On 29 June, the Council gave its final green light to the digital omnibus on AI. The high-risk obligations of the AI Act now arrive later: December 2027 for Annex III systems, August 2028 for Annex I. The dates are fixed; the earlier idea of tying them to the availability of standards was dropped.
The market read this as relief. I think that reading is wrong, and expensively so.
What was actually postponed
A specific set of documentation, conformity and quality-management duties for a specific class of systems. That is all. It is a real easing for providers staring at Annex III timelines, and I will not pretend otherwise, two extra years of runway matter when the standards are not ready.
But look at what did not move. Transparency obligations and the Commission's enforcement powers over general-purpose AI models go live on 2 August 2026 (the details are here). The GDPR never paused; every consequential automated decision about a person still runs through Article 22 and the transparency and legal-basis machinery around it. NIS2 supervision in Hungary has entered its uncomfortable phase. DORA's first critical-provider examinations are running this year. And the liability layer is arriving on schedule: the revised Product Liability Directive treats software, expressly including AI, as a product, with national transposition due by December 2026. Hungary has already legislated for it.
Rules can be delayed. Accountability cannot. When an AI system injures someone's interests, rejects them, misprices them, leaks their data, signs something it should not have signed, a court, a regulator or a counterparty will ask who answers for it. None of them will wait for 2027.
Agents act. Agents fail.
This is no longer a thought experiment. The pattern of the last twelve months is delegation growing faster than oversight.
Measurement first. Anthropic's Economic Index, one of the few public datasets on actual AI use, shows "directive" use, where a task is handed over rather than worked on together, rising from 27% to 39% of usage in roughly eight months. Companies did not become better at supervising machine work in that time. They became more comfortable not supervising it.
Now the failure inventory. In the Workday litigation, a US federal court allowed a collective action over algorithmic screening to move forward in June, the claim concerns recruitment tools through which, over the relevant period, over a billion applications are said to have been rejected. An internal AI tool at a major tech company reportedly "resolved" a live production issue without approval and caused a thirteen-hour outage. In one industry survey, the great majority of companies running agents reported at least one agent-related security incident within a year. California has legislated to cut off the obvious defence: "the AI did it autonomously" no longer works there.
Each of these has its own facts, and some of the reported numbers deserve caution. The direction does not. The question of 2026 is not what AI can do. It is who answers for what it does.
The rulebook, re-read
Here is the reframe I keep offering boards, and the reason this journal exists.
Europe's digital rulebook, GDPR, AI Act, NIS2, DORA, DSA, is usually experienced as five compliance programs: five gap assessments, five policy folders, five steering committees, five external counsel workstreams. Run that way, it deserves its reputation: slow, expensive, demoralising.
Read together, the same rulebook is something else: the accountability infrastructure of the agent economy. Strip the regime labels and every one of these laws asks the same five questions. Who decided the system may run? On what data, and under whose rights? Who watches it while it runs? What happens when it fails? Who answers, with evidence, afterwards?
A company that can answer those five questions once, in its ownership model, its vendor contracts, its logging and its incident playbooks, has, in substance, answered GDPR accountability, AI Act governance, NIS2 management responsibility and DORA operational resilience at the same time. A company that answers them five times, in five programs, pays roughly five times for one capability and still cannot produce a straight answer when an agent does something expensive.
What the winners are building
Concretely, from matters I see, the companies handling this well share four habits. They put one named owner over AI, data and cyber risk together, close to the board, instead of splitting it across a DPO silo, a CISO silo and an innovation team. They buy accountability in their vendor chain: audit rights, incident duties, model-change notice and exit terms in AI and cloud contracts, negotiated before dependence sets in. They log decisions, not just documents, approval trails and monitoring records that show who allowed what, when. And they rehearse failure: not whether an agent will misfire, but who pulls it, who tells the regulator, who faces the counterparty.
None of this requires waiting for a harmonised standard. All of it is testable today, by courts applying product liability, by authorities applying the GDPR and NIS2, by counterparties reading your contracts, and by claimants' lawyers, who have discovered AI faster than most defendants.
The gap moved
The omnibus did not close the accountability gap. It moved the gap, away from the conformity paperwork of 2027 and into the operational present: the agent already running in your sales stack, the screening tool already scoring your applicants, the vendor contract already signed without an AI clause.
The next twenty-four months will sort companies into two groups: those that treated the delay as permission to stop thinking, and those that used it to build the one layer that every regime, court and counterparty will eventually test. The second group will ship faster. That is the quiet irony of digital regulation done properly, the accountability layer is not the brake. It is what lets you delegate to machines and survive being wrong.
Status notes, 9 July 2026: the omnibus has been adopted by Parliament and Council; publication in the Official Journal was expected in July, check before citing the final dates. The Workday figures come from press reporting of the June procedural decision, and the agent-incident survey figure from industry research; both are indicative rather than audited. Nothing here is advice on any specific system or dispute.
