Ingolstadt: The most consequential date in European technology regulation this year was 2 August, and it passed without producing a single obligation. High-risk obligations under the AI Act were due to bite that day. They did not, because the digital omnibus entered into force on 27 July and moved them.
The new dates are 2 December 2027 for standalone high-risk systems listed in Annex III, and 2 August 2028 for artificial intelligence embedded in products already covered by Union product-safety law under Annex I. The second date is the one that matters to any factory floor or vehicle assembly line, because that is where embedded systems live. Providers of driver assistance, industrial inspection and medical device software gained two additional years without amending a line of their compliance plans.
The Commission’s stated reason was infrastructural rather than political. Harmonised standards from CEN and CENELEC, which give a high-risk system a presumption of conformity, were not finished. Neither was the conformity assessment capacity the Act assumes. A rule that cannot be complied with in the prescribed way is a rule that invites improvisation, and improvisation in conformity assessment produces uneven enforcement across 27 supervisory authorities.
Deferral is not repeal
The requirements themselves survived the omnibus intact. Risk management systems, data governance, technical documentation, logging, human oversight and accuracy obligations all still apply, and deployer duties still attach. Only the date moved. Firms treating the deferral as a reprieve are making a bet that the standards will arrive late enough to justify a second postponement, which is a bet on the same institutional failure repeating.
The omnibus was not purely deregulatory either. It inserted a prohibition into Article 5 covering artificial intelligence generated non-consensual intimate imagery and child sexual abuse material, and it carved out regulatory relief for small mid-cap companies while removing duplicated requirements for embedded systems already governed by sectoral law. A package sold as simplification therefore added one of the Act’s sharpest bans.
The cost of a moving target
The strategic damage is harder to quantify than the compliance saving. The Act’s original selling point to industry was predictability. A firm could price a three-year certification programme against a fixed statutory date. Moving that date once converts the date into a forecast, and forecasts get discounted. The rational response for a mid-sized provider is now to slow spending until the standards actually exist, which is precisely the behaviour that will leave the market unready again in 2027.
Smaller providers absorb this worse than large ones. A company with a standing regulatory affairs function can maintain readiness through a delay. A company of forty engineers cannot keep a compliance programme warm for two years, so it stops and restarts, and restarting costs more than continuing. The deferral was justified partly on the burden it lifted from smaller firms, and it may end up redistributing burden toward them.
What to watch is narrow. Whether CEN and CENELEC publish usable harmonised standards with enough margin before December 2027, and whether notified body capacity expands to match. If either lags again, the argument for a third date will be identical to the argument for the second, and the case for treating the deadline as real will be weaker still. The amending package is tracked in Parliament’s legislative train schedule, and the Council recorded its final approval in a June press release.





