Executive AI governance dashboard showing AI inventory, transparency decisions, supplier evidence and cyber resilience controls on a compliance timeline.

Insights

The AI Act Deadline Moved, But The Governance Work Did Not

Niall Carney

The AI governance clock changed today.

On 27 July 2026, the European Commission confirmed that the AI Omnibus has entered into force across the EU. The headline is attractive: the application of many high-risk AI obligations has been pushed back, with new timelines for Annex III systems and AI embedded in physical products.

Some organisations will read that as a pause button.

That would be a mistake.

The delay changes the compliance calendar. It does not remove the operational risk. It does not remove the need to know where AI is being used, who owns it, what data it touches, which suppliers are involved, how people are informed, what evidence is kept and how the organisation would respond if an AI-enabled process fails under pressure.

For leaders, the practical message is simple: the deadline moved, but the governance work did not.

Why this matters now

The AI Omnibus entered into force today, 27 July 2026. The Commission says it is intended to simplify implementation, support innovation, extend timelines, expand access to regulatory sandboxes and give companies clearer legal and procedural footing.

The most visible change is the high-risk timetable. The Commission now says rules for Annex III high-risk AI systems, including areas such as biometrics, critical infrastructure, education, employment, migration, asylum and border control, apply from 2 December 2027. For AI embedded in physical products such as machinery, toys and lifts, the date moves to 2 August 2028.

The Official Journal text gives the reason. Delayed standards, common specifications, alternative guidance and national authority readiness created implementation challenges. The extra time is meant to make compliance more workable and reduce avoidable cost.

But not everything moved.

The Commission published Article 50 transparency guidance on 20 July, and those transparency obligations still start from 2 August 2026. The FAQ is clear that providers of direct-interaction AI systems, such as chatbots, AI agents and avatars, need people to be informed when they are interacting with AI unless that is obvious. Providers of generative AI systems must address machine-readable marking and detectability. Deployers must inform people about emotion recognition and biometric categorisation, and must clearly label certain deepfakes and AI-generated or manipulated text published for public-interest purposes without human review or editorial control.

There is a limited transition for systems already on the market before 2 August 2026 in relation to Article 50(2) marking and detection, with a new date of 2 December 2026. That is useful breathing room. It is not a reason to leave AI use unmanaged.

The regulatory message is now more nuanced. Some high-risk duties have more runway. Some transparency duties are imminent. The governance burden shifts from panic compliance to disciplined preparation.

The real risk is unowned AI use

Most organisations do not fail at AI governance because they lack a policy document.

They fail because AI use spreads faster than ownership.

A customer team trials an AI assistant. A marketing team uses generative tools for public content. HR tests a screening workflow. A service desk switches on a chatbot feature in an existing platform. A cyber team experiments with AI-assisted triage. A supplier quietly adds AI into a workflow that already affects customers, employees or operational decisions.

None of those examples is necessarily wrong. The risk is that they become invisible.

If leaders cannot see the AI estate, they cannot classify it. If they cannot classify it, they cannot decide which obligations apply. If they cannot identify providers, deployers, data flows, human controls, user disclosures and supplier dependencies, they cannot create credible evidence. And if they cannot create evidence, they are left relying on intention rather than assurance.

That is why the extended high-risk timetable should be used to build a practical AI register now. Not a theoretical spreadsheet that sits outside delivery. A live management record that connects AI systems to business services, user groups, data types, suppliers, contractual terms, decision impact, transparency requirements, monitoring, incident routes and accountable owners.

The organisations that benefit most from the delay will not be the ones that wait longest. They will be the ones that use the extra time to remove ambiguity.

Transparency is an operating control

Article 50 is sometimes treated as a labelling exercise.

That is too narrow.

Transparency affects product design, customer communications, content workflows, procurement, user experience, accessibility, brand trust, incident response and evidence management. It asks a basic question: does the person affected by the AI system understand enough about what is happening to calibrate their trust?

For direct interaction systems, that means knowing whether users are dealing with AI. For generated or manipulated content, it means thinking about marking, detectability and downstream use. For deepfakes and certain public-interest text, it means a visible disclosure unless a valid human review or editorial control route applies. For biometric categorisation and emotion recognition, it means informing people who are exposed to the system.

The FAQ also makes the provider and deployer split commercially important. A provider places or puts an AI system into service under its name or trademark. A deployer uses an AI system under its authority. A legal person can remain the deployer even when contractors or freelancers operate the system on its behalf. Providers outside the EU can still be caught where output is used in the EU.

This is why transparency cannot be left to the last screen in a product journey or the last paragraph in a policy. It needs design decisions, supplier commitments, content-production rules, approval routes and records that prove what happened.

For many businesses, the near-term priority is not writing a grand AI governance manual. It is making sure every live AI use case has a named owner, a transparency decision, a user-facing wording choice, a human review route where needed, and evidence that can be produced later.

The AI Act Deadline Moved, But The Governance Work Did Not: editorial image for Transparency is an operating control

High-risk delay buys design time

The high-risk delay matters. It gives organisations more time to prepare for demanding requirements around risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy, robustness and post-market monitoring.

But the new dates are not distant in operating-model terms.

Classifying AI systems takes time because classification depends on intended purpose, business context and the actual use case. An AI tool used for general productivity may not create the same obligations as a system used to screen job applicants, assess access to education, support critical infrastructure decisions or influence access to essential services.

The hard work sits in the detail. What is the system intended to do? Who is affected? Is it merely assistive, or does it materially shape a decision? Does a human genuinely review the output, or simply rubber-stamp it? Which data is used? How is performance monitored? What can the supplier evidence? What changes would count as significant? Who can stop or roll back the system?

Those questions are easier to answer before a system is embedded into a process, a contract, a customer journey or a staff workflow.

The delay should therefore become a governance design window. It should be used to map the estate, prioritise the riskiest use cases, align procurement, update templates, define evidence requirements and agree the decision rights for approving AI use.

AI governance now overlaps cyber resilience

AI governance is not only a legal and ethics topic. It is increasingly a cyber resilience topic.

The EU Action Plan on Cybersecurity and Artificial Intelligence, published earlier this month, makes the dual-use point clearly. AI can help detect vulnerabilities, prevent cyber attacks and strengthen critical infrastructure protection. It can also be used by malicious actors to automate attacks, identify weaknesses and conduct cyber operations at greater speed and scale.

The NCSC and its Five Eyes partners made the same leadership point in June. They warned that AI is accelerating the speed, scale and sophistication of cyber threats, and told leaders to reduce attack surface, accelerate patching, address legacy systems, strengthen identity and access controls and prepare for incidents before they happen.

Recent threat evidence reinforces the problem. Rapid7 reported that vulnerability exploitation accounted for 38% of incident response cases in Q1 2026, overtaking social engineering, and that half of actively exploited vulnerabilities in the wild were zero-click, network-facing issues. The NCSC also warned on 23 July that the Laundry Bear campaign against Zimbra used a view-based zero-click exploit, and that AI played a role in the development of a simple codebase for the operation.

The governance implication is direct. AI systems need secure access design, data controls, logging, monitoring, change control, supplier accountability and incident response routes. AI used inside security operations also needs assurance. A tool that helps prioritise vulnerabilities, summarise alerts or automate response can improve resilience, but it can also create new failure modes if it is deployed without boundaries.

The board question should therefore be broader than compliance. Can the organisation use AI at speed without losing control of access, evidence, data, accountability and recovery?

The AI Act Deadline Moved, But The Governance Work Did Not: editorial image for AI governance now overlaps cyber resilience

Supplier management becomes decisive

Most organisations will not build every AI system they use.

They will buy AI-enabled SaaS products, switch on embedded features, commission bespoke tools, use general-purpose models through enterprise platforms and rely on suppliers who may themselves be using AI inside managed services.

That makes supplier management central to AI governance.

Contracts and assurance processes need to answer practical questions. Is the supplier a provider, a deployer, or both? Where is the model hosted? What data is processed, retained or used for improvement? How are outputs marked? What records exist for prompts, outputs, human review and changes? What happens if the model behaviour changes? How are incidents reported? Can the customer suspend a feature quickly? What evidence is available for audit, regulator engagement or internal assurance?

The Article 50 provider/deployer definitions make those questions more than procurement hygiene. They shape accountability. The AI Omnibus may simplify some administrative burdens, but it does not remove the need to know which party is responsible for which control.

For leaders, the safe assumption is that every important AI supplier needs a control appendix, not just a data-processing clause.

The board-level AI governance test

Boards do not need to review every prompt or technical parameter. They do need evidence that AI is governed as part of business resilience and accountable growth.

There are seven practical tests.

First, can the organisation identify every material AI use case, including embedded AI in existing platforms and supplier-operated workflows?

Second, has each use case been classified by intended purpose, affected user group, data type, decision impact and regulatory relevance?

Third, is there a named business owner who can approve, pause, change or retire the AI system?

Fourth, have transparency obligations been assessed and translated into clear user communications, content labels, review routes and records?

Fifth, does procurement require AI suppliers to provide evidence on data use, model changes, security, monitoring, incident reporting, marking, audit support and exit arrangements?

Sixth, are cyber controls aligned to AI use, including identity, access, logging, monitoring, secure configuration and incident response?

Seventh, can leaders produce a defensible evidence pack showing how AI risks are identified, controlled, monitored and improved?

If the answer is unclear, the organisation may have AI ambition, but it does not yet have AI governance.

The AI Act Deadline Moved, But The Governance Work Did Not: editorial image for The board-level AI governance test

The Antares perspective

Antares sees the AI Omnibus as a useful reset, not a reason to slow down.

The immediate opportunity is to move AI governance out of policy language and into the operating model. That means a usable AI register, clear ownership, risk-tiered approvals, supplier evidence, transparency decisions, human review rules, security controls, incident routes and board reporting that leaders can actually use.

The best AI governance will be proportionate. It will not treat a low-risk productivity assistant in the same way as an employment-screening workflow or a customer-facing agent. But proportionate does not mean informal. It means the level of control matches the level of impact, and the evidence is good enough to stand up later.

The delay in some high-risk dates gives organisations time to do this properly. The imminent Article 50 transparency deadline gives them a reason to start now.

A delayed deadline is not a delayed risk. It is an opportunity to build AI governance before unmanaged AI becomes a business dependency.

A delayed deadline is not a delayed risk.

Antares recommended actions

These are Antares's recommended first actions for organisations turning the issues in this article into practical governance and delivery.

  1. Create a live AI inventory covering purchased tools, embedded platform features, internal builds, pilots, supplier-operated workflows and generative AI content processes.
  2. Classify AI use cases by intended purpose, affected users, data type, decision impact, regulatory relevance, supplier dependency and business criticality.
  3. Identify Article 50 transparency obligations for direct-interaction systems, generated or manipulated content, deepfakes, public-interest text, emotion recognition and biometric categorisation.
  4. Assign a named business owner for every material AI system, with authority to approve, pause, change or retire the use case.
  5. Define human review and editorial control standards for AI-generated public-interest content, including who reviews, what they check and what evidence is kept.
  6. Update supplier assurance so AI vendors evidence data handling, output marking, model changes, security controls, monitoring, audit support, incident reporting and exit arrangements.
  7. Prioritise high-impact or potentially high-risk use cases now, using the extended timetable to design controls before systems become embedded in operations.
  8. Align AI governance with cyber resilience by reviewing identity, access, logging, monitoring, secure configuration, vulnerability management and incident routes for AI-enabled workflows.
  9. Create an AI evidence pack for board and regulator use, including inventory, classifications, decisions, reviews, supplier records, transparency choices and incident rehearsals.
  10. Report progress in business terms, showing where AI is used, which risks have been reduced, which obligations are imminent and which decisions still need leadership action.

If you'd like to discuss your own transformation, we'd be pleased to start the conversation.