top of page

EU AI Act 2027 Delay: What It Means for Your SAP and ERP AI Programme

Sep 13
4 min read

Jeet Poptani, Chief Transformation Officer at AumentoAI, on why a regulatory delay is the moment to get governance right, not the moment to pause.


Enterprise AI programmes run on deadlines, and one of the biggest just moved. Under the EU AI Act's Omnibus VII revision, the compliance deadline for stand-alone high-risk AI systems under Annex III has shifted from 2 August 2026 to 2 December 2027 — a sixteen-month extension. Product-embedded high-risk systems get a parallel twelve-month extension, from August 2027 to August 2028.

I've had three separate conversations in the last fortnight where a client's instinct was to deprioritise their AI governance workstream in response. That's the wrong read, and it's worth being precise about why — because the parts of the Act that actually bite an ERP and agentic AI programme in the near term haven't moved at all.

What didn't change

Article 50's transparency obligations — the duty to disclose when someone is interacting with an AI system, and to label AI-generated content appropriately — remain in force on their original schedule: 2 August 2026. If your Joule deployment, your customer-facing chatbot, or any agentic workflow interacts with employees or customers without disclosure, that obligation lands in months, not years.

More importantly, the delay is explicitly about giving harmonised technical standards more time to be finalised — it is not a signal that the underlying substance is softening. Risk management, technical documentation, human oversight and post-market monitoring requirements for high-risk systems are unchanged in substance. The Cloud Security Alliance's research is blunt on this point: organisations that were behind on AI system inventories and risk classification before the delay are still behind, and a further slip in the standardisation timeline could trigger fresh legislative changes rather than a further grace period.

Why this is an SAP and ERP problem specifically

This isn't abstract compliance theatre for most of the enterprises I work with — it's directly in the path of the agentic ERP rollout every CIO is now planning. SAP's own Autonomous Enterprise push, announced at Sapphire 2026, puts more than fifty Joule agents into live business processes: financial close, procurement exceptions, supply chain decisions, HR workflows. A meaningful share of those use cases sit inside, or close to, the EU AI Act's high-risk categories — employment decisions, creditworthiness assessments, critical infrastructure management. An agent approving supplier payments or flagging credit risk isn't a low-risk chatbot; it's precisely the category Annex III was written for.

Running that kind of agent into production without an AI system inventory, a documented risk classification, and a human-in-the-loop decision model isn't just a compliance exposure — it's the same governance gap that makes agentic AI unreliable operationally, regulation aside. The Act, in this sense, is codifying the discipline good programme leadership already requires.

What I'd tell a CFO or CIO to do in the next two quarters, regardless of the new date

  • Build the AI system inventory now, mapped to risk category. This is the piece the CSA's own research found most enterprises hadn't completed even under the original deadline. It's also the foundation for every other governance decision — you cannot classify what you haven't catalogued, and you cannot govern what you haven't classified.

  • Treat Article 50 as the live deadline, because it is. Any customer- or employee-facing AI interaction needs a disclosure plan by August 2026. This is a smaller lift than full Annex III compliance and there's no extension to hide behind.

  • Design human-in-the-loop before you scale agent count, not after. Whatever the regulatory calendar says, decision rights and escalation paths for high-risk agentic workflows are the difference between an audit finding and a management-approved control. Build it once, into the Joule Studio agent design process itself, rather than retrofitting it per agent.

  • Use the extra runway on standards, not on slippage. SAP, its SI partners and the harmonised technical standards bodies will spend the next sixteen months converging on what "compliant" concretely looks like for an ERP-embedded agent. Enterprises that stay engaged with that process, rather than shelving governance until closer to December 2027, will implement the eventual standard once. Everyone else will implement it twice — once informally now, and again properly under deadline pressure.

The differentiator hiding in this

Multi-vendor AI governance — running Joule, Microsoft Copilot, an Anthropic Claude integration and whatever else has been independently procured inside one enterprise, under one risk framework — is board-level work that very few transformation partners are actually equipped to do well. It sits at the intersection of programme delivery, regulatory literacy and C-suite communication, not any single vendor's certification track. In European enterprise contexts particularly, it's becoming the single clearest way to differentiate a transformation partner from a systems integrator that only knows how to configure the software.

The deadline moved. The work didn't.

AumentoAI advises CFO, CIO and board audiences on multi-vendor AI governance, EU AI Act readiness, and embedding compliance into agentic ERP programmes from day one. Book a Value Advisory Session to scope an AI system inventory and risk classification for your environment.

Comments


bottom of page