---

The timeline shifted (and may shift again)

The most important trend is the timeline itself. The Digital Omnibus package delayed several obligations, and many Annex III high-risk duties now track toward 2 December 2027. That does not mean "do nothing until 2027" — it means teams that start scoring and closing gaps now enter the deadline with evidence already in place. Treat any published date as a planning anchor to verify with counsel, not a fixed promise; the schedule has moved before and can move again.

GPAI obligations move to the front

General-purpose AI model obligations (transparency, technical documentation, copyright policy, systemic-risk testing for large models) bit earlier than the high-risk deployment duties. For SaaS teams building on third-party models, that shifts attention upstream: the model provider's documentation becomes an input you must understand and pass downstream into your own conformity story.

From one-time audit to continuous monitoring

The old pattern — hire counsel, get a report, file it — is giving way to continuous gap monitoring. Systems change monthly: new models, new data, new use cases. A one-time audit is stale on arrival. Readiness tooling that re-scores after each change keeps the gap list live, which is what regulators and customers increasingly expect to see.

Convergence with other regimes

EU AI Act is rarely the only regime in play. Teams shipping globally also weigh the OECD AI Principles, national implementations, and sector rules (e.g., GDPR where personal data is involved). The trend is toward a single internal risk-and-gap view that maps to multiple frameworks at once, rather than a separate compliance project per regime.

Authoritative references

  • EU AI Act (Reg. 2024/1689): https://eur-lex.europa.eu/eli/reg/2024/1689/oj
  • Digital Omnibus (amending regulation): https://artificialintelligenceact.eu/
  • European Commission AI policy: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai