Governance
The EU AI Act: the calendar moved, the governance work did not
The Digital Omnibus pushes high-risk obligations to December 2027 and August 2028, but Article 50 transparency is still due. How a CTO should read the delay.
The EU AI Act calendar changed this summer. The Digital Omnibus on AI, now in force, postpones some of the most anticipated deadlines. The wrong reading is "we have eighteen more months, we'll deal with it later". The right one: some obligations are due this year, and the delay is an opportunity to work properly, not an exemption.
What changed
According to Gibson Dunn's analysis of the agreement, the new dates are:
- Stand-alone high-risk systems (Annex III) — recruitment, credit scoring, education, law enforcement, border control: application pushed to 2 December 2027.
- AI embedded in regulated products (Annex I) — medical devices, machinery, vehicles: 2 August 2028.
- Article 50 transparency (telling users they are interacting with AI): unchanged, 2 August 2026, so already applicable.
- Marking of generated content: grace period to 2 December 2026 for systems already on the market before 2 August 2026.
- New prohibition (Article 5) on systems generating non-consensual intimate imagery and child sexual abuse material.
- Regulatory sandboxes: deadline pushed to 2 August 2027; AI Office investigative powers strengthened.
Law firms agree on the reason: harmonized technical standards and national authorities weren't ready. The delay does not come from dropping the requirements. (Final texts and their transposition should be checked with your legal counsel; this article is an architect's reading, not legal advice.)
Three misreadings to avoid
"Nothing applies before 2027." Wrong: Article 50 transparency has applied since 2 August 2026. A customer chatbot, a voice assistant or an agent writing to third parties must identify itself as AI. It is an interface requirement, but it is also handled in architecture (where and how the notice is displayed, logged and tested).
"This only concerns providers." Wrong: deployers have their own obligations. If you use AI to screen candidates or decide on credit, the high-risk category concerns you even if you didn't build the model.
"The delay removes the work." Wrong: the substantive requirements don't change — documentation, real human oversight, traceability, data governance. Organizations that wait until 2027 will find that modifying an existing system costs more than designing it compliant.
What a CTO can do now
- Inventory AI systems in use, including those bought from vendors and those teams use informally.
- Classify each system by risk level and document the reasoning — the absence of analysis is itself a failing.
- Check Article 50 at every customer touchpoint: AI disclosure, marking of generated content before December 2026.
- Build traceability into new architectures: log inputs, outputs, model version and any human decision.
- Name an owner for AI compliance, tied to existing governance (GDPR, security).
For the detail of both frameworks, see our article on GDPR and the AI Act.
- The Digital Omnibus pushes high-risk to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
- Article 50 transparency has applied since 2 August 2026; content marking has a grace period to 2 December 2026.
- The delay comes from lagging standards and authorities, not from relaxed requirements.
- Inventory, classification, transparency and traceability: four workstreams to start now.
Sources
Related reading
Does this challenge sound familiar?
A first conversation to assess it together, at no cost.