- Instrument
- Digital Omnibus on AI (amending Regulation (EU) 2024/1689)
- Proposal
- 19 November 2025
- Political agreement
- 7 May 2026
- Parliament approval
- 16 June 2026 ✓
- Council adoption
- PENDING
- OJ publication
- PENDING
- Legal status
- PROVISIONAL, new dates not yet in force
- Binding today
- Original 2024/1689 dates, incl. 2 Aug 2026 for high-risk
When the European Parliament approved the Digital Omnibus on AI on 16 June 2026, the headline more or less wrote itself: the AI Act’s high-risk obligations, which were due to bite on 2 August 2026, will now apply only from 2 December 2027. Sixteen months of breathing room, and most readers stopped reading right there.
It is worth reading the reason instead, because the obligations did not move because Brussels lost its nerve. They moved because the technical standards that are supposed to make those obligations possible to meet simply are not finished, and the institutions decided they could not credibly enforce rules for which the compliance machinery does not yet exist.
The standards are not there.
The Act tells you what a high-risk system has to do. Article 9 requires a risk management system, Article 11 technical documentation, Article 12 record-keeping, Articles 14 and 15 human oversight, accuracy, robustness and cybersecurity. It does all of this at the level of principle. What it does not do, and was never meant to do, is tell you how to satisfy any of it in code.
The risk management system shall be understood as a continuous iterative process planned and run throughout the entire lifecycle of the high-risk AI system.
Regulation (EU) 2024/1689, Article 9That translation is the job of harmonised standards, and it matters more than most people building AI systems realise. A provider that builds to a harmonised standard cited in the Official Journal earns a presumption of conformity, which is to say that if you follow the standard, the law treats you as compliant unless proven otherwise. It is the cleanest and by far the most important compliance route in the entire regime.
The body responsible for drafting those standards, CEN-CENELEC’s Joint Technical Committee 21, was asked to deliver them by August 2025, and it did not. As of June 2026 the committee is still working through somewhere in the region of thirty-five separate deliverables, of which only around eight have been published, and most of those are adopted ISO/IEC documents rather than the home-grown European standards that actually carry the conformity mapping. Not a single AI Act harmonised standard has yet been cited in the Official Journal, and prEN 18286, the flagship standard covering quality management, is at the time of writing still out for a formal vote.
None of this is hidden. The Commission’s own guidance states plainly that the standards were not ready within the requested timeline, that the work remains ongoing, and that their delayed availability puts the August 2026 application of the high-risk rules in jeopardy. That is the regulator conceding, in its own words, that the instrument you need in order to obey the law has not been built. So the law waited for the tool.
What did not move.
This is where the relief narrative quietly turns into a liability, because while the Omnibus postponed the high-risk regime, it postponed almost nothing else.
Postponed
Still live
One deadline moved, for one part of the Act, for one reason.
As of 29 June 2026
The prohibited practices under Article 5 and the AI literacy duty under Article 4 have both applied since February 2025. The obligations on general-purpose AI models in Articles 51 to 55 have applied since August 2025. The transparency duties in Article 50, which cover disclosing to a person that they are dealing with a machine and marking AI-generated output, still apply from 2 August 2026, exactly as originally scheduled. The watermarking obligation for synthetic content was not pushed out to 2027 either: it lands on 2 December 2026, and with a shorter grace period than the Commission had first proposed.
So an organisation that reads “the AI Act has been postponed” and stands down is, in practice, standing down on obligations that go live in roughly five weeks. The risk-based architecture, the four tiers, the conformity-assessment regime and the AI Office’s oversight role have not shifted at all. One deadline moved, for one part of the Act, for one specific reason.
- Feb 2025Prohibitions + AI literacy
- Aug 2025GPAI obligations
- Today29 June 2026
- 2 Aug 2026Transparency (Art. 50)
- 2 Dec 2026Watermarking (Art. 50(2))
- 2 Aug 2027Sandboxes (new date)
- 2 Dec 2027Annex III high-risk
- 2 Aug 2028Annex I high-risk
A fixed date, not a moving one.
The Commission’s original draft was, in fairness, the cautious version. It proposed to tie the new deadline directly to the standards, so that the rules would apply six or twelve months after the Commission formally confirmed the standards were ready, with the 2027 date sitting behind that only as a backstop.
Parliament and Council rejected that approach and replaced the conditional trigger with hard calendar dates: 2 December 2027 for standalone high-risk systems, and 2 August 2028 for high-risk AI embedded in already-regulated products. It is worth being clear about what that swap actually does, because the consequence runs in the opposite direction to the relief most people took from it. The deadline no longer depends in any way on whether the standards arrive, so if CEN-CENELEC slips again, the date holds regardless, and the obligations apply in December 2027 whether the harmonised standards exist by then or not.
A conditional deadline is, in effect, a promise that you will not be asked to comply before the tools exist. A fixed deadline is the reverse. It commits you to comply on a date certain, and it quietly transfers the entire question of whether the tools exist by then from the regulator’s desk to yours. The standards gap, in other words, did not close. It simply moved onto your balance sheet.
Compliance you cannot buy.
There is a conclusion buried in all of this that most of the legal commentary steps carefully around.
When the harmonised standards are late, the clean route to a presumption of conformity is closed, because you cannot point to a published standard and say you followed it when there is no published standard to follow. What you are left with is the harder obligation of demonstrating conformity directly, showing with actual evidence that your system manages risk across its lifecycle, keeps complete and tamper-evident records, supports genuine human oversight and fails safely when something goes wrong.
That kind of evidence is not the sort of thing you can buy off a shelf, inherit from a certificate, or write once into a PDF and file away, because what the Act is really asking for is a risk management system that runs continuously, documentation that reflects the system as it actually is rather than as it was at sign-off, and logs that are both complete and resistant to tampering. Those are properties of a running system, not assertions in a document about one.
The article-by-article EU AI Act mapping, with evidence drawn from production, was published in April. Our April compliance declaration
This is the work we built Hivemind to do. Every mission produces a tamper-evident audit record, risk is assessed automatically at the end of each run with every finding mapped back to a specific article of the Act, and the technical documentation is generated from live production state rather than maintained by hand. We set the whole thing out, article by article and with the evidence drawn straight from the production system, in our April compliance declaration, and there is no need to repeat it here. The point of this piece is narrower than that mapping: the standards gap is not a reason to wait, it is precisely the reason the evidence now has to come from the system itself.
The runway is the opportunity.
Brussels delayed its hardest rules because the machinery needed to enforce them was not built in time, and that is not, as it is often read, a signal that the underlying requirement has gone soft. If anything it is a measure of how genuinely difficult that requirement is to meet, given that even the bodies whose entire job was to operationalise it could not deliver on schedule.
The companies that read December 2027 as permission to stop will, in all likelihood, arrive at that date in much the same state the standards bodies arrived at August 2025: late, and short. The eighteen months of runway are the opportunity, and the standards gap, properly understood, is the market.
The standards gap is the market.
A note on status. As of late June 2026 the Digital Omnibus on AI has been approved by the European Parliament but has not yet been formally adopted by the Council or published in the Official Journal. Until it is published, the original dates set out in Regulation (EU) 2024/1689 remain legally in force, including the 2 August 2026 date for standalone high-risk systems. The reading advanced here, that the standards gap is in effect a market signal, is ours, and not a position taken by the European Commission.