‹ All news

Nobody called it an AI project

Nobody called it an AI project

Most software is untouched by the EU AI Act — and the things that do cross the line are rarely the ones anyone labelled an AI project. A plain-English guide to who it applies to, what the deferral actually changed, and why bolted-on AI widens the gap.

Someone in your engineering team is building a dashboard.

It pulls in commit history, pull request times, review comments. It uses a bit of AI to spot patterns. The plan is to show it to managers, so they can finally see who is productive and who is struggling.

Nobody has called it an AI project. It has no budget line. It will ship in three weeks.

It is probably the most heavily regulated thing your company will build this year.

First, the relief that isn't

You may have seen that the big EU AI Act deadline moved. It did. The rules for most high-risk systems slipped from this month to December 2027, and a further category to August 2028.

Sixteen extra months. Most compliance programmes exhaled.

Before you re-plan around that, two things.

One: something did land this month and was not delayed. If your software talks to people, generates content, or claims to read emotion, it has to say so. That duty is live now.

Two, and this is the one that matters: the extra time lets you produce evidence. It does not let you reconstruct it. More on that at the end.

Who this actually applies to

Here is the part almost nobody explains properly, so let me do it in plain words.

The AI Act is not a blanket rule about using AI. Most software is untouched. Whether it applies to you comes down to three questions.

Did you build it, or did you buy it?

If you bought a tool and use it as it comes, you have the lighter set of duties — use it properly, keep an eye on it, make sure a human is actually in charge.

If you built it, or put your own name and brand on someone else's, you carry the heavy set: documentation, testing, risk assessment, records.

What does it decide?

Not what it does — what it decides. A tool that suggests something to a person is in a different world from one that determines an outcome.

Who does it decide about?

This is the hinge. The EU wrote a list of areas where getting it wrong damages someone's life: hiring and managing people, credit and insurance, education and exam marking, healthcare, critical infrastructure, policing, border control, justice.

If your system makes or materially shapes decisions about people in those areas, you are in the heavy category. If it doesn't, you are very probably not.

The good news, said plainly

Your developers using an AI assistant to write code faster are almost certainly fine. Autocomplete is not a regulated activity. Copilot, Cursor, ChatGPT at work — as coding help, none of that puts you in the high-risk bracket.

I want to say that clearly, because a lot of what is written about this Act is designed to frighten people into buying something.

The tools your vendors sold you are mostly not the problem.

What you build with them can be.

Three ways ordinary work crosses the line

One: the dashboard. The moment engineering data is used to evaluate, rank or compare people, you are in the employment category. It doesn't matter that it started as a curiosity, or that it lives in a spreadsheet, or that nobody called it AI. What matters is that it shapes decisions about people's work.

Two: the allocator. A model that decides who picks up which ticket, who reviews which change, who gets the interesting project. That is task allocation. Same list, same category.

Three: your name on it. Take a supplier's assistant, wrap it, brand it, roll it out internally as your own — and you can stop being the customer and start being the maker, with everything that carries. Many organisations have done this without noticing, because it felt like configuration rather than construction.

None of these look like AI projects. That is precisely why they are the risk.

Now the part about your shiny new tools

So if the assistants are mostly fine, where does bolted-on AI actually hurt you?

Look at what the rules ask for. Not clever technology. Not a better model. They ask for evidence: what risks you considered, where your data came from, how the thing was built, who checked it, who was accountable, what they decided and why.

Every one of those is a record of a decision.

Now look at what a bolted-on AI tool does. It makes things faster. More code, more documents, more dashboards, more decisions taken more quickly by more people.

It produces output. It does not produce evidence.

Which means the faster your organisation goes with tools bolted onto the way it already works, the further ahead of its own paper trail it gets. You are not closing the gap. You are widening it, efficiently.

Why sixteen extra months solves less than it looks

I argued in June that the Act reads less like a tax on good delivery than a description of it — that almost everything it asks for is what a well-run project produces anyway. The deferral has not changed that. It has only changed when the bill arrives.

Here is the thing about the delay.

The systems that will be assessed in 2027 are being designed now. This quarter. The decisions that will need to be evidenced are being made in meetings, in chat threads, in a call somebody didn't write up.

You cannot go back in 2027 and remember 2026 properly. Nobody can. Either the record of how you decided exists because of the way you work — or it does not exist at all.

That is why a deferral is not relief. It is a longer run-up to the same bar, and most organisations will spend it accumulating undocumented decisions.

What to do on Monday

Three things, none of which require a compliance programme.

Find your dashboard. Ask what is being built that touches decisions about people — hiring, evaluating, allocating, assessing. Look in the places nobody labelled AI.

Check whose name is on it. For every AI tool in use, know whether you are the customer or, quietly, the maker.

Then start writing decisions down as you make them. Not a document nobody reads — just the decision, who made it, what they knew at the time, and what would change their mind.

Sixteen months is a generous amount of time to build that habit.

It is a very short amount of time to invent a memory.

This is guidance on how to work, not legal advice. Whether a specific system falls into a regulated category depends on detail, and that is a conversation for qualified counsel.

‹ All news
Follow Subscribe