Vesster
All insights
ComplianceAug 15, 20266 min read

The EU AI Act Just Deferred Its Hardest Obligations. Do Not Exhale.

Brussels pushed the AI Act's high-risk deadlines to 2027 and 2028. The deferral buys calendar time, not readiness, and the pilots that died never failed on paperwork.

The EU AI Act Just Deferred Its Hardest Obligations. Do Not Exhale.

If you run AI in a regulated business, the headline from Brussels reads like relief. The Digital Omnibus entered into force on 27 July 2026, and as reported by DLA Piper, the heavy Annex III high-risk obligations that everyone was bracing for have been pushed back, to 2 December 2027 and 2 August 2028. A year of pressure just came off the calendar. The natural instinct is to exhale and re-prioritize the AI governance work to the bottom of the pile.

However, the deferral did not move the part of the regime that has teeth right now. As the same coverage and the AI Act Office summary make clear, from 2 August 2026 the Article 50 transparency obligations, the GPAI enforcement powers, and the full penalty regime all take effect. That penalty regime is not symbolic. Fines run up to 7% of global turnover or EUR 35 million. So the law did not get softer. It got rescheduled, and the enforcement machinery switched on ahead of the obligations it will eventually enforce.

That gap between what was deferred and what went live is the whole story, and most organizations are reading it backwards.

What moved, and what did not

Be precise about the two clocks, because they are running at different speeds.

The capability clock was deferred. The detailed conformity assessments, the technical documentation, the risk-management system requirements for Annex III high-risk uses, those are the obligations that demand real engineering, and those are the ones now sitting in 2027 and 2028. That is the work people were dreading, and it is the work that got more time.

The accountability clock was not deferred. Transparency duties under Article 50, the supervisory powers over general-purpose models, and the fines, all of that is present tense from 2 August 2026. In plain terms, the authority to investigate you and to penalize you arrived before the deadline for the hardest technical controls. Regulators can now act. What they will eventually check against is what got postponed.

Reading those two clocks together, the deferral is not a reprieve. It is a runway. And a runway is only useful to an organization that has decided where it is trying to take off to.

The deferral buys calendar time, not readiness

Here is the uncomfortable number. As reported in the Responsible AI Labs analysis, as of April 2026, 78% of organizations had not taken meaningful steps toward compliance. That figure was already alarming under the old timeline. Under the new one, it is a trap.

The trap is that time and readiness feel like the same resource, and they are not. Calendar time is what the Omnibus gave back. Readiness is a different thing entirely, and it does not accrue by waiting. An organization that was not ready in April 2026 and now has until 2027 or 2028 has not become more ready. It has become later, with the same gap intact and a shorter honest runway than the headline suggests, because governance is not a document you assemble in the final quarter before a deadline.

This is the part that the "we got more time" reading misses. Governance is an architecture you build once, not a filing you produce on a due date. The controls that the high-risk regime will eventually demand, an auditable record of every consequential decision, a policy layer your compliance team owns and can prove, a way to show which model made which call and why, are not paperwork you generate retroactively. They are properties a system either has because it was built with them, or lacks because it was not. You cannot backfill an audit trail for decisions a system already made without recording them.

An organization that treats the deferral as permission to wait will arrive at 2027 in exactly the position it is in today, except with less time to change it.

The pilots that died never failed on paperwork

There is a second reason the compliance-deadline framing is the wrong one to organize around. The projects that fail do not fail at the conformity assessment. They fail long before, and for reasons the AI Act does not even name.

Roughly 40% of agentic-AI projects are projected to be cancelled by 2027 (Thoughtworks). Notice what that failure is not. It is not a regulator rejecting a technical file. It is pilots that could never cross from a demo into production, because the moment an agent has to act on regulated data, under an identity, with a record someone can inspect, the demo architecture has nothing to offer. The pilot dies at the security review, or the risk committee, or the first month it drifts and no one notices, and none of those deaths appear on a compliance timeline.

That is why aligning your plan to the deferred deadline is a category error. The deadline is a legal date. The wall the pilot hits is an architectural one, and it does not move when Brussels moves a date. An organization optimizing for the 2028 filing is optimizing for the wrong constraint. The constraint that actually stops the work is the one that was always there: can this system act in a regulated process at all, and can you defend how it did?

Build for that wall, and the compliance filing becomes something you can produce, because the evidence already exists as a byproduct of running the system correctly. Skip it, and no amount of deferral saves you, because you were never going to reach the filing in the first place.

The reframe

The wrong question, the one the Omnibus headline invites, is "how much longer do we have before we must comply?" That question treats governance as a deadline to be met as late as possible, and it leads directly to arriving at the deadline with nothing built.

The better question is this. If the enforcement powers and the fines are live now, and the technical obligations are simply the bill that comes due later, what is the foundation we would have to build so that being audited is a report we can run, not a project we have to start? Answer that, and the deferral is genuine runway, time to build the governed foundation while the pressure is briefly off. Answer it the other way, and 2 August 2028 will arrive exactly like 2 August 2026 did for the 78%, as a date that caught them unbuilt.

The calendar moved. The work did not. And the organizations that use the extra time to build the foundation, rather than to postpone thinking about it, are the ones for whom the deferral was actually a gift.

If you want to pressure-test whether your highest-stakes AI process could survive an audit today, rather than in 2028, book a meeting and bring us the one you would least want a regulator to see.

Sources

Weighing this on a real process?

Bring it to us and we'll give you a straight read on where agents fit, and where they don't.