[{"data":1,"prerenderedAt":30},["ShallowReactive",2],{"nr-en-eu-ai-act-hochrisiko-aufschub-compliance":3},{"slug":4,"title":5,"dek":6,"date":7,"time":8,"publishedAt":9,"updated":10,"updatedAt":10,"dateFmt":11,"updatedFmt":10,"kind":12,"tier":13,"author":14,"authorName":15,"topics":16,"tracker":22,"trackerLabel":23,"headlineStat":24,"image":25,"ogImage":26,"imageAlt":5,"csv":10,"minutes":27,"words":28,"html":29},"eu-ai-act-hochrisiko-aufschub-compliance","EU AI Act: The High-Risk KI Postponement Is No Free Pass","Since August 2026, GPAI rules are in effect – and companies must act now. The postponement until 2027 applies only to high-risk systems, not to already active compliance obligations.","2026-08-31","09:20","2026-08-31T09:20:00+02:00","","August 31, 2026","analyse","standard","ideal-syka","Ideal Syka",[17,18,19,20,21],"EU AI Act","GPAI","Compliance","Access Governance","Regulation","\u002Feu-ai-act-fahrplan","EU AI Act Timeline","35% of German companies see machine identities as their biggest AI security gap","\u002Fnewsroom\u002Fimg\u002Feu-ai-act-hochrisiko-aufschub-compliance.webp","\u002Fog-nr\u002Feu-ai-act-hochrisiko-aufschub-compliance.en.png",3,504,"\u003Cp>Many German companies are underestimating the current situation: while the deadline for high-risk AI systems has been pushed back to December 2027, enforcement measures for General Purpose AI (GPAI) have been active since \u003Cstrong>August 2, 2026\u003C\u002Fstrong>. The European AI Office can now request documentation from providers, evaluate models, and order recalls. Violations carry fines of up to \u003Cstrong>€15 million or 3% of global turnover\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Ch2>The essentials\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Cstrong>GPAI rules have been in effect since August 2, 2026\u003C\u002Fstrong> – the postponement applies only to high-risk systems\u003C\u002Fli>\n\u003Cli>\u003Cstrong>35% of German companies\u003C\u002Fstrong> identify machine identity management as their biggest AI security gap (Keeper Security study 2026)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Code of Practice requires technical safeguards\u003C\u002Fstrong>: centralized credential management, time-limited access, audit-proof logging\u003C\u002Fli>\n\u003Cli>\u003Cstrong>December 2027\u003C\u002Fstrong> is the new deadline for high-risk systems – but measures already in effect must be implemented by then\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>The Digital Omnibus postpones, but not everything\u003C\u002Fh2>\n\u003Cp>The Digital Omnibus, which stakeholders provisionally agreed on in early 2026, does bring relief – but only for part of the requirements. Classification and conformity assessment of high-risk systems is pushed to December 2027. This gives organizations more planning time. However, this postponement does not change measures that are already in effect: the voluntary \u003Cstrong>GPAI Code of Practice\u003C\u002Fstrong> is already binding for providers wanting to demonstrate compliance.\u003C\u002Fp>\n\u003Cp>The Code of Practice&#39;s chapter on Safety and Security is clearer than many political discussions: it&#39;s not about policy papers, but about \u003Cstrong>Access Governance\u003C\u002Fstrong> – the technical protection of model weights, defense against insider threats, and strict access control.\u003C\u002Fp>\n\u003Ch2>Machine identities: The underestimated vulnerability\u003C\u002Fh2>\n\u003Cp>This is where the real problem lies: every training cluster, every fine-tuning pipeline, and every inference endpoint brings machine identities that require credentials. These are typically provisioned faster than they can be properly managed.\u003C\u002Fp>\n\u003Cp>A Keeper Security study shows that \u003Cstrong>35% of German companies\u003C\u002Fstrong> already identify machine identity management as one of their biggest AI security gaps – a figure above the global average. This is no accident: German companies often operate complex AI infrastructures with many decentralized access points.\u003C\u002Fp>\n\u003Cp>To meet Code of Practice security expectations, organizations must implement three things:\u003C\u002Fp>\n\u003Cdiv class=\"tbl-scroll\">\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>Measure\u003C\u002Fth>\n\u003Cth>Requirement\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\u003Ctr>\n\u003Ctd>\u003Cstrong>Centralized management\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003Ctd>Infrastructure credentials stored in a central vault\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>\u003Cstrong>Just-in-time access\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003Ctd>Time-limited permissions instead of permanent access\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>\u003Cstrong>Logging\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003Ctd>Audit-proof documentation of all privileged sessions\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2>What this means for you\u003C\u002Fh2>\n\u003Cp>Anyone waiting now, thinking the 2027 deadline is sufficient, is confusing two different things: the postponement for high-risk systems and already active GPAI requirements. Companies that secure their infrastructure credentials today and implement Access Governance are laying the groundwork for required compliance proof – and avoiding costly fixes later. For German mid-market companies, this means concretely: if you train or deploy AI models, you should now inventory your machine identities and manage them centrally. This is not optional – it&#39;s part of the rules already in effect.\u003C\u002Fp>\n\u003Ch2>Sources\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.it-daily.net\u002Fit-sicherheit\u002Fcloud-security\u002Feu-ai-act-freipass\">it-daily\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>Editorially owned by \u003Ca href=\"\u002Fen\u002Fautor\u002Fideal-syka\">Ideal Syka\u003C\u002Fa>. Sources and method: \u003Ca href=\"\u002Fen\u002Fredaktion\">Newsroom &amp; method\u003C\u002Fa>. Tips and corrections: \u003Ca href=\"mailto:ai@i6eal.de\">ai@i6eal.de\u003C\u002Fa>.\u003C\u002Fem>\u003C\u002Fp>\n",1788173776423]