Insight · 4 min read

The EU delayed its AI deadline. Don't delay the work.

The Digital Omnibus on AI became law today, pushing high-risk compliance to December 2027. The requirements it defers are the same ones that make AI systems work at all.

Jacqueline DeStefano-Tangorra

By Jacqueline DeStefano-Tangorra, CPA, CFE, CDMP · Founder & CEO, Omni Business Intelligence Solutions · Contact the author

The European Union moved its central AI compliance deadline back by sixteen months, and the amendment carrying that change entered into force today. If August 2026 was the date on your calendar, it is no longer the date. The reflex in most companies will be to push the AI governance work to the back of the queue. That is the wrong call, and not for the reason compliance consultants usually give.

What moved, and what stubbornly did not

The Digital Omnibus on AI was published in the EU's Official Journal on 24 July and took effect today. Lewis Silkin describes it as the first formal set of amendments to the AI Act since the Act was adopted in June 2024. The headline change is timing. Obligations for stand-alone high-risk systems, the category covering uses such as employment, education, and access to essential services, shift from 2 August 2026 to 2 December 2027. For AI built into products already regulated under EU product-safety law, the date is now 2 August 2028. Far less has been said about what did not move. Freshfields notes that the transparency obligations under Article 50 still take effect on 2 August 2026, with only the marking of AI-generated content getting a grace period until 2 December 2026, and is explicit that the underlying high-risk obligations are not changed in substance. The deadline moved. The requirements did not.

A deferred deadline is not a deferred capability

Look at what the high-risk regime actually asks for. Holland & Knight's reading of the Act points to technical documentation covering a system's purpose, design, and performance under Article 11, and to obligations under Article 26 for deployers to assign human oversight and to retain automatically generated logs for six months. Freshfields adds risk management and governance to that list. Strip the regulatory framing off and what remains is simply a description of a system you can operate. Every item is something you would want before letting software make or shape a decision that affects a customer, an employee, or a dollar. That is the part operators miss. These are not compliance artifacts bolted onto a working system. They are the things that make the system work. You cannot tell whether an AI agent is drifting if you are not logging what it did. You cannot fix a bad output if you cannot trace which data produced it. You cannot put a human in the loop if nobody has defined which decisions require one. Companies that stop building these because the deadline moved will not have a compliance problem in December 2027. They will have an operating problem long before then.

Controls built for the examiner are the ones that fail

Our founder came out of Big Four accounting, and the pattern here is a familiar one. A control designed to satisfy an examiner is thin. It exists as a document, it gets performed the week before fieldwork, and it catches nothing. A control designed because the process genuinely needs it runs every day, and it satisfies the examiner as a byproduct. The first kind evaporates the moment a deadline moves, which is exactly what just happened. The second kind does not, because it was never about the deadline. Sixteen extra months is also precisely enough time to build the second kind badly, if you start in month fourteen. The organizations that are ready in December 2027 will be the ones running this as an operating program now, treating the regulation as a floor rather than as the goal.

What the extra time is actually for

Start with an inventory, because most companies cannot answer the first question. Where is AI already making or influencing decisions here, including the features your vendors switched on without asking? The pattern we see is that the list runs longer than leadership expects, and the surprising entries usually arrive through a SaaS subscription rather than through a project. Then classify. Which of those uses touch hiring, credit, access to services, or anything else where a wrong answer lands on a person? Those deserve real oversight whatever any regulator requires. The rest can run lighter, and saying so out loud is how you keep the program affordable. Then fix the data underneath, because this is the sequencing most programs invert. Logging, lineage, and agreed definitions are prerequisites for oversight, not follow-on work. Whether the Act reaches your company is a question worth putting to counsel rather than assuming in either direction. Holland & Knight notes that it can apply to providers outside the Union where the output of an AI system is used in the Union, which means server location is not the deciding factor many operators assume it is. But notice that the sequence above does not change based on that answer. That is the tell. When the right operational move is identical whether or not the rule applies to you, the rule was never the reason to do it.

Related

Keep reading

Insight · 6 min read

The linear marketing funnel is over. What replaces it is measurable.

Read →

Insight · 7 min read

Agentic AI is quietly rewriting customer acquisition for small businesses

Read →

Insight · 6 min read

AI runs on trust. Trust runs on clean data.

Read →

Get in touch

Senior experts on every engagement

Tell us what you're working through. Every inquiry is read and answered personally by our advisory team.

Jacqueline DeStefano-Tangorra

Led by Jacqueline DeStefano-Tangorra, CPA, CFE, CDMP

Founder & CEO, Omni Business Intelligence Solutions

Forbes Technology Council member · Featured by the Wall Street Journal, Business Insider, CNBC, NASDAQ, and Microsoft

Backed by a team of 20+ data, AI, and BI specialists across various teams — the right expert joins at the right moment.

Start the conversation →