If you built your 2026 plan around the 2 August 2026 high-risk deadline in the EU AI Act, that plan is out of date. The deadline moved, and it moved late.
What actually changed, and when
The Digital AI Omnibus was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It deferred the obligations that most compliance teams had been building toward. The current calendar:
- 2 August 2026 — general application, including the Article 50 transparency duties. Systems already on the market before that date have a grace period to 2 December 2026.
- 2 August 2027 — Member States must have at least one regulatory sandbox running. This was itself postponed from 2 August 2026.
- 2 December 2027 — obligations for high-risk systems under Article 6(2) and Annex III. This is the one that moved, from August 2026.
- 2 August 2028 — obligations for high-risk systems under Article 6(1) and Annex I.
So the Act is not fully in force, and will not be for another two years. Anyone telling you otherwise is working from a 2025 briefing.
What a deferral actually does to a hiring plan
The instinct is to slow down. That is the wrong read, and it is worth being specific about why.
A deferral does not reduce the amount of work. It moves the date by which the work must be finished and lets organizations do it properly instead of in a panic. The obligations themselves did not shrink. Conformity assessments, technical documentation, post-market monitoring, human oversight design and registration in the EU database all still have to exist, and they have to exist for systems that in many cases are still being built.
What changes is the shape of the hire. An organization facing an August 2026 cliff hires a contractor to get over the cliff. An organization facing December 2027 hires someone permanent to build a function. The second is a better job and a harder search.
The extraterritorial point that people keep missing
The Act reaches any provider or deployer placing an AI system on the EU market or whose system’s output is used in the EU, regardless of where the organization sits. A US nonprofit with European donors, a university with EU research partners, a health system using a model whose output crosses a border: these are in scope, and their boards frequently do not know it.
This is the practical reason the governance role is no longer a European role. It is a role wherever the output lands.
And on the American side: NIST, which is a different instrument entirely
The United States has no federal equivalent to the AI Act, and it is worth being precise about that rather than implying one exists. What it has is the NIST AI Risk Management Framework, published by the National Institute of Standards and Technology, together with the Generative AI Profile that accompanies it.
The difference is not cosmetic:
- The EU AI Act is binding law. It carries obligations, conformity assessments and penalties, and it applies whether or not an organization finds it convenient.
- The NIST AI RMF is voluntary guidance. Nobody is fined for ignoring it. It is a structure for organizing risk work — Govern, Map, Measure, Manage — and it is genuinely good at that.
In practice organizations use both, and that is the right instinct. NIST gives you the operating model. The AI Act tells you which parts of it are not optional if your output touches Europe. ISO/IEC 42001 sits alongside as the certifiable management system standard, which is what an auditor will actually ask to see.
For a hiring manager the practical consequence is this: a candidate who can only recite the AI Act’s risk tiers is a compliance reader. A candidate who can run a NIST-style risk process and map its outputs onto the Act’s evidentiary requirements is the person who can actually build the function. The second is much rarer and worth paying for.
What we are actually seeing in postings
Across the roles published on AI-Governance-Jobs.com, the pattern is consistent: employers are still inventing the titles. The same scope appears as AI Governance Lead, Responsible AI Manager, AI Risk Officer, Model Risk Manager and Director of AI Compliance, often inside the same sector. Candidates arrive from audit, legal, security and privacy rather than from a dedicated pipeline, because no dedicated pipeline exists yet.
That is a description problem before it is a supply problem. A qualified internal auditor who has never searched the phrase “AI assurance” will not find the role that wants exactly what they can do.
Four things worth doing before December 2027
- Inventory the systems, not the vendors. Most organizations can name their AI vendors and cannot name the decisions those systems influence. The Act regulates the second.
- Decide who owns it by name. Not a committee. A person whose job description contains the obligation.
- Write the documentation as you build, because reconstructing technical documentation for a system that shipped eighteen months ago is where the real cost lands.
- Hire earlier than the deadline suggests. The people who can do this work are being hired now, by organizations that read the deferral as breathing room rather than as a reprieve.
For readers in France, Belgium and Switzerland
For a large part of our readership the AI Act is domestic law rather than a foreign regulatory story. Our co-founder Stephan Pochet, a credentialed senior auditor, writes on these subjects in French:
- IA en entreprise : la gouvernance n’est plus une option
- 75 ans, deux hivers, une explosion ou une bulle ?
Frequently asked questions
Is the EU AI Act fully in force in 2026?
No. General application and the Article 50 transparency duties began on 2 August 2026, but obligations for high-risk systems under Annex III were deferred to 2 December 2027, and those under Annex I to 2 August 2028, by the Digital AI Omnibus that entered into force on 27 July 2026.
Why were the high-risk deadlines pushed back?
The European Commission proposed the deferral in the Digital Omnibus on AI published 19 November 2025, citing the state of readiness across standards, notified bodies and Member State infrastructure. The regulatory sandbox requirement was postponed on the same basis, from 2 August 2026 to 2 August 2027.
Does the EU AI Act apply to organizations outside Europe?
Yes, where an AI system is placed on the EU market or where its output is used in the EU, regardless of where the provider or deployer is established.
Should we delay hiring for AI governance because the deadline moved?
The obligations did not shrink, only the date moved. A deferral turns an emergency contract hire into a permanent function build, which is a harder search, not an easier one, and the candidates capable of doing it are being hired now.
What job titles cover this work?
AI Governance Lead, Responsible AI Manager, AI Risk Officer, Model Risk Manager and Director of AI Compliance are all in current use for overlapping scope. The vocabulary is unsettled, which is itself a barrier to candidates finding the roles.
Where can I follow this coverage?
New roles, essays and framework updates are posted on LinkedIn at https://www.linkedin.com/company/grc-careers-llc, and the roles themselves are at AI-Governance-Jobs.com.
Sources: the Digital AI Omnibus, in force 27 July 2026 (OJEU, 24 July 2026); European Commission, Digital Omnibus on AI, 19 November 2025; Regulation (EU) 2024/1689, Articles 6 and 50 and Annexes I and III.
