Timeline note: the Digital Omnibus postponing Annex III high-risk obligations was approved in June 2026. Confirm the position as published in the Official Journal before relying on any date here.
It is tempting to read the postponement as relief. It is not, for two reasons that operate at the same time.
What did not move
Article 50 transparency obligations still apply from 2 August 2026. If your agents interact with people, those people have to be told they are dealing with AI. Synthetic content needs marking. That is a near-term, in-force obligation and it did not shift.
What moved, and what that actually buys
The stand-alone high-risk obligations under Annex III moved to December 2027, with product-embedded high-risk systems later still. The enforcement date moved. The architecture did not become simpler.
Four things break in most enterprise agent programs, and none of them get easier with time:
- Authority. An agent adjusts a limit. Which human authority was that action derived from? If the answer is "the system prompt," that is not an answer a reviewer accepts.
- Enforcement point. Policy that lives in a document is not policy. Controls have to operate at the moment of action — most stacks check permissions at login and never again.
- Reconstruction. Article 12 will require logging sufficient to trace how an output happened. Chat transcripts are not traceability.
- Oversight that is not theater. A human in the loop approving 400 agent actions a day is a rubber stamp with a job title. Reviewers know the difference.
The penalty structure, stated correctly
Two tiers get conflated constantly, and getting this wrong in front of a compliance audience is expensive. The headline €35M or 7% of global turnover applies to prohibited practices. Non-compliance with high-risk obligations sits at €15M or 3%. Supplying incorrect information to authorities is €7.5M or 1%. For SMEs the applicable figure is the lower of the two, not the higher.
The real risk in a delay
Seventeen months is exactly enough time to build the governance layer properly. It is also exactly enough time to defer it internally four more times and then cram in late 2027. Same calendar, very different outcomes — and the second path produces controls designed to pass a review rather than to work.
Outside the EU, the clock never had a deadline
The more important correction to the relief-reading: for most enterprises the binding constraint was never this statute. A US bank's agents answer to an examiner today — and since April 2026 the model risk framework expressly excludes them, which means the bank's own authority model is what gets examined. An Indian enterprise's agents inherit the DPDP Act and the RBI's supervisory posture today. Gulf institutions building sovereign-scale platforms face their supervisors on their own calendars, not Brussels'. The deferral moved one jurisdiction's enforcement date; it moved nothing about what an agent in production already owes.
If your program quietly re-baselined its governance work to December 2027 last month, that is worth a conversation before the re-baseline becomes the architecture.