On August 2, 2026, the European Union's AI Act reached a threshold that its architects likely did not anticipate: the high-risk system obligations became legally enforceable while the technical standards that grant presumption of conformity remained unfinished. This is not a minor administrative delay. It is a structural gap between legal mandate and implementation pathway that leaves providers of biometric identification, employment screening, and critical infrastructure systems in a precarious position—legally exposed without clear guidance on how to satisfy the law.
The Act follows the New Legislative Framework model, which separates essential requirements (set by legislation) from technical specifications (developed by standards bodies). In 2024, the European Commission issued its standardization request to CEN-CENELEC, tasking Joint Technical Committee 21 with translating broad legal language—"adequate" risk management, "appropriate" human oversight—into auditable, testable criteria. The typical development cycle for such standards runs 24 to 36 months. We are now at month 24. No harmonized standard has been finalized or referenced in the EU Official Journal.
Providers of Annex III high-risk systems face a choice between two costly paths. Self-assessment against ambiguous essential requirements demands extensive legal interpretation and documentation, with no guarantee that authorities will accept the conclusions. Third-party conformity assessment via notified bodies, where available, adds expense and delay. Both routes are more legally exposed than the standards-based compliance pathway the regulation envisioned.
The asymmetry is predictable but no less consequential: large incumbents can afford conservative interpretation and extensive documentation; they will survive this gap, possibly even benefit from it. Smaller vendors, open-source projects, and academic deployments—those without dedicated compliance departments—face an unknowable burden. The cost of uncertainty falls hardest on actors least equipped to absorb it.
This pattern appears elsewhere. Illinois SB 315 mandates algorithmic audits for employment decisions but provides no standardized protocols, leaving vendors to invent their own. The recurring structure is worth noting: regulation increasingly assumes technical infrastructure that standardization bodies have not yet built. The law moves at legislative speed; standards move at consensus speed. When the former outpaces the latter, compliance becomes a function of resources rather than design.
The next six to twelve months will determine whether this cliff is brief or becomes a permanent market asymmetry. If harmonized standards arrive soon, the gap will be a footnote—a stressful but survivable transition. If delays continue, the Act may inadvertently consolidate market position among those who could afford to navigate the ambiguity, undermining one of its stated purposes: to ensure AI systems placed on the European market are safe and respect fundamental rights.
The EU flag flies over a regulatory framework with teeth but incomplete scaffolding. The question now is not whether the obligations are justified, but whether compliance is achievable on terms that do not exclude the non-incumbent.
Sources:
- European Commission standardization request to CEN-CENELEC (2024)
- CEN-CENELEC Joint Technical Committee 21 working documents
- EU AI Act, Annex III (high-risk systems classification)