EU Delays AI Act High-Risk Requirements to December 2027 – While Agents Are Already in Production
AI agents are moving into production at large enterprises faster than the public frameworks meant to regulate them. According to Gartner's 2026 CIO Survey, 17 percent of CIOs have already put AI agents into production, and a further 42 percent plan to do so within a year. Meanwhile, the US standards body NIST has not committed to the agent-specific standards projected for the second half of 2026, and the EU has postponed the AI Act's high-risk deadline to December 2, 2027. Into the vacuum that opens up, a governance layer is being built from below — by software vendors shipping their own governance products, and by regulators improvising liability positions case by case. This is a map of that landscape as it stood in late September 2026.
What NIST Has Actually Promised – and What It Hasn't
NIST's Center for AI Standards and Innovation launched the AI Agent Standards Initiative on February 17, 2026. According to the reporting, the initiative rests on three pillars: agent security, agent identity and authorization, and open-source agent protocols. Many in the industry hoped for a fast route to clarity.
That clarity has not arrived so far. Agent-specific "overlays" — supplementary standards building on existing frameworks — were projected for the second half of 2026, but NIST has not formally committed to those deliverables. According to analysis from the Cloud Security Alliance, published in March 2026, finalized agent-specific standards should not be expected before 2027 at the earliest.
It is worth emphasizing what this means for the timeline: the second-half-2026 timing is a projection, not a deadline NIST has bound itself to. The analysis this story builds on — written by Dana Ellison and published at Forkast and Yahoo News on September 27, 2026 — frames the situation as "three months to NIST," but that is the author's construction, not an official commitment. The only concrete date in the landscape is thus an absence: no committed delivery before next year at the earliest.
Why does this matter? Because standards are, in practice, the infrastructure of accountability. Without a shared definition of what an agent is, who owns its identity, and which controls must be in place, every question of accountability becomes a matter of judgment — for regulators, courts, or the vendors selling the control tools themselves.
The Regulator Improvises: Ferguson's Liability Signal
One answer to the vacuum came on September 25, 2026, when FTC Chairman Andrew Ferguson spoke at the Reuters Momentum AI conference in Austin. According to reporting on the event, Ferguson stated that developers bear full liability for their agents, and that he explicitly rejects the "autonomous actor" defense — the argument that sufficiently autonomous agents should be treated as independent decision-makers rather than as instruments of their creators.
Both points are significant. Placing liability on the developer removes the most obvious escape route for companies that might otherwise claim the agent "acted on its own initiative." And the rejection of the autonomy defense signals that the regulator will largely treat agents as products, not as actors — that is, traditional product liability is being extended over a technology that behaves less predictably than most products.
There are important caveats, however. The statement is known through secondary reporting; no transcript or FTC document exists in the available source material. That means the precise wording, the nuance, and any conditions attached to Ferguson's position cannot be verified here. Furthermore, this is a statement, not a rule: it suggests how the FTC is thinking, but it establishes no enforcement standard that companies can target. In practice, that is exactly what characterizes the regulatory vacuum this story is about — liability signals arriving piecemeal, instead of a framework.
The EU: A Deadline Pushed Behind Both Standards Timelines
The European picture points in the same direction. The EU has postponed the deadline for the high-risk-related obligations in the AI Act from August 2, 2026, to December 2, 2027. The European Parliament voted 423 to 57 for the delay on June 16, 2026, and the Council adopted it on June 29.
The postponement moves the EU's binding requirements for high-risk AI to a point after even the most optimistic standards timeline from the Cloud Security Alliance. When finalized agent-specific standards can, according to CSA analysis, arrive no earlier than 2027, the EU's high-risk obligations on December 2, 2027 land at roughly the same time. That means even the jurisdiction that has traditionally regulated first is, in practice, leaving the agent field to the industry's own governance arrangements for the near term.
One open issue remains: the details of the AI Act's distinction between systems that decide on their own and functions that merely assist — the distinction that will be decisive for which agent systems fall under the high-risk requirements — are not documented in the available source material. That will become central as the postponement period draws to a close.
The Vendors Fill the Vacuum
While public frameworks drag on, the market has responded with products. Between August and October 2026, five major players launched governance products aimed at AI agents, each intended to build an enterprise control layer where none exists from the state:
- SAP launched AI Agent Hub, a vendor-neutral overview of the agents in use across an organization — in practice an inventory layer, which is a precondition for all other governance.
- Collibra shipped Guardian Agents, aimed at operational governance and monitoring of agents while they run.
- Dataiku announced general availability of its Agent Management platform.
- Island, which recently raised $400 million at a $6.4 billion valuation, has shifted focus toward an "agentic control plane" — a security layer governing what agents can do across systems.
- Microsoft launched Copilot Autopilot with integrated Entra identity management on September 25 — the same day as Ferguson's statement, and an integration that points to the core of the agent problem: agents need their own identities and permissions, not just humans'.
The wave of launches within a few weeks shows that vendors see a real commercial need: companies putting agents into production need something to govern them with, and right now that something is coming from software houses, not from standards bodies.
But this layer has a structural peculiarity the reader should note: it is defined by the same commercial interests that sell the agents, or by neighbors in the value chain who profit from the governance need. A company governed by vendor A's governance tools is evaluated against vendor A's definitions of safe, controlled, and auditable. That need not be bad — vendor standards are often better than none — but it is something other than a neutral, tested, enforceable norm.
The Numbers Enterprises Are Actually Working With – With Caveats
How serious is the risk companies take by putting agents into production without a framework? The most-cited figures come from vendor-commissioned surveys, and that should weigh on the interpretation.
AvePoint's State of AI 2026 report, produced with Osterman Research, surveyed 750 global IT leaders and found that 88.4 percent of organizations had experienced a security breach tied to AI agents in the past twelve months. The most common attack forms were data leakage (50.1 percent) and manipulation via untrusted inputs (49.6 percent). The survey was commissioned by AvePoint, which itself sells governance tools, and — as the source itself points out — the figures should be read as indicative, not definitive. A breach figure that high may in practice capture everything from serious incidents to very low-threshold events, and the definition of "breach" is the survey's own.
The same applies to a Harris Poll survey commissioned by Collibra in September 2026, in which 76 percent of decision-makers reported critical obstacles to moving agents from pilot to production. Collibra sells precisely the kind of production governance the survey shows a need for.
When both of these figures come from vendor-commissioned surveys conveyed through a single piece of reporting (Ellison's analysis, syndicated to both Forkast and Yahoo News — it is the same article, not two independent confirmations), they should be used as direction, not as grounds for absolute claims. What gives them weight nonetheless is their consistency with more neutral indicators: the Gartner deployment figures show that agents are actually in operation now, and the launch wave shows that the market treats the security and control need as real enough to pay for.
The Question the Vacuum Leaves
The situation in late September 2026 can be summarized as follows: the official standards timeline is non-binding and unmet until at least 2027; the EU's binding requirements are delayed to December 2027; regulatory signals arrive improvised, case by case; and the interim is filled by commercial governance products and vendor-commissioned risk analyses.
The open question is whether this can hold. Vendor-defined governance plus improvised liability placement does not have to collapse — but it has two obvious weaknesses. One is comparability: without shared standards, a company, a regulator, or a court cannot evaluate an agent's control layer against anything common. The other is the incentive structure: those who define what good agent governance is profit from definitions that fit their own products.
What would it take for NIST to commit to the projected overlays? That is not documented in the sources — no binding timeline exists. Until one does, the governance of AI agents rests with those who have the strongest commercial reason to deliver it quickly. For companies putting agents into production now, the practical consequence is simple: they are governing to the vendors' standards, not society's — and that may prove a costly difference when the official frameworks finally arrive.

