EU eases AI compliance deadlines, but liability risks remain, Relm’s Davey warns

WorkAI.TV Editorial Desk
4 Min Read

Share with your CISO

The EU’s AI Omnibus, which took effect July 27, 2026, pushed compliance deadlines for high-risk AI systems out to December 2027 for stand-alone systems and August 2028 for embedded ones. Brussels is framing this as breathing room for smaller firms, not a rollback. But Claire Davey of specialty insurer Relm argues the regulatory reprieve changes nothing about actual liability exposure, with more than 60 P&C insurers already filing generative AI exclusions and Verisk’s ISO exploring new exclusions for agentic AI risks.

What this means for your business

Companies that interpret a delayed enforcement date as a delayed liability date are confusing legal timelines with legal risk. Intellectual property infringement, negligence, privacy violations, and breach of contract don’t wait for a regulator’s start gun. If your organization is deploying AI systems today, particularly in hiring, credit decisions, or customer-facing automation, the exposure clock is already running. Where you sit on that spectrum depends less on your geography than on how much autonomous output your systems are producing without documented human review.

The insurance market is functionally ahead of the regulator here, and that gap matters. When 60-plus P&C groups file AI exclusions and Verisk starts drafting agentic AI carve-outs, they’re not predicting future risk, they’re responding to claims patterns they’re already seeing. Davey’s firm sells into this future, which gives her comments a natural tilt toward urgency, but the tilt doesn’t make the argument wrong. Insurers pricing exclusions before statutes take effect is the clearest possible signal that the legal exposure is real and present, not hypothetical. The regulatory delay simply means there’s no compliance checkbox that also reduces your premium or your courtroom exposure.

The renewal conversation Davey describes is the concrete decision this reframes. When your underwriter asks how AI outputs are checked, who owns the model, and whether governance is documented, the right answer isn’t a roadmap. It’s evidence. Organizations that treated the AI Act’s original 2026 deadlines as their governance trigger are now discovering they built a compliance program, not a risk program, and those aren’t the same thing. I’d revise this view if insurers started reversing exclusions as governance practices matured, but the direction of travel right now is the opposite.

Concept deep-dive: High-risk AI systems

Under the EU AI Act, “high-risk” designates systems whose outputs directly affect consequential decisions about people, think of it as any model where a wrong answer changes someone’s job, loan, or freedom. The categories include biometrics, employment screening, credit and essential services, law enforcement, and migration. These systems face the heaviest documentation, testing, and human oversight requirements. The compliance deadline extension affects exactly this tier, which means the systems carrying the most liability exposure are also the ones now operating longest without statutory guardrails.

Based on reporting from EU eases AI compliance deadlines, but liability risks remain, Relm’s Davey warns, originally published 2026-07-31 12:06:00.

TAGGED:
Share This Article