Skip to main content
ControlRoom

AI Act: Rinvio Obblighi Alto Rischio 2027 nel Project Management del PMO

The Digital Omnibus delay does not suspend the AI Act: it only shifts deadlines for high-risk systems, leaving transparency, prohibited practices, and GPAI obligations untouched. The framework helps PMOs decide whether to rebaseline compliance milestones or maintain the documentation pace already underway.

AI Act rinvio obblighi alto rischio 2027 project management pmo: è il tema che guida questa analisi. The postponement of high-risk obligations under the AI Act to 2027 has a direct impact on anyone running project management inside a PMO. If your project has already gone through classification screening and started risk documentation ahead of the 2 August 2026 deadline, news of the delay may feel like relief. But the operational question stays the same: stop, slow down, or keep going? The real risk at this stage isn't technical, it's interpretive. If the postponement is read as a general suspension of the AI Act, a PMO risks loosening controls even on obligations the extension never touched. This includes transparency requirements on AI-generated content, which apply to a far broader set of projects than those covered by the high-risk classification.

What the postponement actually changes, and what it leaves untouched

The Digital Omnibus does not suspend the AI Act framework: it moves forward two specific deadlines, tied to two distinct categories of high-risk systems. Obligations for standalone Annex III systems — employment, education, access to essential services — move from 2 August 2026 to 2 December 2027. Obligations for high-risk systems embedded in products already regulated under Annex I — machinery, medical devices — move to 2 August 2028 (Regulation (EU) 2026/1744). Everything else in the regulatory framework stays in place. The Article 50 transparency obligations on labeling AI-generated or AI-manipulated content remain fixed at 2 August 2026 (Regulation (EU) 2024/1689). The ban on systems generating non-consensual images and synthetic child sexual abuse material takes effect immediately, as an explicit exception to the general postponement (Regulation (EU) 2026/1744).

Two different deadlines for different systems in the same project

The practical complication for a PMO starts exactly here: a project that integrates multiple AI components can end up with different compliance deadlines for different modules. A standalone scoring system and a medical device that incorporates an AI module, within the same program, no longer share the same milestone. Rebaselining the entire plan onto the furthest-out date would mean losing sight of the obligations that are still fixed at 2026.

System categoryRegulatory referenceOriginal deadlineNew deadlineSource
Standalone high-risk (employment, education, access to essential services)Annex III, AI Act2 August 20262 December 2027Regulation (EU) 2026/1744
High-risk embedded in regulated products (machinery, medical devices)Annex I, AI Act2 August 20262 August 2028Regulation (EU) 2026/1744
Transparency — labeling of AI-generated or AI-manipulated contentArticle 50, AI Act2 August 2026Unchanged: 2 August 2026Regulation (EU) 2024/1689
Prohibited practices — non-consensual images and synthetic CSAMProhibited practices, AI ActAlready in forceUnchanged: in force immediately, explicit exception to the postponementRegulation (EU) 2026/1744

The framework: separate the scope of the postponement from the scope of the plan

To turn this distinction into a rebaselining decision, a PMO needs a simple criterion before touching any milestone. For each AI system in the project, verify which of the four rows in the table it falls under. Only after that check does it make sense to decide whether to move a date in the plan or leave it as is. The postponement covers specific deadlines for specific categories of systems, not the AI Act framework as a whole. Treating it as a general pause means wrongly applying the same logic to obligations that follow different calendars.

  • Does the project's AI system fall under Annex III (employment, education, essential services)? The new deadline is 2 December 2027.
  • Is the AI system embedded in a product already regulated under Annex I (e.g., medical device, machinery)? The new deadline is 2 August 2028.
  • Does the project generate or manipulate content via AI intended for an audience? The labeling obligation (Article 50) stays at 2 August 2026, unchanged.
  • Does the project include functionality close to prohibited practices (e.g., generating non-consensual images)? The ban is already in force, with no postponement at all.
  • Before rebaselining any milestone, check which of these categories each AI system in the project falls under — not the project as a whole.

The mechanism: selective rebaselining, not a full reset

The table in the previous section is a starting point, not an endpoint. The operational mechanism for a PMO is simple in logic but demands discipline in execution: you don't rebaseline the project, you rebaseline the single milestone tied to a deadline that has actually moved. A project integrating multiple AI systems can hold several different milestones at once. Some stay fixed at 2 August 2026 (transparency, prohibited practices), others shift to 2 December 2027 or 2 August 2028, depending on the system category. Moving the entire compliance roadmap to the furthest date is the most common mistake: it frees up short-term capacity, but leaves exposed the obligations the delay never touched.

Simulated example — Simulated scenario

A PMO manages an AI-based candidate-screening project, classified as high-risk under Annex III. In the original plan, a documentation and risk-management sprint was scheduled for Q3 2026, ahead of the August deadline. With the postponement to 2 December 2027, the team has two options: move the documentation-compliance milestone to the new date, or keep the current pace to avoid disrupting work already underway. Applying the selective rebaselining mechanism, the PMO moves only the milestone tied to formal Annex III compliance documentation. It leaves unchanged the milestone for periodic risk review, already built into the plan as a recurring activity independent of the regulatory deadline.

Practical steps to update the plan without losing ground

  • In the project plan, separate the risk classification and assessment milestone (which can continue unchanged) from the high-risk documentation-compliance milestone (which may shift depending on the system category).
  • Update the date only for the high-risk compliance milestone: for Annex III systems, the new deadline is 2 December 2027; for Annex I systems, 2 August 2028. Leave the Article 50 labeling milestone unchanged.
  • Log the rationale for every date shift in the plan, referencing Regulation (EU) 2026/1744 and the affected system category, so the reasoning behind each rebaselining stays traceable.
  • Keep the existing periodic risk-review cadence active, even without an imminent deadline. Stopping this activity only to rebuild it under pressure in 2027 costs more time than it saves now.
  • Before communicating the postponement to the team, verify that the message explicitly distinguishes shifted deadlines from unchanged ones, so the whole project doesn't ease up on transparency and prohibited-practices controls.

Trade-off

  • Benefit: Rebaselining only the milestones actually affected by the postponement frees up short-term team capacity without sacrificing oversight of cross-cutting obligations already in force.
  • Cost: Requires accurate upfront classification of each AI system in the project: without this mapping, selective rebaselining isn't applicable, and the team falls back to the binary choice of stopping everything or continuing everything unchanged.
  • Risk: If the team reads the postponement as a general suspension, it risks loosening controls on transparency and prohibited practices as well — obligations that remain unchanged and carry no extension.
  • Prerequisite: The project must already have distinguished, in the plan or classification register, which systems fall under Annex III, which under Annex I, and which generate content subject to the labeling obligation.
  • Limit: This framework addresses how to decide the rescheduling of compliance milestones; it does not cover the documentation structure of decision traceability itself, nor voluntary certification requirements such as ISO 42001, which remain distinct topics.

What changes for project governance, not just for the calendar

The selective ribaselining described above answers the question of when to move a date. A different question remains open: how to preserve evidence of why that date moved, and why others stayed fixed. This is where the tool the PMO uses to manage the plan comes in — not as a regulatory compliance engine. ControlRoom does not calculate or determine an AI system's compliance status under the AI Act: it remains an interpretive layer over deterministic data. What it does provide is a place to record, in a traceable way, each system's risk classification, human reviews carried out, and the rationale for every milestone shift in the project's decision log.

This article focuses on the ribaselining decision: which milestones to move, which to leave fixed, based on the actual deadlines set by Regulation (EU) 2026/1744. The full structure of an AI decision audit trail in a project — what to record, at what granularity, for how long to keep it — is a distinct topic, covered separately. The same applies to adopting voluntary certification schemes such as ISO 42001 for PMO AI governance, which responds to a different organizational logic than the regulatory-deadline compliance discussed here.

  • Is the rationale for every shifted milestone recorded with explicit reference to Regulation (EU) 2026/1744 and the system category (Annex III or Annex I)?
  • Are the milestones related to transparency (Article 50) and prohibited practices still present in the plan, not removed alongside the ones actually deferred?
  • Has the project team received communication that explicitly distinguishes shifted deadlines from unchanged ones, avoiding the generic message of an "AI Act delay"?
  • Does the periodic risk-review cadence, independent of the regulatory deadline, remain active in the operational plan?
  • Where multiple AI systems exist within the same project, is each one's classification documented separately, so the correct deadline applied to each can be demonstrated?

Relief over the postponement is legitimate, but it should be measured against its actual scope: two specific deadlines moved, not an entire regulation suspended. For a PMO that had already started classification and documentation, the time gained is not a reason to stop — it is margin to consolidate what is needed regardless. When December 2, 2027 and August 2, 2028 arrive, a clear mapping of systems by category will be required. A plan that distinguishes affected milestones from unchanged ones will also be needed, with a documented trace of every decision made in the meantime.

Want to go deeper on the method?

Read the AI Process Intelligence framework