On 29 June 2026 the Council of the EU gave its final sign-off to the AI Act “simplification” package — the so-called Digital Omnibus — following the European Parliament’s endorsement on 16 June and the political agreement reached back on 7 May. The act now heads to the Official Journal and enters into force shortly after publication.

The headlines wrote themselves: the AI Act has been delayed. And in a narrow sense, they are right. But “delay” is the most dangerous word in compliance, because of what founders and boards hear when they read it: we can stop.

They cannot. Here is the version that actually matters when you are the one accountable for it.

What genuinely moved

The deferrals are real, and they are meaningful:

  • High-risk systems under Annex III — the classic “AI that scores, ranks, screens, or decides about people” category — move from 2 August 2026 to 2 December 2027. That is roughly sixteen months of additional runway.
  • High-risk AI embedded in regulated products (medical devices, machinery, and the rest of the New Legislative Framework) gets a twelve-month deferral, to 2 August 2028.
  • The obligation on Member States to stand up at least one regulatory sandbox slips from August 2026 to 2 August 2027.
  • The package also widens SME and small mid-cap flexibilities — reduced documentation burdens and proportionate expectations for smaller operators. If you are a scale-up, you should confirm whether you qualify, because it changes what “good enough” looks like for your technical file.

If your product sits squarely in one of those buckets, you have been handed time. The question is what you do with it.

What did not move an inch

This is the part the headlines skip, and it is the part that ends up in incident reports.

  • Prohibited practices have been enforceable since 2 February 2025. Social scoring, certain biometric categorisation, manipulative systems — those bans are live now, not in 2027.
  • General-purpose AI model obligations have applied since 2 August 2025, and the GPAI Code of Practice is in place. If you fine-tune or materially modify a third-party model, you may be a provider of a GPAI model in your own right — with obligations you inherited without noticing.
  • The Article 50 transparency obligations still apply from 2 August 2026. Deepfake labelling, disclosure that a user is interacting with an AI system, and marking of AI-generated content were not deferred. If you ship a chatbot, generate media, or publish AI-assisted text to the public, your clock still runs out this August.

The deadline that made the news is the one that moved. The three that will actually catch you out are the ones that did not.

The trap we are already watching teams walk into

The predictable failure mode is a board that reads “December 2027,” reallocates the compliance budget, and disbands the working group. Eighteen months later, the same company discovers three things at once: it never finished classifying its systems, it quietly became a GPAI provider through a fine-tune, and its August 2026 transparency obligations lapsed without anyone owning them.

None of that is a documentation problem. It is a sequencing problem — and sequencing is exactly what a deferral tempts you to get wrong.

What to actually do this quarter

This is the shortlist we are running with clients right now:

  1. Finish the classification, regardless of the new dates. You cannot manage an obligation you have not scoped. Map every system to a risk tier — prohibited, high-risk, limited, minimal — and write down why. That work is unchanged by the Omnibus and it is the foundation for everything else.
  2. Resolve your GPAI status. For every third-party model you build on, determine whether your modifications make you a provider. This is the single most common surprise in AI governance right now.
  3. Ship the August 2026 transparency work. Treat Article 50 as the live deadline it is: disclosure, labelling, and machine-readable marking, designed in — not bolted on after launch.
  4. Convert runway into quality, not silence. The extra sixteen months are a chance to build controls once and build them properly — a single integrated control set that also earns you ISO 42001 and feeds your ISO 27001 evidence — rather than a licence to defer the whole programme and cram it in 2027.

The deadline moved. The work did not. The companies that understand the difference will spend the next eighteen months getting ahead; the ones that heard “delay” will spend them exactly where they are — and then panic.

Working out where your systems land, or whether a fine-tune made you a GPAI provider? That is a 30-minute scoping conversation, not a research project.