The text hit the Official Journal on a Friday, July 24, and somewhere in a compliance function the shoulders finally came down. Relief. The high-risk obligations that had been eating every Thursday steering committee since last autumn were no longer due in nine days, they were due on December 2, 2027, and a calendar that had felt like a countdown suddenly had air in it again. Then the second thought landed. The inventory was still a spreadsheet with forty-odd rows and no owners, nobody had written down what the screening model was actually supposed to do, and sixteen extra months only feels enormous until you subtract the work that has not started.

Seen it before. 25 years in enterprise software delivery teaches you what teams do with a deadline extension, and it is almost never "get ahead": they stop, the program loses its forcing function, and they restart in month eleven with the same unanswered questions and less runway. Let me be fair to the other reading, because there is a real one. For an organization already mid-build, the deferral is genuinely good news, and simplification was not a bad instinct. But the date was never the hard part.

What actually changes on August 2, 2026?

Less than the relieved reading assumes. Transparency obligations under Article 50 still apply from August 2, 2026, including the plain duty to tell a person they are talking to a machine. The general-purpose AI model rules, which have applied since August 2025, were left alone, and the Commission's enforcement and penalty machinery still switches on as planned. What moved is the high-risk layer, and only that: standalone Annex III systems (hiring, credit scoring, biometric identification, and the rest of the list) now apply from December 2, 2027, while AI embedded in regulated products such as medical devices and machinery moves to August 2, 2028. Systems already placed on the market before August 2, 2026 get a grace period until December 2, 2026 for synthetic content marking. So the deadline did not disappear. It split.

And this is settled law now, not a lobbying fight. The European Parliament adopted the package on June 16, 2026, the Council of the EU signed off on June 29, and the text was published as Regulation (EU) 2026/1744 on July 24, entering into force July 27. I spent most of the spring telling clients to plan for both outcomes, because the parliamentary arithmetic looked genuinely uncertain. That advice is stale. Gibson Dunn's read of the postponed high-risk deadlines and other key changes lands on the same practical point: the substance of the high-risk obligations survived the simplification largely intact. What you owe an assessor did not shrink. Only the day it comes due.

Why is the Digital Omnibus deferral a window, not relief?

Because deferred is not deleted, and the readiness gap it exposes was never about the calendar. Look at what organizations actually have in place. In the 2026 AI and Compliance Survey from Compliance Week and konaAI, published April 30 and drawn from 193 compliance, ethics, risk and audit leaders, more than 83% report using AI tools while only about 25% have implemented a strong governance framework. Read them together. Adoption is finished; governance has barely started, and the sixteen months just granted are the entire distance between those two figures.

25%
of organizations have implemented a strong AI governance framework, while more than 83% already use AI tools. The deferral did not close that gap. It just moved the date it becomes visible.

Here is the trap. A runway is only an advantage to whoever is running on it. The risk management system, the technical documentation, the data governance, the logging, the human oversight design, the post-market monitoring: every one of those duties is still there in the same words, waiting at the end of a road that now has a confirmed length. An organization that reads December 2, 2027 as permission to go quiet does not arrive prepared in 2027. It arrives with the identical unanswered questions, having spent the one thing the Omnibus actually gave it. We walked through the underlying obligations in detail in the EU AI Act compliance requirements guide, and almost none of that changed on Friday.

How does requirements discipline produce an audit trail?

Because an audit is a requirements interview with legal consequences attached. Strip away the acronyms and an assessor is asking three questions about every system in scope: what was this thing supposed to do, who decided that and on what basis, and how do you know it still does it. None are infrastructure questions. They are questions about intent, and about whether the intent was ever written down in a form somebody else can check.

This is where most governance programs quietly fail, and it took me a while to see it. My first instinct, honestly, was that this was a documentation problem: teams knew what their systems did, they simply had not typed it up. Then I started sitting in the workshops. They did not know. Or rather, four people knew four different versions, the fraud threshold had been tuned twice by someone who left in 2024, and the reason it was set where it was lived in a Slack thread nobody could find. You cannot document your way out of that. Documentation formats a decision; it does not recover one.

63%
of breached organizations either have no AI governance policy or are still developing one. Governance debt does not stay theoretical. It shows up in incidents, and then in the file an investigator reads.

So what does the work actually look like between now and December 2027? Start with an inventory that includes the systems procurement never saw, because those are the ones that will surprise you. For each system, recover the intended purpose in one testable sentence, then the decisions it influences, the rules it must respect (regulatory, contractual, and the internal ones nobody has written since 2019), and the human oversight that is supposed to catch it when it is wrong. Write each of those as a requirement with an owner and a date. Order matters. Only then wire evidence to them: a log that answers a requirement, a test that proves one, a review that signs off on one. Do it in that order and the audit trail is a byproduct. Do it in the other order and you get a very expensive folder of screenshots that answers no question an assessor actually asked. Tooling and competent legal counsel both matter here, genuinely, but neither can hand you an intent that was never captured.

What the assessor asks, and what answers it Every question on the left is a requirements question. Every answer on the right is a requirements artifact. THE ASSESSOR ASKS What was it supposed to do? WHAT ANSWERS IT A validated, testable requirement. Who decided, and on what basis? A traced decision, with an owner and a date. How do you know it still does it? A test and a log, tied back to the requirement. The audit trail is a byproduct of requirements discipline, not a separate deliverable.
Governance readiness is not a document you write at the end. It is what traceable requirements leave behind.

Telefónica did not wait for a deadline, and the timeline is on the public record. The company published its ethical AI principles in 2018, then designed a "Responsible AI by Design" methodology in 2019, well before the AI Act existed in enforceable form. Five years early. Between 2020 and 2021 it built and iterated an assessment questionnaire with risk evaluation baked in, the thing most organizations are only now scrambling to procure. In 2022 it piloted the governance model across four global business units. The model itself was formally approved in December 2023 and rolled out through 2024.

Two details matter most. First, roughly 4,000 employees completed the internal AI ethics course, which means the discipline reached the people writing the requirements, not just the committee reviewing them. Second, the questionnaire went through three versions, and the later ones explicitly incorporate EU AI Act requirements alongside UNESCO's recommendation and NIST standards. That is what using a runway looks like: by the time the regulation bit, the company had more than 500 AI applications running inside a structure that could already answer for them. It is not a compliance department output. It is a requirements habit that happens to satisfy a regulator.

Source: UNESCO Global AI Ethics and Governance Observatory, "Insights from Practice: Telefonica's AI governance journey".

Notice the sequence. It is not a platform purchase followed by a scramble to feed it. The artifacts came first, the questionnaire got sharper through use, and the tooling landed on top of a practice that already existed. That ordering is the whole lesson, and it is the same ordering that separates an AI governance program that survives contact with an auditor from one that produces a binder.

How does this connect to agentic AI programs?

Directly, and uncomfortably. An agent does not just output a prediction you can review; it takes steps, calls systems, and chains decisions, which means the audit question mutates from "what did the model say" to "what was this agent permitted to do, and who drew that boundary." A boundary is a requirement. Mature governance for autonomous agents remains rare while adoption climbs, a gap we measured in the agentic AI adoption gap, and the sixteen-month runway is precisely when most enterprises plan to scale agents hardest. Scale ungoverned behaviour now, explain it in 2027. That is also the failure pattern behind the forecast that a large share of agentic AI projects get cancelled by 2027: not model quality, unclear intent.

The reprieve is a window, and windows close on a schedule.

Regulation (EU) 2026/1744 is in force. No ambiguity left. Standalone high-risk obligations now apply from December 2, 2027 and embedded AI from August 2, 2028, while the Article 50 transparency duties and the enforcement regime still land on August 2, 2026. Deferred is not deleted: the documentation, logging, oversight and monitoring duties are unchanged in substance.

The gap the runway is supposed to close is not a tooling gap. More than 83% of organizations use AI and only about 25% have a strong governance framework, because governance readiness is a requirements problem: what the system is supposed to do, who decided, and how you prove it still holds. Recover that intent, write it as testable requirements with owners, and wire the evidence to it. The audit trail falls out of that work. It cannot be retrofitted.

What are the most common questions about EU AI Act readiness?

Transparency obligations under Article 50 still apply from August 2, 2026, including the duty to tell people they are interacting with an AI system. The general-purpose AI model rules, which have applied since August 2025, were left alone, and the Commission's enforcement and penalty powers still switch on as planned. What moved is the high-risk layer: standalone Annex III systems now apply from December 2, 2027, and AI embedded in regulated products from August 2, 2028. Systems already on the market before August 2, 2026 get until December 2, 2026 to comply with synthetic content marking.
Confirmed and in force. The European Parliament adopted the AI simplification package on June 16, 2026, the Council of the EU gave final approval on June 29, 2026, and the text was published in the Official Journal on July 24, 2026 as Regulation (EU) 2026/1744. It entered into force on July 27, 2026. This is no longer a political question about whether the delay will happen. It is a fixed, finite runway with a date on the end of it.
No. Deferred is not deleted. The technical documentation, risk management, data governance, logging, human oversight, accuracy, and post-market monitoring duties for high-risk systems are unchanged in substance. Only the date they bite moved. An organization that treats December 2, 2027 as sixteen extra months of quiet arrives at the same audit with the same unanswered questions, minus the runway it just spent.
Because an audit is a requirements interview with legal consequences. An auditor asks what the system was supposed to do, who decided that, on what basis, and how you know it still does it. Those are not infrastructure questions. They are questions about validated, traceable, testable requirements. A team that cannot state in writing what done and safe mean for an AI system cannot produce documentation an assessor will accept, no matter which governance platform it buys.
Discovery first, tooling second. Inventory the AI systems actually in use, including the ones procurement never saw. For each one, recover the intended purpose, the decisions it influences, the rules it must respect, and the human oversight that is supposed to catch it when it is wrong. Write those down as testable requirements with owners and dates, then wire the evidence to them. Legal counsel and a governance platform both matter, but neither can produce an intent that was never captured.
It raises the stakes rather than lowering them. Agentic systems act across steps and systems, so the audit question shifts from what did the model output to what was this agent permitted to do, and who bounded it. That boundary is a requirement. Mature governance for autonomous agents is still rare while adoption accelerates, and the organizations scaling agents hardest during the runway are the ones building the most undocumented behaviour to explain in 2027.
Nicolas Payette, CEO and Founder of Specira AI
CEO and Founder, Specira AI

Nicolas Payette has spent 25 years in enterprise software delivery, leading digital transformations at companies like Technology Evaluation Centers and Optimal Solutions. He founded Specira AI to solve the root cause of project failure: unclear requirements, not slow code.