Governance

The AI Act 'delay': a reprieve or a trap?

The Digital Omnibus moved the headline deadline — but transparency obligations, Spain's draft AI law, and your supervisor didn't move. A practitioner's reading.

by Yerbabuena Digital·July 8, 2026·2 min read

Everyone read the same headline in June: “EU delays the AI Act.” Here is what the headline missed — and what it means if you run AI systems in a regulated business.

What actually moved

The Digital Omnibus — politically agreed in May and given the Council’s final green light on 29 June 2026 — pushed the high-risk obligations of Annex III (credit scoring, recruitment, biometrics and similar stand-alone systems) from August 2026 to 2 December 2027, and high-risk AI embedded in regulated products to 2 August 2028. That part of the headline is true. (Formal caveat: the text still awaits Official Journal publication as we write.)

What didn’t move

Article 50 transparency obligations apply from 2 August 2026. If your systems talk to customers, generate content, or produce anything a person might mistake for human work, disclosure and marking duties arrive in weeks, not years: chatbots must identify themselves, synthetic content must be marked machine-readably, deepfakes and AI-written public-interest text must be labeled. The Commission published its final Code of Practice on Transparency on 10 June 2026; systems already on the market get a grace period for machine-readable marking only — until 2 December 2026. The Act’s penalty regime becomes applicable on the same 2 August date: up to €15M or 3% of global turnover for transparency violations.

Spain went the other direction. While Brussels extended deadlines, the Spanish government sent its draft AI law — the Proyecto de Ley Orgánica para el buen uso y la gobernanza de la IA — to Congress on 26 May 2026, with sanction bands up to €35M or 7% of turnover and AESIA as market surveillance authority. Notably for financial services: under the draft, the Banco de España supervises AI Act compliance for financial entities. AESIA has already published sixteen implementation guides. The enforcement machinery is being built during the “delay.”

Your supervisor never paused. The ECB’s supervisory priorities for 2026–28 put AI governance squarely inside banking supervision, and the EBA has said existing governance and outsourcing frameworks already apply to banks’ AI. If you are supervised, the binding timeline is your supervisor’s, not Brussels’.

The pattern we keep seeing

Teams treat governance as a deadline problem. It isn’t. It is an architecture problem: retrofitting evidence, access control, and audit trails into a system that shipped without them costs a multiple of designing them in. The organizations using the next seventeen months to build governed systems — an AI inventory, risk classification, human oversight that is real rather than ceremonial, logs that reconstruct decisions — won’t merely be compliant in December 2027. They will be the ones whose security reviews take days instead of quarters, which in practice decides who ships. That is the work behind our AI Governance & Trust and Agentic AI & Agent Automation practices.

So: reprieve or trap? A reprieve for paperwork. A trap for anyone who reads it as permission to stop.

This is a practitioner’s reading, not legal advice. If a specific obligation matters to your business, verify it against the final texts.


Where we can help: If Article 50 or Annex III planning is on your Q3 roadmap, AI Governance & Trust covers inventory, risk classification, and audit-ready evidence. For production agent controls and inventories, see Agentic AI & Agent Automation. Book a Discovery Workshop — we reply with a direct assessment, not a sales sequence.

#EU AI Act#Digital Omnibus#AI governance#Article 50#Spain
Back to Insights