Insights

AI Act delayed.
Resilience is not.

·AI ActNIS2DORABusiness ContinuityCompliance
AI Act high-risk (standalone)2 December 2027
AI Act high-risk (in products)2 August 2028
NIS2 security measures17 October 2026
CrowdStrike outage 20248.5M devices

On 29 June 2026 the EU Council gave its final green light to the Digital Omnibus on AI: the EU AI Act (Regulation EU 2024/1689) obligations for high-risk systems, originally due on 2 August 2026, slip to 2 December 2027 — and to 2 August 2028 for systems embedded in products. In many companies the file was shelved with a sigh of relief: “let’s talk about it in 2027”. That is the wrong reading. The obligation to keep AI-dependent processes resilient does not come only from the AI Act — and the NIS2 and DORA timelines have not moved by a single day.

What was actually postponed (and what was not)

The delay covers only the obligations for high-risk systems — those in Annex III (including HR analytics and candidate screening, biometrics, credit scoring, management of critical infrastructure) and the Article 15 requirements on accuracy, robustness and cybersecurity. Everything else follows the original calendar, and one obligation was even brought forward:

AI Act obligationDateStatus
Ban on unacceptable practices, AI literacy obligation2 February 2025Already in force
Obligations for general-purpose AI models (GPAI)2 August 2025Already in force
Transparency for AI-generated content2 December 2026Brought forward: grace period cut from 6 to 3 months
Ban on non-consensual sexual deepfakes and AI-generated CSAMDecember 2026New ban introduced by the Omnibus
Standalone high-risk systems (Annex III), incl. Art. 152 December 2027Postponed (was 2 August 2026)
High-risk systems embedded in products (Annex I)2 August 2028Postponed

Note the transparency detail: anyone generating or manipulating content with AI — published texts, images, audio — will have to make it recognisable earlier than originally planned. The delay is not a blanket amnesty: it is a redistribution of deadlines. For the full picture of the obligations, see our dedicated AI Act page.

The calendar that did not move: NIS2 and DORA

Here is the point most readings of the delay miss: business continuity for AI systems is not an AI Act invention. The NIS2 Directive (Article 21(2)(c), transposed in Italy by Article 24 of Legislative Decree 138/2024) requires essential and important entities to ensure “business continuity, such as backup management and disaster recovery, and crisis management” — and the security measures become mandatory from October 2026, three months from now, not in 2027. The law does not distinguish between traditional software and AI systems: if a critical process depends on an artificial intelligence tool, the continuity plan must cover that too.

For the financial sector this is already the present: DORA (Regulation EU 2022/2554) has applied since 17 January 2025 and requires ICT business continuity policies (Article 11), backup and restoration (Article 12) and digital operational resilience testing (Articles 24-26) — covering third-party ICT services, a category cloud AI services fall squarely into. Anyone supplying banks, insurers or intermediaries is already seeing these questions in vendor questionnaires.

The uncomfortable summary: for a NIS2 entity using AI in a critical process, the AI Act delay changes little or nothing. The obligation to make sure that process survives an AI system failure already exists — and the real deadline is October 2026.

The CrowdStrike lesson, two years on

Exactly two years ago, on 19 July 2024, a faulty update to the CrowdStrike Falcon sensor crashed around 8.5 million Windows devices within hours: grounded flights, hospitals in emergency mode, banks at a standstill. The lesson was not about CrowdStrike: it was that entire business processes depended on a single software component from a single vendor, and no continuity plan had accounted for it.

With AI the same dependency is more insidious, because it often appears in no inventory: the quoting tool that “works with AI” inside the ERP, the document workflow that runs through a cloud model, the assistant the sales team uses for offers. And AI systems have their own ways of stopping: a vendor changing model or pricing, degrading answer quality, and even a regulatory block — in June 2026 the US government suspended the export of one of the most advanced AI models on the market for almost three weeks, and whoever had it in production without an alternative could only watch. A continuity plan that assumes “the AI service is always there” is not a plan: it is a hope.

What to do now: four concrete moves

The time gained from the delay is only worth something if it gets used. Four actions, in order:

  • 1Inventory of AI dependencies — which processes rely on AI systems, including those hidden inside third-party SaaS and business applications. If your ERP vendor added “AI features” in the latest update, that is a new dependency that did not exist yesterday.
  • 2Documented manual fallback — for every critical process using AI, a written procedure describing how to work without it: who does what, with which tools, and for how long it is sustainable. It is the minimum requirement NIS2, DORA and the AI Act all converge on.
  • 3RTO and RPO for AI systems too — bring AI dependencies into the existing disaster recovery plan with defined recovery targets and periodic tests — a plan that has never been tested is documentation, not protection.
  • 4Annex III operators should use the delay well — HR analytics, candidate screening, credit scoring, biometrics: the Article 15 documentation (robustness, redundancy, fail-safe plans) now has a 2 December 2027 deadline. Eighteen months well spent are worth more than a last-quarter sprint.

The frameworks for this already exist: ISO/IEC 27001 for information security and ISO 22301 for business continuity. Organisations that have implemented them — we are certified to ISO/IEC 27001, 27017, 27018 and ISO 9001 — extend the scope to AI systems; those that have not have one more reason to start from backup and disaster recovery, the foundation of every continuity plan.

Sources

  • Council of the European Union — press release “Artificial intelligence: Council gives final green light to simplify and streamline rules”, 29 June 2026
  • Regulation (EU) 2024/1689 (AI Act) — Articles 6, 15, 26 and Annex III
  • Directive (EU) 2022/2555 (NIS2), Article 21 — transposed in Italy by Legislative Decree 138/2024, Article 24
  • Regulation (EU) 2022/2554 (DORA) — Articles 11, 12, 24-26
  • Vincenzo Calabrò — “Business Continuity e Disaster Recovery nell’era dell’Artificial Intelligence”, 12 July 2026
  • Microsoft — estimate of Windows devices affected by the CrowdStrike outage, July 2024

Frequently asked questions

Answers to the most common questions about the AI Act delay and the obligations that remain.

Do your processes hold up if the AI stops?

We start from the dependency inventory — AI systems included — and build a continuity plan with defined RTO and RPO, documented fallbacks and real tests. Before October 2026, not after.