Insights on Intelligent Deep Storage, AI-Ready Data & Cloud Innovation | CAEVES Blog

The AI Act Delay Is Not a Pause: How to Use the Extra Time

Written by Jaap van Duijvenbode | Aug 6, 2026, 9:00:00 AM

By Jaap van Duijvenbode

Co-Founder and VP Product Strategy & Customer Experience

Summary: The EU Digital Omnibus on AI moved high-risk obligations under the AI Act to December 2027 for stand-alone systems and August 2028 for AI embedded in regulated products.
Transparency duties still applied from August 2nd, 2026, but the delay does not reduce the preparation required. Understanding and governing the data AI systems rely on takes time - making the extra months an opportunity to build the right data and governance foundations.

What actually changed

Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on July 27, 2026, days before the original 2 August 2026 deadline for high-risk AI systems. The headline change is a delay: obligations for stand-alone high-risk systems listed in Annex III, such as AI used in employment decisions, now apply from December 2nd, 2027. Systems embedded in products covered by sector legislation follow on August 2nd, 2028.

What did not change is just as important. The Article 50 transparency obligations, which require disclosure when people interact with an AI system and labeling of AI-generated content, applied on schedule from August 2026. Watermarking duties for systems already on the market follow on December 2nd, 2026, alongside new prohibited practices. Obligations for general-purpose AI models have applied since August 2025.

Why "delayed" does not mean "later"

The delay was tied to the availability of harmonized standards and national supervisory structures, not to a view that organizations need less preparation. A significant part of preparing for high-risk compliance depends on understanding and governing the data AI systems rely on - and that work takes time:

  • Inventory: which AI systems are in use, including assistants and agents embedded in everyday software.
  • Data lineage: which data trains, grounds or feeds each system, and where that data lives.
  • Access and governance: who can reach that data, and whether the AI system inherits permissions it should not have.
  • Record keeping: whether you can show an auditor what a system was asked, what it retrieved and what it returned.

Building the inventory may be the most straightforward task. The other three become considerably more challenging for unstructured content: the contracts, reports, emails and archives that assistants increasingly draw on.

Using the extra 16 months well

Treat the delay as a chance to build a durable governance foundation rather than a last-minute compliance project. Three steps pay off whatever the final standards look like:

  1. Map AI systems to their data sources. For each assistant or agent, document which repositories it can reach and on whose behalf.
  2. Close the permission gap. AI systems should see only what the requesting user could already open. Test that assumption before an auditor does.
  3. Make answers traceable. Require that AI outputs cite their sources and that queries are logged. This supports transparency duties today and high-risk documentation later.

This work is also reusable. Inventories, lineage and access controls serve GDPR, NIS2 and internal risk programs as much as the AI Act.

The bottom line

The Omnibus moved a date, not the destination. The organizations that will meet December 2027 comfortably are the ones that start on their data foundations in 2026.

Want to assess your AI data inventory and lineage readiness? Talk to our specialists.

Sources