Infrastructure Briefings
The EU AI Act Deadline That Didn't Happen, and What Still Applies to Your Events
2 August was meant to be the date high-risk AI rules in the EU AI Act kicked in. They were deferred to December 2027 back in July. The timetable moved. The direction did not.
The date that quietly passed
Ten days ago, on 2 August, the original deadline for high-risk AI system obligations under the EU AI Act came and went with none of the obligations actually landing. That is not an oversight. The EU's Digital Omnibus on AI, which moved through Parliament in June, Council at the end of June, and was published in the Official Journal on 24 July before entering into force on 27 July, pushed the standalone high-risk deadline out to 2 December 2027. Product-embedded high-risk AI has an even longer runway, to 2 August 2028.
I am not a lawyer and none of this is legal advice. But I have had the same conversation with three different clients this year, all running events with an EU footprint or EU delegates, and it goes roughly the same way: "so do we relax now."
The honest answer
The timetable moved. The direction did not. The high-risk category still exists, the obligations that go with it still exist, they simply do not bite for another year and a half on standalone systems, longer on product-embedded ones. Treating the deferral as a cancellation is the mistake I would actively steer a client away from, not because the deadline pressure is real today, but because building the habit of checking where AI touches your delegates is worth having regardless of when a specific clause takes effect.
What "high-risk" would plausibly cover in events
Worth being specific here, because the phrase gets used loosely. In an events context, the kind of AI use that would plausibly sit in or near the high-risk category is the kind that makes a consequential decision about a person: automated screening of attendees or staff against a watchlist or risk profile, biometric entry systems that identify or verify someone to get them into a venue, and anything doing significant automated assessment of people rather than content.
Most of what events businesses actually use day to day sits well outside that: drafting copy, summarising a call, answering a delegate FAQ through a chatbot, generating a first pass at a proposal. That everyday use mostly attracts transparency expectations rather than high-risk obligations, meaning the general direction of travel is "say when it's AI," not "prove it is safe before you switch it on." Still worth doing properly. Just a different, lighter kind of worth doing properly.
A conference venue in the north west is a useful contrast to keep in mind here. It runs facial matching at fast entry lanes for one of its larger trade shows, which is a genuinely plausible candidate for the high-risk conversation. Its chatbot answering parking questions on the same website is not, whatever the marketing page for either tool happens to call itself.
Why "AI-powered" on a supplier's spec sheet is not enough
A badge on a vendor's website that says "AI-powered entry management" or "AI-driven attendee screening" tells you almost nothing about which category that system falls into, or what it actually does with a delegate's data or image. It is a marketing term, not a classification. If you are procuring anything that screens, verifies or scores people at your events, whether the vendor calls it AI or not, the question that matters is what decision the system is making about a person and how reversible that decision is if it gets it wrong. Do not let the badge substitute for asking that question directly.
A one-page register: where does AI touch our delegates
This does not need to be a legal exercise, and treating it as one is usually why it never gets started. A single page, kept honestly, does most of the work:
- Every point where AI reads, screens, verifies or scores a delegate, attendee or member of staff, not just where it talks to them.
- Whether that use is disclosed to the person it affects, in plain language, somewhere they would actually see it.
- Whether a human can override or review the outcome if someone asks.
- Whether the supplier providing the tool can tell you plainly what it does, in specific terms, not just in the language on their marketing page.
Keep it updated as you add tools, not as a one-off audit. It is a much smaller job done little and often than it is done once, retrospectively, after someone asks a question you cannot answer.
Be honest when a chatbot is a chatbot
The simplest, cheapest thing any events business can do this month, EU footprint or not, is stop letting a chatbot pretend to be a person. If a delegate is talking to an automated assistant on your website or WhatsApp line, say so, plainly, near the start of the conversation. It costs nothing, it is exactly the direction both UK and EU rules are pointing, and it is the kind of thing that looks obviously right in hindsight if a delegate ever complains that they thought they were talking to a human and were not.
This week
Start the one-page register above, even a rough first pass, for whichever of your events touches EU delegates or runs on EU soil. If you are not sure whether a supplier's tool falls into a category worth worrying about, that specific question, what is this system actually deciding about a person, is worth putting directly to the supplier rather than assuming the answer from their marketing copy. If you would like a second opinion on where AI currently touches your delegates across the business, that is a natural early thread in a Discovery Lab.