from 2 August 2026, out to December 2027 and August 2028. Anyone running a CX or AI programme with EU exposure could be forgiven for filing the Act under "later." That would be a mistake.

One set of obligations was deliberately left untouched by the delay, and it activated on schedule on 2 August 2026. It is the one most likely to land on a contact-centre director's desk rather than a compliance team's: the duty to disclose when a customer is talking to AI.


What actually moved, and what didn't

According to legal trackers at Holland & Knight and Inside Global Tech, the June amendments pushed back the rules for AI systems used in the Act's named high-risk categories, including biometrics, critical infrastructure, education, employment, migration, asylum and border control, to 2 December 2027. Obligations for AI embedded in physical products such as robotics and industrial machinery move to 2 August 2028.

What stayed in place:

In other words, the parts of the Act with the heaviest compliance engineering, model documentation, conformity assessments, human oversight design, got two more years. The part that changes what a customer sees on a chat window did not.

Why this lands on CX, not just legal

Article 50 requires that customers be told, clearly and in plain language, when they are interacting with an AI system rather than a human, and that AI-generated or manipulated content be marked as such. For any contact centre, digital assistant, or voice AI deployment serving EU customers, that is an operational build, not a policy memo: disclosure language in the conversation flow, a way to escalate to a human on request, and content-marking on anything AI-generated that reaches a customer.

Firms that treated the whole Act as one delayed deadline now have a gap between what they assumed and what is actually enforceable. The high-risk provisions bought breathing room for the technically hard work. The disclosure duty did not.


The Gulf contrast

The timing is a useful comparison point for firms operating across both Europe and the GCC. The World Economic Forum's January 2026 analysis on Gulf AI implementation noted that Gulf regulators have shown a willingness to introduce AI guidance quickly, then iterate with industry as system behaviour evolves, rather than legislate the full scope up front and then walk parts of it back under implementation pressure, which is broadly what has now happened with the EU AI Act's high-risk provisions.

Neither approach is without cost. The EU's phased retreat has created exactly the kind of "which bit still applies" confusion this article exists to clear up. The Gulf's faster, more iterative style (visible in Saudi Arabia's new AI training-data exception and the UAE's central bank guidance) puts more of the interpretive burden on firms in real time, with implementing detail arriving after the headline rule. Programmes operating across both regions need a compliance calendar that tracks actual commencement dates jurisdiction by jurisdiction, not a single "AI Act" or "AI regulation" line item.

What to check now


The bottom line

A regulatory delay is not blanket relief, and treating it as one is how compliance gaps open. The EU AI Act's toughest engineering requirements now have breathing room to 2027 and 2028. The requirement to tell a customer they are talking to a machine did not get that breathing room. If your CX operation serves EU customers, that is the deadline that already passed.