What changed in May 2026
On 7 May 2026, the Council of the EU announced that Council and Parliament negotiators had reached a provisional agreement to simplify and streamline certain AI Act rules. The release was updated on 18 May 2026 and states that the agreement still needs endorsement, legal-linguistic review and formal adoption.
The headline change for many companies is timing. According to the Council, the provisional agreement would introduce fixed delayed application dates for high-risk rules: 2 December 2027 for stand-alone high-risk AI systems and 2 August 2028 for high-risk AI systems embedded in products.
That matters, but it should not be read as a signal to pause governance work. A provisional political agreement is not the same thing as procurement readiness.
What has not changed
The AI Act remains in force. The European Commission states that the AI Act entered into force on 1 August 2024 and is being applied progressively. Prohibited practices and AI literacy obligations already started applying from 2 February 2025.
The Commission also describes the AI Act as the EU's comprehensive legal framework for AI, with risk-based obligations for specific uses of AI. In other words, the direction of travel has not changed: organisations still need to understand where AI is used, what risks it creates and what evidence supports their governance claims.
For companies selling into enterprise or regulated markets, the practical pressure often arrives through customer review before formal enforcement dates arrive.
Why buyers will still ask now
Procurement teams do not only ask AI questions because a regulator has reached a deadline. They ask because they need to manage supplier risk, data exposure, customer commitments, internal policy, security review and board accountability.
A buyer reviewing an AI-enabled product may still need to know the intended purpose, model or vendor dependencies, data categories, human oversight approach, risk classification rationale, incident handling process and whether the vendor can maintain evidence over time.
That is why the commercial question is different from the legal calendar question. The legal calendar asks when a formal obligation applies. The buyer asks whether they can trust the system today.
The evidence to prepare anyway
The strongest response is not a vague statement that the company is monitoring the AI Act. It is a reusable evidence pack that shows how AI is governed in practice.
Start with an AI system inventory, use-case register, supplier and model register, data map, AI Act role view, risk classification rationale, human oversight notes, control catalogue, training records and a buyer response summary.
These artefacts are useful even when dates move because they support procurement, diligence, internal governance, investor conversations and board reporting. They also make future legal review easier because the factual basis is already organised.
The practical takeaway
Regulatory deadlines may move. Customer trust deadlines usually do not. If AI is part of your product, operations or supplier chain, the useful question is not only when the next formal date lands. It is whether you can answer a buyer's evidence questions without starting from scratch.
AI Act Ready helps teams turn scattered AI activity into a structured evidence pack: inventory, role map, risk view, supplier record, controls and reusable procurement responses.