Telling someone an AI was involved is now enforced law. Proving why it made its decision is not, until December 2027.

On 27 July 2026, a new European Union regulation entered into force six days before the deadline it existed to rewrite. Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, states its justification for the compressed timeline in its recitals: it took effect "as a matter of urgency" because the AI Act provision it amended was due to apply on 2 August 2026, six days later.

What it changed, and what it left standing, draws a line worth examining closely.

What moved

The AI Act, in force since August 2024, classifies certain uses of AI as "high-risk": hiring and performance evaluation, credit scoring, insurance underwriting and pricing, biometric categorization. Annex III of the Act lists these uses, and until last month, businesses deploying AI in any of them faced a hard compliance date of 2 August 2026: human oversight mechanisms, bias testing, audit logging, conformity assessment, registration in an EU database.

That date is gone. Under the new regulation, standalone Annex III systems now have until 2 December 2027, a deferral of sixteen months. High-risk AI embedded in regulated products, such as medical devices or machinery, moves from an original 2027 date to 2 August 2028.

The European Commission's own account of why gives a specific, checkable reason rather than a political one: the harmonized technical standards and conformity assessment infrastructure that businesses would need to actually demonstrate compliance were not ready. The Council's press release describes a delay calibrated to run "once the Commission confirms the needed standards and tools are available," not a fixed political concession. Regulators built the rule two years ago. The scaffolding to check whether anyone was following it did not get built in time.

What didn't

Article 50 of the AI Act imposes a narrower duty: tell people when they are interacting with an AI system, and label AI-generated or synthetic content, including deepfakes. This obligation was not deferred. It took effect on 2 August 2026 as originally scheduled, and national market surveillance authorities are now the ones enforcing it.

There is one narrow exception, and the precision of it matters: generative AI systems already on the market before 2 August 2026 get a four-month grace period, until 2 December 2026, specifically for the machine-readable marking format of that labelling requirement. The underlying duty to disclose that a user is talking to a machine applies from 2 August 2026 regardless of when the system launched. One law firm covering the rule put the distinction bluntly: organizations.

Put the two provisions side by side. Telling someone an AI is involved: live law, enforced now. Explaining why that AI made the decision it made, with a human accountable and a record an auditor could examine: pushed to December 2027.

The framing gap

Co-rapporteur Arba Kokalari described the package during the Parliament debate as pressing "the pause button" on the AI Act and reducing red tape, a characterization widely repeated in coverage of the vote. Set against the text of the regulation, the framing is accurate for the calendar and incomplete for the substance. The requirements for human oversight, bias testing, and audit trails were not narrowed, removed, or simplified. They were rescheduled. A business preparing to deploy an AI hiring tool in the EU in 2027 will eventually face the identical bar a business would have faced in 2026, just later, and with less runway than it looks like today, since much of that runway will be consumed by the same standards-setting process that caused this delay in the first place.

Consumer advocacy group BEUC's response to the final deal took a sharper line, characterizing the Omnibus as opening room for further deregulation even while acknowledging that some protections, including the stricter rules for AI used in credit scoring and in pricing life and health insurance, remain intact in the underlying Act. That is a genuine disagreement about direction, not a dispute over what the text says: BEUC and the Commission agree on the mechanics, and differ on whether delaying enforcement of a rule that still exists on paper amounts to weakening it in practice.

One provision buried in the amendments adds a specific, and slightly counterintuitive, texture to that debate. The regulation introduces a new Article 4a, creating a legal basis for processing special categories of personal data, including data on race, health, and other sensitive attributes, specifically for the purpose of detecting and correcting bias in AI systems. The same law that pushed the deadline for mandatory bias testing to December 2027 simultaneously made it legally easier to do that testing voluntarily, before then. Regulators removed the compliance clock and left the tool on the table.

What this settles, and what it doesn't

The regulation resolves a question that had been genuinely open since November 2025, when the Commission first proposed the delay: whether the deferral would become law before the original deadline arrived. It has. Businesses that spent the past year building toward an August 2026 high-risk compliance date now have a real, enforceable extension, not a proposal subject to trilogue collapse.

What it does not resolve is the question underneath it. The AI Act's core distinction, between an AI system disclosing its own presence and an AI system justifying its own decisions, is not a drafting artifact. It reflects two different kinds of difficulty. Disclosure is a switch: a label, a line of text, a watermark embedded in an image file. Every provider can implement it uniformly, and regulators can verify compliance by looking. Explainability is infrastructure: a record of what data went into a decision, why the system weighted it the way it did, who had the authority to override it, and whether that authority was ever exercised. Building that infrastructure after a system is already making decisions is considerably harder than building it in from the start, which is precisely why the standards bodies the Commission was waiting on have not finished the job.

The Digital Omnibus did not make that infrastructure less necessary. It made it someone else's near-term deadline, for sixteen months. Any business using AI in hiring, lending, or insurance underwriting, whether headquartered in the EU or simply serving EU customers and candidates from elsewhere, given the Act's extraterritorial reach, now has to decide whether to treat that as license to wait or as time to build the harder half of the system properly, before an auditor, a rejected applicant, or the next regulatory cycle asks the question the calendar just postponed.

This is the distinction Occams Ai was built to close, not just describe. Disclosure is a line of code any team can ship in an afternoon. Explainability, the audit trail, the human sign-off, the record that holds up when a regulator or a rejected applicant asks for it, takes real engineering, and December 2027 is closer than it looks: the standards bodies the Commission is waiting on are still finishing their work, which means the real building window is shorter than the deadline suggests, and it is already open. Your team shouldn't have to become AI-governance engineers to get through it. That build is exactly what our Applied Intelligence practice takes off your plate: the oversight structure, the bias testing, the audit trail, put in place around the AI you're already running, without pulling your people off the work that actually grows the business. Start a conversation with our team. Thirty minutes to see where the gap actually is, and how much of the work we can carry for you before the deadline becomes someone else's emergency instead of yours.