Skip to content

Governance Debt: Brussels Moved the Deadline. It Did Not Move the Work.

Blog  ✺  AI  ✺  Governance  ✺  Strategy

In May, Brussels did something rare. It gave everyone more time. The EU AI Act's high-risk obligations, due this August, moved to December 2027. Across the continent, compliance programs exhaled. Some of them then quietly stopped. That second part is the expensive part.

The deferral was agreed on 6 May 2026 in the negotiations over the Digital Omnibus, Brussels' package for simplifying its own digital rulebook, and confirmed by Member States a week later. It is being read, widely, as relief. It is better read as a loan, because the obligations did not shrink by a single article. Only the due date moved. And debt that is deferred, in engineering as in finance, accrues interest.

TLDR: The Digital Omnibus agreement postpones the EU AI Act's obligations for stand-alone high-risk systems, the Act's list covering credit scoring, recruitment screening and the like, from 2 August 2026 to 2 December 2027, and for high-risk AI built into regulated products such as medical devices and machinery to 2 August 2028. Everything else stands: the prohibitions in force since February 2025, the general-purpose AI obligations in force since August 2025, and the Article 50 transparency rules, which still apply from 2 August 2026. Penalties for high-risk breaches remain at up to €15 million or 3% of worldwide turnover. The requirements did not change. Only the date did. For the roughly 75% of organizations with no fully implemented AI governance program, the sixteen extra months are not breathing room. They are the cheapest months of compliance work they will ever be offered.

What moved, and what did not

The mechanics first, because the headline hides the fine print.

Two dates moved. Stand-alone high-risk AI systems, the category the Act lists in its Annex III and which covers credit scoring, recruitment screening, exam evaluation and similar uses, now have until 2 December 2027. High-risk AI built into regulated products such as medical devices and machinery, listed in Annex I, has until 2 August 2028. The Commission's original idea of tying the start date to the availability of technical standards was dropped in favor of fixed dates.

Everything else on the calendar stayed. The prohibited practices, from social scoring to untargeted facial recognition scraping, have applied since February 2025. The general-purpose AI obligations on transparency, documentation, and copyright have applied since August 2025. The Article 50 transparency duties, disclosing chatbots as chatbots and labeling AI-generated content, still take effect on 2 August 2026, with only a four-month grace period for watermarking on systems already deployed. The Omnibus even added obligations, banning AI-generated non-consensual intimate imagery outright and giving the EU AI Office real investigation and inspection powers.

So the deferral is narrower than the celebration. What moved is precisely the hardest part: the conformity assessments, best understood as CE marking for AI, plus the risk management systems and the data governance documentation for high-risk uses. The part that takes longest is the part that just became easiest to postpone internally.

Why the deadline moved

The official reason is genuinely sound. Member states missed their own August 2025 deadlines for establishing national enforcement authorities, and without those structures, the certification bodies that are supposed to check compliance cannot even be accredited. Harmonized standards were late. A deadline that arrives before the infrastructure to meet it is not regulation. It is theater.

The unofficial context is louder. The delay followed sustained pressure from large technology firms and came wrapped in a broader deregulatory package. Industry association CCIA welcomed it and asked for more. Consumer organization BEUC called it deregulation "almost to the exclusive benefit of Big Tech," and Finance Watch warned that consumers will pay the price for a "deregulate to accelerate" strategy.

Both readings can be true at once, and for practitioners the argument is largely beside the point. Arba Kokalari, one of the European Parliament's lead negotiators on the file, described the agreement as "pressing the pause button on the AI Act." I have written before about the value of pause buttons in AI strategy, and this is a good moment to be precise about what one does. A pause stops the clock. It does not do any of the work. Every requirement a high-risk provider or deployer faced on 5 May, they still face. In December 2027 the same conformity assessments come due, for AI estates that will by then be eighteen months larger and more entangled.

The debt mechanics

Here is why deferral behaves like debt rather than relief.

The foundational work of AI Act compliance has long lead times and compounds badly. An inventory of AI systems cannot be reconstructed retroactively; systems ship every quarter, and each undocumented one is a future archaeology project. Risk classification decisions need the reasoning written down while the people who made them are still employed. Data governance for training data has to exist before the training run, not after. None of this parallelizes well under deadline pressure, which is exactly how most organizations will attempt it.

And most organizations are starting from nothing. A January 2026 study of 365 senior leaders found 75% without a fully implemented AI governance program and 62% without even an inventory of the AI applications in use. I took that study apart in The Confidence Gap, and its relevance here is direct: an organization that does not know what it runs cannot classify what it runs. The first six months of any serious compliance effort are spent discovering the estate, and that clock has not started at most firms.

The interest on the loan arrives in three forms. First, the scramble premium: when thousands of firms hit the same December 2027 deadline together, the consultants, auditors, and certification bodies they all need simultaneously will price accordingly. GDPR ran this exact experiment. Second, rework: systems built between now and 2027 without classification in mind will need retrofitting, and retrofitting governance into a deployed system costs a multiple of designing it in. Third, exposure: the transparency obligations landing this August still carry teeth, and an organization that filed the whole AI Act under "2027 problem" will discover the misfiling at an awkward moment.

an empty runway with mountains in the background
Photo by Jonathan Letniak / Unsplash

What the sixteen months are for

The organizations that come out of this ahead will treat the deferral as scheduling freedom, not as absolution. The work is unglamorous and none of it requires waiting for final standards.

Build the inventory now, while it is small enough to build. Assign every system an owner and a provisional risk classification, and write down why. Practice the impact assessments on one real high-risk candidate to learn where your documentation actually lives. Wire the AI registry into procurement so new systems enter classified instead of being excavated later. This is the same ownership-and-inventory work that effective AI governance required before any regulator asked for it. The AI Act did not invent the need. It priced the neglect.

A note for Swiss readers, because the deferral is being misread here too. Switzerland has chosen a different path: no horizontal AI act, but implementation of the Council of Europe's AI Framework Convention, signed in March 2025, through sector-specific amendments and the revised data protection law. Proportionate at home. But the AI Act applies to anyone placing AI systems on the EU market or whose outputs are used there, and for a Swiss bank, insurer, or manufacturer serving EU customers, Brussels' timeline is the binding one regardless of Bern's restraint. The Swiss approach lowers the domestic floor. It does not lower the export ceiling.

There is also a quieter competitive angle. Sixteen months is long enough to make compliance a capability rather than a cost. The firms that can classify, document, and assess AI systems routinely will ship high-risk use cases, the valuable ones, in credit, hiring, and underwriting, while competitors are still queuing at their first certification body.

The GDPR rerun

We have run this experiment before, at continental scale, with the same actors. GDPR was adopted in 2016 with a two-year runway. The runway was spent, by most firms, not preparing. The final six months before May 2018 produced a consulting gold rush, template privacy policies of dubious fit, and compliance programs assembled in a quarter that then took five years to make real. The firms that used the runway instead of watching it are, for the most part, the ones whose data operations became an asset rather than a permanent remediation project.

The AI Act's deferral has just extended the runway. It has not changed what happens at the end of it. Deadlines are the one part of a regulation that can move. The work never does.

Governance debt compounds like the technical kind. The deadline is just the day the debt is collected.

Mehr

The Platform Trap: Everyone Is Building an AI Platform. Almost Nobody Is Building One People Want to Use.

The Confidence Gap: 92% of Executives Are Certain AI Is Working. Half of Them Don't Know Who Is Using It.