Writing / 2026

The EU Gave You a Reprieve, Not a Pardon

The Digital Omnibus deferred the AI Act's high-risk duties, not its live ones. Build the deferral ledger, one row per system and obligation, before relief becomes surprise.

In July the EU moved a compliance deadline backward. Regulation 2026/1744, the Digital Omnibus amendment to the AI Act, took effect on 27 July and pushed the high-risk obligations that were due on 2 August out by more than a year. The AI programs I’ve seen reacted the way relief invites: the whole topic slid into next year’s planning cycle.

That reaction confuses the part that moved with the parts that didn’t. Here is the claim, stated so it can be wrong: the deferral changed your sequencing, not the amount of discovery work you owe in 2026. If your in-scope inventory, ownership map, and evidence gaps aren’t written down by December, the reprieve made you slower, not safer.

The instrument is a deferral ledger: one row per system per obligation, not a memo. Each row records the system, the EU-use trigger (per regulatory divergence as a routing problem , “used in the EU” is a property of traffic you must be able to detect, not of where your company sits), whether you are provider or deployer for that system (you can be both, and the duties differ), the applicable article or annex, the deadline, a named owner, the evidence gap, and the next decision with its review date. The amendment sorts every row into one of three columns. Law-firm analyses from Akin Gump and Cooley lay out the chronology, and it goes like this.

Column one is live now. Article 50’s transparency obligations took effect on 2 August as scheduled: covered interactive systems must disclose to people that they are dealing with AI. The duty applies extraterritorially when outputs are used in the EU, and it reaches deployers as well as providers, so buying someone else’s chatbot does not outsource it. Which duties land on you depends on the role column in your ledger, which is exactly why the ledger has one. The amendment also sharpened Article 25, which obliges the original provider to cooperate with any downstream party that becomes a provider in its own right by rebranding, substantially modifying, or repurposing the system, with fines up to 3% of global turnover or €15 million, whichever is higher. If your product wraps a vendor model closely enough to make you a provider, that clause is now part of your vendor relationship. Rows in this column belong in this quarter’s work.

Column two has a date this year. Machine-readable marking and detection for generative systems, meaning the synthetic audio, image, video, and text your products emit, got an extension for systems already on the market, to 2 December 2026. Under three months from this post. Marking has to survive your render path, which makes it an engineering project rather than a policy memo; it gets its own treatment here before December. There is also a voluntary Code of Practice on AI-generated content, final since June, which the Commission says signatories can rely on to demonstrate compliance with the marking and detection rules; that trade is worth having counsel read this month. Rows in this column get a weekly cadence. The clock is too short for quarterly.

Column three is the actual deferral. Annex III high-risk systems, the employment screeners, credit scorers, and essential-service gatekeepers, now come due 2 December 2027; Annex I product-legislation systems, 2 August 2028. Context worth knowing: the harmonised standards those obligations lean on were late. The first European standard supporting the Act, EN 18286 for quality management, was published by CEN-CENELEC in late July and still awaits its Official Journal citation; the rest are expected late 2026 into early 2027.

The unfinished standards are also the best objection to starting now: why build controls against a measuring stick that hasn’t arrived? Answer the objection by splitting the column. Standards-dependent work, such as the specific shape of your QMS and conformity documentation formats, can and should wait for the texts. No-regret work cannot: knowing which systems are in scope, who owns each, what testing and oversight evidence exists today, and what evidence your vendors will hand you when someone asks. That work is organizational, it has a long lead time, and no standard will do it for you. Fifteen months is comfortable if the ledger exists this fall and brutal if it starts in mid-2027.

Your board may raise the cynical read: Brussels blinked once, wait for the next blink. Maybe. But the obligations that survived untouched (transparency, marking, provider cooperation) are the cheap-to-verify ones, insurers are starting to ask for the same evidence , and enterprise customers already do. The bet that everything slips is a bet against every party acquiring a claim on your paper trail. The ledger costs an analyst-week. The EU moved a deadline. It did not move the direction.