Every obligation in this Regulation resolves, in practice, into a question of proof. Can you show which systems you run? Can you show which of them are high-risk, and on what reasoning?
Then there is the set of questions the deferral has scheduled rather than cancelled. From 2 December 2027 for Annex III systems, and 2 August 2028 for Annex I, Article 26 will ask a deployer of a high-risk system: who was assigned oversight, and did they have the competence, training and authority to exercise it, as Article 26(2) requires? Can you produce the logs Article 26(6) requires you to retain for at least six months? Can you show workers and their representatives were informed before deployment, as Article 26(7) requires?
None of that can be manufactured after the question is asked. Log retention is not a policy you adopt in November 2027 — it is a system configuration that either was or was not set years earlier, and the six months of history the Act asks for must already exist on the day the duty bites. Oversight assignments and workforce notifications are the same: they are records of things done at the time, or they are nothing. The organisations that will struggle are not the reckless ones. They are the ones that did everything sensibly and wrote none of it down.
There is a second-order exposure that boards notice faster than regulators do, and it does not wait for 2027: your customers’ procurement teams. EU-based buyers are already putting AI Act representations into contracts. A firm that cannot answer a supplier questionnaire loses the deal long before it meets an authority.