On 29 June 2026 the EU Council gave its final green light to the Digital Omnibus on AI: the EU AI Act (Regulation EU 2024/1689) obligations for high-risk systems, originally due on 2 August 2026, slip to 2 December 2027 — and to 2 August 2028 for systems embedded in products. In many companies the file was shelved with a sigh of relief: “let’s talk about it in 2027”. That is the wrong reading. The obligation to keep AI-dependent processes resilient does not come only from the AI Act — and the NIS2 and DORA timelines have not moved by a single day.
What was actually postponed (and what was not)
The delay covers only the obligations for high-risk systems — those in Annex III (including HR analytics and candidate screening, biometrics, credit scoring, management of critical infrastructure) and the Article 15 requirements on accuracy, robustness and cybersecurity. Everything else follows the original calendar, and one obligation was even brought forward:
| AI Act obligation | Date | Status |
|---|---|---|
| Ban on unacceptable practices, AI literacy obligation | 2 February 2025 | Already in force |
| Obligations for general-purpose AI models (GPAI) | 2 August 2025 | Already in force |
| Transparency for AI-generated content | 2 December 2026 | Brought forward: grace period cut from 6 to 3 months |
| Ban on non-consensual sexual deepfakes and AI-generated CSAM | December 2026 | New ban introduced by the Omnibus |
| Standalone high-risk systems (Annex III), incl. Art. 15 | 2 December 2027 | Postponed (was 2 August 2026) |
| High-risk systems embedded in products (Annex I) | 2 August 2028 | Postponed |
Note the transparency detail: anyone generating or manipulating content with AI — published texts, images, audio — will have to make it recognisable earlier than originally planned. The delay is not a blanket amnesty: it is a redistribution of deadlines. For the full picture of the obligations, see our dedicated AI Act page.
The calendar that did not move: NIS2 and DORA
Here is the point most readings of the delay miss: business continuity for AI systems is not an AI Act invention. The NIS2 Directive (Article 21(2)(c), transposed in Italy by Article 24 of Legislative Decree 138/2024) requires essential and important entities to ensure “business continuity, such as backup management and disaster recovery, and crisis management” — and the security measures become mandatory from October 2026, three months from now, not in 2027. The law does not distinguish between traditional software and AI systems: if a critical process depends on an artificial intelligence tool, the continuity plan must cover that too.
For the financial sector this is already the present: DORA (Regulation EU 2022/2554) has applied since 17 January 2025 and requires ICT business continuity policies (Article 11), backup and restoration (Article 12) and digital operational resilience testing (Articles 24-26) — covering third-party ICT services, a category cloud AI services fall squarely into. Anyone supplying banks, insurers or intermediaries is already seeing these questions in vendor questionnaires.
The uncomfortable summary: for a NIS2 entity using AI in a critical process, the AI Act delay changes little or nothing. The obligation to make sure that process survives an AI system failure already exists — and the real deadline is October 2026.
The CrowdStrike lesson, two years on
Exactly two years ago, on 19 July 2024, a faulty update to the CrowdStrike Falcon sensor crashed around 8.5 million Windows devices within hours: grounded flights, hospitals in emergency mode, banks at a standstill. The lesson was not about CrowdStrike: it was that entire business processes depended on a single software component from a single vendor, and no continuity plan had accounted for it.
With AI the same dependency is more insidious, because it often appears in no inventory: the quoting tool that “works with AI” inside the ERP, the document workflow that runs through a cloud model, the assistant the sales team uses for offers. And AI systems have their own ways of stopping: a vendor changing model or pricing, degrading answer quality, and even a regulatory block — in June 2026 the US government suspended the export of one of the most advanced AI models on the market for almost three weeks, and whoever had it in production without an alternative could only watch. A continuity plan that assumes “the AI service is always there” is not a plan: it is a hope.
What to do now: four concrete moves
The time gained from the delay is only worth something if it gets used. Four actions, in order:
- 1Inventory of AI dependencies — which processes rely on AI systems, including those hidden inside third-party SaaS and business applications. If your ERP vendor added “AI features” in the latest update, that is a new dependency that did not exist yesterday.
- 2Documented manual fallback — for every critical process using AI, a written procedure describing how to work without it: who does what, with which tools, and for how long it is sustainable. It is the minimum requirement NIS2, DORA and the AI Act all converge on.
- 3RTO and RPO for AI systems too — bring AI dependencies into the existing disaster recovery plan with defined recovery targets and periodic tests — a plan that has never been tested is documentation, not protection.
- 4Annex III operators should use the delay well — HR analytics, candidate screening, credit scoring, biometrics: the Article 15 documentation (robustness, redundancy, fail-safe plans) now has a 2 December 2027 deadline. Eighteen months well spent are worth more than a last-quarter sprint.
The frameworks for this already exist: ISO/IEC 27001 for information security and ISO 22301 for business continuity. Organisations that have implemented them — we are certified to ISO/IEC 27001, 27017, 27018 and ISO 9001 — extend the scope to AI systems; those that have not have one more reason to start from backup and disaster recovery, the foundation of every continuity plan.
Sources
- Council of the European Union — press release “Artificial intelligence: Council gives final green light to simplify and streamline rules”, 29 June 2026
- Regulation (EU) 2024/1689 (AI Act) — Articles 6, 15, 26 and Annex III
- Directive (EU) 2022/2555 (NIS2), Article 21 — transposed in Italy by Legislative Decree 138/2024, Article 24
- Regulation (EU) 2022/2554 (DORA) — Articles 11, 12, 24-26
- Vincenzo Calabrò — “Business Continuity e Disaster Recovery nell’era dell’Artificial Intelligence”, 12 July 2026
- Microsoft — estimate of Windows devices affected by the CrowdStrike outage, July 2024
Related
Frequently asked questions
Answers to the most common questions about the AI Act delay and the obligations that remain.
No. The Digital Omnibus approved by the EU Council on 29 June 2026 only postpones the obligations for high-risk AI systems: to 2 December 2027 for standalone systems (Annex III) and to 2 August 2028 for those embedded in products. The bans on unacceptable practices and the AI literacy obligation (since February 2025) and the obligations for general-purpose AI models (since August 2025) remain in force. Transparency obligations for AI-generated content actually arrive earlier than planned: the grace period was cut from six to three months, with the deadline now 2 December 2026.
Standalone high-risk AI systems (Annex III): 2 December 2027. High-risk AI systems embedded in products: 2 August 2028. National regulatory sandboxes: 2 August 2027. Transparency for AI-generated content: 2 December 2026. The ban on non-consensual sexual deepfakes and AI-generated child sexual abuse material takes effect in December 2026.
Because continuity obligations do not come only from the AI Act. The NIS2 Directive (Article 21(2)(c), transposed in Italy by Article 24 of Legislative Decree 138/2024) requires essential and important entities to maintain business continuity plans, backup management and disaster recovery — with security measures becoming mandatory from October 2026. DORA has already applied since January 2025 for financial entities. If a critical process depends on an AI system, the continuity plan must cover it: the law does not distinguish between traditional software and AI.
Using a general-purpose AI assistant does not make a company an operator of high-risk systems. But it does create an operational dependency: if the tool stops — because of a vendor outage, a network issue or even a regulatory block, as happened in June 2026 with the temporary export suspension of a frontier AI model — the processes that rely on it stop too. The question to ask is not “are we AI Act compliant?” but “what do we do if this tool does not respond tomorrow morning?”. Every critical process needs a documented manual procedure.
With the same tools used for the rest of IT: an inventory of processes that depend on AI systems (including those embedded in third-party SaaS), RTO and RPO targets for each, a documented and tested manual fallback procedure, and periodic recovery tests. The ISO/IEC 27001 (information security) and ISO 22301 (business continuity) frameworks provide the structure: organisations that have already implemented them only need to extend the scope to AI systems, not start from scratch.