Brussels has bought UK founders time. The hard part is deciding what to spend it on
Under Regulation (EU) 2026/1744, the AI Omnibus that entered into force on 27 July, the EU’s high-risk AI obligations now start on 2 December 2027 for standalone systems such as hiring and credit-scoring tools, and on 2 August 2028 for AI built into regulated products such as medical devices, according to the European Commission. The UK’s May King’s Speech, meanwhile, included no standalone AI bill, relying instead on a planned Regulating for Growth Bill that would give ministers powers to run statutory sandboxes. For now, then, a UK AI company faces a lighter regime at home and a known, later date for the heavier one next door. DC Cahalane, a Sure Valley Ventures venture partner, argued in FT Adviser this week that the gap is an opening for investors backing UK start-ups. He is right that there is a window. Whether early EU compliance work is an asset at exit or capital spent before any customer asks for it depends on details his piece skips.
Strategic Insight: A deferral changes when a cost falls due, not whether it falls due. For a start-up the useful question is narrower than whether to comply early or late. It is which pieces of compliance are cheap to build now and ruinous to retrofit, and which can safely wait for the Series A.
Why two deferrals landing together matters
Until this summer, 2 August 2026 was the date the AI Act set for the bulk of its high-risk rules. That date has gone. The Omnibus was split from the wider Digital Omnibus package and fast-tracked precisely so that the new timetable would be law before the old deadline arrived. We covered the political deal and the new dates in May; the difference now is that they are fixed in the Official Journal rather than in a political agreement.
At home, the direction is clear for now. May’s King’s Speech contained no standalone AI bill, an outcome Bird & Bird noted had been signalled repeatedly by Liz Kendall and Kanishka Narayan, the Technology Secretary and AI Minister at the time. What was announced instead is a cross-cutting Regulating for Growth Bill that would let government temporarily relax specific rules inside supervised sandboxes, and strengthen regulators’ duty to support growth. The AI Growth Lab’s planned sandboxes would rely on those powers.
The real story is sequencing, not arbitrage
Cahalane frames the split between an ex-ante EU regime and a US model of after-the-fact enforcement as a trap for start-ups: US-first builds up compliance debt that must be paid down in costly rewrites before entering Europe, whilst EU-first can consume seed capital on paperwork. The UK, in his reading, lets founders iterate at something close to US speed while designing for the EU standard they will eventually meet.
That is a fair description of the opportunity, but it is not regulatory arbitrage. Nothing about the UK regime lets a company avoid EU obligations if it sells into the EU: Article 2 of the AI Act covers providers placing systems on the EU market wherever they are established. What the UK offers is sequencing. A company can reach product-market fit under a principles-based regime, then meet EU requirements on a timetable it now knows, rather than meeting them speculatively while the harmonised standards that define compliance are still being written.
| Metric | Value | Strategic implication |
|---|---|---|
| Standalone (Annex III) high-risk obligations | Obligations start 2 December 2027, previously 2 August 2026 | Sixteen extra months for recruitment, credit, education and similar use cases; possibly enough for a seed-stage company to reach a Series A first |
| Product-embedded (Annex I) high-risk obligations | Obligations start 2 August 2028, previously 2 August 2027 | Twelve extra months for medical-device and similar AI; the Omnibus also moves machinery out of the full high-risk regime |
| Article 50 transparency duties | Most applying since 2 August 2026; watermarking grace to 2 December 2026 only for generative systems already on the market | Not deferred. UK products that serve EU users and interact with people or generate content are likely already in scope |
| High-risk compliance cost (Cahalane’s estimate) | About £130,000-£280,000 to set up, plus £40,000+ a year | Unsourced in the FT Adviser piece; treat as one investor’s working assumption, not a benchmark |
Strategic Reality: Cahalane puts the breathing room at “16 to 24 months”, which overstates the product-embedded side. Article 113 of the AI Act originally applied Annex I obligations from 2 August 2027, so the move to August 2028 is twelve months. The sixteen-month figure is right for standalone systems only.
What the deferral actually changes, and what it does not
The Omnibus deferred the AI Act’s Chapter III obligations for high-risk systems. According to White & Case’s analysis, the deferral is limited to that chapter. It does not touch the transparency rules in Article 50, which took effect on 2 August, and it adds new prohibitions on AI that generates child sexual abuse material or non-consensual intimate imagery of identifiable people.
The package also narrowed scope in ways that matter more to some start-ups than the dates do. AI that only assists users or optimises performance is no longer automatically a “safety component” if its failure creates no health or safety risk. Machinery is no longer among the products whose AI safety components must meet the full high-risk rules, with machinery-specific legislation expected to cover them instead. And some forms of relief that used to apply only to SMEs, including simplified technical documentation and mitigated penalties, now extend to small mid-caps.
Critical Context: The deferral exists largely because the tools for compliance are not ready. White & Case describes the extension as time for businesses to get to grips with standards, guidance and assessment procedures that are not yet finished. A founder who builds to today’s draft interpretation may be building to a target that moves before 2027.
Success factors that get overlooked
- Classification before cost. For many UK AI start-ups the bigger saving may be not deferral but discovering they are not high-risk at all. The clarified safety-component test and the machinery carve-out both reward a careful classification exercise done once, early and in writing.
- Transparency is already live. Chatbot disclosure and content labelling apply now. A start-up that treats the whole AI Act as a 2027 problem may already be non-compliant on the part that is cheapest to fix. We set out the scope of those Article 50 labelling duties in July.
- Data lineage is the expensive retrofit. Cahalane warns that a US-first strategy builds compliance debt that ends in costly architectural rewrites. In our view, data records are where that debt is hardest to pay down: documentation can be written later, but a record of where training data came from depends on having captured it at the time.
- The buyer may set the pace before the regulator does. Cahalane argues that start-ups with audit trails and data provenance clear enterprise procurement more quickly. If he is right, the practical deadline for a B2B start-up is the first large customer’s due-diligence questionnaire, which may arrive well before December 2027.
The implementation reality for a seed-stage company
Cahalane’s practical suggestion is that seed and pre-seed companies should spend roughly 90% of their capital on product-market fit and domestic traction, with around 8% to 12% going to data lineage and governance foundations, leaving formal EU audits and conformity assessment to be funded from Series A onwards. As a rule of thumb it is sensible, and it matches the argument above: build what cannot be retrofitted, defer what can be bought later.
The difficulty is that the split presumes a founder knows which bucket a given task falls into. On Cahalane’s own split, data lineage and governance take 8 to 12 per cent of a seed round, while formal audits and conformity assessment wait for growth capital, and those assessments will run against standards that are not yet finished. One easy way to waste capital is to commission an external AI Act readiness exercise before knowing whether the product is in scope.
Hidden Cost: Compliance built too early carries a maintenance bill. Every policy document, risk register and technical file has to be kept current as the product pivots. For a seed-stage company that changes direction twice before a Series A, premature documentation is paid for three times.
Who gains, who carries the risk
The window does not benefit everyone equally. Its value depends on where a company sits in the funding cycle, what it sells and to whom.
For founders, the gain is optionality: a clear date against which to plan an EU launch, and a domestic regime built on sector-led principles rather than an AI statute. The risk is complacency, especially on the transparency duties that already apply. For investors, the window is a diligence question. Cahalane’s piece argues that investors need better tools to judge whether a portfolio company’s data structures are genuinely audit-ready, which is a fair point, though the answer may be better diligence questions rather than a new platform.
| Stakeholder group | Primary impacts | Support needs | Success metrics |
|---|---|---|---|
| Seed and pre-seed founders | Room to reach product-market fit before high-risk duties bite; transparency duties apply now | A written risk classification; lightweight data-lineage logging from launch | Classification signed off before first EU customer; no retrofit needed on data records |
| Venture investors | Compliance posture becomes a valuation and exit variable by 2027-28 | Diligence questions that test data provenance, not policy documents | Portfolio companies pass enterprise procurement reviews without remediation |
| Enterprise buyers and acquirers | Must assess suppliers against rules that apply from 2027 and 2028 | Evidence of classification and governance from suppliers | Fewer post-acquisition remediation surprises |
| UK sector regulators | Expected to support growth while regulating AI inside their remit | A clear legal basis for sandbox modifications | Sandbox outcomes that carry weight with EU buyers, not just UK ones |
What actually drives value at exit
Cahalane’s claim is that start-ups which embed data provenance, audit trails and Article 50 transparency during this period will clear enterprise procurement faster and achieve higher exit valuations. The logic is plausible, and it is the core of the bull case, but the piece offers no evidence for it. The narrower point stands on its own: a target that cannot show where its data came from presents a risk that is hard for a buyer to quantify.
The more defensible version of the argument is about optionality, not premium. A company whose foundations are EU-ready can choose when to enter the EU market or accept an acquirer who sells there. A company that has to rebuild its data pipeline to do either has lost that choice, and lost it at the moment it has the least negotiating leverage.
🎯 Success Factor: The test of early compliance spend is whether it closes off a retrofit. Data lineage, model version records and user-facing AI disclosures pass that test. Policy manuals written before the product has settled usually do not.
A staged approach for the window
💡 Implementation Framework: Build what you cannot retrofit, buy the rest later
Phase 1: Classify and disclose (Now to end of 2026)
- Produce a written classification of every product against Annex I and Annex III, using the clarified safety-component test
- Confirm Article 50 compliance for any EU-facing chatbot or generative feature, including watermarking by 2 December 2026 where the grace period applies
- Start logging data sources, processing steps and model versions as a matter of engineering routine
Phase 2: Build the foundations (2027, before the Series A)
- Turn logs into a documented data-governance process an auditor could follow
- Track the harmonised standards as they are published and map gaps against them
- Test regulated use cases in a UK sandbox where one is open to your sector
Phase 3: Formal conformity (Series A onwards, ahead of December 2027 or August 2028)
- Fund quality management and conformity assessment from growth capital
- Where a notified body is required, engage one early rather than near the deadline
- Refresh classification if the product has pivoted since Phase 1
Priority actions by stage
For companies not yet selling into the EU
- Classify now, in writing: A one-off exercise that tells you whether the high-risk regime applies at all, and costs little compared with anything that follows.
- Log from launch: Record data sources and model versions in your engineering workflow. It costs little now and a great deal to reconstruct later.
- Design disclosure into the interface: Build AI-interaction notices and content labels into the product rather than bolting them on before an EU launch.
For companies already serving EU customers
- Close any Article 50 gap immediately: These duties are live. Check chatbot disclosure and content marking against your actual product, not your policy.
- Answer the procurement questionnaire before it arrives: Prepare the governance evidence your largest prospective customer will ask for, and use it as the spine of your technical file.
- Map your date: Confirm whether you face December 2027 or August 2028, and plan the conformity spend into your next raise.
For companies in regulated UK sectors
- Look at the AI Growth Lab: The first advisory pilot, covering legal services, opened for applications in August with a 27 September deadline. The government describes legal services as the first focus, with lessons feeding into the wider programme.
- Treat sandbox findings as evidence, not permission: The government states that taking part gives no regulatory approval or exemption even in the UK. A documented supervised test can still be useful material when preparing EU compliance evidence.
- Watch the sector-specific carve-outs: The Omnibus lets the Commission limit the AI Act where sector law already contains equivalent AI requirements. Medical-device and other regulated-product firms should track the delegated acts.
Resource Reality: Phase 1 is mostly founder and engineering time rather than a consultancy engagement. The significant spend, whatever the true figure proves to be, sits in Phase 3, and the Omnibus has moved that spend later, closer to the point where a start-up that has raised a Series A has institutional capital to meet it.
The challenges the bull case skips
Challenge 1: The UK sandbox is not yet law
Cahalane writes that “the regulating for growth bill puts the AI growth lab (a cross-economy statutory sandbox regime) into law”. That is premature. The Bill was announced in May’s King’s Speech but, as of 18 September, does not appear on Parliament’s bills register, so it has not yet been introduced. The AI Growth Lab currently operating is an advisory sandbox in which regulators explain how existing rules apply; the government states that taking part gives no exemptions from legal obligations. Bird & Bird also flags open questions about how rules would be switched off and whether successful trials would become permanent by secondary legislation with limited parliamentary scrutiny.
Mitigation Strategy: Plan on the advisory version of the sandbox, which exists today, and treat statutory modification powers as upside. Do not build a product whose UK route to market depends on a rule being disapplied until the Bill is on the statute book.
Challenge 2: Deferred standards mean a moving target
The standards that will define conformity for high-risk systems are part of why the deadline moved. Build to a draft and you may find the final version asks for something different.
Mitigation Strategy: Invest in outcomes that any standard will require, such as traceable data, versioned models and documented human oversight, and defer format-specific documentation until the relevant standard is final.
Challenge 3: A political deferral can be revisited
According to Politico, the deal came amid US pressure on the EU’s tech laws and warnings from European industry and governments that strict rules had left the bloc at a disadvantage in the AI race. The same forces could push for further delay, and a different political mood could tighten rules again. Planning a funding schedule around a date that has already moved once carries its own risk.
Mitigation Strategy: Treat December 2027 as the latest date rather than the likely one, and avoid structuring capital so that compliance work can only start after a raise that might slip.
Challenge 4: The UK regime may not stay light
The question is not closed. Parliament’s Joint Committee on Human Rights has called for statutory AI oversight, and Bird & Bird suggests the government drafted the Regulating for Growth Bill broadly to stop it becoming a vehicle for binding AI safety amendments. A founder betting on UK lightness is betting on that holding.
Mitigation Strategy: Build to the EU baseline where it is cheap to do so. Foundations that satisfy the stricter regime insulate a company against UK policy drift in either direction.
Reality Check: The window is real but modest. Sixteen months for standalone systems and twelve for embedded ones are unlikely on their own to decide which start-ups succeed; they may decide which ones arrive at a Series A with a clean data history and which arrive with a remediation project.
The strategic takeaway
The deferrals give UK AI companies something more useful than a head start on rivals: a known timetable. After months of uncertainty about whether the original deadline would hold, a founder can plan EU compliance against dates now set in law, with no standalone UK AI bill in the government’s programme. The companies that use the window well will not be the ones that complied earliest, but the ones that spent least on work they later had to redo.
Three factors that decide whether early spend pays
- Scope certainty: Knowing, in writing, whether you are high-risk at all. Everything else depends on it.
- Retrofit avoidance: Spending early only on what cannot be rebuilt later, chiefly data provenance and model records.
- Buyer alignment: Timing governance evidence to the first enterprise customer who asks for it, which for many B2B companies may come before the regulator.
Measuring the window by what you avoid
The usual measure of compliance progress is documents produced. A better one for a start-up in this window is remediation avoided: how much of the product would need rebuilding if an EU customer, an acquirer or a regulator asked for evidence tomorrow. That number should fall steadily through 2027.
For investors, the parallel measure is diligence confidence. Cahalane’s argument that the regulatory split filters well-governed companies from the rest is persuasive if investors can tell them apart. That depends less on new tooling than on asking the right questions about data lineage at seed stage, when the answers are still cheap to fix.
Strategic Insight: The deferral rewards founders who understand the difference between being compliant and being ready to become compliant. The first is expensive and often premature at seed stage. The second costs little, and it is what an acquirer is likely to look for.
Your next steps
Immediate actions (this week):
- Check every EU-facing chatbot and generative feature against Article 50 disclosure and labelling duties
- Confirm whether any generative system relies on the 2 December 2026 watermarking grace period
- If you operate in legal services, decide whether to apply to the AI Growth Lab before 27 September
Strategic priorities (this quarter):
- Produce a written high-risk classification for each product, applying the clarified safety-component test
- Put data-source and model-version logging into the engineering workflow
- Add AI Act readiness questions to board and investor reporting
Long-term considerations (this year):
- Track harmonised standards as they are published and map gaps
- Plan conformity assessment spend into the Series A budget against your 2027 or 2028 date
- Monitor the Regulating for Growth Bill’s progress and the scope of its sandbox powers
Source: AI regulation shift could open up opportunities in UK start-ups (FT Adviser, 16 September 2026), a comment piece by DC Cahalane of Sure Valley Ventures. EU dates are verified against the European Commission’s announcement and White & Case’s analysis of the Omnibus; the UK position against Bird & Bird’s King’s Speech analysis. For our earlier analysis of the wider package, see how the Digital Omnibus complicates Britain’s regulatory bet.
This strategic analysis was written by Resultsense, a UK-focused AI news and analysis publication. We will be watching whether the Regulating for Growth Bill gives the AI Growth Lab real powers to disapply rules, and whether Brussels holds to its new dates. Read more analysis at Insights, or get in touch.