Since the political agreement on the Digital Omnibus in May 2026, a particular sentence has been circulating in management meetings: the AI Act has been delayed, so this can wait. That reading is wrong in a way that will cost the organisations who adopt it, because what moved was a set of application dates — not the obligations, not the classifications, and not the work required to meet them.
The change is also not yet law. Understanding both points precisely is worth more than any amount of general commentary.
What actually changed
The Commission adopted the Digital Omnibus proposal on 19 November 2025, and a political agreement was reached on 7 May 2026. Among its targeted amendments to the AI Act, the one drawing most attention aligns the application of high-risk obligations with the availability of the standards and support tools needed to comply with them.
Following that agreement, as set out on the European Commission: AI Act page:
- Annex III high-risk systems — those high-risk by virtue of their use case, such as employment, credit, education and essential services — apply from 2 December 2027.
- Annex I high-risk systems — those high-risk because they are embedded in products already covered by Union harmonisation legislation — apply from 2 August 2028.
The mechanism matters as much as the dates. The deferral was justified by linking application to the availability of harmonised standards, common specifications and Commission guidelines. This was not a concession that the obligations were unreasonable; it was an acknowledgement that firms cannot demonstrate conformity against standards that do not yet exist. The detail of the proposal is set out in the European Commission: Digital Omnibus on AI regulation proposal.
The caveat that most summaries omit
A political agreement is not the same as applicable law. The amended timeline takes legal effect only on publication in the Official Journal of the European Union. Until that point, the dates in force remain those in the EUR-Lex: Regulation (EU) 2024/1689 (AI Act) as originally adopted.
For most organisations this is a technicality that resolves itself. For a few — those making contractual commitments, drafting supplier obligations, or setting board-level compliance dates in the intervening period — it is not. If a contract references “the applicable date under the AI Act”, it is worth knowing which text that phrase currently points to. Confirm the position against the Official Journal rather than against a summary, including this one.
What did not change at all
The deferral is narrow. The following are unaffected and, in several cases, already apply:
- The prohibitions. The practices banned outright under the Act — including certain manipulative techniques, social scoring, and defined uses of emotion inference and biometric categorisation — were among the earliest provisions to apply.
- General-purpose AI obligations. The regime for GPAI model providers, including transparency and documentation duties, runs on its own timetable.
- The classification rules. What makes a system high-risk has not been relaxed. A system that will be high-risk in December 2027 is high-risk in design today.
- AI literacy. The requirement that staff dealing with AI systems have adequate understanding is not tied to the high-risk timetable.
- Every other legal regime. The GDPR applies now. Sectoral supervision applies now. Employment, consumer and anti-discrimination law apply now. An AI system that processes personal data unlawfully is not protected by an AI Act deadline in 2027.
The Commission has also confirmed that it will develop guidelines during 2026 on the practical application of high-risk classification, on transparency requirements, and on serious-incident reporting. Work in progress is published under European Commission: guidelines for providers and deployers of high-risk AI systems, and the consolidated position on dates is maintained in the AI Act Service Desk: timeline for implementation of the EU AI Act.
Why the extra time is less than it appears
Two years sounds generous until it is decomposed. Conformity for an Annex III system typically requires a risk management system across the lifecycle, data governance covering training and testing data, technical documentation, logging, transparency to deployers, human oversight design, and accuracy, robustness and cybersecurity measures — plus, for many, a conformity assessment and registration.
Several of those are not documentation exercises. Data governance frequently reveals that training data provenance was never recorded. Human oversight design often reveals that the reviewer cannot actually override the system, or lacks the time to. Logging requirements regularly reveal that the system was never built to reconstruct a past decision. Each of these is an engineering change with a lead time, and each becomes materially more expensive after deployment than before.
There is also a queue effect. If most organisations treat the deferral as permission to defer, demand for conformity assessment, specialist advice and standards interpretation will concentrate into the final year. Being early is cheaper than being compliant on time.
Provider or deployer changes what you owe
Most organisations reading about the AI Act assume they are deployers, using systems built by someone else. That assumption is frequently wrong, and the consequences of getting it wrong are significant, because provider obligations are substantially heavier — conformity assessment, technical documentation, quality management and post-market monitoring among them.
You may become a provider without procuring anything. Putting a high-risk system on the market under your own name or trade mark can make you one. So can substantially modifying a system, or changing its intended purpose such that it becomes high-risk when it was not before. A firm that fine-tunes a general-purpose model for a hiring workflow, brands the result internally and deploys it across its own recruitment has moved considerably closer to the provider side than it usually realises.
Resolve this per system rather than as a single organisational answer. The same firm may be a deployer of one vendor tool, a provider of an internally adapted system, and out of scope entirely for a third. Record the reasoning for each, because the classification drives everything downstream.
What to do with the time
The useful work is unglamorous and mostly independent of the final legal text.
- Inventory. Establish what AI is actually in use, including systems embedded in procured software that no one classifies as AI internally. Most organisations underestimate this substantially.
- Determine your role per system. Provider and deployer obligations differ. Fine-tuning or substantially modifying a system can change your role.
- Classify provisionally. Identify which systems plausibly fall in Annex III or Annex I, and record the reasoning. Revisit when the classification guidelines are published.
- Close the gaps that take longest. Data provenance, logging and genuine human oversight have the longest lead times. Start there rather than with policy documents.
- Fix what is already unlawful. Prohibited practices and data protection failures are live exposure today, whatever happens to the 2027 date.
A structured framework helps organise this without waiting for legal certainty. The NIST: AI Risk Management Framework is not an EU instrument and confers no presumption of conformity, but its Govern, Map, Measure and Manage structure maps closely enough to the Act’s requirements to be a practical starting point for firms that need to begin now.
What this cannot tell you
An article cannot classify your systems. Classification is fact-specific, turns on intended purpose and deployment context, and in borderline cases will require legal advice against the final published text. Nor is the position fully settled: the amended timeline awaits Official Journal publication, the harmonised standards it depends on are still being developed, and the classification guidelines are not yet issued.
What can be said with confidence is that the direction of the obligations has not changed, that the earliest and hardest work is independent of the final dates, and that an organisation which cannot currently produce an inventory of its AI systems has a problem no deadline extension will solve. Verify the current legal position against the Official Journal before making a commitment that depends on it.
Further reading: European Commission: AI Act; European Commission: Digital Omnibus on AI regulation proposal; EUR-Lex: Regulation (EU) 2024/1689; AI Act Service Desk: implementation timeline; European Commission: guidelines for high-risk AI systems.
See how an AI Readiness & Governance Assessment builds your system inventory and classification view.




