A Delayed Deadline Does Not Defer Accountability
Why governance work continues even when regulatory deadlines move.
In July 2026 the European Union completed the Digital Omnibus on AI — the first substantive amendment to the AI Act since its adoption. The European Parliament endorsed the final text on 16 June, the Council on 29 June. The headline travelled quickly: the high-risk obligations that were due to apply from 2 August 2026 now apply from 2 December 2027 for stand-alone systems, and from 2 August 2028 for AI embedded in regulated products. In many organisations the headline was received as permission to pause.
That reading mistakes a deadline for the obligation behind it. A deadline defines when compliance will be examined. Accountability is defined by what the organisation was doing in the meantime.
What moved — precisely
The deferral is real, and it is narrow. Obligations for stand-alone high-risk AI systems under Annex III — employment, education, credit, critical infrastructure and the other listed uses — now apply from 2 December 2027. Obligations for AI embedded in products already governed by EU product safety legislation under Annex I apply from 2 August 2028, with a targeted carve-out for machinery. Systems that generate synthetic content and were already on the market before 2 August 2026 receive a short grace period, until 2 December 2026, to implement machine-readable marking. The deadline for national regulatory sandboxes moves to August 2027. That is the extent of the relief.
What never moved
The prohibitions on unacceptable AI practices have applied since February 2025 — and the omnibus extended them, adding a ban on systems used to generate non-consensual intimate imagery or child sexual abuse material, with technical safeguards required by 2 December 2026. The AI literacy obligation has applied since February 2025 and was not touched. The obligations on providers of general-purpose AI models have applied since August 2025, with the Code of Practice in place. The Act’s governance architecture and penalty framework have been in force since August 2025.
And on 2 August 2026, two things arrive exactly on schedule. The transparency obligations of Article 50 apply: people must be informed when they are interacting with an AI system, and AI-generated content must be disclosed and marked, subject only to the narrow legacy grace above. And the European Commission’s enforcement powers over providers of general-purpose AI models take effect — the authority to compel documentation, evaluate models, require corrective measures and impose fines of up to 3% of global annual turnover or €15 million. The omnibus also widened supervision at EU level, extending the AI Office’s scope to AI systems built on a general-purpose model within the same undertaking and to systems embedded in the largest online platforms. Registration duties for systems self-assessed as non-high-risk, proposed for removal, survived in simplified form.
An organisation summarising the omnibus as “the AI Act is delayed” has read the coverage, not the text.
The clocks that were never regulatory
Three forces price AI governance independently of the AI Act’s calendar, and none of them moved.
Liability. From 9 December 2026, the new Product Liability Directive brings software — including AI systems, whether embedded, stand-alone or supplied as a service — within a strict liability regime, with disclosure duties in litigation and presumptions that ease a claimant’s burden of proof. It applies to products placed on the market from that date onward. Liability does not wait for a conformity deadline; it attaches to what the product does.
Procurement. The European Commission’s model contractual clauses for AI procurement, updated in 2025, are migrating from public buyers into private contracting practice. Organisations selling AI-enabled products and services increasingly meet governance questions inside a tender or a vendor questionnaire — long before they would meet a supervisory authority.
Enforcement build-out. As of mid-2026, only nine Member States had designated both national authorities the Act requires; most of the rest were partway there. The institutional map will fill in unevenly over the coming two years — but the obligations on companies apply regardless of how ready any given authority is. Institutions catch up. Obligations do not wait for them.
Evidence cannot be backdated
The strongest reason the delay defers little is structural. Governance evidence accrues in real time. An inventory of AI systems, the reasoning behind each classification, records of who approved what, logs of oversight and intervention, documentation of vendor and model changes — these exist in December 2027 only if the operating structure that produces them exists well before December 2027. A compliance position is assembled from records; records are generated by running governance, not by drafting it.
None of that foundational work waits on harmonised standards. Finding every AI system in the organisation, deciding what each one is, assigning who may approve, change or stop it, and making human oversight real are standard-agnostic. The European standards bodies are working to an accelerated target of late 2026 for the key deliverables, with citation in the Official Journal to follow — which means the standards, when they arrive, will presuppose exactly this base. They will not substitute for it.
What the window is for
Read as sequencing rather than reprieve, the additional time is genuinely valuable. It is enough to complete the inventory and classification as though the original dates still held, because that work does not get easier later. It is enough to stand up the record-keeping and oversight spine while the AI portfolio is still small — the cheapest it will ever be. And it frees attention for where 2026 actually bites: transparency obligations, general-purpose model dependencies, and the contracts through which external AI enters the organisation.
Making regulation operational starts before the deadline does. That has not changed — because it never depended on the date.
Scope. The EU AI Act’s application timeline following the Digital Omnibus on AI (adopted June 2026), and its operational implications for organisations. Sector-specific regimes are outside scope.
Assumptions. Based on the final omnibus text as adopted by Parliament (16 June 2026) and Council (29 June 2026), entering into force in July 2026. Dates cited are those set in that text.
Sources. Regulation (EU) 2024/1689 (EU AI Act), consolidated by the Digital Omnibus on AI — EUR-Lex; European Parliament press release, 16 June 2026 — europarl.europa.eu; Council of the EU press release, 29 June 2026 — consilium.europa.eu; Freshfields, The final Digital Omnibus on AI (July 2026); AI Act Explorer, Enforcement of Chapter V and National implementation plans — artificialintelligenceact.eu; Directive (EU) 2024/2853 on liability for defective products — EUR-Lex; European Commission Public Buyers Community, Updated EU AI model contractual clauses (2025) — public-buyers-community.ec.europa.eu; CEN-CENELEC, acceleration of JTC 21 deliverables (October 2025) — cencenelec.eu.
Intended use. A briefing for executives and governance owners planning the 2026–2028 window. It is a governance perspective, not legal advice; confirmed legal interpretation belongs with counsel.