EU AI Act delay shifts compliance pressure to buyer questionnaires
The European Union’s AI Act deadline for high-risk systems just moved to December 2027, yet the first serious compliance pressure for many non-EU AI vendors will not come from a regulator. It will arrive in a customer questionnaire. That is the practical reality vendors outside the EU should not miss, as documented by the International Association of Privacy Professionals IAPP. A regulation deadline can shift through an amending law. A contract renewal, vendor-risk review, or board evidence file often cannot. The political deal changed the timeline debate, but procurement has its own clock.
The European Commission’s current AI Act implementation page reflects the Digital Package on Simplification and the political agreement reached 7 May 2026. Following that agreement, rules for AI systems used in certain high-risk areas — including biometrics, critical infrastructure, education, employment, migration, asylum, and border control — are set to apply from 2 Dec. 2027. For systems integrated into products such as lifts or toys, the rules are set to apply from 2 Aug. 2028. That timing matters. It gives many organizations more room to prepare for high-risk AI obligations. It also creates a new risk: some vendors may treat extra time as a reason to postpone evidence work. For legal reliance, current law, political agreement, implementation guidance, and final adopted text should not be collapsed into one sentence. For procurement planning, however, the practical message is simpler: buyers now have more reason to ask vendors what evidence exists, not less.
The delay creates a different false comfort. Vendors who assume they have years to gather compliance documentation may find themselves locked out of deals months from now. Enterprise procurement teams do not wait for legislative clarity. They build their own risk frameworks, often drawing directly from regulatory language. When a buyer asks for evidence of conformity assessment, risk management documentation, or human oversight protocols, they are not asking out of regulatory obligation alone. They are asking because their own liability exposure begins the moment they deploy the system, not when the regulator fines them. The first serious EU AI Act question for many non-EU AI vendors may not come from a regulator. It may arrive in a customer questionnaire.
The Precedent That Proves This Problem Is Not New
Europe’s two most powerful data protection authorities delivered a pointed verdict at the European Parliament in July 2026: the compliance deadline that matters for automated hiring decisions is not December 2027. It is May 2018 — the date GDPR Article 22 took effect, and the date by which employers were already required to ensure that any AI-driven candidate screening involving meaningful consequences on an applicant included genuine human review, not a rubber stamp. The European Data Protection Supervisor (EDPS) and the European Data Protection Board (EDPB) co-hosted a formal conference at the European Parliament in Brussels, titled “Hired by an Algorithm: Data Protection and AI Regulation in Modern HR Practices.” EDPS Supervisor Wojciech Wiewiórowski delivered the opening remarks — a signal that the event carried institutional weight well beyond its origin as a trainee-organized initiative, as reported by Tech Times Tech Times
The conference’s central finding was unambiguous: AI candidate screening tools that filter applicants without genuine human review were in violation of GDPR Article 22 from the moment they were deployed, not from the moment an AI Act deadline passes. That prohibition has been in force for eight years. For any employer currently using an algorithm to screen CVs, rank applicants, or score video interviews, the legal exposure is not hypothetical. It is accumulated. GDPR Article 22 has applied to automated hiring since before the AI Act was proposed. Under GDPR Article 22, individuals — including job applicants and employees — have the right not to be subject to decisions based solely on automated processing, including profiling, that significantly affect them, unless specific legal safeguards are in place. Those safeguards are demanding: the decision must be necessary for a contract, explicitly authorized by EU or member state law, or based on freely given and specific consent. No EU member state has specifically authorized automated rejection in recruitment as of 2026. The most commonly deployed exception — explicit consent — requires conditions that are structurally difficult to satisfy in recruitment contexts, because a job applicant who can only access consideration by passing through an employer’s screening platform is not, in the EDPB’s assessment, giving consent freely.
The Court of Justice of the European Union’s SCHUFA ruling of December 7, 2023 (C-634/21) brought the question into sharper focus by determining that any candidate scoring tool that materially influences a selection decision falls within Article 22’s scope, even where downstream human review nominally occurs. The Court’s criterion was practical: if the downstream decision-maker relies heavily on the algorithmic score, the score-maker — not just the employer making the final call — may be the Article 22 controller. A human recruiter who clicks “approve” or “reject” primarily on the basis of an AI-generated ranking, without independent evaluation of the candidate’s file, is not providing the meaningful human review the regulation requires. A February 2025 CJEU ruling (Case C-203/22) added a further enforcement dimension. The Court held that when a controller claims trade secret protection for its scoring logic, it must still disclose that logic to the relevant supervisory authority or court. The trade-secret shield does not protect HR AI vendors from GDPR investigations into how their algorithms reach conclusions about candidates.
The Procurement Question That Reverses Everything
One implication of the SCHUFA ruling that the July 2026 conference brought into focus is one that many employers and HR technology vendors have not yet acted on: Article 22 liability does not rest only with the employer deploying the system. Under the CJEU’s “heavily relied upon” standard, an AI vendor whose scoring output materially shapes which candidates advance — without the employer conducting genuinely independent evaluation — may itself be the Article 22 controller, subject to the full weight of GDPR enforcement. This is the data point that reverses everything. The vendor who thought they were selling a tool becomes a regulated entity. The vendor who assumed the employer carried all risk now carries their own. The vendor who delayed evidence work because the AI Act deadline moved now faces a GDPR compliance question that has been active since 2018.
Procurement teams understand this. They have been trained by years of GDPR enforcement to ask for evidence of data protection impact assessments, records of processing activities, and controller-processor agreements. Now they are adding AI Act questions to the same questionnaire. The vendor who cannot answer those questions will not get a second meeting. The vendor who provides vague assurances will be flagged for further review. The vendor who treats compliance as a future task will find themselves excluded from current deals. This is not speculation. It is the pattern that emerged after GDPR took effect, and it is repeating for the AI Act.
The practical point is this: the AI Act deadline moved, but the evidence standard did not. Buyers still need to explain to their boards why a particular AI system is safe to deploy. They still need to document how they assessed risk, ensured human oversight, and verified transparency. They still need to show that the vendor can provide the necessary documentation. The delay in regulatory application does not pause procurement diligence. It accelerates it, because buyers now have more time to ask harder questions.
The False Comfort of Extended Deadlines

The risk for vendors is that they interpret the delay as permission to postpone evidence work. This would be a mistake. The AI Act’s high-risk provisions may apply from 2027, but the GDPR’s Article 22 has been in force since 2018. The SCHUFA ruling has been in effect since 2023. The February 2025 CJEU ruling on trade secrets has been in effect since 2025. These are not future obligations. They are current law. A vendor who relies on the AI Act timeline to delay compliance may find themselves facing GDPR enforcement before the AI Act ever applies to them.
The procurement question is the mechanism through which this enforcement happens. A buyer asks for evidence. The vendor cannot provide it. The buyer walks away. The vendor loses the deal. The vendor’s reputation suffers. The vendor’s competitors who prepared evidence capture the market. This is not a theoretical scenario. It is the pattern that played out after GDPR took effect, when vendors who had not prepared for data protection requirements found themselves locked out of European markets. The same pattern is now playing out for AI compliance.
The data point that reverses everything is this: the AI Act deadline moved, but the procurement clock did not. Buyers are asking questions now. Vendors who answer them will win deals. Vendors who do not will lose them. The evidence gap is not a future problem. It is a current one. The question is not whether the regulator will enforce the AI Act in 2027. The question is whether the buyer will enforce it in the next procurement cycle.
The Structural Shift in Enterprise Risk Management
Enterprise procurement teams have become sophisticated risk managers. They do not rely on regulatory deadlines alone. They build their own compliance frameworks, often drawing from multiple regulatory sources. A single procurement questionnaire may ask about GDPR compliance, AI Act readiness, data security standards, and sector-specific regulations. The vendor who can answer all these questions with documented evidence will pass the review. The vendor who cannot will fail it. This is the structural shift that vendors outside the EU must understand.
The delay in the AI Act’s high-risk application does not change this dynamic. It reinforces it. Buyers now have more time to conduct thorough vendor assessments. They can ask for more documentation. They can demand more evidence. They can compare vendors on their compliance readiness. The vendor who prepared early will stand out. The vendor who delayed will fall behind. The evidence gap is not a regulatory problem. It is a commercial one.
The practical implication is clear: vendors should start building their evidence packages now, not in 2027. They should document their risk management processes. They should prepare conformity assessments. They should establish human oversight protocols. They should verify transparency requirements. They should do this not because the regulator will ask in 2027, but because the buyer will ask in the next procurement cycle. The procurement clock is ticking. The evidence gap is real. The false comfort of extended deadlines is the most dangerous illusion in AI compliance today.
Sources
1. International Association of Privacy Professionals
2. European Data Protection Board
4. Court of Justice of the European Union
5. Tech Times
