July 4, 2026 · 1,001 words · 5 min read
The deadline moved. Your risk didn't.
The EU is pushing back central parts of its AI regulation. Anyone building or operating AI systems in an enterprise has had, since late June, considerably more time on paper for the strictest requirements.
Concretely: on June 29, the Council of the EU gave its final approval to the Digital Omnibus, a package that simplifies the AI Act—the EU’s law for AI systems—and moves its most important deadlines. Affected is the most demanding part of the law: the obligations for high-risk systems. Those are AI systems that help decide about people, say in hiring, credit, or public services (Annex III), and AI embedded in regulated products such as medical devices (Annex I). For the first group, the deadline moves from August 2, 2026 to December 2, 2027; for the second, to August 2, 2028.
Sixteen months of gifted time. That’s how it sounds, anyway.
I suspect that in many companies, a governance budget went quiet that same week. The logic is tempting: if the obligation only bites at the end of 2027, then traces, evals, and human-in-the-loop can go back to where unloved topics live. Phase 2.
That logic is, I think, the most expensive conclusion you can draw from the omnibus.
What actually changed
First, the sober inventory, because the delay is not a free pass. The Article 50 transparency obligations still arrive on August 2, 2026: disclosure for interactive systems, for emotion recognition and biometric categorization, for deepfakes and AI-generated content. There is a transition period until December 2, 2026, but only for labeling by providers of synthetic-content systems already on the market before August 2, 2026. If you offer a chatbot, the omnibus still leaves you with an obligation in a few weeks, not an option.
What got postponed are the heavy lifts: the requirements for high-risk systems. The reason is unspectacular and understandable. Harmonized standards aren’t finished, national authorities haven’t been designated, conformity-assessment tooling is missing. The EU isn’t postponing because the requirements are wrong, but because the infrastructure to verify them doesn’t exist yet.
That’s the first thing the phase-2 logic misses: the requirements themselves are known and adopted. What moved is the date they apply and get audited—not the direction they point.
The harder deadline was never in Brussels
The second point weighs more. A few days ago I wrote about the OLG Hamm ruling: a chatbot invented medical specialist titles, and the court attributed the statements to the operator. Under current law. Without the AI Act. AI liability is an architecture problem, and that problem has no effective date in the Official Journal.
Civil liability doesn’t do transition periods. And the postponement of the high-risk obligations pauses neither the GDPR nor the MDR, which keeps applying to medical devices unchanged. If you operate AI in healthcare, in finance, or in any other regulated environment, you had a complete compliance stack long before the AI Act. The AI Act layers on top of it. If that one layer arrives later, the others are relieved by exactly nothing.
The building blocks at stake are the ones from the liability post: guardrails, source grounding, human-in-the-loop at the critical points, traces, evals. None of them was ever AI Act paraphernalia. They are what makes a system attributable and defensible today, when something goes wrong. And something goes wrong, regardless of what gets decided in Brussels.
The AI Act will demand more than these building blocks in 2027—above all documentation, quality management, and the conformity assessment itself. But that’s paperwork on top of a foundation. Without the foundation, it’s paperwork over a hole.
If you need a deadline, you have a different problem
There’s a simple test for what governance really is in a company. Move the legal deadline and watch what happens. If building continues, it was system design. If it gets cut, it was theater for the auditor.
That sounds harsher than intended, because the reflex is understandable: budgets are finite, and a deadline is the strongest argument in a steering meeting. But an architecture that only exists because of a deadline gets dismantled at the first postponement and missed at the next incident. Then you’re standing without traces in front of the question of why the system said what it said, and without evals in front of the question of whether the fix actually works.
There’s also a practical detail in the omnibus that rarely gets quoted: grandfathering. Systems placed on the market before the new dates only grow into the high-risk obligations once their design is substantially modified; for systems used by public authorities, a hard backstop applies in August 2030. That sounds like another gift. In practice, though, every living AI system changes continuously: models get swapped, prompts get reworked, data sources get added. Whether that legally amounts to a substantial modification is, in the end, a question for lawyers. But if you build your roadmap on grandfathering, you’re building yourself an incentive not to improve your own system. That’s not a strategy—that’s standstill with a legal justification.
What I recommend instead
The delay is reasonably justified, and alarmism would be the wrong response. The right reading is a different one: the EU moved the exam date, not the material. If you harden the building blocks in production now, December 2027 becomes a conformity exercise. If you wait, it becomes a rescue project with sixteen months less runway than it seems today.
The omnibus is a gift. But to those already building—not to those who wait.
Sources: Council of the EU press release, June 29, 2026, adopted legislative text PE 30/2026, AI Act, Article 50.
This is not legal advice—it’s an architect’s reading of a regulatory delay.