TLDR: The European Union Digital Omnibus proposes a 16-month deferral of Annex III obligations under the European Union Artificial Intelligence Act, yet that proposal awaits Official Journal ratification; regulated-industry operators that paused compliance programmes in anticipation carry an active board-level governance gap that enforcement timelines alone leave open.
What the EU AI Act Already Enforces
The European Union Artificial Intelligence Act (EU AI Act), Regulation EU 2024/1689, entered force on 1 August 2024 with a tiered application schedule designed to give operators a phased runway for compliance. That runway began well over a year ago, and several of its stages are already operative law.
The first layer came into force on 2 February 2025: the prohibition of specific AI practices under Article 5, covering real-time biometric surveillance in public spaces, social scoring by public authorities, and subliminal manipulation techniques. These prohibitions apply across all operators active in the European Union (EU), and the EU AI Office, established as the Act’s supervisory body and operational since early 2024, has maintained active guidance on their scope.
A second, more technically demanding layer followed on 2 August 2025: the general-purpose artificial intelligence (GPAI) model rules under Title VIII, Articles 51 to 56. Providers of GPAI models exceeding defined compute thresholds became subject to systemic risk assessments, transparency documentation requirements, and incident reporting obligations to the EU AI Office, which subsequently published a General-Purpose AI Code of Practice to guide providers through these requirements.
A third layer applies from 2 August 2026: Article 50 transparency obligations require all AI systems interacting with humans to disclose the AI nature of the interaction, and providers of emotion-recognition and biometric categorisation systems must notify users of those functions. The Act has therefore generated operative compliance obligations across three successive tranches before the Annex III high-risk provisions reach their application date.
Annex III: Still Operative Law on 2 August 2026
Annex III of the EU AI Act designates eight categories of high-risk AI systems: AI in healthcare (medical devices and patient risk scoring), financial services (creditworthiness assessment and insurance underwriting), critical infrastructure, employment and workforce management, education and vocational training, law enforcement, migration and border control, and the administration of justice. Operators deploying AI systems in any of these categories are subject to the full conformity assessment framework under Title III, which requires a risk management system, data governance documentation, technical documentation, transparency disclosures, human oversight measures, accuracy and robustness standards, and, where applicable, registration in the EU’s public AI database.
The application date for these obligations is 2 August 2026, under the EU AI Act as published and operative. The conformity assessment process for a high-risk AI system is a multi-month, cross-functional exercise demanding documented risk classification, alignment with harmonised standards, technical assessments, and in some cases a third-party conformity assessment body review. Regulated industry operators carry the most material exposure: a hospital deploying an AI-assisted diagnostic tool, a bank using an AI creditworthiness model, an insurer relying on AI underwriting, or a logistics company operating AI-driven critical infrastructure management each falls within the Annex III perimeter. The breadth of this perimeter across financial services and healthcare encompasses the majority of large regulated operators active in the EU.
The Omnibus Deferral: A Legislative Proposal, Not a Legal Reprieve
In April 2025, the European Commission published the EU Digital Omnibus package, Commission document COM(2025)163, which proposes, among a range of digital-regulation simplifications, a deferral of Annex III high-risk AI obligations from 2 August 2026 to 2 December 2027: a 16-month extension.
The proposal reflects a genuine political signal. The Commission acknowledged administrative burden concerns from regulated industries and sought to harmonise the compliance calendar across the EU’s digital regulation architecture. Treating that signal as enacted law, however, confuses legislative intent with operative obligation.
As of July 2026, the Digital Omnibus awaits completion of the full EU legislative process: European Parliament review, Council of the European Union position, trilogue negotiation where applicable, and publication in the Official Journal of the European Union. Until the Official Journal carries the amending text, the 2 August 2026 Annex III deadline remains operative law. A compliance programme calibrated to a December 2027 deadline is, as a matter of EU law, a programme calibrated to an unratified proposal. Should the Omnibus process encounter amendment, delay, or partial rejection during trilogue, operators that depopulated their AI compliance programmes face the original deadline with documented programme gaps already visible to supervisors and auditors.
The risk profile is asymmetric. Operators that maintained preparation through the Omnibus legislative process retain full compliance standing regardless of the eventual outcome. Operators that paused preparation gain a reprieve if the Omnibus passes in its current form, but carry the governance cost of the pause in their documented audit trail either way.
Three Compliance Positions and Their Risk Profiles
Three positions characterise how regulated-industry operators have responded to the Omnibus proposal, with diverging risk profiles.
Position A: Full August 2026 readiness. The operator completes Annex III conformity assessments across all in-scope AI systems by the original deadline. The investment demand is the highest of the three positions, and the regulatory exposure is eliminated regardless of the Omnibus outcome. Operators in Position A are also best placed to satisfy board and investor requests for AI governance documentation, since their conformity evidence exists, has been independently audited, and reflects the original statutory timeline.
Position B: Phased approach with a documented, board-approved risk posture. The operator prioritises the highest-risk AI applications for August 2026 conformity and maintains a written, board-approved plan for remaining systems. This position demonstrates the proportionality principle in good faith; regulators assessing compliance posture give weight to structured, approved plans, even where full conformity is achieved across phases. For most regulated operators managing large AI system portfolios, Position B represents the minimum defensible posture and the floor below which board fiduciary obligations begin to apply.
Position C: Waiting for the Omnibus. The operator halts compliance work pending passage of the Digital Omnibus. This position generates an active governance gap in the compliance record. The operator’s AI risk posture awaits documentation, independent audit, and board-level approval during the precise period that Corporate Sustainability Reporting Directive (CSRD) obligations and investor Environmental, Social and Governance (ESG) due diligence already require such disclosure. The assessment from Kainjoo’s regulatory advisory practice is direct: Position C generates risk rather than managing it. The proposed deferral, paradoxically, widens the compliance gap for operators that treat an unratified Commission proposal as operative law, by demotivating the preparation that boards, auditors, and institutional investors already demand on the original timeline.
Why Board Accountability Operates on a Different Timeline Than Enforcement
The enforcement timeline of the EU AI Act and the accountability timeline of corporate governance operate on different cycles, and the second cycle already applies.
The Corporate Sustainability Reporting Directive (CSRD), Directive 2022/2464, already requires covered companies, including large regulated entities across healthcare and financial services, to disclose governance processes for material digital and technology-related risks. AI systems deployed in credit assessment, patient safety, and actuarial underwriting meet materiality thresholds for most covered companies. Auditors reviewing CSRD disclosures and institutional investors conducting ESG due diligence use these disclosures to evaluate AI governance maturity. A company disclosing that it deferred AI risk documentation pending a Commission proposal presents a governance signal that analysts and auditors can quantify in their assessments, independent of any enforcement action.
Early-mover practice among large regulated operators illustrates the board-level logic. Siemens published a Responsible AI framework and documented AI ethics governance structures spanning its healthcare technology, industrial automation, and energy infrastructure divisions, with stated alignment to EU AI Act risk classification requirements across each business area. Roche, whose AI systems in drug discovery, patient safety, and diagnostic support place it within the Annex III healthcare perimeter, has published an AI and Data Ethics framework that addresses the regulatory and ethical requirements applicable to AI systems across its operating markets. Both companies treated compliance mapping as a governance obligation independent of enforcement commencement, driven by board and investor demand for documented AI risk posture before the enforcement date arrived.
The board accountability dynamic follows a consistent logic. A board that approved an AI system deployment in creditworthiness assessment, patient risk scoring, or insurance underwriting carries fiduciary responsibility for that deployment’s regulatory profile. A documented conformity plan provides the board with evidence that governance processes were active and proportionate. A programme gap, accumulated during a period the operator characterised internally as a regulatory reprieve, leaves auditors and institutional shareholders reviewing a governance record with gaps spanning an active period of regulatory application.
The deferral trap is, at its core, a category error. The EU Digital Omnibus may pass, be amended, or face further delay in the legislative process. Whatever its eventual fate, the governance expectation from boards, auditors, and investors operates on the original calendar: the expectation that a material AI deployment carries a documented risk posture is already encoded in the CSRD reporting cycle and in the due diligence frameworks of institutional capital. Operators that substituted a Commission proposal for a compliance programme will find that any reprieve applies only to enforcement; the governance gap is already part of the record.
EU AI Act: Phased Implementation Schedule (as of July 2026)
| Provision | Scope | Status (July 2026) | Key Date |
|---|---|---|---|
| Prohibited AI Practices (Article 5) | All operators in the EU | IN FORCE | 2 February 2025 |
| GPAI Model Rules (Title VIII, Articles 51-56) | GPAI model providers | IN FORCE | 2 August 2025 |
| Article 50 Transparency Obligations | All AI systems interacting with humans | IN FORCE | 2 August 2026 |
| Annex III High-Risk AI Systems (Title III) | Healthcare, finance, critical infrastructure, employment, law enforcement | DEFERRAL PROPOSED (unratified) | 2 August 2026 (current law) / 2 December 2027 (proposed) |
References
- European Union Artificial Intelligence Act (Regulation EU 2024/1689): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689
- EU AI Office: https://digital-strategy.ec.europa.eu/en/policies/ai-office
- EU Digital Omnibus (COM(2025)163): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=COM:2025:163
- Siemens Responsible AI Framework: https://www.siemens.com/global/en/company/sustainability/responsible-ai.html
- Roche AI and Data Ethics Framework: https://www.roche.com/sustainability/society/innovation/artificial-intelligence
- Corporate Sustainability Reporting Directive (Directive 2022/2464): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022L2464
- EU AI Office, General-Purpose AI Code of Practice: https://digital-strategy.ec.europa.eu/en/policies/ai-act-codes-practice
This article presents regulatory and governance analysis for informational purposes; it does not constitute legal advice. Readers should consult qualified legal counsel regarding their specific compliance obligations under the EU AI Act and related regulations.



