The Act That Postponed the Hard Part

Share

The Digital Omnibus on AI is now law. Political agreement was reached on 7 May 2026, and the thing itself - Regulation (EU) 2026/1744 - was published in the Official Journal on 24 July and entered into force three days later, with time to spare before the very August deadline it was designed to push back. It is the first set of amendments to the AI Act since the Act was adopted in June 2024.

Four deadlines were deferred. One was not.

Annex III high-risk systems - the use-based category: employment screening, credit scoring, eligibility for public benefits, the places where an algorithm's output changes what happens to a specific person - moved from 2 August 2026 to 2 December 2027. Sixteen months.

Annex I high-risk systems - the product-regulated ones, where the AI sits inside something already governed by sectoral safety law: medical devices, lifts, radio equipment - moved from 2 August 2027 to 2 August 2028. A year.

Transparency under Article 50(2) - the obligation to mark synthetic content in a machine-readable format, moved from 2 August to 2 December 2026, four months, and only for systems already on the market before 2 August 2026. Anything placed on the market after that date complies from the day it ships.

National regulatory sandboxes - the requirement that each Member State stand up at least one, moved from 2 August 2026 to 2 August 2027.

And one obligation was added rather than deferred. From 2 December 2026, Article 5 prohibits AI systems used to generate or manipulate non-consensual intimate imagery of an identifiable person, and, in a parallel provision, child sexual abuse material. Hold onto that, because it is the proof of capability: these are the same institutions, in the same instrument, on the same day, writing a new prohibition onto a sixteen-month horizon while pushing existing obligations out past it. The legislature can move quickly. And it moves quickly when the harm is vivid, the category is narrow, and nobody with a balance sheet is going to file a submission objecting.

General-purpose AI enforcement did not move at all. Full enforcement powers over GPAI providers, penalties included, from 2 August 2026, exactly as originally scheduled. Fines up to 3% of worldwide annual turnover, or €15 million, whichever is higher.

What moved and what didn't

Look at what separates the deferred obligation from the untouched one.

Annex III conformity assessment falls largely on deployers: the hospital buying a diagnostic tool, the regional bank buying a credit model, the HR platform buying a screening algorithm. Organisations whose core business is not AI, integrating somebody else's system into a decision that lands on a person, and now required to produce technical documentation, post-market monitoring, and a conformity assessment procedure more or less from nothing.

GPAI enforcement falls on the model developers themselves. Organisations that have run policy and compliance functions built for precisely this kind of paperwork since before the Act existed, and that have been rehearsing model-level disclosure since the first draft of the Code of Practice. For them, 2 August 2026 was a date to be ready for. For a mid-sized deployer, 2 August 2026 was a wall.

So the deadline that stayed put is the one falling on the actors who could meet it, and the deadlines that moved are the ones falling on everybody else.

The objection that has to be answered first

There is a strong argument that this framing is unfair, and it deserves to be met head-on rather than left in a footnote.

The delay was not granted solely because deployers were unready. A substantial part of the official reasoning is that the harmonised standards do not exist yet. CEN-CENELEC is still drafting the technical standards that are supposed to be the backbone of the Annex III requirements, and conformity assessment is an exercise in demonstrating conformity to something. You cannot assess a system against a standard that has not been published. On that account the deferral is not a favour to anyone; it is an admission that the compliance infrastructure lagged the compliance deadline, and that holding the original date would have produced a great deal of expensive documentation certifying nothing in particular.

That is true, and it is the best argument available for the postponement. It also does not answer the question this piece is asking, for two reasons.

First, the standards have been late for years, and were visibly going to be late long before May 2026. The date moved when the date got close, not when the problem became apparent. A risk that everyone can see and nobody acts on until the deadline is in view is not a surprise; it is a schedule.

Second, and more to the point: whatever the reason, the interval exists. The standards argument explains why the postponement happened. It says nothing about what occurs inside the sixteen months, which is the only thing anyone downstream of an Annex III system will experience.

The exercise, run once

So run the two minutes on the configuration this instrument leaves in place. Not on anyone's motives. On the arrangement.

It is January 2028. A hiring-screening tool, deployed at scale since early 2026, has been producing discriminatory outcomes, documented in an academic audit. Conformity assessment obligations for exactly this category took effect five weeks ago. Write down why nobody caught it sooner.

Four answers, none of which require the audit to exist yet.

Because the obligation that would have required testing was not binding until December 2027, and a deployer who checks the calendar before checking the model is not being negligent - it is being compliant. The deadline and the harm do not share a clock. Only one of them was moved.

Because "high-risk" is a category assigned at the point of classification, not a property verified against what the system does once it ships. The Government That Governs Itself made the same observation about a different list, and the control that was tested once made it about controls: a label applied at the start and never re-tested describes a sorting exercise, not an inspection.

Because the actors this deferral was granted to protect - deployers without in-house compliance infrastructure - are also the actors least likely to run a rigorous self-assessment in the absence of a binding requirement to. The extension was granted on the premise that they were not ready to comply. It did not also arrange for anyone to check on them while they got ready.

Because a deferred obligation produces no violation, no violation produces no case file, and no case file is the only kind of evidence most oversight processes are built to notice. The sixteen months are not a gap in enforcement. They are a gap in the record of whether enforcement would have found anything; which is the more durable of the two, because it cannot be filled in retrospectively.

The thing that cuts the other way

A pre-mortem that only produces convenient findings is not a pre-mortem; it is an argument wearing the costume of one. So here is the part of the omnibus that does not fit the pattern.

The same instrument extends the simplified regime previously reserved for SMEs to a newly defined category of small mid-cap enterprises (under 750 employees and under €150 million in turnover). Simplified technical documentation templates that notified bodies are obliged to accept. More proportionate quality-management expectations. Preferential treatment in the calculation of fines. That is a real, specific concession to exactly the class of actor this site has spent half a year arguing gets squeezed, and it is larger than it sounds: the SME ceiling in EU law is 50 employees and €10 million, so this pulls a whole tier of mid-sized European companies into the lighter regime for the first time.

It does not dissolve the argument. A simplified template is help with the paperwork; it is not help with the engineering that has to happen before there is anything worth documenting, and a preferential fine calculation matters only to firms that get as far as being fined. But it is evidence in the other direction, it was adopted in the same act, and a reading that cannot accommodate it is not describing the instrument - it is describing a thesis.

The mechanism, not the motive

This site opened with an argument about who benefits when compliance is expensive: complexity is a cost that scales down as the balance sheet scales up, so raising the bar protects whoever can already clear it. That is the regulator's gift, and this is the same mechanism operating through a different lever.

Nobody lowered a standard here. Nobody needed to. They left the standard exactly where it was for the actors already positioned to meet it, and moved it for everyone else; and the moving was done for reasons that are true, defensible, and were going to be reached anyway.

That is what makes sequencing the more interesting lever. Substance attracts scrutiny; a date does not. Amend what a provision requires and you will be asked to justify the amendment. Change when it starts applying and you have altered nothing anybody can point to. The obligations are identical. The text is identical. Only the interval before the text does anything has grown, and intervals are not the sort of thing anyone writes an op-ed about.

The Clause has no view on whether the delay was warranted. It observes only that a deadline is the one part of a statute requiring no interpretation whatsoever; which makes moving it the single cleanest thing that can be done to a law without touching what the law says.

The GPAI door got its lock on the day the law said it would. The other door got a later date stamped on the frame. And a frame, unlike a lock, does nothing at all until somebody remembers to check it.

Nobody broke the law in this scenario. That was rather the point of moving the date.