In June 2026, only nine of 27 EU Member States had fully designated the national competent authorities required to oversee the AI Act. This administrative bottleneck is the primary reason for the recent regulatory pivot. On July 24, 2026, the EU published Regulation (EU) 2026/1744, the Digital Omnibus on AI, which entered into force on July 27. It is a pragmatic admission that the infrastructure for enforcement simply does not exist.
The regulation effectively resets the clock on the most demanding requirements of the AI Act. Annex III high-risk system obligations, originally slated for August 2, 2026, are now deferred to December 2, 2027—a 16-month reprieve. Annex I embedded products receive a 12-month delay, moving from August 2, 2027, to August 2, 2028.
Not everything is on hold. Article 50 transparency obligations remain locked to the original August 2, 2026, timeline. Similarly, obligations for General Purpose AI (GPAI) models remain unchanged. The AI Office retains its expanded oversight mandate for these models and systems built upon them. The EU is prioritizing the visibility of high-level models while pushing the granular, resource-heavy conformity assessments for high-risk systems into the future.
The enforcement-infrastructure gap is compounded by a profound lack of corporate readiness. A September 2024 survey by Deloitte Legal Germany of 500 AI decision-makers found that 53.8% had taken zero measures toward compliance, with only 26.2% having initiated any process. By February 2026, CSA research indicated that over 50% of organizations still lacked a systematic inventory of their AI systems. Without an inventory, conformity assessments are impossible.
The technical reality is even more precarious. According to a January 2026 CSA survey, only 12% of respondents expressed confidence in their ability to prevent Non-Human Intelligence (NHI) attacks. Even fewer—8%—felt confident in their legacy Identity and Access Management (IAM) systems to handle the complexities of AI and NHI integration. This data suggests that while regulators are stepping back to build infrastructure, the technical surface area is expanding faster than the defensive capabilities of the firms using these systems.
This phenomenon, often termed Vulnerability Inflation, is driven by technical discovery and deployment velocity that consistently outpace defensive infrastructure. As the technical surface area expands, regulatory enforcement is visibly lagging behind the reality of AI deployment. The EU is essentially buying time for both the state and the private sector to catch up to the technical baseline, acknowledging that the current security posture is insufficient for the AI Act’s rigid requirements.
The market is already pricing this governance gap. While the EU defers mandates, industry players are moving to fill the void. The Nvidia Alliance is actively building governance tools, effectively privatizing the compliance layer that the state has yet to standardize. Simultaneously, firms like Cyera and Oasis are seeing the market value the governance gap at roughly $1 billion. Capital is flowing into tools that provide the visibility the EU is currently struggling to mandate.
The Commission is acknowledging that the current state of AI security—characterized by low confidence in NHI attack prevention and inadequate IAM—is not yet ready for the rigid requirements of the AI Act. The regulatory pause provides a window, but the underlying technical and security deficits remain, and they are growing. The administrative and technical lag necessitates this shift in timeline to prevent a total collapse of compliance efforts.
Member states must now use this 16-month window to finalize their national competent authorities. Without these bodies, the oversight mandate remains theoretical. The delay is a direct response to the inability of the current regulatory framework to meet the operational reality of the market.
Corporate entities also face a critical period. With over 50% of organizations lacking a basic AI inventory, the next year must be dedicated to foundational data governance. Compliance is not merely a legal hurdle but a technical requirement that requires significant internal restructuring.
The focus on GPAI models remains the only constant in this shifting landscape. By maintaining the original timeline for these high-level systems, the EU signals that it views large-scale models as the primary risk vector, regardless of the state of local enforcement infrastructure.
Ultimately, the success of the AI Act hinges on the specific utilization of this reprieve. If Member States fail to finalize national competent authorities and firms do not move beyond basic inventory management to active security hardening by the new deadlines, the regulatory cycle will face further, more disruptive adjustments as the gap between deployment and oversight widens.
