
The question came in a customer’s executive team meeting, almost as an aside. They had read in the news that the AI Act was being delayed. Did that mean the work could now move to 2027? The relief in the room was understandable. Budgets are tight, autumn agendas are full, and here was Brussels apparently granting permission to breathe. But the honest answer was no. What moved to 2027 is not what the organisation needed to do. It is a fraction of it.
The more revealing part of the conversation came a few minutes later. The same headline had created another impression: that even basic AI literacy obligations were still somewhere in the future. They were not. Those duties had already been in force for about a year. That gap between the law, the headlines and what decision-makers believed is the real subject of this piece. The Digital Omnibus is being read in boardrooms as a pause. Read closely, it is nearly the opposite: a fixed construction window. The question it puts in front of an executive team is not what you may now delay. It is what you should now build.
What moved, and what did not
The useful way to read the Omnibus is simple: only one category of obligations was deferred. The full obligations for high-risk AI systems moved back. For stand-alone high-risk systems, such as recruitment, credit scoring and critical infrastructure, the new date is December 2027. For high-risk AI embedded in regulated products, such as medical devices and machinery, the date is August 2028. These are important changes, but they are narrower than many headlines suggested.
What did not move matters even more for most organisations. The duties that touch AI already in everyday use — assistants, chatbots, generated content and general-purpose models — remain in force. Users must be told when they interact with AI. Synthetic content and deepfakes must be labelled or disclosed. General-purpose AI obligations are already live. AI literacy measures have also applied since early 2025. The wording was softened, but the duty was not removed.
That is the point most leadership teams need to see. The obligations that moved are mainly about high-risk systems many organisations have not yet deployed at scale. The obligations that did not move are about the AI many organisations are already using. Nothing was cancelled. A few dates moved.
Sixteen months of predictability
There is a more useful way for executives to read the deferral: the EU has handed you roughly sixteen months of predictability, which is the commodity transformation programmes most conspicuously lack. A conditional deadline cannot be planned against; a fixed one can. You now know, with unusual certainty for this field, what will be required of high-risk systems and exactly when.
The less comfortable reading arrives when you examine what the deferred obligations consist of. Risk management. Data governance. Technical documentation. Logging. Human oversight assigned to named people with the competence, training and authority to exercise it. Monitoring in operation. Strip out the legal grammar and read that list as a chief operating officer rather than a lawyer: it is a specification for an organisation that knows what its AI does, on what data, under whose oversight, and how it improves. That is not compliance paperwork with a deadline attached. It is the missing operating model behind most stalled AI programmes.
This is why I keep telling leadership teams that the deferral is build time rather than breathing room. The research on why AI programmes fail points, again and again, not at the technology but at the organisation’s ability to learn: to retain feedback, adapt to context and improve over time. The capabilities the AI Act will eventually demand of high-risk systems are the same capabilities that separate the organisations capturing value from the ones stacking pilots. Classification forces portfolio clarity. Documentation forces you to make the implicit explicit. Logging and monitoring force feedback loops into existence. Build them for the regulator and you will find the business needed them anyway.
Governance you can show a customer
There is a commercial edge here too, and it matures faster than the deadlines. Procurement teams and boards have started asking suppliers to show how they govern their AI. Reassurance is no longer enough. They want proof.
That proof can take many forms, from a classified use-case portfolio and documented oversight to clear ownership and, increasingly, a recognised AI management system such as ISO/IEC 42001. A certificate is persuasive precisely because it is inconvenient. It cannot be bought, only earned. The sixteen months in which your competitors are exhaling is time in which that proof can be built.
The fair question: why build now?
The fair objection is about scarce attention. Budgets are under pressure; why spend this year’s energy on a deadline sixteen months out?
Three answers. First, your organisation’s first AI Act deadline was not deferred. It has already passed. The literacy duty has applied since early 2025, and the transparency obligations arrived this August. If your customer-facing chatbot does not disclose itself, or your marketing team publishes synthetic content unlabelled, you are not early for 2027; you are late for 2026. The build has to start from the duties already live, and they concern the systems you already run.
Second, governance debt compounds. Retrofitting classification, documentation and data governance across dozens of embedded use cases in late 2027 will cost a multiple of building the discipline now, while adoption is still scaling and each new use case can be born documented rather than excavated later.
Third, the Omnibus deferred your obligations. It did not defer your competitors’ progress. The window is the same length for everyone; the only variable is what it contains.
Start here, this quarter
1. Classify the portfolio. Map where AI is used in the organisation, including recurring uses of general-purpose tools. Pay particular attention to ordinary tools used in sensitive contexts such as recruitment, credit, employee evaluation, safety or access to services. The risk is not only in dedicated AI systems; it is also in what people are allowed to do with general-purpose tools.
2. Close the gaps that never moved. Transparency disclosures, labelling of synthetic content, literacy measures — verify them and document them. These are this year’s obligations, and they are also the quickest credibility you can build with your regulator, your board and your customers.
3. Build documentation as operating intelligence, not filing. The records the law will demand of high-risk systems are the ones a well-run operating model wants anyway: what runs, on what data, under whose oversight, improving how fast. Build them once, for both purposes.
4. Make the governance visible. Whether through ISO/IEC 42001 or a lighter equivalent, turn the internal discipline into external proof. The buyers asking to see it are not waiting for 2027 either.
The deadline was never the point
Organisations that read July’s regulation as a pause will spend 2027 discovering what it actually was: a countdown with the excuses removed. The dates are now fixed, and the requirements are known. More importantly, the capabilities they demand are the same ones AI value has been waiting on all along: clarity about what runs, discipline about data, oversight with real authority, and feedback that improves the next iteration.
Regulation tells you when. Your operating model decides whether. The question in front of your leadership team this autumn is not what you are allowed to delay. It is what you choose to build now — and sixteen months, spent building, is a long time.
About the author

For nearly three decades, Lenni Laukkanen has helped organisations develop and grow through technology. He argues that AI is not a technology question but a leadership one: it rarely fails as a tool — it exposes ways of operating built for a world that no longer exists. As founder of Astu Labs, trusted advisor to executive teams and keynote speaker, he helps leaders navigate the organisational changes required to capture value from AI. A runner, cyclist and adventurer, he holds that organisations, like athletes, change one deliberate step at a time. More at lennilaukkanen.fi.
*The views and opinions expressed by the author do not necessarily state or reflect the views or positions of Hyperight.com or any entities they represent.