Timeline note: the Digital Omnibus postponing Annex III high-risk obligations was approved in June 2026. Confirm the position as published in the Official Journal before relying on any date here.
It is tempting to read the postponement as relief. It is not, for two reasons that operate at the same time.
What did not move
Article 50 transparency obligations still apply from 2 August 2026. If your agents interact with people, those people have to be told they are dealing with AI. Synthetic content needs marking. That is a near-term, in-force obligation and it did not shift.
What moved, and what that actually buys
The stand-alone high-risk obligations under Annex III moved to December 2027, with product-embedded high-risk systems later still. The enforcement date moved. The architecture did not become simpler.
Four things break in most enterprise agent programmes, and none of them get easier with time:
- Authority. An agent adjusts a limit. Which human authority was that action derived from? If the answer is "the system prompt," that is not an answer a reviewer accepts.
- Enforcement point. Policy that lives in a document is not policy. Controls have to operate at the moment of action — most stacks check permissions at login and never again.
- Reconstruction. Article 12 will require logging sufficient to trace how an output happened. Chat transcripts are not traceability.
- Oversight that is not theatre. A human in the loop approving 400 agent actions a day is a rubber stamp with a job title. Reviewers know the difference.
The penalty structure, stated correctly
Two tiers get conflated constantly, and getting this wrong in front of a compliance audience is expensive. The headline €35M or 7% of global turnover applies to prohibited practices. Non-compliance with high-risk obligations sits at €15M or 3%. Supplying incorrect information to authorities is €7.5M or 1%. For SMEs the applicable figure is the lower of the two, not the higher.
The real risk in a delay
Seventeen months is exactly enough time to build the governance layer properly. It is also exactly enough time to defer it internally four more times and then cram in late 2027. Same calendar, very different outcomes — and the second path produces controls designed to pass a review rather than to work.