top of page

Delayed, Not Deleted: What the EU's New AI Deadlines Really Mean for Police Forces

  • Autorenbild: Ivona
    Ivona
  • vor 11 Minuten
  • 5 Min. Lesezeit

For most of the past two years, police technology teams across Europe worked toward a single date: August 2nd 2026. That was the day the EU Artificial Intelligence Act's heaviest obligations were supposed to land on the systems that forces use to profile suspects, assess evidence and identify people in public spaces. Then, three weeks before the deadline, the date moved.


On 24th July 2026, the EU published Regulation 2026/1744 (the Digital Omnibus on AI), delaying compliance deadlines for high-risk AI: standalone systems (Annex III, covering law enforcement and justice) moved from August 2026 to December 2nd 2027, while embedded products (Annex I) moved to August 2028.


While headlines frame this as a broad delay of Europe's AI rules, treating it as a reprieve is a critical and costly mistake for police leadership.

European police command center with monitors displaying biometric wireframes, data analytics, and a 2027 compliance timeline.

How the Timeline Actually Shifted

The European Parliament passed the amendments on 16 June 2026 (423 to 57, with 174 abstentions), followed by Council approval on 29 June. The delay was practical rather than political, driven by standardisation bodies falling behind on the technical benchmarks needed for high-risk compliance.


Crucially, the Omnibus leaves all core requirements intact: prohibitions, risk assessments, data governance, and human-oversight mandates are unchanged. The amendment simply extends the preparation runway—it does not soften the rules.


The Policing Rules That Never Moved

The AI Act's outright bans under Article 5 have been active and fully enforceable since 2nd of February 2025, carrying strict penalties of up to €35 million or 7% of global turnover with no grace periods or remediation pathways. These unamended rules directly restrict law enforcement by prohibiting predictive policing tools that assess criminal risk based solely on profiling or personality traits rather than objective evidence, banning untargeted scraping of facial images from CCTV or the internet to build databases, and outlawing real-time remote biometric identification in public spaces by default.


The only narrow exceptions for live biometric identification—such as searching for missing or trafficking victims, averting imminent threats to life or terrorism, or tracking serious offense suspects—mandate prior judicial authorization, fundamental rights assessments, and EU database registration. Consequently, any system falling within these prohibited categories represents an immediate operational and legal violation that must be shut down today, rather than in 2027.


The Deadline Nobody Noticed: Transparency

The Omnibus left Article 50 largely untouched, which means the AI Act's transparency obligations became enforceable on 2nd August 2026 — twelve days before this article was written.


Article 50 requires four disclosures: that a person is interacting with an AI system rather than a human; that content is artificially generated or manipulated, marked in a machine- readable format; that emotion recognition or biometric categorisation is being used; and that a deepfake image, audio or video has been artificially produced. Fines reach €15 million or 3% of global turnover. A limited grace period runs to 2nd of December 2026 for machine-readable marking in generative systems already on the market before August, and content created before August 2nd needs no retroactive labelling — though the Commission encourages it.


The Act does contain carve-outs for law enforcement uses authorised by law, and forces should take proper legal advice on where those boundaries sit for their own operations. But two exposures are easy to overlook. The first is the public-facing side of the organisation: press offices, prevention campaigns, recruitment material and community engagement channels that increasingly use generative tools. The second is procurement. Article 50 binds deployers, not only developers. An agency that licenses a third-party chatbot for its non-emergency contact line inherits obligations it did not write a line of code for.


On 20 July 2026, the Commission published its final Article 50 guidelines alongside a voluntary Code of Practice on AI transparency, signed by around 190 organisations by late July. For police services, adhering to this Code serves as a crucial public signal to build and maintain community trust through visible, verifiable commitments to transparency.


A New Prohibition Aimed at Child Protection

The Omnibus inserted a new prohibition into Article 5 covering AI systems designed to generate non-consensual intimate imagery — so-called nudification tools — and child sexual abuse material. The ban reaches both providers placing such systems on the EU market and deployers using them for those purposes, and it applies from December 2nd 2026.


This is a rare instance of AI legislation moving faster than the harm rather than behind it, and investigators working child protection cases should expect it to reshape the vendor landscape they encounter in evidence.


Why the Extra Sixteen Months Are Not Spare Time

While regulatory deadlines have moved, Europol’s 2026 IOCTA report highlights an expanding "velocity gap" where criminal innovation outpaces institutional adaptation in weeks versus procurement cycles. Generative AI tools, voice cloning, and deepfakes have lowered technical barriers, fueling industrialised online fraud, data-theft extortion, and ephemeral digital evidence across more than 120 ransomware operations. Consequently, the 16-month compliance extension is not a reprieve; it is a critical operational window for police forces to build essential governance foundations—such as data inventories, audit trails, and human-oversight protocols—before lawful AI adoption becomes mandatory.


Where Switzerland Stands

Although Switzerland sits outside the direct scope of the EU AI Act and plans no overarching horizontal statute, Swiss law enforcement will remain heavily regulated. By signing the Council of Europe’s Framework Convention on Artificial Intelligence, the Federal Council committed to a technology-neutral, sector-specific regime aimed primarily at state actors, with an implementing consultation draft slated for late 2026. In practice, however, Swiss police cannot operate in isolation from EU rules: cross-border evidence sharing with partner agencies in cities like Vienna and Lyon, combined with reliance on international software vendors who manufacture to EU specifications, means the AI Act’s Annex III requirements will function as the de facto operational standard across Switzerland.


What to Do in the Next Six Months


  1. Audit All AI Systems: Conduct a full inventory of all operational tools—including unlabelled AI such as transcription software, automated contact-triage, bundled analytics, and translation tools (e.g., Stockton Police's frontline real-time translation deployment).


  2. Screen Against Article 5 Prohibitions: Prioritize auditing against outright bans immediately, as these carry the highest penalties and are already active.


  3. Address Article 50 Transparency: Implement required disclosures for public-facing chatbots, generative media, and biometric or emotion-recognition systems.


  4. Establish Human Oversight Protocols: Formalize clear review procedures, override authority, and audit logging before deploying systems, rather than attempting to retrofit them later.


  5. Update Procurement Language: Embed mandatory AI Act conformity clauses in all current contracts to prevent costly renegotiations ahead of the December 2027 deadline.


The Real Test

The deferral bought European policing time. It did not change what the destination looks like, and it did nothing whatsoever about the pace of the threat. The forces that emerge well from this period will not be the ones with the most advanced tools. They will be the ones that can explain, in public and under scrutiny, exactly what their systems do, who supervises them, what happens when they are wrong, and why the trade-off is justified. Regulation is one audience for that explanation. Courts are another. The public is the one that ultimately decides whether the technology is legitimate.


December 2027 is the compliance deadline. Public confidence has no deadline at all, and it is harder to rebuild than any system on the inventory.


 
 
 

Kommentare


© 2011-2025

International Association of Recognized Police Officers

Postfach 314, CH-8050 Zürich

Switzerland

CH-UID CHE-389.960.512

  • LinkedIn IARPO
  • X  Profile IARPO
  • Twitter Social Icon
  • IARPO Facebook Page
  • Join IARPO
bottom of page