Ultreia Strategic Management
A read of the Digital Omnibus calendar for leaders in Europe and across the Americas.
In July 2026 a headline landed that many leaders read as relief: the EU is delaying part of its AI law. The headline is accurate. But it is easy to read the delay as more time than it actually gives, and that is worth looking at closely.
The calendar did change. Not for everything, and not the same way for an organization operating in Europe as for one operating in the Americas. This piece separates what moved from what did not, and what that means depending on where your organization sits.
The EU AI Act entered into force in 2024, and its obligations activate in phases. The heaviest phase, covering high-risk systems, was set for August 2, 2026.
By late 2025, implementation was behind: technical standards and national authorities were not ready. To address that, the European Commission proposed the Digital Omnibus on AI, a package adjusting some of the deadlines. The European Parliament endorsed it on June 16, 2026, and the Council of the EU gave final approval on June 29. Publication in the Official Journal of the EU is still pending, expected within weeks.
One detail worth keeping in mind: until that publication happens, August 2, 2026 remains the legally binding date. The extension is a closed agreement, but not yet law.
The delay is real, but partial. High-risk obligations for standalone systems move from August 2, 2026 to December 2, 2027. Those for AI embedded in regulated products move to August 2028. That is where most of the relief sits.
The delay is real, but partial.
Other pieces barely moved. Transparency obligations, the ones that apply to chatbots and AI-generated content, still activate on August 2, 2026. Systems already on the market before that date get a short grace period until December 2026; new ones comply immediately.
The delay is in high-risk. The active obligations stayed.
What moved
High-risk standalone systemsAug 2, 2026 → Dec 2, 2027
AI in regulated productsAug 2, 2026 → Aug 2028
What stayed
Prohibited practicesIn force since Feb 2025
General-purpose modelsIn force since Aug 2025
Transparency obligationsAug 2, 2026 (unchanged)
And some things did not move at all. Prohibited practices have been in force since February 2025. General-purpose model obligations, since August 2025. The Omnibus even added a new prohibition: from December 2026, AI that generates non-consensual intimate content or child abuse material is banned. The fines did not change either: up to 35 million euros or 7% of global turnover for prohibited practices.
There is a nuance in the new dates worth understanding. December 2027 and August 2028 work as ceilings, not fixed dates. The approved mechanism lets the Commission activate the obligations sooner, once technical standards are ready, with a six-month transition. The real deadline may arrive somewhat earlier than the ceiling suggests.
For an organization in Europe, most of this is already part of the internal conversation. The useful point here is one of nuance: the delay applies to part of the obligations, not all, and the new dates are ceilings that can move up. A plan that assumes "everything moved to 2027" is likely leaving out transparency and the obligations already in force.
For an organization in Mexico City, San Juan, Bogotá, or Miami, the point is different. The regulation does not depend on where the company is headquartered, but on where its systems' outputs have an effect. We covered this in The EU AI Act and the Americas. If an organization sells to European clients, processes European data, or supports operations connected to European entities, the exposure exists with or without the delay.
There is a stretch where the two realities connect. Many European organizations rely on service centers, analytics teams, or partners in the Americas that use AI in work tied to European operations. In those cases the exposure travels along the chain and does not stop at the EU border. It is a point that tends to fall off the radar on both sides.
The exposure travels along the chain and does not stop at the EU border.
With the calendar sorted out, three things tend to bring clarity quickly.
Three moves to sort your exposure across the corridor.
One is a system inventory with each system's classification and date. Since not everything moved to the same deadline, knowing which system falls under which date avoids both unnecessary rush and late surprise.
Another is identifying which obligations are already live today, especially transparency, prohibited practices, and general-purpose models. Those apply regardless of the delay.
The third, for organizations operating on both sides of the corridor, is mapping the full exposure, including the chain outside the EU, not just headquarters. That map usually reveals more than the internal team assumes, because it cuts across regulation, commercial strategy, and operations.
I work between Europe and the Americas, and regulatory changes like this one almost always read differently depending on which side of the corridor you view them from. What looks settled on one side looks foreign on the other, and the reality often sits in the middle.
If your organization operates on both sides and you want a clear read on what applies to you and when, that is exactly the kind of conversation I have with my clients. If it helps, I am here.
Tamary Diaz Otero is the Founder and Principal Advisor at Ultreia Strategic Management. She works with CEOs and senior leaders navigating international strategy, cross-border growth, and complex organizational decisions across Spain, the United States, Latin America, and the Caribbean. She is based between Puerto Rico and Spain.
If this raised questions relevant to your organization, she would like to hear from you.
Seguimos.