The AI Act deferred the hard part

Brussels moved the high-risk deadlines to late 2027 and 2028. It did not move the burden of proof. A model that will face scrutiny then needs a track record that starts now, because you cannot backfill evidence.

2 min read

Brussels gave European compliance teams the sentence they wanted. The AI Act's high-risk obligations are deferred, to December 2027 for standalone systems and August 2028 for embedded ones (Gibson Dunn's analysis of the postponement). Most boardrooms drew the natural conclusion, that they now have more time.

They misread what was deferred. The deadline moved. The burden of proof did not, and the evidence that proof demands accumulates in real time or not at all. The duties already in force stayed in force, with general-purpose model duties applying since August 2025 and transparency duties since August 2026.

What proof will be made of

When a high-risk system faces scrutiny, the questions will be archival. How was this model validated before deployment, and by whom? What has its error rate been, measured how, over what period? When it was wrong, who was told, and what changed?

Every answer is a record with a date on it. Start keeping records in mid-2027 and you can account for six months of a system's life. Any assessor will read the silence before that for exactly what it is, and you cannot buy the missing months at any price. If you own a system that will one day be classified high-risk, that conversation is already on your calendar.

The backfill temptation

Expect a small industry of retrospective documentation as 2027 approaches (e.g. validation reports written long after deployment and approval chains formalised backwards). Some of it will be sincere. All of it proves the ability to write documents, not the practice of running a governed system. Regulators are trained to tell the two apart, the same skill that separates an evaluation from a pilot.

What to log from today

Five habits, none of which waits on legal certainty about the final standards:

  • Version everything. "Which model decided this" should be a lookup, not an investigation.
  • Backtest before deployment on frozen data and keep the result, including every prediction the model got wrong.
  • Record approvals with names and dates.
  • Score outcomes against predictions continuously, so performance in production is a curve, not a claim.
  • Route every material error to a named owner and keep the outcome.

Do these five things from today and you arrive at your compliance date with an unbroken record that predates the obligation. The same evidence also tells you whether your models deserve the trust they are getting.

This is what Model Passports are. A passport holds the version history, validation record, backtests, approvals and scored outcomes of every model, accumulated as the system runs rather than assembled for an audience. Evidence produced as a by-product of operating cannot be bought in 2027, which is why it is worth starting now. To start the record, start here.

New essays land on LinkedIn first. Follow 3RDi to catch them, or get a demo to see Prophesee on your own data.