AI projects: the AI Act moves its deadlines, PMI publishes its standard

On 2 August 2026, the EU AI Act’s transparency obligations become applicable. The heaviest requirements — those covering high-risk systems — have just been pushed back by more than a year. Between those two dates, the Project Management Institute published the first global standard on AI in project work. For organisations that deliver AI, the calendar has just been rewritten.

What becomes applicable on 2 August 2026

Three things take effect this week, and they reach far more organisations than most people assume.

Transparency obligations come first. Any organisation that puts its name or trade mark on an AI system generating content becomes a “provider” under the regulation. An in-house chatbot carrying your branding is enough. You must then clearly tell people they are interacting with an AI system, and ensure the content produced is marked in a machine-readable format. For that second obligation, systems placed on the market before 2 December 2026 have until that date.

For deployers — organisations simply using these tools — the obligation covers disclosure of deep fakes and informing people subject to emotion recognition or biometric categorisation.

2 August 2026 is also the deadline for member states to designate their market surveillance authorities, which gain enforcement powers on that date. Norton Rose Fulbright notes, however, that most member states are not on track, and designations will likely continue over the following months.

The deferral of high-risk obligations

The Digital Omnibus on AI, proposed by the European Commission on 19 November 2025, was endorsed by the European Parliament on 16 June 2026 and given final approval by the Council on 29 June 2026. It moves the most structural deadlines.

Obligation Application date
Prohibitions and AI literacy 2 February 2025 (unchanged)
General-purpose AI models (providers) 2 August 2025 (unchanged)
Transparency 2 August 2026
Designation of market surveillance authorities 2 August 2026
High-risk — standalone systems (Annex III) 2 December 2027
High-risk — AI embedded in a regulated product (Annex I) 2 August 2028

There is a technical rationale behind the deferral: it gives the European standardisation committee time to publish harmonised AI Act standards. Once they appear in the Official Journal, those standards will create a presumption of conformity, which will considerably simplify life for providers.

Why the delay does not translate into free time

It is tempting to treat December 2027 as a 2027 problem. That misreads the requirements, for a reason rooted in their legal nature.

High-risk obligations belong to product safety law, not data protection law. They require detailed technical documentation, a conformity assessment and a declaration, all produced during the development life cycle. Norton Rose Fulbright makes the decisive point: these obligations are considerably harder to retrofit once a product has launched.

Put differently, an AI project starting today and shipping in 2027 is already, in practice, in scope. Providers of standalone systems in financial services or HR technology, many of whom have never dealt with product safety law, are the most exposed.

The PMI standard fills a blind spot

On 9 June 2026, PMI published The Standard for Artificial Intelligence in Portfolio, Program and Project Management — the first published global standard on applying AI to professional project work, and the first ANSI-approved AI standard for the profession. It runs to 275 pages.

The reasoning behind it is straightforward: almost every AI deployment inside an organisation takes the form of a project. New systems, augmented workflows, AI-driven products — all of them are scoped, governed and shipped by project, program and portfolio teams. Yet until now that discipline had no published standard of its own.

The document sets out eight guiding principles, five performance domains and a full life-cycle framework covering the design, deployment and oversight of AI initiatives. It is deliberately technology-agnostic and built around human-in-the-loop oversight at every stage. It addresses head-on the questions organisations are wrestling with today: AI business cases, tool selection, AI-specific risk management, ethics oversight, and compliance with emerging requirements such as the EU AI Act and ISO/IEC 42001.

According to ECI Research, cited by PMI at the announcement, 92% of organisations report AI capabilities integrated into at least one stage of their software delivery lifecycle, up from 71% in early 2024. The standard is a free digital download for PMI members; non-members can access it for $74.95.

What this changes for you

  1. Inventory your AI systems before 2 August, not after. The question is not “do we run an AI project” but “do we operate a tool that generates content under our brand”. An internal chatbot, a customised writing assistant or a meeting-notes generator puts you inside the transparency perimeter from this week.
  2. Treat the December 2027 deferral as design time, not reprieve. For every AI project shipping in 2027 or later, write technical documentation, conformity assessment and human oversight into the deliverables at scoping stage. Retrofitting them afterwards costs substantially more.
  3. Give your teams a shared frame. The AI literacy obligation has been applicable since February 2025 and has not moved. The PMI standard supplies exactly the common language legal, audit, finance and business teams need to agree on how an AI project is approved, governed and delivered.

The hard part is no longer knowing what AI can do, but organising how it gets delivered — which is precisely what our training programmes in project management and continuous improvement address.

Sources


Comments

Leave a Reply

Your email address will not be published. Required fields are marked *