Your Backlog Does Not Move the Deadline.

A compliance deadline is a legal milestone, not a workload estimate. Some dates can move by formal amendment, but your backlog is not one of those amendments. The regulator does not grade effort. You either planned backward from the date in force or you did not.

Sorena AI TeamRegulatory Intelligence4 min read

Plan around the legal date

A compliance deadline changes only when the law changes it. Regulators do not move published dates because a team is overloaded.

The EU AI Act entered into force on 1 August 2024 and applies in stages. Chapters I and II, including prohibited AI practices and AI literacy obligations, applied from 2 February 2025. The general-purpose AI model rules, governance chapters, penalty rules, and Article 78 applied from 2 August 2025. The Regulation's general application date is 2 August 2026. In June 2026, the Council gave final green light to simplification changes that delay high-risk rules to 2 December 2027 for stand-alone high-risk AI systems and 2 August 2028 for high-risk AI systems embedded in products. Track that legal change without assuming it moved AI inventory, transparency, literacy, governance, or GPAI duties.

NIS2 carried a transposition deadline of 17 October 2024 and repealed NIS1 from 18 October 2024. DORA became applicable on 17 January 2025. The work had to follow those dates.

A phased rollout creates several deadlines

"Applies progressively" means a sequence of separate deadlines. Under the AI Act, prohibitions applied first, followed by general-purpose AI obligations, the general application date, and delayed high-risk dates. Clearing one phase does not satisfy the next.

Treat every amendment or deferral as a regulatory change. Identify which obligation moved, which systems it covers, which internal dates change, and which duties stayed in place.

Missing the date can trigger enforcement

These deadlines carry enforcement consequences. The AI Act sets penalties of up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher, for the most serious violations. NIS2 requires Member States to provide maximum administrative fines of at least EUR 10 million or 2% of worldwide annual turnover for essential entities, and makes management bodies responsible for approving and overseeing cybersecurity risk-management measures. DORA became applicable to financial entities on 17 January 2025 and gives supervisors a detailed rulebook for ICT risk, incidents, testing, and third-party risk.

Some obligations assign responsibility to named management bodies. Workload is not a defense for missing them.

Plan backward from the date, not forward from today.

Start with the fixed legal date and work backward. Set the internal readiness date, evidence freeze, owner review, dependency deadline, and escalation date. Attach the expected evidence to each checkpoint.

If a formal amendment moves the date for your obligation, update the plan deliberately and preserve the old record.

Give every deadline an owner and evidence

Every deadline needs a named owner and evidence. NIS2 places responsibility on management bodies, not shared inboxes.

Regulators need records: the approved policy, completed assessment, tested control, and dated log. Collect and organize that evidence before the deadline. Sorena Law Tracker maintains the obligation, due date, and owner in a live regulatory register. The same discipline applies to ESG and CSRD reporting.

Plan for overlapping deadlines

The AI Act, NIS2, DORA, and CSRD have overlapping dates. A single organization can face several obligations at once.

A financial entity can owe DORA duties from 17 January 2025 and still fall under NIS2 where DORA does not cover the issue. A manufacturer using AI may face AI Act inventory, literacy, transparency, GPAI, and high-risk planning milestones while its sustainability team follows CSRD's phased calendar.

Keep one view of applicable obligations and critical dates so the team can plan across them.

Work backward from the deadline

Plan backward from the legal date. Name the owner, list the evidence, and set checkpoints early enough to complete the work before the deadline.

Frequently asked questions

Isn't a phased rollout basically extra time to comply?+

No. A phased rollout is a sequence of separate deadlines, not one soft one. The [EU AI Act](/artifacts/eu/artificial-intelligence-act), for example, has already applied some obligations in 2025, has a 2 August 2026 general application milestone, and now has delayed high-risk dates in 2027 and 2028. Clearing an early phase does not buy you time on a later one, and a delay to one obligation does not move the others.

What does missing an EU compliance deadline actually cost?+

It depends on the regime, but the numbers and supervisory consequences are large. The [AI Act](/artifacts/eu/artificial-intelligence-act) reaches up to EUR 35 million or 7% of global turnover for the most serious violations. [NIS2](/artifacts/eu/nis2-directive) requires Member States to set maximum fines of at least EUR 10 million or 2% of worldwide turnover for essential entities and places responsibility on management bodies. [DORA](/artifacts/eu/digital-operational-resilience-act) became applicable on 17 January 2025 and gives financial supervisors a detailed operational-resilience rulebook for ICT risk, incident reporting, testing, and third-party risk.

What does planning backward from a deadline mean in practice?+

It means starting from the fixed date and subtracting every step that has to happen before it: review cycles, evidence collection, sign-offs, remediation, and buffer. What remains is your real start date, which is usually earlier than instinct suggests. Each step becomes a checkpoint with a named owner, so the deadline arrives as something you pass rather than something you hit.

Sources

Share

See Sorena do the work

Book a demo and watch one real compliance workflow go from question to audit-ready output.