All posts

The Calendar Moved. The Work Didn't.

The Digital Omnibus is law. Four of the five benefits everyone is listing are real, one is wrong, and none of them mean less work between now and December 2027.

The new dates. Only two of them moved.
The new dates. Only two of them moved.

Four days ago, on 2 August, the EU AI Act's transparency obligations started applying. Nobody noticed, because for the previous three months the entire conversation had been about the deadline that moved instead of the one that didn't.

Here's where things actually stand. Regulation (EU) 2026/1744 — the Digital Omnibus on AI — was adopted by Parliament on 16 June, cleared the Council on 29 June, signed on 8 July, published in the Official Journal on 24 July, and entered into force on 27 July. It amends the AI Act directly, in all 27 member states, with no transposition step. The AI Act you read in the spring is a different document now.

The headline is the deferral. High-risk obligations for stand-alone Annex III systems — employment, education, credit, biometrics, law enforcement, critical infrastructure — move from 2 August 2026 to 2 December 2027. High-risk AI embedded in regulated products under Annex I moves from 2 August 2027 to 2 August 2028.

Then came the listicles. A tidy set of five organisational benefits has been circulating since June: shared responsibility for AI literacy, more flexible post-market monitoring, lighter documentation for smaller firms, an easier legal basis for using sensitive data to detect bias, and no more EU database registration for low-risk systems.

Four of those are real. One is wrong. And not one of them means less work.

Five claims, checked against the adopted text.
Five claims, checked against the adopted text.

Claim by claim

AI literacy is now shared. Real, but smaller than it sounds. Article 4 used to require providers and deployers to ensure a sufficient level of AI literacy among staff. It now requires them to take measures that support the development of that literacy, with the Commission and member states picking up a role in promoting it through guidance and practical examples. That is a genuine shift from an outcome obligation to a process one. It is also the change with the least enforcement consequence attached, because Article 4 never carried a standalone fine. What it changes is how much you have to document to show you tried. Worth noting: this one applied from 27 July with no deferral, which means that for roughly eighteen months organisations were held to a stricter standard than the one now in force.

Post-market monitoring got more flexible. The softest claim of the five. Article 72 was amended, and the proportionality logic is real: your monitoring system is meant to be proportionate to the technology and the risk, and where you already run monitoring under sectoral law you can integrate rather than duplicate, provided the protection is equivalent. What did not change is the substance. The monitoring plan is still part of your Annex IV technical documentation. The duty is still to actively and systematically collect, document and analyse performance data across the system's lifetime. Logs accumulating unread in a bucket never satisfied Article 72 and still don't. "More flexible" here means fewer prescribed forms, not fewer obligations.

Lighter documentation for SMEs and small mid-caps. The most concrete win in the package. The Omnibus writes a new category into the Act: the small mid-cap, defined as a firm that isn't an SME but employs fewer than 750 people with turnover up to €150 million or a balance sheet up to €129 million. Simplifications previously reserved for SMEs now reach them: a simplified technical documentation form that the Commission must establish and notified bodies are required to accept, quality management expectations proportionate to the size of the organisation, more proportionate penalty treatment, and priority access to regulatory sandboxes. If you sat just above the SME threshold, this is the provision that actually changes your cost base.

An easier legal basis for bias detection. Real, and narrower than the summaries suggest. A new Article 4a extends the ability to process special categories of personal data for detecting and correcting bias beyond providers of high-risk systems, to providers and deployers of all AI systems and models. But the Commission's proposal to lower the threshold from "strictly necessary" to merely "necessary" did not survive. After pushback from the EDPB and EDPS, the co-legislators put strict necessity back. The permission is exceptional, available only where bias detection cannot be achieved by other means including synthetic data, and it comes bundled with cumulative safeguards: pseudonymisation, access controls, limits on onward sharing, deletion when done. It also creates no obligation to perform bias detection at all. This is a narrow door, not an open one.

No EU database registration for low-risk systems. This one is wrong. The Commission did propose exactly that — dropping registration for systems providers self-assess as non-high-risk under Article 6(3). Both the Council and the Parliament rejected it. The final text keeps the registration obligation and simplifies the Annex VIII information required. You also still have to document your Article 6(3) assessment before placing the system on the market, and national competent authorities can ask to see it.

If you have written "no registration required" into a compliance plan on the strength of a summary, that is a finding waiting to happen. Registration got lighter. It did not go away.

What got harder

The simplification framing has crowded out the other half of the package.

A new Article 5 prohibition covers AI systems that generate child sexual abuse material or non-consensual intimate imagery. It applies from 2 December 2026, and products currently on the market have to be gone by then, not merely relabelled.

Article 50 transparency did not move at all. Telling people they are dealing with an AI system, labelling deepfakes, disclosing AI-generated text published on matters of public interest — all of that has applied since 2 August. The only concession is a grace period to 2 December 2026 for machine-readable marking of synthetic content by systems already on the market before that date.

The AI Office also came out of this with more, not less: expanded oversight over systems built on general-purpose models, including those embedded in very large platforms and search engines.

Why the deferral happened

It is worth being clear-eyed about the reason for the extra time, because it tells you what to do with it.

The high-risk obligations were postponed largely because the machinery needed to comply with them wasn't ready. The harmonised standards from CEN-CENELEC's JTC21 slipped well past their original target, and analyses through the spring suggested full readiness may not arrive before the end of 2026. The Commission's original design tied application to a decision on standards readiness; the co-legislators dropped that conditional trigger and set fixed dates instead. Certainty in exchange for a date.

So the deferral is an admission that the guidance was late, not a judgment that the requirements were excessive. The underlying obligations are unchanged: risk management, data governance, technical documentation, human oversight, accuracy and robustness, conformity assessment, post-market monitoring. All of it survived intact, with a later start date.

Sixteen months is less than it sounds

Here is the part that should shape your planning. Some of the evidence the AI Act asks for is longitudinal. A post-market monitoring plan is a document you can write in a fortnight; twelve months of monitoring data showing the plan was actually operating is not. Conformity assessment against standards that are still stabilising takes time you don't control. Classifying your systems and reconstructing training data lineage across teams that have changed twice since the model shipped takes longer than anyone budgets.

Work backwards from 2 December 2027 rather than forwards from today and the runway compresses fast. The organisations that will struggle are the ones treating the deferral as sixteen months of silence followed by a documentation sprint.

Sequencing the work backwards from the deadline, not forwards from today.
Sequencing the work backwards from the deadline, not forwards from today.

What to do with the time

Classify first. You cannot scope any of this until you know which of your systems land in Annex III, which are caught as safety components under Annex I, and which you are self-assessing as non-high-risk under Article 6(3) — and remember that last group still gets registered and still needs its assessment written down.

Check whether you are now a small mid-cap. The simplified documentation form and proportionate quality management expectations are worth real money, and the category is new enough that plenty of firms sitting between 250 and 750 employees haven't noticed they qualify.

Start post-market monitoring before you are obliged to. Not for the regulator — for yourself. If your first twelve months of evidence begin in December 2026, you arrive at the deadline with a track record instead of a template.

Treat the transparency obligations as live, because they are. That deadline passed on Sunday.

The pattern underneath

Every simplification in this package moves work rather than removing it. Literacy shifts from an outcome you guarantee to a process you evidence. Monitoring loses prescribed forms and keeps the duty to actually monitor. Registration gets fewer fields and stays mandatory. Bias detection gains a legal basis and arrives wrapped in conditions you have to demonstrate you met.

That is a fair description of AI governance generally. The obligations that survive contact with reality are the ones about what your systems are doing now, continuously, and whether you can show it. Deadlines move. Evidence requirements don't.

Which is the whole reason we built Tahara around continuous checks rather than annual attestations. If your compliance position is a document written in 2026 describing systems as they were in 2026, December 2027 will be an unpleasant conversation regardless of how much runway you thought you had.