Blog

EU AI Act: why postponement is not a postponement of homework

The political agreement on the Digital Omnibus delays the EU AI Act's high-risk rules, but transparency and classification already require action now.

· Victor Angelier

The EU AI Act is no longer an abstract future law for organisations. With the provisional political agreement on the Digital Omnibus, the direction is clear: the intention is that the heaviest obligations for high-risk AI systems will take effect later. That agreement is not yet a formally applicable amending law; according to the cited analyses, legal-linguistic revision, formal approval and publication have yet to follow. Until then, the existing AI Act remains authoritative. Meanwhile, the transparency rules and the official classification guidelines are becoming concrete in 2026. In our assessment, the combination creates a curious situation: some deadlines are shifting, but the work that organisations must do now remains largely the same.

The law firms Gibson Dunn and Orrick describe the Omnibus arrangements and outline exactly what is shifting. According to the cited analyses, the political agreement provides for 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for embedded Annex I systems. Formal entry into force is still to follow. In our analysis, however, postponement is not exemption: the extra time is intended to actually get registration, quality management, logging and traceability in order.

Three steps that are already relevant now

The official AI Act page of the European Commission brings together the text of the law, the four risk categories and, in the updated explanation, the timeline associated with the Omnibus agreement. In our assessment, anyone who combines that information with the new guidelines will see that there are three steps organisations would do best to take now, regardless of the later entry-into-force dates.

1. Classifying: which system falls under which category?

The first question is which AI systems count as high-risk. The Commission's draft guidelines explain how Article 6 and Annexes I and III are to be applied, with examples from areas including recruitment, credit, medical devices and systems with system access; the consultation ran until 23 July 2026.

In our assessment, for organisations this means: start with an inventory of the AI landscape. Which applications are in use, for what purpose, and under which annex might they fall? Without that overview, every further step is guesswork.

2. Transparency: marking and the duty to inform

Part of the obligations, by contrast, is not shifting. The guidelines on the transparency of AI-generated content give concrete form to Article 50. According to the official Commission page, the EU AI Act as a whole starts applying on 2 August 2026, and that page confirms that the transparency obligations of Article 50 come into force at that point and have not been postponed. These obligations concern, among other things, machine-readable marking of AI-generated content and duties to inform those affected, with specific attention to deepfakes and other situations mentioned by the guidelines.

In our assessment, the organisational impact is tangible: labelling, detection and processes that demonstrably show where AI was involved. This does not require a major system migration, but it does require policy and record-keeping that are ready in time.

3. Logging and control: the verifiable layer

In our analysis, the high-risk rules ultimately revolve around demonstrability. Both Gibson Dunn and Orrick point out that organisations with existing AI applications must assess whether substantial modifications after the new deadlines could bring a system under the high-risk rules after all. In our analysis, this makes a control layer necessary: traceable logs, traceable system and model configuration, and human oversight of sensitive workflows.

In our assessment, the proposed deferred deadlines provide room to set up that architecture carefully rather than in a rush. Anyone who starts now with logging and version management of AI configurations will, in our assessment, be in a stronger position in 2027 and 2028.

What this means in practice

The common thread in the sources consulted — the official Commission pages and the legal analyses by Gibson Dunn and Orrick — is, in our analysis, that the EU AI Act becomes an architecture question: not only "do we use AI responsibly", but "can we demonstrate how, when and with what oversight we deployed AI". For professionals who work with confidential information — lawyers, notaries, company doctors, journalists and compliance teams — that is a familiar reflex: recording what you do and why.

Here the law touches on the idea behind I am Vera. Vera is not a chatbot and not its own language model, but positions itself as a verification layer around AI use. In our assessment, that positioning aligns with the three steps above. Pre-processing and anonymisation take place on EU infrastructure via the Semantic Privacy Shield; the workflow is designed to send only anonymised content to the selected AI models, and if a privacy check fails, nothing is forwarded.

On the point of transparency and control, a verification console can help by making verification steps visible: which models were consulted, how the answers differ and which activities have been recorded. This does not eliminate errors — the professional final judgement always remains with the user. But it gives more insight into what happens under the bonnet, and in our assessment that supports the logging and control needs that suit sensitive workflows. Anyone who wants to view and edit documents within the same secure environment can use Vera Office for that.

Conclusion

In our analysis, the Digital Omnibus changes the pace of the EU AI Act, not the direction. On the basis of the provisional agreement, the high-risk obligations are intended to arrive later, but the transparency rules around Article 50 and the classification guidelines are already here. Organisations that use the staggered deadlines to classify, set up transparency and build a verifiable control layer can, in our assessment, make their AI landscape compliant in a controlled way — instead of pushing the work forward to a deadline that is closer than it appears.

← All articles