Skip to main content

News29 Apr 2026

The AI Act keeps moving. What happens to the decisions already made?

The EU AI Act has been delayed again and its timelines are still being argued over. The decisions already made under it cannot move with them.

A sealed brass cylinder in its case on a river marker, the water moving past it

The EU’s AI Act has been delayed again. Legislators in Brussels failed to agree on whether parts of the regulation should be pushed back, and timelines, obligations, and scope are still being debated.

That is not the Act going away. It is the Act still taking shape — which means the rules a decision is made under this year may not be the rules it is later judged against.

The AI Act did not arrive as a single switch-on moment

It took shape gradually — proposed, reworked, politically agreed, brought into force, and now still being implemented in phases.

EU AI Act timeline

  1. 2021

    Proposal tabled

    The European Commission tables the first draft of a horizontal regulation for AI.

  2. 2022

    Amendments negotiated

    Council and Parliament negotiate amendments through the year.

  3. 2023

    Political agreement

    Trilogue lands a provisional deal between the Council, Parliament, and Commission.

  4. 2024

    Law enters force

    The text becomes law, with obligations switched on in stages over the years that follow.

  5. 2026

    Delay debated

    Legislators in Brussels fail to agree on whether parts of the regulation should be pushed back. Timelines and obligations are still being contested.

  6. Ongoing

    Phased implementation

    Requirements land over time. Standards are still being defined. Guidance is still being written.

Recent discussions in Brussels show the same pattern. The disagreement is not about whether the AI Act applies — it is about how and when it can realistically be enforced. The latest round produced requests to extend compliance timelines and proposals to delay high-risk obligations, not because the regulation has gone away but because the machinery around it is not yet ready to operate. Authorities are still being designated. Conformity assessment bodies are not yet in place. Harmonised standards are still emerging.

As one legal analysis put it, the current changes “introduce a degree of uncertainty, whilst at the same time giving the prospect of additional time.”

The framework exists. The machinery does not.

What is compliant today may not be compliant next year

Most governance programmes are built on a simple idea: the rules stabilise. You define policy, implement controls, align systems, and then operate.

The AI Act is not a fixed rulebook. Interpretations evolve, guidance is layered in over time, and standards determine how compliance is measured. What passes review next year may not match the conditions that existed when the original decision was made.

A system produces an outcome. A loan is declined. A transaction is flagged. A customer is scored.

At that moment, a specific policy exists. A specific model version. A specific threshold. The decision is the consequence of all three meeting at one specific time.

At execution

What is in force, right now

Policy
A specific version exists
Model
A specific version exists
Threshold
A specific value exists

The reasoning is reconstructed, not observed

Six months later, the regulation has shifted, the guidance has been reinterpreted, the policy has been updated and the model has been retrained. The context in which the decision was made no longer exists in the same form. Then a regulator asks why the decision happened — not under today’s rules, but under the rules that existed then.

The organisation looks back. It finds logs, events, and fragments spread across systems. The inputs can be recovered and the outcomes located, but the reasoning is reconstructed — assembled from what remains rather than observed as it was.

This is not a failure of one system. It is structural. Across AI governance, the data already exists: risks are catalogued, incidents are recorded, frameworks are published. But they exist side by side, not as a single coherent artefact. Even recent work to map the AI risk landscape underlines this — datasets can be brought together into a shared interface, but the connections between them still have to be drawn by the reader.

The information is there. The decision is not.

In a system where compliance evolves over time, reconstruction becomes unreliable. You are not proving what happened — you are interpreting it through the present.

The decision is captured as it is made

A system built for stable policy breaks here. A system built for moving policy assumes this from the start.

Policies will change, standards will evolve, interpretations will shift. So the decision is captured at the moment it is made, rather than referenced later. The input, the policy, the context, the outcome, the version, and the timestamp are preserved together as they were.

When the rules change, that record does not have to be reinterpreted. It can be checked against the policy version recorded with it, rather than against the policy in force today.

That is a narrower claim than being right. The record does not establish that the policy was well drafted or that the outcome was correct. It establishes what was decided, on what inputs, under which version — the part that reconstruction cannot supply.

Asked

Was this decision compliant under the rules in force on 14 March?

RCP-AIACT-00481 VerifiedResolved in 2.0 seconds

MeshQu does not replace the systems that make these decisions. It captures what those systems do not retain: the decision as it stood at execution.

The AI Act will not arrive as a single, stable regime. It will continue to evolve through standards, guidance, and enforcement. The rules will keep moving; a decision already made will not. If it was not recorded as it was made, no delay to the timetable recovers it.


A record made at execution can still be read under the rules that applied then.

Sources & context

Sources behind this analysis

  1. 01POLITICO
  2. 02EUROPEAN COMMISSION
  3. 03BRUEGEL
  4. 04CEPS
  5. 05DLA PIPER
  6. 06A&O SHEARMAN
  7. 07CLIFFORD CHANCE
  8. 08EURONEWS
  9. 09OECD
  10. 10MIT AI RISK INITIATIVE

Cited in this piece

The work this piece rests on — the author’s own list first, then everything it links out to.

  1. 01POLITICO
  2. 02
    AI Act regulatory framework and timeline

    digital-strategy.ec.europa.eu

    EUROPEAN COMMISSION
  3. 03BRUEGEL
  4. 04CEPS
  5. 05DLA PIPER
  6. 06A&O SHEARMAN
  7. 07CLIFFORD CHANCE
  8. 08EURONEWS
  9. 09OECD
  10. 10MIT AI RISK INITIATIVE