- On 7 May 2026 the Council of the EU and the European Parliament reached a provisional agreement deferring EU AI Act high-risk obligations for standalone systems, including credit scoring, from 2 August 2026 to 2 December 2027. The agreement still requires formal adoption before it becomes binding.
- Colorado's SB 24-205 was due to take effect 30 June 2026. Its successor, SB 26-189, narrows the law's scope and pushes the effective date to 1 January 2027, following the same pattern as the EU: ambitious deadline, market not ready, deadline moved.
- Penalties under the original EU framework reach €15 million or 3 percent of global annual turnover, whichever is higher, for breach of Article 9 to 17 provider obligations and Article 26 deployer obligations once the rules bind.
- Neither delay changes the substance of what regulators will eventually require: documented data lineage, bias testing, automatic logging of AI-assisted decisions retained for at least six months, and a human review point for adverse outcomes.
- Caribbean and LATAM lenders with EU-linked customers, partners, or vendors face narrower but real exposure, and the compliance architecture regulators are converging on, an auditable record of every AI credit decision, is the same architecture CARICOM policy discussions are already referencing.
What Actually Happened on 7 May
The European Commission's Digital Omnibus initiative, launched in late 2025, set out to simplify parts of the AI Act that industry had flagged as unworkable on the original schedule. On 7 May 2026, the Council presidency and European Parliament negotiators reached a provisional political agreement on the resulting package. Under that agreement, obligations for standalone high-risk AI systems classified under Annex III, the category that includes credit scoring and creditworthiness assessment, move from 2 August 2026 to 2 December 2027. High-risk AI embedded in regulated products under Annex I gets until 2 August 2028. A related watermarking obligation for AI-generated content, under Article 50(2), moves to December 2026.
The agreement is provisional. It has not been formally adopted by both co-legislators, and until it is, the original 2 August 2026 date remains the binding deadline in the text of the law. Several law firms tracking the file, including Gibson Dunn and Hogan Lovells, describe the political agreement as highly likely to be ratified given the short runway before the original date, but "highly likely" is not "in force." Any institution that reads this as a settled two-year reprieve is reading a press release, not a statute.
Three things the delay does not change:
1. The requirements themselves. Nothing in the 7 May agreement removes the substantive obligations: risk management across the AI lifecycle, representative and bias-tested training data, human oversight, and automatic logging. It moves the date those obligations bind, not the content of what they require.
2. Article 26's six-month log retention. Deployers of high-risk systems still have to retain automatically generated logs, at minimum six months, once the deadline binds, whichever deadline that ends up being.
3. Extraterritorial reach. A non-EU lender serving EU residents, or supplying credit outputs into an EU institution's decision chain, remains inside scope regardless of which date applies.
Colorado Told the Same Story, Three Weeks Earlier
Colorado's SB 24-205, the Consumer Protections for Artificial Intelligence Act, was the first US state law written specifically to govern high-risk AI systems in consequential domains, including lending. It required impact assessments, bias audits, and consumer disclosures from any developer or deployer whose AI materially affects a credit decision. Enforcement was due to begin 30 June 2026, with the Colorado Attorney General holding exclusive authority to bring penalties of $20,000 per consumer per violation.
A successor bill, SB 26-189, repeals and replaces SB 24-205. It narrows the scope of what counts as a covered high-risk system and pushes the effective date to 1 January 2027. The reasoning tracked the EU's almost exactly: lenders, credit unions, and AI vendors argued that impact-assessment infrastructure, bias-testing methodology, and documentation standards were not mature enough across the market to meet the original date without either shutting down AI-assisted underwriting or accepting compliance theatre.
Two legislatures, an ocean apart, wrote strict AI rules on an aggressive timeline and then found the same problem: writing a deadline into a bill is easier than building the audit infrastructure the deadline assumes already exists.
Why This Is Not a Green Light
The temptation inside a compliance or product team that has been racing toward August is obvious: the deadline moved, so the sprint can slow down. That reading misunderstands what regulators have actually signalled.
Every delay in this cycle, in the EU and in Colorado, has come with the same accompanying language: implementation efforts should already be underway, and the extra time is for closing gaps, not for starting from zero. The Council and Parliament's own press statement describes the delay as giving businesses room to meet requirements they were already expected to be building toward. Regulators are not saying the requirements were wrong. They are saying the market was not ready on the clock they originally set, which is a different problem with a different fix.
For a credit institution, the practical risk of treating a delayed deadline as a paused deadline is straightforward. Compliance infrastructure, in particular a working audit trail that captures every AI-assisted credit decision, the data considered, the model version, and any human override, cannot be assembled in the final months before a deadline. It has to be built into how the lending system operates for months before an examiner ever asks to see it. An institution that stops building in July 2026 because the date moved to December 2027 will find itself compressing the same eighteen months of work into six, at the point when the deadline is finally locked in and genuinely immovable.
"A delayed deadline is a gift of time, not a cancelled obligation. The institutions that treat it as the latter are the ones that will be assembling audit trails from memory when an examiner finally asks for them."
The Caribbean and LATAM Exposure Question
Most Caribbean and LATAM lenders are not EU entities and do not sit inside the AI Act's primary jurisdiction. That does not mean the exposure is zero, and it does not mean the Act is irrelevant to how these institutions should build.
Direct exposure exists in three situations that are increasingly common as Caribbean fintech expands cross-border. A digital lender or remittance processor serving EU-resident customers, including diaspora communities in France, the Netherlands, or Ireland with Caribbean ties, can fall within the Act's reach for those customers specifically. A Caribbean institution that supplies credit-relevant data or scoring outputs into an EU bank's decision chain, as a data or model vendor, inherits obligations through that relationship. And any institution using an AI platform vendor headquartered or operating in the EU may find AI Act compliance requirements passed down contractually, regardless of where the institution itself is licensed.
Indirect exposure is broader and, in practice, matters more. The EU AI Act functions as the reference architecture that other regulators study when writing their own frameworks, in the same way Basel capital rules became a global reference point well beyond the jurisdictions that wrote them. Caribbean central banks, including the Bank of Jamaica and the Central Bank of Barbados, have published guidance or opened consultation on AI use in credit decisions, and the vocabulary in that guidance, human oversight, documented data lineage, bias testing, auditability, mirrors the EU framework closely. Meanwhile the underlying commercial pressure is real and immediate: CIBC Caribbean has confirmed plans to deploy AI-driven, automated credit decisioning for unsecured lending in Jamaica, and every major Jamaican lender, including NCB, Scotiabank Jamaica, and JMMB, is either deploying or actively building AI underwriting capability. The regulatory scrutiny that follows that adoption curve is not a hypothetical.
| Requirement | EU AI Act (Art. 9-17, 26) | Colorado SB 26-189 | Emerging Caribbean guidance |
|---|---|---|---|
| Impact / risk assessment before deployment | Required | Required | Referenced in draft guidance |
| Bias and proxy-variable testing | Required | Required | Under active consultation |
| Automatic decision logging | Min. 6 months retention | Required, period unspecified | Not yet codified |
| Human review of adverse decisions | Required | Required | Expected under supervisory practice |
| Consumer disclosure of AI involvement | Required | Required | Not yet codified |
What to Build While the Date Is Uncertain
The institutions best positioned for whichever deadline lands, December 2027 in the EU, January 2027 in Colorado, or whatever a CARICOM regulator eventually codifies, are the ones that stop treating the date as the object and start treating the audit trail as the object.
Four things are worth building now, independent of any specific statute. First, automatic logging of every AI-assisted credit decision: the inputs considered, the model version that produced the output, the score or recommendation generated, and any point where a human reviewed or overrode it. Second, documented data lineage for every scoring model in production, showing where training data came from and what testing was done for bias against protected characteristics. Third, a genuine human escalation path for adverse decisions, not a rubber stamp, but a reviewer with the authority and the information to actually change the outcome. Fourth, retention infrastructure that keeps these records for long enough to survive an examination cycle, which in practice means longer than the regulatory minimum, not exactly equal to it.
None of this is EU-specific or Colorado-specific. It is the shape every serious regulatory framework for AI in consequential financial decisions is converging toward, because it is the shape that lets an examiner reconstruct, after the fact, exactly what an AI system did and why. That convergence is the real story behind both delays. The rules are not disappearing. The rule-writers are discovering, in public, that the infrastructure to prove compliance takes longer to build than the political process assumed.