What the AI Act Delay Does Not Change for Investigation Teams

Europe moved the high-risk deadline to December 2027. The requirements did not move with it.

Editorial image for What the AI Act Delay Does Not Change for Investigation Teams

For most of the past two years, agencies evaluating AI-assisted investigative tools have been working toward a single date. Obligations for standalone high-risk systems under Annex III of the EU AI Act were scheduled to apply from 2 August 2026, and law enforcement uses sit squarely inside that annex: assessing the reliability of evidence in a criminal investigation, profiling in the course of detection and investigation, and post-event biometric identification are all named categories.

That date has moved. Under the Digital Omnibus on AI, agreed between the Parliament and the Council in May 2026 and given final approval by the Council at the end of June, the application of the standalone high-risk rules shifts to 2 December 2027. Systems already on the market before that date come into scope only if they are substantially modified afterwards.

The reaction inside a lot of procurement teams was predictable: sixteen months of breathing room. That reading is wrong in a way that will cost some agencies real money, because the deferral was granted for a reason that has nothing to do with the substance of the requirements.

Why the deadline moved, and what it says

The reason given for the postponement was readiness of the supporting machinery rather than any doubt about the obligations themselves. The harmonised technical standards that vendors were supposed to conform to were not finished, and the national authorities meant to supervise the market were not fully stood up. Regulators do not usually enforce a conformity requirement when the conformity target has not been published.

Read that back as a signal and it says the opposite of what the relief-sounding headlines suggested. Nothing in the risk management, data governance, logging, human oversight, accuracy, or technical documentation requirements was softened. They were rescheduled to arrive alongside the standards that make them auditable. When the standards land, they will land as concrete tests rather than principles a vendor can answer with a paragraph of marketing copy.

Meanwhile, part of the framework did take effect this August as originally planned. The transparency duties, the penalty regime for general purpose models, and the full activation of national market surveillance powers were not part of the postponement. An agency that assumed the whole regulation went quiet for another year and a half has already misread its position.

Procurement cycles outlast the delay

The practical problem for public sector buyers is arithmetic. A serious investigative platform does not go from first demo to operational use in a quarter. There is an evaluation, a pilot on real case data, a security review, a data protection impact assessment, a procurement process that may run to open tender, then deployment, then training, then the first cases that actually rely on it. Eighteen months from first contact to routine operational use is normal. Two to three years is not unusual for a national agency.

Which means a tool being evaluated this autumn will still be in service, and quite possibly still being extended and reconfigured, when December 2027 arrives. Every substantial modification after that date pulls the system into scope. A platform selected on the assumption that the rules do not apply yet is a platform that will need re-papering, and possibly re-engineering, at exactly the point it has become load bearing for live casework.

The teams handling this well have stopped treating the compliance date as the trigger for asking compliance questions. They are asking them during evaluation, because the answers determine whether a system can be extended later without a re-certification project attached.

The questions worth asking during evaluation

Most of what the high-risk regime asks for is not exotic. It is documentation, traceability, and the ability to show a human made the decision. What varies enormously between platforms is whether those properties were designed in or bolted on, and that difference is visible during a pilot if the team knows where to look.

Ask what the system logs when it produces a finding, and whether that log is sufficient to reconstruct the finding months later without the vendor's help. Ask whether an analyst can see which specific pieces of source evidence produced a correlation, or only the correlation itself. Ask what happens to a finding when a piece of underlying evidence is withdrawn from the case, because retention and deletion obligations are not satisfied by a system that quietly keeps derived conclusions alive after their source is gone.

Ask where the models run. A platform that sends evidence to an external inference endpoint introduces a transfer, a processor relationship, and a set of questions about training data that an on-premise deployment simply does not have. For agencies handling material from live criminal investigations, this is usually the question that decides the evaluation before any of the others matter.

Ask which functions are optional. Biometric components in particular carry different legal weight in different member states, and a platform that treats face clustering or voice comparison as an inseparable part of its core pipeline is harder to deploy lawfully across jurisdictions than one where those modules can be switched off per deployment.

The case file is the real audit

There is a version of AI Act compliance that is entirely paperwork, and agencies that have been through a GDPR programme will recognise it: a conformity file, a register entry, an impact assessment, a signature. That work is necessary and it is not the part that determines whether the tool survives contact with a court.

The part that matters is whether a finding produced with machine assistance can be explained to a defence lawyer eighteen months later. Which evidence supported it. What the system asserted, and what the analyst concluded. Who reviewed it, and when. Whether the same inputs would produce the same output today. A platform that can answer those questions from its own records is compliant in the sense that matters, and will keep being compliant when the standards are published.

The delay to December 2027 buys time to get that right. It does not reduce what right means, and it does not help the agency that spends the extra time not asking.

Request a Pilot

SentraLink runs entirely inside your environment, on-premise or air-gapped, with per-finding traceability to source evidence and biometric modules that are optional per jurisdiction.

Request a Pilot