AI Governance After the EU AI Act Delay: Why Compliance Dates Are Not a Strategy

AI Governance After the EU AI Act Delay: Why Compliance Dates Are Not a Strategy

For roughly two years, one date organised enterprise AI planning across three continents: 2 August 2026. It was the day the European Union's Artificial Intelligence Act was scheduled to apply in full to high-risk systems — the hiring screeners, credit models, biometric tools, and education-access algorithms listed in Annex III. Budgets were built around it. Board papers referenced it. Vendors sold against it.

That date arrived two days ago, and the obligations everyone was preparing for did not. On 27 July 2026, Regulation (EU) 2026/1744 — the Digital Omnibus on AI — entered into force, deferring stand-alone high-risk obligations to 2 December 2027 and embedded-product obligations to 2 August 2028 (European Parliament & Council, 2026). Two months earlier, Colorado repealed and replaced the first comprehensive state AI law in the United States, trading a duty-of-care regime for a narrower disclosure framework effective 1 January 2027 (Skadden, 2026).

The temptation to read this as regulatory retreat is understandable and, in our view, a mistake. This editorial argues that the 2026 reset exposes a structural weakness in how most organisations approached AI governance in the first place: they built to a date rather than to a capability. Readers responsible for deploying, procuring, auditing, or signing off on AI systems will find here what actually changed, what did not, why the delay happened, and which parts of a governance programme hold their value regardless of which legislature blinks next.


Executive Summary

  • The EU did not repeal its high-risk AI rules. Regulation (EU) 2026/1744 deferred them: Annex III stand-alone systems to 2 December 2027, Annex I embedded systems to 2 August 2028 (European Parliament & Council, 2026).
  • 2 August 2026 was not cancelled. Article 50 transparency obligations — chatbot disclosure, synthetic-media marking, deepfake labelling — took effect as originally scheduled, with a narrow extension to 2 December 2026 for content-marking on systems already on the market.
  • A new prohibition on AI systems generating non-consensual intimate imagery and child sexual abuse material was added to the Act and applies from 2 December 2026.
  • The primary driver of the deferral was not a change of political conviction but a standards bottleneck: the harmonised European standards that give effect to the Act's high-risk requirements were not ready (CEN-CENELEC, 2025; AI Standards Hub, 2025).
  • Under Article 40, only standards whose references are cited in the Official Journal confer presumption of conformity. Certification to ISO/IEC 42001 is valuable but is not, by itself, AI Act conformity.
  • In the United States, direction of travel is toward federal consolidation: Executive Order 14365 (11 December 2025) directs agencies to challenge conflicting state AI laws, and Colorado's rewrite followed within months.
  • Evidence suggests capability is outrunning oversight. Stanford's 2026 AI Index recorded 362 documented AI incidents in 2025, up from 233 in 2024, alongside 88% organisational AI adoption (Stanford HAI, 2026).
  • The same data shows genuine progress: organisations reporting no responsible-AI policy fell from 24% to 11%, and AI-specific governance roles grew 17% in 2025 — but knowledge and training gaps remain the top-cited barrier.
  • The durable recommendation: build the artefacts that every regime demands — a system inventory, documented risk assessments, evaluation records, data provenance, incident logging, and named accountability — because those survive rewrites; deadline-specific paperwork does not.

What Actually Changed — and What Did Not

The European Union: a deferral with teeth attached

The Digital Omnibus on AI was proposed by the European Commission on 19 November 2025 as part of a wider simplification package. Parliament endorsed it on 16 June 2026, the Council gave final approval on 29 June 2026, the act was signed on 8 July, published in the Official Journal on 24 July, and entered into force on 27 July 2026 — a compressed schedule the regulation itself justified by the imminence of the 2 August date (European Parliament & Council, 2026; Freshfields, 2026).

It is worth being precise about what moved, because both over-compliance and under-compliance are now easy errors.

Table 1 — Revised EU AI Act application timeline (as amended by Regulation (EU) 2026/1744)

DateWhat appliesWho it primarily affects
2 Feb 2025Prohibited practices; AI literacy dutiesAll providers and deployers in scope
2 Aug 2025General-purpose AI model obligations; governance structuresFoundation model providers
2 Aug 2026Article 50 transparency obligations (chatbot disclosure, emotion-recognition and biometric-categorisation notices, deepfake and synthetic-content labelling)Anyone operating EU-facing AI interfaces or generating synthetic media
2 Dec 2026Machine-readable content marking for systems already on the market before 2 Aug 2026; new prohibition on NCII/CSAM generationGenerative AI providers
2 Aug 2027Member State AI regulatory sandboxes; Commission delegated acts for Annex I sectorsNational authorities; regulated-product manufacturers
2 Dec 2027High-risk obligations, Annex III stand-alone systems (employment, credit, education, essential services, law enforcement, migration)Providers and deployers of consequential-decision systems
2 Aug 2028High-risk obligations, Annex I embedded systems (medical devices, machinery, and similar)Manufacturers under existing EU product-safety law

Callout — What the deferral does not change The substantive obligations were largely untouched. Risk management systems, data governance, technical documentation, logging, human oversight, accuracy and robustness requirements, and quality management systems all remain in the text. Sixteen months were added to the clock, not subtracted from the workload.

The United States: consolidation, contested

Colorado's Artificial Intelligence Act (SB 24-205, 2024) was the first comprehensive US state AI statute, built on the EU's conceptual architecture: risk-based duties, impact assessments, and a duty of care against algorithmic discrimination. Its effective date slipped from 1 February 2026 to 30 June 2026, and on 14 May 2026 Governor Polis signed SB 26-189, repealing and replacing it with an Automated Decision-Making Technology Act focused on disclosure and adverse-outcome notification, effective 1 January 2027 (Skadden, 2026; Hunton, 2026).

That reversal did not happen in isolation. Executive Order 14365, Ensuring a National Policy Framework for Artificial Intelligence, issued 11 December 2025, directs federal agencies toward a "minimally burdensome national policy framework" and establishes machinery to challenge conflicting state laws (Executive Office of the President, 2025). Reporting also indicates the original Colorado act faced constitutional challenge, with enforcement paused pending litigation. Readers should treat the litigation position as live and jurisdiction-specific rather than settled.


The Delay Was an Engineering Problem Before It Was a Political One

This is the part of the story most commentary skips, and it is the part professionals should internalise.

The AI Act does not specify, in the statute, how to build a compliant risk management system. It delegates that work to harmonised European standards drafted by CEN-CENELEC's Joint Technical Committee 21 under Standardisation Request M/593 and its amendment M/613. Under Article 40, conformity with a harmonised standard whose reference has been published in the Official Journal creates a presumption of conformity with the corresponding legal requirement. Without those citations, providers face binding obligations without an agreed method of demonstrating they have met them.

JTC 21 is among the largest committees in European standardisation history, drawing more than 300 experts from over 20 countries (CEN-CENELEC, n.d.). Scale of that kind buys legitimacy and costs time. By October 2025, the CEN and CENELEC technical boards had adopted exceptional acceleration measures — including direct publication after a positive enquiry vote, bypassing separate formal votes — to try to make priority deliverables available by Q4 2026 (CEN-CENELEC, 2025). Public trackers of the committee's work indicate that as of mid-2026 no AI Act harmonised standard had yet been cited in the Official Journal, meaning none yet confers Article 40 presumption. That should be read as a status observation rather than a permanent condition.

Two practical consequences follow, and both are frequently misunderstood:

  • ISO/IEC 42001 certification is not AI Act conformity. ISO/IEC 42001:2023 is the first international AI management system standard and is genuinely useful — it gives organisations a certifiable, auditable structure for AI governance (ISO/IEC, 2023). But presumption of conformity attaches only to OJ-cited harmonised standards, and JTC 21's quality-management work has proceeded as a bespoke European standard rather than direct adoption of 42001. Buyers should treat a 42001 certificate as evidence of managerial maturity, not as a compliance passport.
  • Aligning to draft standards still pays. A draft confers no legal presumption, but the underlying controls — documented risk assessment, dataset governance, logging, human oversight design — are the same controls the final text will require. Work done against drafts converts into evidence later.

The Argument: Deadline-Driven Governance Is Fragile Governance

Here is the editorial position, stated plainly.

Organisations that organised their AI governance around 2 August 2026 have just discovered that their programme was scheduled by a legislature rather than by their own risk exposure. That is a design flaw, and the delay is the second time it has surfaced — Colorado's three effective dates in two years made the same point in a different jurisdiction.

The independent evidence suggests the risk is not hypothetical. Stanford's 2026 AI Index — the ninth edition of its annual audit — reports 88% of organisations using AI in at least one business function, while documented incidents in the AI Incident Database rose to 362 in 2025 from 233 in 2024 (Stanford HAI, 2026). Incident counts are an imperfect instrument: they reflect reporting intensity and media attention as much as underlying failure rates, and a rise partly signals better detection. But a near-56% year-on-year increase alongside near-universal adoption is not easily explained by measurement artefacts alone.

The same report contains the more encouraging counter-signal, which we think deserves equal weight: the share of businesses reporting no responsible AI policies fell from 24% to 11%, and AI-specific governance roles grew 17% during 2025. Governance is being built. The problem is what it is being built for. When knowledge and training gaps remain the most-cited barrier to responsible AI implementation, the constraint is capability, not paperwork — and capability does not appear on a deadline.

An organisation that spent 2025 assembling a system inventory, defining who signs off on model changes, and instrumenting logging has lost nothing to the deferral. An organisation that spent 2025 drafting an Annex III conformity file to a template now has sixteen months of runway and a document.


What Holds Still When the Law Moves

Not everything in an AI governance programme is regime-specific. The useful mental model is to sort your assets into two columns.

Table 2 — Regime-dependent versus regime-independent governance assets

Regime-dependent (rewrite when the law changes)Regime-independent (build once, reuse everywhere)
Conformity assessment route and CE marking fileAI system inventory with owner, purpose, and criticality rating
Jurisdiction-specific disclosure wordingDocumented risk assessment method applied consistently
Registration in a public databaseEvaluation and testing records with versioned results
Statutory impact-assessment templatesTraining-data provenance and licensing records
Deadline-linked project plansIncident detection, triage, and post-incident review process
Regulator-facing reporting formatsNamed human accountability for each consequential decision point
Sector-specific derogations and exemptionsThird-party and model-supplier due diligence file

The right column is not a compliance artefact. It is an operating capability, and it is what makes the left column cheap to produce on demand. Every major framework converges on it. The NIST AI Risk Management Framework organises the same material under Govern, Map, Measure, and Manage; NIST has confirmed AI RMF 1.0 is under revision and has extended the ecosystem with control overlays for securing AI systems and, on 7 April 2026, a concept note for a critical infrastructure profile (NIST, 2023, 2026). ISO/IEC 42001 organises it as a management system. The EU organises it as a conformity obligation. The underlying evidence they each demand is remarkably consistent.

Table 3 — Three reference points, three different jobs


ISO/IEC 42001:2023NIST AI RMF 1.0 (+ profiles)EU harmonised standards (JTC 21)
NatureCertifiable management system standardVoluntary risk frameworkTechnical standards supporting binding law
Legal effectNone directly; contractual and assurance valueNone; widely referenced in US policy and procurementPresumption of conformity once cited in the OJ
Best used forDemonstrating governance maturity to customers and auditorsStructuring risk work and cross-functional languageMeeting Chapter III Section 2 requirements defensibly
Main limitationCertifies process, not system outcomesNot auditable; no certification pathNot yet available as cited harmonised standards

Figure Descriptions for the Design Team

Figure 1. The Evidence Spine of AI Governance Purpose: Show that a single evidence chain satisfies multiple regimes, reducing duplicated effort. Layout: Horizontal left-to-right flow with six connected stages, each a rounded rectangle: (1) System Inventory → (2) Risk Classification → (3) Data & Provenance Record → (4) Evaluation & Testing Log → (5) Human Oversight Design → (6) Incident & Change Log. Solid arrows connect stages left to right; a dashed feedback arrow runs from stage 6 back to stage 2, labelled "re-assess on material change." Right-hand panel: Three stacked labels — "EU AI Act conformity file," "ISO/IEC 42001 audit evidence," "NIST AI RMF Measure/Manage" — each connected to the spine by thin dotted lines from stages 2–6, showing shared dependency. Visual hierarchy: Spine stages in the primary brand colour at full weight; regime labels in muted grey to indicate they are outputs, not inputs. Caption: "One evidence chain, three regimes. The artefacts regulators ask for differ; the underlying record does not."

Figure 2. Two Regulatory Clocks, 2024–2028 Purpose: Contrast the original and amended EU timelines against the US state-to-federal shift. Layout: Two parallel horizontal timelines sharing a common date axis (Aug 2024 → Aug 2028). Upper track: EU AI Act, with markers at 1 Aug 2024 (entry into force), 2 Feb 2025, 2 Aug 2025, 2 Aug 2026, 2 Dec 2026, 2 Dec 2027, 2 Aug 2028. Show the original 2 Aug 2026 high-risk marker as a hollow circle with a curved dashed arrow relocating it to 2 Dec 2027 (solid circle). Lower track: United States, with markers at May 2024 (Colorado SB 24-205 enacted), 11 Dec 2025 (EO 14365), 14 May 2026 (SB 26-189 signed), 1 Jan 2027 (ADMT Act effective). Caption: "Deferrals on both tracks. The obligations moved in time, not in substance."


The Counterargument, Taken Seriously

An editorial that only argues one side is advocacy. There is a legitimate case that the deferral was correct and that some organisations were right to slow down.

Requiring conformity against standards that do not yet exist is not a rigorous regime; it is a lottery in which well-resourced firms buy assurance and smaller ones guess. Compliance spending diverted into speculative documentation is real money not spent on evaluation infrastructure, red-teaming, or monitoring. There is also a reasonable argument — advanced by the Commission itself in framing the simplification package — that a burden falling hardest on SMEs and EU-based deployers has competitive consequences the Act's drafters underweighted.

Against that sits a concern raised within the standards community itself: emergency acceleration measures displace the consensus process that gives European standardisation its legitimacy in the first place (Cantero Gamito, 2025). If standards are rushed to meet a political clock, the presumption of conformity they confer is worth less than it appears.

Both concerns point the same direction. The organisations best positioned are those whose governance rests on their own risk analysis, with regulatory mapping layered on top — not the reverse.


Latest Developments

  • 11 December 2025 — Executive Order 14365 issued in the United States, directing federal agencies toward a national AI policy framework and establishing mechanisms to challenge conflicting state laws (Executive Office of the President, 2025).
  • 14 May 2026 — Colorado Governor Polis signs SB 26-189, repealing SB 24-205 and replacing it with a disclosure-focused ADMT framework effective 1 January 2027 (Skadden, 2026).
  • 16 and 29 June 2026 — European Parliament endorses, and the Council gives final approval to, the Digital Omnibus on AI.
  • 24 July 2026 — Regulation (EU) 2026/1744 published in the Official Journal; enters into force 27 July 2026.
  • 2 August 2026 — Article 50 transparency obligations apply as originally scheduled.
  • Ongoing — NIST has confirmed AI RMF 1.0 is being revised and released a concept note for a Trustworthy AI in Critical Infrastructure profile on 7 April 2026 (NIST, 2026). Timing of the revised framework has not been announced; readers should treat expected publication dates as forecasts.

Practical Takeaways

  1. Correct your compliance calendar today, then stop treating it as the plan. Annex III obligations now apply from 2 December 2027; Annex I from 2 August 2028. Article 50 applied from 2 August 2026.
  2. Audit your Article 50 exposure this month. Chatbot disclosure, emotion-recognition notices, and synthetic-media marking are live obligations with distinct scopes and different responsible parties. Conflating them produces both gaps and wasted effort.
  3. Complete the inventory first. If you cannot list every AI system in production, its owner, and what decision it influences, no framework will help you. This is the single task most organisations have not finished and cannot skip.
  4. Convert the sixteen months into capability, not slack. Instrument logging, stand up evaluation pipelines, and run one full mock conformity exercise on your highest-risk system while the stakes are low.
  5. Renegotiate supplier terms now. Ask vendors for model documentation, evaluation results, provenance disclosures, and incident-notification commitments. Contracts signed in 2026 will still be running in December 2027.
  6. Treat certifications as evidence, not shields. Value ISO/IEC 42001 for what it demonstrates about process discipline; do not represent it internally or externally as AI Act conformity.
  7. Track harmonised standards, do not wait for them. Align to drafts, and record the mapping so that when references are cited in the Official Journal you can show continuity rather than starting over.
  8. If you operate in the US, maintain two postures. The federal preemption push and state-level rewrites are unresolved; assume divergence between EU and US obligations rather than harmonisation.
  9. Log incidents even when nobody requires it. Incident data is the only input that tells you whether your controls work, and it is the first thing a regulator, auditor, or plaintiff will ask for.

Key Insights

  1. The EU deferred high-risk AI obligations; it did not repeal them, and the substantive requirements are essentially unchanged.
  2. 2 August 2026 remained a live date for Article 50 transparency duties, which are frequently and incorrectly assumed to have moved.
  3. The deferral was driven substantially by unfinished harmonised standards, not by a reversal of regulatory intent.
  4. Under Article 40, presumption of conformity attaches only to standards cited in the Official Journal — a distinction with direct commercial consequences.
  5. ISO/IEC 42001 certification signals governance maturity but does not, on its own, establish EU AI Act conformity.
  6. Colorado's repeal-and-replace and Executive Order 14365 point toward US consolidation, but the position remains contested and jurisdiction-dependent.
  7. Documented AI incidents rose to 362 in 2025 from 233 in 2024 while organisational adoption reached 88% — capability is outpacing oversight.
  8. The share of organisations with no responsible-AI policy fell from 24% to 11%, so the deficit is now capability and skills rather than policy existence.
  9. Governance assets divide cleanly into regime-dependent artefacts and regime-independent capabilities; only the second category retains value across rewrites.
  10. Programmes scheduled by legislatures inherit legislative volatility. Programmes scheduled by risk exposure do not.

Frequently Asked Questions

1. Has the EU AI Act been delayed or cancelled? Delayed, in part. Regulation (EU) 2026/1744 deferred high-risk obligations for Annex III stand-alone systems to 2 December 2027 and for Annex I embedded systems to 2 August 2028. Prohibitions, general-purpose AI model rules, and transparency obligations were not deferred.

2. What applied on 2 August 2026? Article 50 transparency obligations: informing people they are interacting with an AI system, notifying subjects of emotion-recognition and biometric-categorisation systems, and marking or labelling synthetic content. A narrow extension to 2 December 2026 covers machine-readable marking for systems already on the market before 2 August 2026.

3. What is the Digital Omnibus on AI? Regulation (EU) 2026/1744 — the first substantive amendment to the AI Act since its 2024 adoption. Proposed 19 November 2025, published in the Official Journal on 24 July 2026, in force 27 July 2026.

4. Why were the high-risk rules delayed? Principally because the harmonised European standards needed to demonstrate conformity were not ready, alongside delays in designating national competent authorities.

5. What are harmonised standards and why do they matter? European standards developed under a Commission mandate. Once their references appear in the Official Journal, Article 40 gives conformity with them a presumption of conformity with the corresponding legal requirement — the practical route most providers will use.

6. Are any AI Act harmonised standards published yet? Public trackers of CEN-CENELEC JTC 21's work indicate none had been cited in the Official Journal as of mid-2026. Several drafts are at advanced stages, and CEN-CENELEC targeted availability of prioritised deliverables in Q4 2026.

7. Does ISO/IEC 42001 certification make us AI Act compliant? No. It demonstrates a certified AI management system and carries real assurance value, but presumption of conformity attaches only to OJ-cited harmonised standards.

8. What new prohibition was added to the AI Act? A prohibition on AI systems designed to generate non-consensual sexual or intimate imagery and child sexual abuse material, applying from 2 December 2026.

9. Is the Colorado AI Act still in force? Colorado's SB 24-205 was repealed and replaced by SB 26-189, signed 14 May 2026, which takes effect 1 January 2027 with a narrower disclosure-based framework. Enforcement of the original act has been affected by litigation; organisations should take current jurisdiction-specific legal advice.

10. What does Executive Order 14365 do? Issued 11 December 2025, it establishes a federal policy favouring a single national AI framework and directs agencies to identify and challenge conflicting state AI laws.

11. Should we pause our AI compliance programme? The evidence argues against it. The obligations are unchanged, the workload is unchanged, and the tasks most organisations have not finished — system inventory, evaluation infrastructure, supplier due diligence — take longer than sixteen months in large enterprises.

12. What is the difference between a provider and a deployer? A provider develops an AI system or has it developed and places it on the market under its own name. A deployer uses such a system under its authority. Obligations differ substantially between the two roles, and many organisations are both.

13. What should a small organisation do first? Build the inventory, classify systems by the consequence of failure, and document who is accountable for each. These three steps cost little, require no legal certainty, and are prerequisites for everything else.

14. How do the NIST AI RMF and the EU AI Act relate? The NIST framework is voluntary and organises risk work under Govern, Map, Measure, and Manage. The AI Act is binding law. They are complementary: the NIST structure produces much of the evidence the Act requires, but confers no legal presumption in the EU.

15. Are AI incident numbers a reliable measure of risk? Only partially. Rising counts reflect improved detection and reporting as well as genuine failures. They are best read as a trend indicator alongside adoption data, not as an absolute measure of harm.


Glossary

  • AI Act — Regulation (EU) 2024/1689, the EU's horizontal, risk-based AI regulation, in force since 1 August 2024.
  • AIMS (AI Management System) — The set of policies, processes, and controls governing AI across its lifecycle, as specified in ISO/IEC 42001.
  • Annex I / Annex III — AI Act annexes distinguishing AI embedded in products already covered by EU product-safety law (Annex I) from stand-alone high-risk use cases such as employment and credit (Annex III).
  • Article 40 — The AI Act provision under which harmonised standards cited in the Official Journal confer presumption of conformity.
  • Article 50 — The AI Act's transparency obligations, covering AI interaction disclosure, emotion-recognition and biometric-categorisation notices, and synthetic content marking.
  • CEN-CENELEC JTC 21 — The joint technical committee drafting European AI standards, including harmonised standards supporting the AI Act.
  • Conformity assessment — The process of demonstrating that a high-risk AI system meets applicable legal requirements before it is placed on the market.
  • Deployer — An organisation using an AI system under its own authority, as distinct from the provider that places it on the market.
  • Digital Omnibus on AI — Regulation (EU) 2026/1744, the amending regulation that deferred high-risk deadlines and added new provisions.
  • Harmonised standard — A European standard developed under a Commission standardisation request that, once cited in the Official Journal, supports presumption of conformity.
  • ISO/IEC 42001:2023 — The first international certifiable standard for AI management systems.
  • NIST AI RMF — The US National Institute of Standards and Technology's voluntary AI Risk Management Framework (NIST AI 100-1), structured around Govern, Map, Measure, and Manage.
  • Presumption of conformity — The legal effect by which following a cited harmonised standard is taken to satisfy the corresponding requirement, subject to rebuttal.
  • Provenance — Documented origin and processing history of data, models, or generated content.
  • Standardisation request (M/593, M/613) — The Commission mandate, and its amendment, instructing CEN-CENELEC to develop AI Act standards.

References

Legislation and Official Journal

European Parliament & Council of the European Union. (2024). Regulation (EU) 2024/1689 of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg/2024/1689/oj

European Parliament & Council of the European Union. (2026). Regulation (EU) 2026/1744 of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI). Official Journal of the European Union, published 24 July 2026; in force 27 July 2026. ELI: reg/2026/1744. https://eur-lex.europa.eu/eli/reg/2026/1744/oj

Government Sources

Executive Office of the President. (2025). Executive Order 14365 — Ensuring a National Policy Framework for Artificial Intelligence (DCPD-202501186). U.S. Government Publishing Office. https://www.govinfo.gov/app/details/DCPD-202501186

National Institute of Standards and Technology. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0) (NIST AI 100-1). U.S. Department of Commerce. https://doi.org/10.6028/NIST.AI.100-1

National Institute of Standards and Technology. (2026). AI Risk Management Framework [Programme page, including 7 April 2026 concept note on a Trustworthy AI in Critical Infrastructure profile]. https://www.nist.gov/itl/ai-risk-management-framework

National Institute of Standards and Technology. (2025–2026). Control Overlays for Securing AI Systems (COSAiS). Computer Security Resource Center. https://csrc.nist.gov/projects/cosais

Standards and Standards Bodies

International Organization for Standardization & International Electrotechnical Commission. (2023). ISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system. ISO. https://www.iso.org/standard/42001

CEN-CENELEC. (2025, October 23). Update on CEN and CENELEC's decision to accelerate the development of standards for artificial intelligence. https://www.cencenelec.eu/news-events/news/2025/brief-news/2025-10-23-ai-standardization/

CEN-CENELEC. (n.d.). Artificial intelligence — CEN-CENELEC areas of work [CEN-CLC/JTC 21 overview]. Retrieved 4 August 2026, from https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/

Research and Industry Reports

Stanford Institute for Human-Centered Artificial Intelligence. (2026). The AI Index 2026 annual report: Chapter 3 — Responsible AI. Stanford University. https://hai.stanford.edu/ai-index/2026-ai-index-report/responsible-ai

AI Standards Hub. (2025, December 17). Navigating the AI Act standards maze. The Alan Turing Institute, BSI and National Physical Laboratory. https://aistandardshub.org/navigating-the-ai-act-standards-maze/

Other Authoritative Sources (Legal and Scholarly Analysis)

Cantero Gamito, M. (2025, November 28). From consensus to exceptionality — What the EU's AI standards crisis reveals about delegated technical governance. ReaLaw Blog. https://realaw.blog/2025/11/28/from-consensus-to-exceptionality-what-the-eus-ai-standards-crisis-reveals-about-delegated-technical-governance-by-marta-cantero-gamito/

Freshfields. (2026). EU AI Act unpacked #34: The final Digital Omnibus on AI. https://www.freshfields.com/en/our-thinking/blogs/technology-quotient/eu-ai-act-unpacked-34-the-final-digital-omnibus-on-ai-key-amendments-to-the-a-102nber

Gibson Dunn. (2026, May 27). EU AI Act Omnibus agreement — Postponed high-risk deadlines and other key changes. https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/

Hunton Andrews Kurth. (2026, May). Colorado AI Act amended and effective date delayed. Privacy & Information Security Law Blog. https://www.hunton.com/privacy-and-cybersecurity-law-blog/colorado-ai-act-amended-and-effective-date-delayed

Skadden, Arps, Slate, Meagher & Flom. (2026, June). Colorado repeals and replaces its AI Act. https://www.skadden.com/insights/publications/2026/06/colorado-repeals-and-replaces-its-ai-act


Editorial Note on Sourcing and Limitations

This editorial relies on primary legal instruments, official standards-body communications, and government publications where available, supplemented by legal analyses from established firms where primary text required interpretation. Statements about the status of unpublished harmonised standards reflect public trackers of CEN-CENELEC work as of mid-2026 and may have changed. The Colorado enforcement position is subject to ongoing litigation and should not be relied on as legal advice. Forward-looking statements about standards availability, framework revisions, and US federal preemption are identified as forecasts rather than established facts. This article expresses the editorial view of OneWise and does not constitute legal, financial, or compliance advice.

One Tech & AI · Tuesday, August 4, 2026 · 24 min read

Expert Perspectives – Read thoughtful opinions and editorial insights from industry experts on emerging technologies, innovation, and digital transformation.

Critical Analysis – Explore in-depth commentary that examines trends, challenges, opportunities, and the broader impact of technology on society and business.

Informed Discussions – Stay engaged with balanced viewpoints, evidence-based arguments, and expert recommendations that encourage informed decision-making.

The 2026 reset will be remembered by some as the year AI regulation lost its nerve. That reading does not survive contact with the text. The European Union added a prohibition, expanded the AI Office's supervisory role, kept transparency obligations on schedule, and moved a set of deadlines that its own standards infrastructure could not support. Colorado narrowed its statute but did not abandon the premise that automated consequential decisions require disclosure. The direction of regulatory travel has changed pace, not destination.

What the reset genuinely exposed is how much AI governance was being performed rather than practised. A programme that collapses when a date moves was never managing risk; it was managing a deadline. The uncertainty is real and will persist — harmonised standards remain unpublished, the US federal-state question is unresolved, and the AI RMF revision has no announced date. Any claim to know how this settles by 2028 is a forecast, not a finding.

But uncertainty about the rules is not uncertainty about the exposure. A hiring model that discriminates, a credit system that cannot explain a refusal, or an agent that acts without a log will damage an organisation on whatever schedule the law happens to be keeping. The firms that come out of this period well will be the ones that stopped asking when they have to comply and started asking whether they could demonstrate, today, that their systems do what they claim. That question has never had a deadline.

TOPIC

Opinion
AI Governance After the EU AI Act Delay: Why Compliance Dates Are Not a Strategy | NewsDesk | NewsDesk