
On June 16 the European Parliament voted 423 in favour of pushing back the biggest deadline in the EU AI Act. The Council signed off on June 29.
August 2, 2026 became December 2, 2027 for standalone high-risk systems โ hiring tools, credit scoring, biometric identification. AI built into regulated products, medical devices among them, moved from August 2027 to August 2028.
Sixteen extra months. If you sell AI into a regulated industry, you probably exhaled.
We think the exhale is premature, and not for the reason you would expect.
Something quieter happened this year. The standard questionnaires enterprise buyers send to vendors before signing anything โ SIG Lite, the Standardized Information Gathering questionnaire most large enterprises use, and CAIQ, the Consensus Assessments Initiative Questionnaire that does the same job in cloud procurement โ grew AI sections.
They now ask things like: how are your AI outputs monitored? How was the model selected? Who are your AI subprocessors โ the outside parties whose models run inside your product? And what happens when the model produces an incorrect result?
Two years ago those questions were not in procurement decks. They are now, and they arrive with a signature line behind them.
Nearly every one of those questions can be answered two ways. You can answer with a policy: here is our documented process. Or you can answer with evidence: here is what happened when we tested it, on this date, and here is what failed.
Regulation, for now, accepts the first. Procurement is starting not to. Enterprise buyers have begun declining self-attestation โ a vendor's own word about its own system โ and asking for an assessment by someone who is not the vendor. The shift is most advanced in financial services, driven by the Digital Operational Resilience Act, then healthcare, then the public sector.
Which means the deadline that actually governs your company may not be December 2027. It may be the next enterprise deal in your pipeline.
If you build, implement or operate AI for customers in healthcare, financial services or government: when the AI section of that questionnaire lands on your desk, what do you send back? A policy document, or test results?
And if it is test results โ who ran them?
We work in AI compliance, so we have a horse in this race. We ask anyway, because we suspect the honest answer for most companies right now is "we have not been asked yet." That is a very different thing from having an answer.
ARIA tests whether an AI system actually follows the policy it is supposed to follow โ continuously, with each finding mapped to the framework clause it touches. Start a conversation โ
Written for people who have to make decisions about AI. What happened, why it matters, and what to do about it โ with every source linked so you can check the work yourself.
Or read it on LinkedIn โ