“We Take AI Ethics Seriously” Is Not an Answer Any More
Read summarized version with

The deal was going well. Good technical fit, engaged stakeholders, a system that did what it promised. Then a security questionnaire arrived with a section nobody on the call had budgeted for, and the answers took three weeks that the timeline did not have.
Nothing about the software was wrong. What was missing was evidence. Not better intentions, not a stronger model. Documentation of who owned the system, what it did when it was uncertain, and how anyone would know if it drifted.
This is the shift I keep watching from the founder's seat. Responsible AI stopped being a values slide and became a gate. And in 2026 something happened that made a lot of teams misread that gate badly.
Short answer: The EU delayed the AI Act's high-risk obligations by sixteen months, to 2 December 2027. It delayed nothing else that matters this year, and it delayed nothing at all in enterprise procurement. Buyers now ask for evidence rather than principles: a named owner, a written policy with a change history, an operating record, and documentation available on request. That expectation is set by ISO/IEC 42001 and NIST AI RMF, neither of which moved.
Brussels blinked. Read the small print.
In November 2025 the European Commission tabled the Digital Omnibus on AI, and after a fraught trilogue the institutions reached political agreement on 7 May 2026. The high-risk obligations for stand-alone Annex III systems moved from 2 August 2026 to 2 December 2027, with AI embedded in regulated Annex I products moving to 2 August 2028. The Council gave final approval on 29 June 2026, after the Parliament endorsed it on 16 June.
The headline everyone read was "the EU delayed the AI Act." That is half true, and the half that is false is the expensive half.

Article 50 transparency obligations stay exactly where they were, applying from 2 August 2026. The Article 50(2) watermarking requirement applies from 2 December 2026 for systems already on the market. A new Article 5 prohibition on AI systems that generate non-consensual intimate imagery and child sexual abuse material also lands on 2 December 2026, and that one did not exist when most governance plans were written. The Article 4 AI literacy duty has applied since February 2025 and was never in scope for delay.
So the practical position is not relief. It is a calendar that got more complicated. A governance programme organised around a single delayed cliff will sail straight past three obligations that never moved.
The deadline moved. The questionnaire did not. The regulator gave you sixteen months, your buyer gave you until Tuesday.
Why the delay changes nothing that matters to you
Here is the part that gets missed, and it is the reason I am writing this rather than a relieved summary.
The procurement gate never rested on the AI Act. It rests on ISO/IEC 42001, the first international AI management system standard, and on the NIST AI Risk Management Framework, with its four functions of govern, map, measure and manage. Neither is a law. Neither carries a penalty. Neither was touched by the Omnibus.
And neither one waited for Brussels in the first place. Enterprise reviewers adopted that vocabulary because they needed a way to compare vendors, not because a regulator told them to. Nobody sent your buyer's third-party risk team a sixteen-month extension. The questionnaire that arrives next quarter will look exactly like the one that arrived last quarter, because it was never keyed to the Act's calendar.
Which produces a strange advantage for anyone paying attention. A meaningful number of your competitors just moved their governance work to late 2027. They will meet the same questionnaire you will, in the same quarter, with sixteen fewer months of operating record than you.
A reviewer cannot test a belief
Principle-era responsible AI was a statement of intent. We value fairness. We believe in transparency. Humans stay in the loop. All of it sincere, and all of it unfalsifiable.
A reviewer cannot test a belief. They can only test a record. So the question stopped being what do you value and became show me. Show me who owns this system. Show me what it does when it is not confident. Show me the last time someone overrode it and what happened next. Show me how you would know if it drifted.
That is why the scrutiny is laddered.

Nothing on rung one is wrong. Principles matter, and a team without them engineers worse systems. But a values page is an answer to a question nobody is asking any more.
The claim that quietly fails a reviewer
One detail worth more than it looks, because I watch vendors get it wrong constantly.
ISO does not certify anyone. ISO writes the standard. Certification is carried out by independent certification bodies, which may themselves be accredited by national accreditation bodies. So "we are ISO 42001 certified" is an incomplete sentence. Certified by whom, accredited by whom, and covering what scope?
Plenty of vendors say certified when they mean aligned to, or mean a gap assessment someone ran internally last year. It usually passes unchallenged on a sales call. It does not pass a reviewer who has read the standard, and it converts a trust conversation into a credibility problem at the worst possible moment.
If you are aligned but not certified, say aligned. It is a perfectly strong answer, and it is the one you can defend.
What procurement-ready actually means
Strip away the framework language and a review is asking four questions.
The question behind the question | What satisfies it |
|---|---|
Who owns this? | A named team accountable for whether the system is still correct, not only whether it is still running |
What happens when it is wrong? | A documented behaviour at low confidence, an escalation path, and a record of it being used |
How would you know? | Evaluation, logging and traces that exist before the incident, not reconstructed after it |
Can you show me? | Evidence produced on request without a three-week scramble |
Notice what is absent. No model benchmark. No architecture diagram. No ethics statement. The review is about operating discipline, which is why it catches so many technically excellent teams off guard.
Responsible Engineering, not a compliance layer
The mistake I see most often is treating this as paperwork to be added once the system works. Governance retrofitted onto a finished system is expensive, thin, and obvious to anyone reading it carefully.
We engineer it into the work instead. Ownership assigned when the system is designed, not when the questionnaire lands. Behaviour at low confidence decided by engineers rather than discovered by users. Logging and evaluation specified alongside the feature. An operating record that accumulates because the system produces it, not because someone assembles it under deadline.
That is not a moral position. It is the cheaper path, and it is the only one that produces evidence with dates on it. You cannot manufacture an operating record retroactively. You can only have started earlier.
Key takeaways
- The Digital Omnibus moved Annex III high-risk obligations to 2 December 2027 and Annex I to 2 August 2028. The Council approved it on 29 June 2026.
- Article 50 transparency still applies from 2 August 2026. Watermarking for existing systems and the new Article 5 prohibition both apply from 2 December 2026.
- A programme organised around one delayed deadline will miss three obligations that never moved.
- The procurement gate rests on ISO/IEC 42001 and NIST AI RMF, not on the Act. Neither moved, and buyers issued no extension.
- Reviewers cannot test a belief, only a record. Principles are rung one of a ladder that now starts higher.
- ISO does not certify anyone. Independent bodies do. Say aligned if you are aligned; it survives scrutiny and certified does not.
- An operating record cannot be produced retroactively. That is the whole argument for starting now rather than in 2027.
Where CoderTrails fits?
We engineer AI systems for regulated, document-heavy businesses. The evidence layer this article describes is part of that work, decided during design rather than assembled when a questionnaire lands. If you want to know what your evidence file would survive today, that is what the AI Readiness Audit looks at. It starts with a 30-minute call.